IT Glossary
Directory synchronization keeps identity data consistent between directories. Learn how it works and why it is not the same thing as provisioning.
August 7, 2026
Directory synchronization is the automated process that keeps identity data consistent between two or more directories, for example between an on-premises Active Directory and a cloud directory such as Microsoft Entra ID or Google Workspace. It copies users, groups, and attributes on a schedule, so a single change never has to be made twice.
The two are routinely confused. Directory synchronization copies identity data between directories, so the same person exists in both. Provisioning creates and removes accounts inside applications. Syncing Active Directory to Entra ID gives nobody a Slack account, and disabling a synced user does not close their Notion seat. Directories talk to directories, while applications need their own connection.
A company runs Entra Connect between its on-premises AD and its Microsoft 365 tenant. Identity data stays consistent and the Microsoft applications behave correctly. Everything else in the stack, roughly 90 tools, sits outside that flow entirely, each with its own user list. The team assumes a synced directory means governed access, and the first access review is where that assumption breaks. Corma connects to those applications directly, so the account picture matches the directory instead of diverging from it.
Synchronization keeps two directories aligned. SCIM is a standard protocol for creating and removing user accounts inside an application. One is directory to directory, the other directory to application.
Typically every 30 minutes for standard attributes, with password hash sync running more frequently. Real-time propagation is the exception rather than the rule.
Changes stop propagating silently. New joiners do not appear in the cloud directory and departures stay active, which is why sync health belongs on the monitoring dashboard.
No. A cloud-only organization has a single directory. Synchronization exists to bridge an on-premises directory that has not yet been retired.