Turn off directory synchronization for Microsoft 365

丁 銘威 25 Reputation points
2025-05-20T02:34:17.3266667+00:00

In my current environment, local AD users, groups, and contacts are synchronized to 365 through the Azure AD connect tool.

If I want to permanently turn off directory synchronization for Microsoft 365, so that all users, groups, and contacts are cloude only, follow Microsoft's documentation

https://learn.microsoft.com/en-us/microsoft-365/enterprise/turn-off-directory-synchronization?view=o365-worldwide#turn-off-directory-synchronization

There is a description that says you must first remove Azure AD connect tool and then issue the command to turn off synchronization. But I have a question, if I remove Azure AD Connect first, will the users and groups on M365 disappear or be deleted?

Microsoft Security | Microsoft Entra | Microsoft Entra ID

Answer accepted by question author
Jinnie Nguyen 315 Reputation points
2025-05-20T09:43:12.3833333+00:00

Hello,

Thank you for your question about permanently turning off directory synchronization for Microsoft 365 and your concern about removing the Azure AD Connect tool first. I’ll guide you through the process following Microsoft’s documentation and address your concern about users and groups.

Instructions to Turn Off Directory Synchronization:

1. Uninstall Azure AD Connect (Recommended First Step):

  • On the server where Azure AD Connect is installed, go to Control Panel > Programs and Features.
  • Find Microsoft Azure AD Connect, select it, and click Uninstall.
  • Action: Follow the prompts to remove the tool completely.

2. Install Microsoft Graph PowerShell Modules:

Open PowerShell as an administrator and run:

Install-Module Microsoft.Graph -Force

Install-Module Microsoft.Graph.Beta -AllowClobber -Force

3. Connect to Microsoft Graph:

Use a Hybrid Identity Administrator account

Connect-MgGraph -scopes "Organization.ReadWrite.All,Directory.ReadWrite.All"

4. Verify Current Sync Status:

  • Run:

Get-MgOrganization | Select OnPremisesSyncEnabled

  • Confirm it shows True.

5. Disable Directory Synchronization:

  • Store the tenant ID and disable sync::

$organizationId = (Get-MgOrganization).Id

$params = @{ onPremisesSyncEnabled = $false }

Update-MgOrganization -OrganizationId $organizationId -BodyParameter $params

-Verify the change:

Get-MgOrganization | Select OnPremisesSyncEnabled

It should now show False.

Will Users and Groups Disappear After Removing Azure AD Connect?

No, removing Azure AD Connect first does not delete users, groups, or contacts in Microsoft 365. These objects remain in the cloud, but their source of authority stays tied to the on-premises AD until synchronization is disabled. Once you run the Update-MgOrganization command, all synchronized objects (users, groups, contacts) are converted to cloud-only, meaning their source of authority shifts to Microsoft Entra ID. This process preserves all objects, and they will not be deleted. Passwords remain the last synchronized value, and the ImmutableID is retained for potential future re-sync (after a 72-hour wait period).

Additional Notes:

  • Microsoft recommends uninstalling Azure AD Connect before disabling sync to avoid portal inconsistencies (e.g., Password Hash Sync showing as enabled). However, even if you disable sync first, objects are not deleted—they just stop syncing.
  • Wait up to 72 hours for the Microsoft 365 admin center to reflect the change (users will show as "In-cloud").
  • If you need to re-enable sync later, you must wait 72 hours after disabling.

If you encounter issues, open a ticket via Microsoft 365 admin center > Help & support.

Best,


If I have answered your question, please accept this as answer as a token of appreciation and don't forget to thumbs up for "Was it helpful"!

Was this answer helpful?

0 comments No comments

3 additional answers

Sort by: Most helpful
  1. Chris Mitchell 0 Reputation points
    2026-05-29T13:28:12.52+00:00

    Just to ease the troubled minds in the future. The above steps worked for me as of May 28th, 2026. Converted my tenant of ~400 objects to cloud-only (literally took five minutes from start to finish) after being Azure Sync connected since 2019 (following converting from an on-prem Exchange server).

    Only change from above is I couldn't run the PowerShell commands from a PowerShell instance run as administrator. The commands threw an error. Ran PowerShell just normally and everything worked perfectly.

    Was this answer helpful?

    0 comments No comments

  2. Michael Kane 6 Reputation points
    2026-01-07T21:37:24.5566667+00:00

    I followed these instructions today, 1/7/26. The app to uninstall was "Microsoft Entra Connect", no references to Azure. Uninstalling the program led to a screen with options to uninstall related apps, and some had to do with SQL Server and/or ODBC drivers. Uninstalling those might have unintended consequences if the domain controller is going to be kept for other uses.

    Also, when running the "Get-MgOrganization | Select OnPremisesSyncEnabled" command to verify if the other graph commands worked, the value returned is null, no words. The first time I ran that command, it returned the word "True", but afterwards just blank.

    Was this answer helpful?

    0 comments No comments

  3. Vasil Michev 128.1K Reputation points MVP Volunteer Moderator
    2025-05-20T06:48:21.43+00:00

    No, it will not result in deleting the objects, but it's also not a required step, just recommended for some scenarios. You can ignore it and disable synchronization without uninstalling the tool.

    Was this answer helpful?

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.