Step 8 — Set Up Provisioning
1

2

3

4

5
Schedule option
When the connector runs

How to check it worked
Related
Last updated
Create the Outbound Provisioning connector — the connector that writes identities and accounts out to your Entra ID or Active Directory target. This is the core of what AOH Sync does. Unlike the Account Import and Identity Ingestion connectors (created automatically when you add a Source or Target System), you create this connector deliberately. (~5 minutes)
Open Connectors and review the categories
Navigate to Connectors in the left sidebar. The page shows three connector categories:
Identity Ingestion — auto-created when you added your Target System; reads your directory's current state.
Account Import — auto-created when you added your Source System; brings Account records into AOH Sync.
Outbound Provisioning — what you are about to create; writes identities and accounts out to your target directory.

The Connectors page after completing Steps 6 and 7. Identity Ingestion and Account Import connectors are already present. Outbound Provisioning is empty until you create one.
Click + New Connector to open the creation wizard.
Step 1 of 4 — Choose your Source System
Select the Source System this connector should read Account data from.

Choose the Source System you connected in Step 6.
Step 2 of 4 — Choose your Target System
Select the Target System this connector should provision identities into.

Choose the Target System you connected in Step 7.
Step 3 of 4 — Confirm connector details
Review and confirm the connector name and settings. The Display Name is auto-filled based on your source and target selection.
The identity mode is set automatically from the target you chose. The identity-matching key is configured per attribute in the mapping editor after the connector is created.
If you selected an Active Directory target, you can optionally set a Target OU Distinguished Name to control which organisational unit provisioned accounts land in.

The Display Name is auto-filled. For Active Directory targets, set the Target OU Distinguished Name if you want provisioned accounts in a specific OU.
Step 4 of 4 — Set a schedule and create
Optionally choose a Sync Schedule from the preset options, then review the summary and click Create Connector.
Every 15 min
Continuously throughout the day
Every hour
Once per hour
Daily 9 AM UTC
Once per day at 9 AM UTC
Weekdays 8 AM UTC
Monday through Friday at 8 AM UTC
On-demand only
Only when you trigger a manual run

Choose a schedule, review the summary, and click Create Connector. You can change the schedule at any time from the connector's Schedule tab.
The new connector appears under Outbound Provisioning on the Connectors page.
Last updated