Microsoft Identity History and Timeline - Active Directory, AD FS, Microsoft Entra ID, and the Bridge Between Them

First Published:
Last Updated:

A handover diagram shows a single box labeled "Microsoft Entra ID". The description indicates that it has already transitioned to Entra ID. However, inside the company, domain controllers are still running, and no one knows whether it's safe to shut them down. This discrepancy is not due to a lack of understanding on the part of the individuals involved.

This article presents a timeline of Microsoft's directory and identity products. It does not focus on introducing features. Instead, it aims to demonstrate, using dates from Microsoft's official documentation, when the lineage of on-premises directories and cloud-based identity services diverged, and how they continue to operate in parallel.

Two Microsoft Identity Lineages and the Bridge Between Them
Two Microsoft Identity Lineages and the Bridge Between Them
There's one crucial point to understand when examining this lineage. In 2023, it was Azure Active Directory that was renamed, not the on-premises Active Directory. Microsoft itself publishes a table listing the names that are not subject to the renaming. This table includes Windows Server Active Directory, Active Directory Domain Services, and Active Directory Federation Services. The addition of a new layer does not mean that the underlying layer has been eliminated.

This article does not evaluate the merits of any particular product. It avoids comparisons with other identity services, and it does not offer advice on which options to choose or which to migrate to. It also does not discuss pricing or billing. Furthermore, it refrains from making any judgments about Microsoft's business decisions. The focus is solely on documenting what each document stated on a particular date, and what state each product is currently in. It also avoids speculating on reasons when official documentation does not provide them.

All information presented in this article was verified as of September 11, 2026.

Related articles on hidekazu-konishi.com:

Background and Method of Creating the Microsoft Identity Timeline

The Three Things That Are All Called Active Directory

The biggest potential source of confusion in this article is that the term "Active Directory" refers to three distinct entities, depending on the context. Before proceeding, it's important to differentiate between these three.

Term Used in This ArticleDescriptionWhere It Operates
Active Directory Domain Services (AD DS)A directory service, functioning as a server role within Windows Server. It handles domain joining, Kerberos, LDAP, and Group Policy.Servers that you manage yourself. This can be on-premises servers or virtual machines in the cloud.
Microsoft Entra IDA cloud-based identity service. This is the same product that was previously known as Azure Active Directory until 2023.A service managed by Microsoft.
Microsoft Entra Domain ServicesA managed domain service. This was previously known as Azure Active Directory Domain Services until 2023.A managed domain within Azure.

⛔ Only the two lower entries in this list have been renamed. The top entry, AD DS, has not been renamed. Microsoft's renaming guidance provides a table listing names that are not subject to renaming, and AD DS appears in the first row of that table.

Windows Server Active Directory, commonly known as Active Directory, and related features and
services associated with Active Directory aren't branded with Microsoft Entra.

⚠ This article avoids using abbreviated terms without qualification. It uses AD DS, Microsoft Entra ID, and Microsoft Entra Domain Services in their full forms. In the historical rows of the timeline, the official name used at that specific point in time is retained. For example, rows from 2013 will remain as "Windows Azure Active Directory" and have not been updated to the current names. This is because the renaming process itself is the central theme of this article, and changing the names would obscure that theme.

⚠ The terminology used throughout this article adheres to Microsoft's official documentation. The server role for federation is AD FS, not ADFS. As mentioned in the renaming guidance table above, it is officially referred to as Active Directory Federation Services (AD FS). Within direct quotations, the original terminology of the source material is retained.

References: New name for Azure Active Directory / Active Directory Domain Services overview / Overview of Microsoft Entra Domain Services

The Lineage Column

Each row in the timeline includes a column that indicates which lineage it describes. The values are three in number:

  • On-premises — This lineage describes directory services that you manage yourself, including Windows Server releases and the server roles within them.
  • Cloud — This lineage describes identity services managed by Microsoft.
  • BridgeThis lineage represents the synchronization processes that connect the two. It refers to the tools used to replicate on-premises directory content to cloud-based identity services.

⛔ There is a specific reason for the third column. The rows in this column begin in 2014 and continue up to just before the verification date. The most concrete evidence that both lineages are still active is the continued existence of these "bridges." Bridges only exist when both sides are present.

⚠ However, the intervals between rows are not consistent. There are no rows in this column between 2015 and 2021. ⛔ This does not mean the product did not exist. It simply means that no events within that period met the criteria this article uses for inclusion. The product's status itself will be detailed later, in a list reflecting its state as of the verification date.

The Type Column

The type of date is also a column. This is to keep one word from covering a product shipment, a name change, and the end of sales all at once. The values used are as follows:

  • Release — Indicates a product or version has been shipped.
  • GA — Represents a row where the product has officially reached general availability.
  • Preview — Indicates the start of a preview release.
  • Renamed — Represents a row where the product name has changed.
  • Announcement — Represents the announcement itself. Announcement dates and effective dates are handled separately.
  • Policy — Indicates a row where support period guidelines have been established.
  • Plan for change — Represents a row where future changes have been announced. This refers to announcements, not actual implementations.
  • End of sale — Indicates the point at which new purchases are no longer available.
  • Retired — Represents a row where both product availability and support have ended.
  • Deprecated — Indicates a row where a deprecation was announced.

The Primary Sources This Article Used

Each row includes the URL for the corresponding primary source. This article used the following categories of sources:

  • Microsoft Entra documentation on learn.microsoft.com — Including renaming guidance, release and announcement lists, and individual pages related to hybrid identity. The wording at the top of each page is read verbatim.
  • Windows Server documentation on learn.microsoft.com — Including pages related to AD DS and AD FS, functional level pages, and pages detailing new features for each version.
  • Microsoft Lifecycle pages — Providing start dates for each product, as well as end dates for mainstream and extended support. The dates for each Windows Server version mentioned in this article were sourced from these pages.
  • Archive on learn.microsoft.com/previous-versions/ — Documents from the era of Windows Server 2003 R2 through 2008 R2. This archive contains information not found in current documentation.
  • Official Microsoft blogs — Including microsoft.com/security/blog and the official blog for the Microsoft Entra team.

⛔ Secondary media and summary articles were not treated as primary sources. This topic is subject to a large number of secondary articles, and some of these contain inaccuracies regarding dates and scope. Areas prone to such inaccuracies are named in the text.

⚠ This article does not utilize any AWS documentation. How these products function within AWS is a separate topic in itself, and relevant information has been directed to existing resources.

Why the Date Precision Differs from Row to Row

This article's timeline does not provide daily precision for every row. The reason lies in the nature of the primary sources.

  • Microsoft Lifecycle pages specify start dates to the day. The rows for each version of Windows Server are therefore daily.
  • Renaming guidance and release lists carry dates in the body. The corresponding rows are therefore daily.
  • Release and announcement lists are divided by monthly headings. For rows where dates can only be obtained from these headings, the dates are recorded to the month.
  • Notes on product lifecycle pages sometimes give only the month. Where that is the source, the date is recorded to the month. This applies to one of the rows where a product name changed.

⚠ This article does not create dates to increase precision. Even if secondary articles list daily dates, if the primary source only mentions dates to the month, this article will record the dates to the month.

A Trap in Microsoft's Own Blog Archive

⛔ The publication dates on Microsoft's older blog posts cannot be used as is.

Microsoft has moved articles previously hosted on the TechNet and Azure blogs to the Microsoft Community Hub. The publication dates embedded on the pages of these moved articles reflect the date of the move, not the original publication date.

Here is an example measured on the verification date. A post announcing the general availability of the hybrid identity synchronization tool displays a publication date of 9/8/2018. However, the event that post describes occurred in 2015. In contrast, articles originally written and published directly on the Community Hub have accurate dates; a post from April 2025 displays 4/1/2025, and a post from August 2026 displays 8/10/2026.

⇒ Therefore, this article does not treat a date displayed on a Community Hub page as evidence on its own. For events that occurred before the move, rows are only created if there is a corresponding entry on the Microsoft Lifecycle page or a documentation page describing the same information. Otherwise, no row is created, and the reason for this is explained in the next section.

What This Timeline Does Not Include

Here's what has been excluded, and the reasons why:

  • A comprehensive timeline for Azure. The launch dates of Azure's various services are already held by an existing article on this site. This article only takes over the directory and identity rows that article holds, at a finer granularity. It does not include rows for other Azure services.
  • Rows for AD FS 2.0 and 2.1. The former was a downloadable update for Windows Server 2008, while the latter was offered as a server role in Windows Server 2012. However, this article could not verify the initial release dates for these two versions using primary sources. Therefore, no rows have been created. The AD FS rows in this article are linked to specific versions of Windows Server for which Microsoft publishes dates.
  • The date when the cloud-based synchronization tool reached general availability. As mentioned in the previous section, this date could not be confirmed using primary sources. The relevant product appears in the text only as its state on the verification date.
  • The date when Conditional Access reached general availability. For the same reason, this date could not be confirmed. This feature does not have a row in the timeline and will only appear in the corresponding table in a later section. This approach is intended to allow readers to understand why this feature is included in the table but not in the timeline, without requiring them to search for the explanation.
  • Directories prior to Windows 2000. Windows NT domains represent the predecessor to the systems described here. This article begins with the version that Microsoft explicitly identifies as the origin of Active Directory in its current documentation.
  • All features for each version. Each version of Windows Server includes a large number of features. This article only includes features that impacted the relationships between the lineages.
  • Attack methods. While there is extensive documentation on attack methods targeting directories, this article does not cover that topic.

What This Article Leaves to Other Articles

This article focuses solely on the product lineage from Microsoft's perspective. Implementation details and configuration are held by existing articles on this site.

Microsoft Identity Historical Timeline (Updates from 2000)

Below is a timeline of Microsoft's directory and identity products. The rows are listed in chronological order, with links to primary sources provided for each.

Index by year:

  • 2000 - The directory ships, and claims built from its contents start leaving the organization's boundary.
  • 2008 - The single name "Active Directory" becomes a name that covers multiple server roles.
  • 2013 - The lineage of cloud-based services begins, and tools for synchronization are developed to connect the two.
  • 2015 - The synchronization tool gets its name, and the on-premises functional level stops moving.
  • 2022 - The product family is announced, and a name change progresses across three distinct dates.
  • 2024 - The on-premises side changes a design it had kept for 24 years, and the bridge starts being replaced.

2000-2008 - The Directory Ships, and Claims Start Leaving the Boundary

During this period (2000-2008), the foundational elements of what is now called AD DS were coming together. Simultaneously, mechanisms for extending beyond its boundaries were also emerging. ⚠ A key point to note is that at this stage, only a single lineage existed.

DateLineageTypeSummary
2000On-premisesReleaseActive Directory was released alongside Windows 2000. Microsoft documents this product's origin in Windows Server documentation from 2024 onwards, stating: Active Directory uses an Extensible Storage Engine (ESE) database since its introduction in Windows 2000 that uses an 8k database page size. ⇒ This means that the database design of AD DS, as of the verification date, has been continuous since this version. The page size did not change for 24 years. ⚠ This row only lists the year. The primary source documents reviewed for this article only mention the product name and do not include a specific date. ⛔ This article does not invent a date to make the precision uniform. References: What's new in Windows Server 2025
2006-03-05On-premisesReleaseWindows Server 2003 R2 was released, marking the initial delivery of Active Directory Federation Services. Microsoft Lifecycle records the start date of this version as 2006-03-05. Archived documentation from that time describes this feature as follows: Active Directory Federation Services (AD FS) is a feature in the Windows Server® 2003 R2, Windows Server 2008, and Windows Server 2008 R2 operating systems that provides Web single-sign-on (SSO) technologies ⛔ Trademark symbols are retained as they appear in the original source. The quotation has not been altered. ⇒ This marked the first time that the contents of the directory could be accessed from outside the organization's boundaries. At that time, this feature handled tokens of the Security Assertion Markup Language (SAML) 1.1 and WS-Federation types. ⛔ It was not the directory itself that was accessed from outside. Only assertions created from the directory's contents were accessible. References: Windows Server 2003 R2 - Microsoft Lifecycle / Overview of AD FS
2008-05-06On-premisesReleaseWindows Server 2008 was released, and the directory was given the name Active Directory Domain Services as a server role. The beginning of the documentation at that time stated: By using the Active Directory® Domain Services (AD DS) server role in the Windows Server® 2008 operating system, you can create a scalable, secure, and manageable infrastructure for user and resource management ⇒ From this version onwards, the name "Active Directory" became a name that encompassed multiple server roles. The federation feature was also provided as a server role in this version. ⚠ This article defines three things called Active Directory at the outset because that division starts here. References: Windows Server 2008 - Microsoft Lifecycle / Active Directory Domain Services Overview

2012-2014 - The Cloud Lineage Begins, and the First Sync Tool Appears

During this period, a second lineage began. And within less than two years, a tool was needed to connect the two. ⚠ Note the order: seventeen months after the cloud-side directory reached general availability, the connection was established.

DateLineageTypeSummary
2012-10-30On-premisesReleaseWindows Server 2012 was released. Microsoft Lifecycle records the release date as 2012-10-30. ⚠ This row is included to indicate that the lineage continues for the on-premises environment. The functional level for this version is listed in a later section. References: Windows Server 2012 - Microsoft Lifecycle
2013-04-08CloudGAWindows Azure Active Directory reached general availability. This marks the date that the cloud-based directory service began to be offered for production use. ⇒ A second lineage begins here. The product would later be renamed Microsoft Entra ID ten years after this date. ⛔ The product name in this row has been preserved in its original form. This is to prevent the renaming event from being erased from the timeline. References: Windows Azure Active Directory general availability
2013-11-25On-premisesReleaseWindows Server 2012 R2 was released. Microsoft Lifecycle records the release date as 2013-11-25. ⚠ As of the verification date, the functional level for this version is still one of the levels Microsoft documents as usable. The functional level of the 2013 release is still listed in the interoperability table. References: Windows Server 2012 R2 - Microsoft Lifecycle / Active Directory Domain Services Functional Levels
2014-09-01BridgeReleaseThe synchronization tool that connects the two lineages was released. Microsoft Lifecycle records the launch date for this product as 2014-09-01, and a note on the same page states: Initially released in September 2014, Azure AD Sync changed its name to Azure AD Connect in June 2015, starting with version 1.0.8641.0. ⇒ This row is the first row in the Bridge column. Additional rows will continue to be added to this column up to the verification date. ⛔ The need for a synchronization tool is a direct consequence of the two lineages existing separately. References: Azure Active Directory (AD) Connect - Microsoft Lifecycle

2015-2021 - The Bridge Gets Its Name, and the On-Premises Level Stops Moving

During the period from 2015 to 2021, the bridge underwent a name change and revisions. Meanwhile, measured by functional level, the on-premises side stopped moving in 2016. ⚠ Standing still and being finished are not the same thing. A later section addresses this distinction.

DateLineageTypeSummary
2015-06BridgeRenamedThe synchronization tool was renamed to Azure AD Connect. Microsoft Lifecycle notes this change, along with the version number. Azure AD Sync changed its name to Azure AD Connect in June 2015, starting with version 1.0.8641.0 ⚠ This row only specifies the month. This is because the primary source only provides information up to the month. ⇒ Therefore, the renaming this article covers is not only the one in 2023. Within this lineage, the name has changed multiple times. References: Azure Active Directory (AD) Connect - Microsoft Lifecycle
2015-09-28On-premisesReleaseMicrosoft Identity Manager 2016 was released. Microsoft Lifecycle records the release date for this version as 2015-09-28, and the end of extended support as 2029-01-10. ⇒ The lineage of self-managed identity management products is also still running at this point. This product's row will reappear in this timeline more than ten years later. References: Microsoft Identity Manager 2016 - Microsoft Lifecycle
2016-10-15On-premisesReleaseWindows Server 2016 was released, establishing a functional level for this version. Microsoft Lifecycle records the release date for this version as 2016-10-15. ⛔ This functional level remained the most recent for the next eight years. Microsoft's documentation states: Windows Server 2019 and Windows Server 2022 use Windows Server 2016 as the most recent functional level. ⚠ This row should be read in conjunction with the row for 2024. References: Windows Server 2016 - Microsoft Lifecycle / Active Directory Domain Services Functional Levels
2018-11-13On-premisesReleaseWindows Server 2019 was released. Microsoft Lifecycle records the release date for this version as 2018-11-13. ⛔ This version does not have a dedicated functional level. The statement highlighted in the previous row applies here as well. ⇒ This indicates that while the on-premises lineage continues to be shipped, it is not moving at the level of the directory functional level. References: Windows Server 2019 - Microsoft Lifecycle
2021-08-18On-premisesReleaseWindows Server 2022 was released. Microsoft Lifecycle records the release date for this version as 2021-08-18. ⛔ This version also does not have a dedicated functional level. Both versions continue to use the functional level of the previous version as the most recent. References: Windows Server 2022 - Microsoft Lifecycle
2021-09-30BridgeReleaseSupport for the 2.x series of the synchronization tool began. Microsoft Lifecycle records the start date for this series as 2021-09-30. ⚠ This row matters because the end of the older series was settled at the same time. The next row provides further details. References: Azure Active Directory (AD) Connect - Microsoft Lifecycle

2022-2023 - The Product Family Is Announced, and the Rename Arrives in Three Dates

During this period, the changes involved were not about the product itself, but about its name and packaging. And the renaming, which is the central focus of this article, occurs here. ⚠ The renaming is not happening on a single date; it is happening on three separate dates.

DateLineageTypeSummary
2022-05-31CloudAnnouncementMicrosoft announced a new product family called Entra. The announcement stated, Microsoft Entra is our new product family that encompasses all of Microsoft's identity and access capabilities. It further described the composition at the time. The Entra family includes Microsoft Azure Active Directory (Azure AD), as well as two new product categories: Cloud Infrastructure Entitlement Management (CIEM) and decentralized identity. ⇒ At this point, the cloud directory remained named Azure AD, becoming a part of the family. The product name would not change for another year. ⚠ One of the two new categories mentioned here will be phased out in 2025. References: Secure access for a connected world - meet Microsoft Entra
2022-08-31BridgeRetiredAll versions 1.x of the synchronization tool were retired. The Microsoft Lifecycle page stated, On August 31, 2022, all 1.x versions of Azure Active Directory (Azure AD) Connect will be retired because they include SQL Server 2012 components that will no longer be supported. A page listing versions stated that, All Microsoft Entra Connect Sync 1.x versions are unsupported and synchronization doesn't function. ⛔ The "bridge" itself was not removed. Only the older versions of the bridge were retired. ⇒ The same page also stated that operation continued for the 2.x versions and subsequent tools. References: Azure Active Directory (AD) Connect - Microsoft Lifecycle / Microsoft Entra Connect: Version release history
2023-03-15BridgePolicyA policy was established defining the support period for each version of the synchronization tool. The version listing page stated, Versions of Microsoft Entra Connect Sync 2.x retire 12 months from the date that a newer version is released. This policy went into effect on 15 March 2023. ⇒ The "bridge" remained in place, but the planks were regularly replaced. ⚠ This was not a policy signaling the end of the product; rather, it was a policy based on the assumption that the product would continue to be updated. References: Microsoft Entra Connect: Version release history
2023-07-11CloudAnnouncementMicrosoft publicly announced the renaming of Azure Active Directory to Microsoft Entra ID. The renaming guidance stated, The name changes were publicly announced on July 11, 2023. The same page also explained the reason for the change, stating, Microsoft renamed Azure Active Directory (Azure AD) to Microsoft Entra ID to communicate the multicloud, multiplatform functionality of the products, alleviate confusion with Windows Server Active Directory, and unify the Microsoft Entra product family. ⛔ Pay particular attention to the second reason. Reducing confusion with the on-premises Active Directory was explicitly stated as a purpose of the renaming. ⇒ In other words, Microsoft changed the name to communicate to users that the two were distinct. The name was not changed because of a replacement. References: New name for Azure Active Directory / Microsoft Entra expands into security service edge and Azure AD becomes Microsoft Entra ID
2023-08-15CloudRenamedThe name change began to appear in the product interface. The renaming guidance stated, The name change across Microsoft experiences started on August 15, 2023. ⚠ The announcement date and the date when the interface began to change were different. The same page further stated that the string replacement was largely completed by the end of 2023. ⇒ If the renaming is written as a single row, this one-month gap disappears. References: New name for Azure Active Directory
2023-10-01CloudRenamedThe display name for licenses changed. The renaming guidance stated, Service plan display names changed on October 1, 2023. It also stated that only the display name had changed, adding, Licensing, pricing, and functionality aren't changing. ⇒ This is the third date related to the renaming. The announcement, the interface display, and the license display name all changed on different dates. ⚠ This article splits the renaming into three rows because that difference matters in practice. There was a period when the name appeared differently in contracts and in the management interface. References: New name for Azure Active Directory

2024-2026 - The On-Premises Side Changes a 24-Year-Old Design, and the Bridge Is Replaced

During this period (2024-2026), the on-premises infrastructure is undergoing a redesign, a change to a design that had remained unchanged since 2000. Simultaneously, the bridge is scheduled to be replaced. ⚠ These two changes are not opposing initiatives. Both are predicated on the continued operation of both redundant systems.

DateLineageTypeSummary
2024-03-30CloudDeprecatedThis date was announced as the planned deprecation date for legacy PowerShell modules used to manage cloud directories. According to the guidance, Azure AD PowerShell for Graph is planned for deprecation on March 30, 2024. ⚠ As of the verification date, this page still states the plan. This article treats this date as the date the deprecation was announced, not the date it was implemented. ⚠ This row is not subject to renaming, as indicated in the same table, which states that the names of features being deprecated will not be changed. ⇒ There are two possible reasons why the name might not be changed: either it will not be changed because it is a separate entity, or it will not be changed because it is being discontinued. ⛔ It is crucial to avoid confusing these two possibilities. References: New name for Azure Active Directory
2024-11-01On-premisesReleaseWindows Server 2025 was released, introducing the first directory functional level update since 2016. Microsoft Lifecycle records November 1, 2024, as the release date. The new features page states the following. The new functional level is used for general supportability and is required for the new 32k database page size feature. The new functional level maps to the value of DomainLevel 10 and ForestLevel 10 for unattended installations. ⛔ A change in design, dating back to the year 2000, also occurred. The same page notes that 8k page sizes were used from Windows 2000, while the transition to 32k brings changes. ⇒ The number of values that multivalued attributes can hold has increased to approximately 3,200. Microsoft describes this as an increase by a factor of 2.6 ⚠ The product being modified after 24 years of design decisions is not simply being maintained; it is actively being developed. References: Windows Server 2025 - Microsoft Lifecycle / What's new in Windows Server 2025
2025-04-01CloudEnd of saleMicrosoft Entra Permissions Management products for the Entra family are no longer available for new purchases. The official announcement states: Effective today, April 1, 2025, Microsoft Entra Permissions Management will no longer be available for purchase by new Enterprise Agreement and direct customers, and effective May 1, 2025, it will no longer be available for purchase by new CSP customers. ⇒ This marks the end of a product that was identified as one of two new categories in an announcement from 2022, after only three years. ⛔ This article does not evaluate the merits of this decision. It only records the date and what the official announcement stated. References: Important change announcement: Microsoft Entra Permissions Management end of sale and retirement
2025-05-01CloudEnd of saleLegacy products for external identities in the cloud are also no longer available for new purchases. According to the renaming guidance, Effective May 1, 2025, Azure AD B2C will no longer be available to purchase for new customers. ⚠ This product is also not subject to renaming. The same table states that the product's name will not be changed. ⇒ Once again, there are two reasons why the name might not be changed. References: New name for Azure Active Directory
2025-09-29CloudAnnouncementThe end-of-support and retirement date for Microsoft Entra Permissions Management has been extended by one month. The updated announcement states: The end of support and retirement of Microsoft Entra Permissions Management has been extended from October 1, 2025, to November 1, 2025, to create space for customers that need more time with migration. This extension is final and customers will be auto-offboarded on November 1, 2025. ⚠ Here again the announcement date and the effective date differ. This article includes separate rows for both dates for that reason. References: Important change announcement: Microsoft Entra Permissions Management end of sale and retirement
2025-11-01CloudRetiredMicrosoft Entra Permissions Management has ceased operations. As stated in the above update, users were automatically offboarded on this date. ⇒ This timeline now includes a row for a product that has actually ended. ⛔ Therefore, this article does not claim that Microsoft never ends a product. It writes that what ended has ended, and that this has not happened to the on-premises directory. References: Important change announcement: Microsoft Entra Permissions Management end of sale and retirement
2026-03BridgePreviewA feature that allows Windows devices to become Hybrid Entra joined immediately at provisioning time, without waiting for Entra Connect sync or requiring AD FS, using on-premises Kerberos, has entered preview. The list of releases and announcements states: This new capability enables a Windows device to become Hybrid Entra joined immediately at provisioning time, without waiting for Entra Connect sync or requiring AD FS. ⚠ Pay close attention to the wording of this sentence. It states that certain components are no longer required, specifically the wait time for synchronization and the need for federation servers. ⛔ It does not state that the on-premises directory itself is no longer required. This feature utilizes on-premises Kerberos. References: Microsoft Entra releases and announcements
2026-04On-premisesGAService Pack 3 for Microsoft Identity Manager 2016 has been generally released. The list of releases and announcements details the features included in this release, including support for Active Directory Federation Services (AD FS) Single Sign-On (SSO). ⇒ A product that was originally shipped in 2015 is receiving a new service pack more than 10 years later. ⛔ Notably, this new feature integrates with federation server roles, not with the cloud. ⚠ This row provides direct evidence that the on-premises lineage is still active as of the verification date. References: Microsoft Entra releases and announcements
2026-04BridgePlan for changeA plan to transition from the existing synchronization tool to a successor has been announced. The list of releases and announcements states: we're beginning the transition from Microsoft Entra Connect Sync to the cloud-native Microsoft Entra Cloud Sync - helping reduce on-premises complexity while improving security, reliability, and day-to-day manageability. The notification states: Beginning in July 2026, we will begin notifying customers through the M365 Message Center, Entra Connect Health, and targeted emails about their individual transition timelines. ⛔ This is an announcement, not an implementation. The same announcement also states that customers with insufficient functionality will not be included in the initial transition. ⇒ For this article, it is important to understand what the successor product is based on. That will be addressed in the next section. References: Microsoft Entra releases and announcements
2026-05BridgePlan for changeA change requiring additional administrator approval for configuration changes to the synchronization tool has been announced. This is listed as Upcoming change - Enhanced admin authorization for Microsoft Entra Connect Sync configuration changes in the list of releases and announcements. ⚠ A change to enhance the security of the existing product is announced in the month following the announcement of the transition. ⇒ The announced transition is not a plan to immediately discontinue the existing product. References: Microsoft Entra releases and announcements
2026-06BridgePreviewA feature to prevent unauthorized changes to on-premises groups has entered preview. This is listed as Public Preview - Prevent unauthorized changes to AD groups with AD group enforcement in the list of releases and announcements. During the same month, an improvement related to on-premises Kerberos was also generally released. ⇒ As of three months prior to the verification date, the cloud product is adding new features to the on-premises directory. ⛔ New protection features are not being added to products targeted for replacement. References: Microsoft Entra releases and announcements

Where the Two Lineages Diverged and What Did Not Move

The Split Started Inside Windows Server, Not Between Clouds

Before the two lineages diverged, the very name "Active Directory" was already splitting internally.

The key point was May 6, 2008. What had previously been called Active Directory began, with this version, to become a collection of server roles. Active Directory Domain Services now handled the directory functions, while Active Directory Federation Services handled federation. ⇒ In other words, the moment the name "AD DS" was created, Active Directory was no longer a single product.

⚠ If you miss this fundamental point, you will not understand the renaming of 2023. The renaming does not even apply to one component within that collection. The target is a separate product on the cloud side.

What Stayed On-Premises, What Moved to the Cloud, and What Sits in Both
What Stayed On-Premises, What Moved to the Cloud, and What Sits in Both

Which Capability Ended Up on Which Side

This article sets out which capabilities reside on which side as of the verification date. ⚠ This table is this article's own arrangement, not a document Microsoft publishes. The basis for each row is provided in the verbatim quotes immediately following, and in the primary sources referenced in each row of the timeline.

FeatureLocationBasis
Domain Join, Kerberos, LDAP, Group PolicyRequires either an on-premises directory or a managed domain within Azure. Not provided by cloud-based identity services alone.Microsoft Entra Domain Services Overview
Directory Schema and ReplicationOn-premises only. Global Catalog and Replication Services are described as components of AD DS.AD DS Overview
Domain and Forest Functional LevelsOn-premises only. As of the verification date, the latest level is Windows Server 2025.Functional Levels Page
Extending Identity Claims Outside the OrganizationAvailable on both sides. Both federation server roles and cloud-based identity services can handle this.AD FS Overview and Entra ID Documentation
One Set of Credentials for On-Premises and CloudSpans both sides. Synchronization tool documentation states this purpose: Users can use a single identity to access on-premises applications and cloud services such as Microsoft 365.Synchronization Tool Documentation
Synchronizing Users and GroupsOn the bridge. Achieved through an agent deployed on-premises and a cloud-based service.Synchronization Tool Documentation
Conditional AccessCloud-only. Microsoft refers to this as a Zero Trust policy engine.Conditional Access Overview
Risk-Based Policy DecisionsCloud-only. To use sign-in and user risk as conditions, a separate product is required.Conditional Access Overview

⛔ None of the rows in this table represent features that have been removed from the on-premises environment and moved to the cloud. Only features that exist solely on the on-premises side, solely on the cloud side, or on both sides are listed. ⇒ The concept of "migration," typically understood as a movement of a feature from one side to another, does not apply here.

References: Active Directory Domain Services overview / Active Directory Domain Services Functional Levels / Microsoft Entra Conditional Access: Zero Trust Policy Engine / Active Directory Federation Services Overview

What the Cloud Side Actually Took Over

The cloud side did take over certain aspects. Specifically, it took over the authorization decision-making process.

The explanation of Conditional Access states:

Modern security extends beyond an organization's network perimeter to include user and device
identity. Organizations now use identity-driven signals as part of their access control decisions.
Microsoft Entra Conditional Access brings signals together, to make decisions, and enforce
organizational policies.

⇒ The material used in making decisions is no longer limited to what sits inside the network boundary. The same page also clearly states where this feature operates.

Conditional Access policies are enforced after first-factor authentication is completed.

⛔ In other words, this feature is not replacing authentication itself. Instead, it acts as a layer that applies additional conditions after authentication has been completed. ⇒ This feature operates on the assumption that a lower layer still exists.

⚠ This feature requires a Microsoft Entra ID P1 license. The same page also states that risk-based policies require a separate product. ⛔ While this article does not discuss pricing, it's worth noting that the functionality is tied to license tiers, and this fact is relevant to the overall design.

References: Microsoft Entra Conditional Access: Zero Trust Policy Engine

The Bridge Has Never Been Removed

The Bridge column began in 2014 and has continued to receive new rows right up until the current verification date. Even as versions have been retired, names have changed, and successors have been announced, new rows continue to be added to this column.

⚠ Look at the product's status, not the density of rows. The lifecycle page for this product, as of the verification date, lists the product's start date as 2014-09-01 and the retirement date field as In Support. ⇒ This means that, from 2014 until the current verification date, no end-of-support date has ever been set.

⛔ And most importantly, what matters is the assumption the successor product makes. The description of the successor product begins with:

Microsoft Entra Cloud Sync is a hybrid identity synchronization service that provides modern,
cloud-managed synchronization of users, groups, and contacts between Active Directory and
Microsoft Entra ID.

And then states its components as follows:

Microsoft Entra provisioning agent: A lightweight, on-premises agent that acts as a secure bridge
between Active Directory and Microsoft Entra ID.

⇒ Even the new synchronization mechanism, managed in the cloud, relies on an on-premises agent and Active Directory. The bridge has been replaced, but not the destination.

⚠ The same page positions this product within Microsoft's strategic direction. Despite this, the product's design includes accessing an on-premises directory. ⛔ This product is not designed to make the second lineage disappear.

⚠ The same applies to managed domain services. The product overview page describes the flow of information in a hybrid configuration as follows:

In hybrid environments, identity information from on-premises AD DS is synchronized to Microsoft
Entra ID, and then made available to the managed domain.

⇒ Even in configurations that utilize domain services within Azure, the information about the users is being passed from the on-premises directory across the bridge. The same page also notes that it can be used in a cloud-only tenant, ⛔ which means it does not always require an on-premises environment. However, for organizations that do have an on-premises environment, this pathway remains a fundamental requirement.

References: What is Microsoft Entra Cloud sync? / What is Microsoft Entra Connect and Connect Health / Overview of Microsoft Entra Domain Services

What the Rename Did Not Change

The Scope of the Rename, in the Primary Source's Own Words

The renaming guidance lists what remains unchanged in a table. The first row of that table is the central point of this article.

The left-hand column of that row lists the correct, unchanged names, presented as a bulleted list: Active Directory, Windows Server Active Directory, Active Directory Federation Services (AD FS), Active Directory Domain Services (AD DS), and various Active Directory features. The description in the right-hand column states:

Windows Server Active Directory, commonly known as Active Directory, and related features and
services associated with Active Directory aren't branded with Microsoft Entra.

⇒ On-premises directories and federation server roles are not subject to the renaming. Further down on the same page, the frequently asked questions provide an even more definitive statement.

We continue to support and enhance Windows Server Active Directory for on-premises identity and
access management and the connection to Azure and other clouds, as many organizations continue to
rely on this solution.

⛔ It states that Microsoft not only supports the product but also enhances it. The row dated 2024-11-01 shows that the enhancement actually happened. ⚠ Reading these two points together is the purpose of this article.

The same page also clearly outlines the scope of the renaming.

All features and capabilities are still available in the product. Licensing, terms, service-level
agreements, product certifications, support and pricing remain the same.

To make the transition seamless, all existing login URLs, APIs, PowerShell cmdlets, and Microsoft
Authentication Libraries (MSAL) stay the same, as do developer experiences and tooling.

⇒ Only the displayed name and associated icons have changed; the connection destinations and calling methods remain unchanged.

References: New name for Azure Active Directory

Two Primary Sources Count the Product Family Differently

⚠ There is one instance where the two primary sources differ. This article will not obscure that discrepancy.

The renaming guidance presents the composition of the product family in a table with three categories. As of the verification date, the table lists three products under identity and access management, two under the new identity categories, and two under network access.

In contrast, the official announcement dated 2025-04-01 counts the same product family differently.

Microsoft Entra ID, Microsoft Entra Suite (encompassing ID Protection, ID Governance, Verified ID,
Internet Access, and Private Access), Microsoft Entra External ID, Microsoft Entra Workload ID,
and more.

⛔ The two primary sources count the same product family using different units. One source categorizes products individually, while the other uses a combined unit for counting. ⇒ Therefore, this article will not present a definitive list of the Entra family's composition. Instead, it will only describe what each page stated on the verification date.

⚠ The composition of the product family is subject to change. Of the two new categories introduced in an announcement from 2022, one has already reached its end of support as of 2025. ⛔ If this article were to present a comprehensive list, that list would inevitably become outdated. Please refer to the official pages for the current status of the product family's composition.

References: New name for Azure Active Directory / Important change announcement: Microsoft Entra Permissions Management end of sale and retirement

What Microsoft Says About AD FS, and What It Does Not Say

⚠ This is the section that requires the most careful wording.

The overview page for the federation server role includes an important disclaimer at the beginning.

Instead of upgrading to the latest version of AD FS, Microsoft highly recommends migrating to
Microsoft Entra ID.

Microsoft also publishes a page compiling resources for decommissioning this server role. It includes a migration guide, a migration workshop, a migration wizard, and a Q&A section on migration.

⛔ However, as far as this article could check, Microsoft's documentation does not state either the end-of-support date or the retirement date for this server role. Neither of the two pages mentioned above, nor the list of releases and announcements as of the verification date, contain any dates.

⇒ Therefore, this article does not state that this server role has no planned end-of-life. It only states that a specific end date could not be confirmed. The absence of information is not proof of non-existence.

⚠ On the other hand, this article has confirmed two facts. First, the status monitoring feature for synchronization tools indicates that it supports this server role from Windows Server 2012 R2 through 2025. Second, a service pack for a self-managed identity management product, listed under the row for 2026-04, includes integration with this server role as a new feature. ⛔ This article does not draw any future predictions based on these two observations.

References: Active Directory Federation Services Overview / AD FS Decommission Reference / What is Microsoft Entra Connect and Connect Health

Where Each Product Stands on the Verification Date

Verification date: 2026-09-11. The status of each product is described as it appears in the primary sources.

ProductStatus as of Verification DateWhere This is Documented
Active Directory Domain Services (AD DS)Currently available as a server role in Windows Server. The functional level and the database design were updated in the version released on 2024-11-01.Windows Server documentation and the new features page for that version.
Active Directory Federation Services (AD FS)Currently available as a server role in Windows Server. Microsoft strongly recommends migration. ⛔ No end-of-life date was confirmed in this article.AD FS overview page and the documentation for decommissioning.
Microsoft Entra IDCurrently available as a cloud-based identity service. Renamed from Azure Active Directory in 2023.Renaming guidance.
Microsoft Entra Domain ServicesCurrently available as a managed domain service. Renamed from Azure Active Directory Domain Services in 2023.Glossary in the renaming guidance.
Microsoft Entra Connect SyncCurrently available. Each version in the 2.x series is retired 12 months after the release of a new version. Migration to a successor was announced for 2026.Version list page and the list of releases and announcements.
Microsoft Entra Cloud SyncCurrently available. Requires an on-premises agent and Active Directory.Overview page for this product.
Microsoft Identity Manager 2016Currently available. Service Pack 3 was generally released in 2026. Extended support ends on 2029-01-10.Microsoft Lifecycle and the list of releases and announcements.
Microsoft Entra Permissions ManagementDiscontinued on 2025-11-01.Official announcement.
Azure AD B2CNo new purchases are available from 2025-05-01.Table in the renaming guidance.

⛔ There are two rows in this table where support has ended or new purchases are no longer possible. Both of these relate to cloud-based products. As of the verification date, the on-premises lineage carries neither kind of row.

References: New name for Azure Active Directory / What's new in Windows Server 2025 / Microsoft Entra Connect: Version release history / Microsoft Identity Manager 2016 - Microsoft Lifecycle

Frequently Asked Questions about Microsoft Identity History

Did Microsoft Entra ID replace Active Directory?

No. It was Azure Active Directory that was renamed, not on-premises Active Directory. The renaming guidance lists Windows Server Active Directory, Active Directory Domain Services, and Active Directory Federation Services as names that are not subject to the change. ⚠ Furthermore, the same page states that Microsoft continues to support and enhance its on-premises product.

Why does the rename have three different dates?

The rename has three different dates because the announcement, the on-screen display, and the license name were updated on separate dates. The renaming guidance states that the public announcement was on 2023-07-11, the on-screen display changes began on 2023-08-15, and the service plan name was changed on 2023-10-01. ⛔ It's important to keep these dates separate because combining them into a single date would obscure the period when the contract and management interface displayed different names.

Is Active Directory Domain Services still being developed?

Yes. With Windows Server 2025, which was released on November 1, 2024, the directory functional level has been added for the first time since 2016. ⚠ Furthermore, it is now possible to modify the page size of the database, which has been in use since 2000. On the page detailing the new features, Microsoft puts the increase in the number of values a multivalued attribute can hold at an increase by a factor of 2.6.

Is AD FS going to be retired?

This article does not answer the question of whether AD FS will be retired with a simple "yes" or "no." ⛔ This is because no confirmed end-of-life date for this server role could be found in Microsoft's documentation. What this article could confirm is that Microsoft strongly recommends migrating to Microsoft Entra ID rather than updating to the latest version, and that they have published a page compiling resources for decommissioning. ⚠ This article does not claim that there are no plans to discontinue it. The absence of that information is not proof that it does not exist.

Do I still need a synchronization tool if I use Microsoft Entra ID?

It depends on your situation. If you maintain user information in an on-premises directory, you'll need a mechanism to replicate that information to the cloud. ⚠ In April 2026 a transition from the existing synchronization tool to its successor was announced. However, the description of the successor product also assumes an on-premises agent and Active Directory. ⇒ The change resulting from the transition is simply where you manage the synchronization configuration; it does not mean you no longer need anything on your on-premises environment.

What is the difference between Microsoft Entra ID and Microsoft Entra Domain Services?

The former is a cloud-based identity service, while the latter is a domain service provided as a managed domain within Azure. ⚠ It was also subject to a name change in 2023, previously known as Azure Active Directory Domain Services. This change is documented in the terminology guide. ⛔ Although the names are similar, it is also distinct from on-premises Active Directory Domain Services.

Which capabilities exist only on the on-premises side?

These are the directory schema, replication, and the functional level. For domain joining, Kerberos, LDAP, and Group Policy, you'll need either a self-managed directory or a managed domain within Azure. ⚠ These are not provided by cloud-based identity services alone. The comparison table in this article provides this breakdown.

Does Conditional Access replace authentication?

No. The overview page for Conditional Access states where this feature operates. Conditional Access policies are enforced after first-factor authentication is completed. ⇒ It's a layer that adds additional conditions after authentication is complete, and it assumes that the underlying authentication process is already in place. ⚠ This feature requires a Microsoft Entra ID P1 license.

Has any product in this timeline actually ended?

Yes. The permissions management product in the Entra family ended its availability on November 1, 2025, and the legacy products for external IDs are no longer available for new purchases as of May 1, 2025. ⛔ This article does not claim that Microsoft never ends a product. It records that some products have ended, and that as of the verification date the on-premises directory lineage carries no such row.

Why does this timeline not tell me whether to decommission my domain controllers?

The decision on whether to decommission your domain controllers depends on what role those directories are currently serving. This article can only cover what happened to which product on which date, and which capability sat on which side as of the verification date. ⛔ This article does not provide migration steps or criteria for making that decision.

Summary

This article presents a timeline of Microsoft's directory and identity products, covering 30 rows. The timeline begins with the release of Active Directory in 2000 and concludes with a row dated June 2026, shortly before this article's verification date.

Three key points can be made:

  1. In 2023, it was Azure Active Directory, not the on-premises Active Directory, that underwent a name change. Microsoft published a table outlining names that are not subject to the name change. ⇒ One of Microsoft's reasons for the name change was to reduce confusion between the two. It was not a replacement.

  1. Both lineages are still active. The on-premises side added a new directory functional level on November 1, 2024, marking the first such addition since 2016, and also made changes to the database design, which dates back to 2000. Meanwhile, even in 2026, the cloud side continues to add new features for on-premises directories. ⇒ If one were to stop, the other would not be a viable recipient of new features.

  1. The bridge connecting the two has never been removed. Synchronization products have existed continuously since 2014 and continue to exist despite product retirements, name changes, and announcements of successor products. ⇒ Furthermore, the successor products themselves rely on on-premises agents and Active Directory.

⇒ Even if a system is described as having migrated to Entra ID, this description does not determine whether you can decommission the domain controllers. The determining factor is which row in the table presented in this article corresponds to the functions that the directory is currently providing. ⛔ At least from the perspective of the product lineage, there is no assumption that one product will eliminate the other.

All information presented in this article was verified as of September 11, 2026. ⚠ Please note that the composition of the product families and the progress of any announced migrations are both subject to change. Always check the verification date when referencing this information.


References:
Tech Blog with curated related content

Written by Hidekazu Konishi