Skip to content
arrow_back
search
ISM-1950 policy ASD Information Security Manual (ISM)

Disable Soft Matching After Synchronisation

Ensure soft matching is turned off after syncing Microsoft AD DS with Microsoft Entra ID to enhance security.

record_voice_over

Plain language

After you sync your local Microsoft Active Directory (AD DS) with Microsoft's cloud service, Microsoft Entra ID, you should switch off something called 'soft matching'. This matters because leaving it on could accidentally link the wrong user accounts together, which might give someone access to things they shouldn't see.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Aug 2024

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Soft matching between Microsoft AD DS and Microsoft Entra ID is disabled following initial synchronisation activities.
policy ASD Information Security Manual (ISM) ISM-1950
priority_high

Why it matters

If soft matching remains enabled after initial sync, AD DS and Entra ID accounts may link incorrectly, enabling unauthorised access to data and services.

settings

Operational notes

After initial synchronisation, confirm soft matching is disabled in Entra Connect/AAD Connect settings and periodically re-check to prevent unintended AD DS–Entra ID account linking.

Mapping detail

Mapping

Direction

Controls