If you are already using Azure Active Directory Connect to sync your on-premise Active Directory to Azure AD, then you should set up a secondary server for a backup. This second server can run in ‘staging’ mode, which means it can still be active but it will not sync any changes with Azure AD. If your primary sync server were to run into issues, you can easily flip your second sync server into active mode.

Agent Install

Download the latest agent on a second domain controller: Download Link

Launch the installer, accept the license terms and click continue

2022-12-16

Clicking customize will show you some advanced settings. For this example, I am going to stick with the express settings

2022-12-16

Enter the credentials for an Azure AD global admin account

2022-12-16

Enter the credentials of an AD enterprise admin account

2022-12-16

On the final screen, leave the “Start the synchronization process…” option unchecked

2022-12-16

Configuring Staging Mode

Reopen Azure AD Connect, and choose Configure

2022-12-16

Select the Configure staging mode task and click Next

2022-12-16

Check “Enable staging mode” and click Next

2022-12-16

On the final screen, this time you do want to check the option to start the sync process. Microsoft’s documentation explains why: “It is recommended to leave the sync process on for the server in Staging Mode, so if it becomes active, it will quickly take over and won’t have to do a large sync to catch up to the current state of the AD/Azure AD sync.

2022-12-16

Done!

2022-12-16