How syncing works
ADAdmin manages your school's users and groups, but those users also need accounts in the platforms your school uses — Google Workspace, Microsoft Entra ID (Microsoft 365), Active Directory, and Apple School Manager. Syncing is the process that keeps those platforms in step with ADAdmin.
What syncing does
When you make a change in ADAdmin — creating a user, updating a name, adding a group membership, changing a password — that change is queued for provisioning. A background service called realsmart-provisioning processes the queue and applies the change to the relevant platform(s).
The result: the person gets a Google or Microsoft account, is added to the right shared drives or Teams, and has the correct access — all without manual work in each platform.
Supported platforms
| Platform | What ADAdmin provisions |
|---|---|
| Google Workspace | Create / update / suspend accounts; group membership; password reset |
| Microsoft Entra ID | Create / update / disable accounts; group membership; UPN changes |
| Active Directory (on-prem) | Account creation and attribute sync via the provisioning service |
| Apple School Manager | Roster sync (users and classes) |
Not every school uses every platform — only enabled platforms are synced.
When sync runs
Syncing runs automatically overnight, once a day per platform — so a change you make during the school day normally reaches Google, Entra or Apple the following morning. You do not need to trigger anything for routine changes.
The exception is on-premise Active Directory: your local connector polls Realsmart through the day, so AD picks changes up much sooner.
For urgent changes — a new joiner who needs access today, or a password you have just reset or imported — trigger a manual sync from the Sync status page instead of waiting. It runs the same job as the overnight sync, scoped to your school. See Trigger a manual sync.
What sync does and does not do
ADAdmin is the source of truth. The provisioning service reads from ADAdmin and writes to platforms. It does not read from platforms back into ADAdmin — changes made directly in Google Admin or Entra will be overwritten at the next sync.
Passwords are sent to platforms when set or reset in ADAdmin — on the same overnight schedule, and only where that platform's password-sync switch is on (see Password import for the per-platform detail). If a user changes their password directly in Google or Microsoft, that change is not pulled back into ADAdmin — but it will be overwritten if the password is reset from ADAdmin.
Deletions in ADAdmin trigger suspension (not permanent deletion) in connected platforms, by default. This is intentional — it gives a recovery window if a user was accidentally removed.
Groups inside groups are honoured on both Google and Microsoft, but each platform is given what it can accept. In Google Workspace the inner group is added as a member of the outer group, so Google understands the nesting itself. Microsoft 365 groups cannot contain another group, so there the inner group's people are written into the outer group's membership instead. Either way you manage one link in ADAdmin — see Put a group inside another group.
Why a change might not appear yet
- Sync is on a schedule — changes are picked up by the next scheduled run, which for the cloud platforms is overnight. If you need it today, trigger a manual sync.
- A sync error occurred — check the Sync status page for errors. See View sync status and logs.
- The platform is not connected — the school may not have that integration enabled.
Related
Was this guide helpful?
We read every response — it decides what we rewrite next.
Thanks for your feedback.