How syncing works
How syncing works
ADAdmin manages your school's users and groups, but those users also need accounts in the platforms your school uses — Google Workspace, Microsoft Entra ID (Microsoft 365), Active Directory, and Apple School Manager. Syncing is the process that keeps those platforms in step with ADAdmin.
What syncing does
When you make a change in ADAdmin — creating a user, updating a name, adding a group membership, changing a password — that change is queued for provisioning. A background service called realsmart-provisioning processes the queue and applies the change to the relevant platform(s).
The result: the person gets a Google or Microsoft account, is added to the right shared drives or Teams, and has the correct access — all without manual work in each platform.
Supported platforms
| Platform | What ADAdmin provisions |
|---|---|
| Google Workspace | Create / update / suspend accounts; group membership; password reset |
| Microsoft Entra ID | Create / update / disable accounts; group membership; UPN changes |
| Active Directory (on-prem) | Account creation and attribute sync via the provisioning service |
| Apple School Manager | Roster sync (users and classes) |
Not every school uses every platform — only enabled platforms are synced.
When sync runs
Syncing runs automatically on a schedule (typically every 15–30 minutes). You do not need to trigger it manually for routine changes.
For urgent changes — such as a new joiner who needs access immediately — you can trigger a manual sync from the Sync status page. See Trigger a manual sync.
What sync does and does not do
ADAdmin is the source of truth. The provisioning service reads from ADAdmin and writes to platforms. It does not read from platforms back into ADAdmin — changes made directly in Google Admin or Entra will be overwritten at the next sync.
Passwords are sent to platforms when set or reset in ADAdmin. If a user changes their password directly in Google or Microsoft, that change is not pulled back into ADAdmin — but it will be overwritten if the password is reset from ADAdmin.
Deletions in ADAdmin trigger suspension (not permanent deletion) in connected platforms, by default. This is intentional — it gives a recovery window if a user was accidentally removed.
Groups inside groups are honoured on both Google and Microsoft, but each platform is given what it can accept. In Google Workspace the inner group is added as a member of the outer group, so Google understands the nesting itself. Microsoft 365 groups cannot contain another group, so there the inner group's people are written into the outer group's membership instead. Either way you manage one link in ADAdmin — see Put a group inside another group.
Why a change might not appear yet
- Sync is on a schedule — changes queue up and are processed within the next scheduled run (usually within 30 minutes).
- A sync error occurred — check the Sync status page for errors. See View sync status and logs.
- The platform is not connected — the school may not have that integration enabled.