Configure Connectors
In brief
The connector configuration guidance now refers to configuring dynamic and AutoReuse TCP port ranges instead of extending TCP and UDP ephemeral ports.
What Entra admins need to know
Review the updated performance and scalability guidance when configuring connector servers.
This editorial summary was generated by AI from the documentation changes. Verify important details in the full Microsoft Learn article.
Documentation change
The comparison below shows only the changed extract. Use the full-page view for complete context.
- Optimize performance between the connector and the application. Physically locate the connector server close to the application servers. For more information, see Optimize traffic flow with Microsoft Entra application proxy.
- Make sure the connector server and the web application servers are in the same Active Directory domain or span trusting domains. Having the servers in the same domain or trusting domains is required for single sign-on (SSO) with integrated Windows authentication (IWA) and Kerberos Constrained Delegation (KCD). If the connector server and web application servers are in different Active Directory domains, use resource-based delegation for single sign-on.
- Consider performance and scalability of your connector deployment, including
extending the TCP and UDP ephemeral portsconfiguring dynamic and AutoReuse TCP port ranges on your connector server. See Understand the Microsoft Entra private network connector for more information. - Consider creating a performance baseline for your private network connectors.
Prepare your on-premises environment
@@ -112,7 +112,7 @@ To enable TLS 1.2: - Optimize performance between the connector and the application. Physically locate the connector server close to the application servers. For more information, see [Optimize traffic flow with Microsoft Entra application proxy](../identity/app-proxy/application-proxy-network-topology.md). - Make sure the connector server and the web application servers are in the same Active Directory domain or span trusting domains. Having the servers in the same domain or trusting domains is required for single sign-on (SSO) with integrated Windows authentication (IWA) and Kerberos Constrained Delegation (KCD). If the connector server and web application servers are in different Active Directory domains, use resource-based delegation for single sign-on.-- Consider [performance and scalability](concept-connectors.md#performance-and-scalability) of your connector deployment, including [extending the TCP and UDP ephemeral ports](concept-connectors.md#expanding-ephemeral-port-range) on your connector server. See [Understand the Microsoft Entra private network connector](concept-connectors.md) for more information.+- Consider [performance and scalability](concept-connectors.md#performance-and-scalability) of your connector deployment, including [configuring dynamic and AutoReuse TCP port ranges](concept-connectors.md#configure-dynamic-and-autoreuse-tcp-port-ranges) on your connector server. See [Understand the Microsoft Entra private network connector](concept-connectors.md) for more information. - Consider creating a [performance baseline](/troubleshoot/windows-server/performance/troubleshoot-performance-problems-in-windows) for your private network connectors. ### Prepare your on-premises environment 