Professional Documents
Culture Documents
Interface of IdFix
The Synchronization Service App, also known as Microsoft Entra Connect, is an application that
facilitates synchronization between your on-premises Active Directory Domain Services (AD DS) and the
Microsoft Entra tenant associated with your Microsoft 365 subscription.
As a monitoring tool is Part of Azure AD Connect installation that provides real-time monitoring and
troubleshooting. View sync cycle status, connector space, and metaverse data and use for Diagnosing
synchronization errors and conflicts.
Included to it
Azure AD Connect Health is a monitoring tool specifically designed for Azure AD Connect. It
serves two primary purposes:
Monitoring ADFS Infrastructure: It keeps track of the status of your Active Directory
Federation Services (ADFS) infrastructure.
Monitoring Sync Engine: It also monitors the synchronization engine of Azure AD Connect.
Synchronization Service Manager: To manage and monitor directory synchronization, you can
use the Synchronization Service Manager console.
Organizations that already use DirSync or Azure AD Sync can benefit from Azure AD Connect Health by
migrating to it or performing an in-place upgrade from supported configurations1.
Azure AD Connect Health helps you monitor the status of this sync engine, ensuring smooth
synchronization between your on-premises identity infrastructure and Azure AD.
It provides insights into any issues or errors related to synchronization, allowing you to take proactive
measures
Synchronization Settings
6. PowerShell Commands to Force Sync in Azure AD Connect
This triggers a delta sync, updating changes since the last sync cycle.
To modify synchronization schedule:
Indication:
New user accounts added in on-premises Active Directory do not appear in Azure AD or take an
unusually long time to appear (more than 30 minutes).
After an on-premises user changes their password, they can’t authenticate to Azure AD.
If the password-writeback feature is used, password resets in Azure AD do not work for on-
premises users.
Synchronization errors are visible under Azure AD Connect Health.
Directory administrators receive email notifications from Azure AD regarding sync issues.
Common Causes:
Connection to Azure AD: Ensure that the Azure AD Connect server has a stable connection to
the necessary URLs, IP addresses, and port numbers (TCP 80 and 443) listed in the Microsoft
documentation. You can verify connectivity using Telnet.
Proxy Configuration: If Azure AD Connect communicates with Azure AD via a proxy, ensure
that the proxy configuration is correctly set in C:\Windows\Microsoft.NET\Framework64\
v4.0.30319\Config\machine.config.
Resolution:
Indication:
Users won’t synchronize, and changes won’t flow between on-premises and Azure AD.
Common Causes:
Firewall rules blocking necessary ports (e.g., 80, 443, 53, 88, 389, 445, 636).
DNS resolution issues.
Network segmentation preventing communication.
Resolution:
Review firewall rules and allow necessary traffic.
Ensure proper DNS resolution.
Adjust network segmentation if needed.