Password Hash Sync
Password hash synchronization errors in Entra ID Connect can disrupt identity synchronization between on-premises Active Directory (AD) and Azure AD. These errors often stem from misconfigurations, connectivity issues, or service disruptions. This section outlines methods to diagnose and resolve common password hash sync errors.
1. Verify Sync Service Status and Logs¶
The Azure AD Connect sync service must be running and healthy. Use PowerShell to check its status and review logs for detailed error messages.
Commands:
# Check sync service status
Get-ADSyncService | Select-Object Status, LastSyncTime
# Restart the sync service if needed
Restart-ADSyncService
Log Location:
Sync logs are stored at:
C:\ProgramData\Microsoft\AzureADSync\Logs
Use Get-ADSyncLog to filter relevant entries. For example:
Log Level Adjustment (for deeper diagnostics):
2. Test Network Connectivity¶
Password hash sync relies on secure communication between on-premises AD and Azure AD. Ensure DNS resolution, firewall rules, and port accessibility are correct.
Commands:
# Test connectivity to Azure AD
Test-Connectivity -SyncServiceAccount "[email protected]" -SyncServicePassword "SecurePassword123!"
# Verify DNS resolution for Azure AD endpoints
Resolve-DnsName -Name "globalcatalog.contoso.com" -Type SRV
Firewall Requirements:
Ensure ports 88 (Kerberos), 389 (LDAP), and 636 (LDAPS) are open between on-premises AD and Azure AD.
3. Validate Sync Configuration¶
Misconfigured sync rules or password policies can trigger errors. Check the following:
- Password Settings: Ensure on-premises AD passwords meet Azure AD requirements (e.g., length, complexity).
- Sync Rules: Use
Get-ADSyncRuleto verify password sync rules are enabled. - Sync Account Permissions: Confirm the sync service account has
Replicating Directory Changespermissions on the domain controller.
Example:
4. Address Account Lockouts¶
Sync service accounts or user accounts can become locked out, causing sync failures.
Steps:
1. Check for lockouts using Azure AD Connect Health:
- Navigate to Azure AD Connect Health > Sync Health > Account Lockouts.
2. Temporarily disable lockout policies for the sync service account if needed.
Note: Avoid disabling lockout policies permanently; use temporary overrides for troubleshooting.
5. Re-run the Sync Cycle¶
For intermittent errors, manually trigger a sync cycle to isolate issues:
Monitor the sync status with:
Key takeaways¶
- Check sync service status and logs for actionable error codes.
- Verify network connectivity and firewall rules for Kerberos/LDAP traffic.
- Validate sync configurations (rules, passwords, permissions) to align with Azure AD requirements.
- Monitor for account lockouts using Azure AD Connect Health.
- Manually trigger sync cycles to test resolution of transient errors.