Fix Entra Connect Sync Errors (Azure AD Connect) [2026]

exodata.io
Cloud |Azure |Cloud |Infrastructure |Security

Published on: 10 March 2026

Most Microsoft Entra Connect Sync errors come down to four things: duplicate or invalid attribute values on-premises, a sync account blocked by Conditional Access or expired credentials, an unsupported Connect Sync version, or a scheduler that is not running. Find the failing run in Synchronization Service Manager > Operations, open the error on the object, fix the data at the source (usually on-premises AD), and run a delta sync. The rest of this guide maps the exact error strings you will see to the fix.

Microsoft Entra Connect Sync (formerly Azure AD Connect) and Microsoft Entra Cloud Sync are the bridge between on-premises Active Directory and Microsoft Entra ID (formerly Azure AD). When sync breaks, new users cannot sign in, password changes do not propagate, group memberships go stale, and Conditional Access policies enforce rules against outdated data. Many sync failures start in AD itself, not in the connector, so if you suspect the on-premises side, check our guide on troubleshooting Active Directory replication first. If users are syncing fine but still cannot sign in to apps, the problem is more likely on the authentication side: see our Azure SSO and AADSTS error guide.

If you are still planning your hybrid identity deployment, our guide to migrating Active Directory to Azure AD covers the full journey from on-premises to cloud identity.

Quick Triage: Entra Connect Not Syncing?

Work through these in order. Most incidents are solved by step 4.

  1. Is the sync service running? On the Connect server, check that the Microsoft Azure AD Sync service (service name ADSync) is started. Connect Health raises “Microsoft Entra Connect Sync Service isn’t running” when it is not.
  2. Is the scheduler enabled and not suspended? Run Get-ADSyncScheduler. You want SyncCycleEnabled : True and SchedulerSuspended : False. If the Connect wizard is open on the server, the scheduler is suspended until you close it.
  3. Is the version supported? Connect Sync 1.x no longer works at all, and each 2.x release retires 12 months after a newer one ships. See the version section below.
  4. What does the last run say? Open Synchronization Service Manager > Operations, select the most recent run with a status other than success, and click the error on the affected object. This is the “management agent run history” that event log and alert messages tell you to view.
  5. Is the sync account blocked? If the error mentions authentication, MFA, or an AADSTS code, a Conditional Access policy or expired credential is hitting the sync account.
  6. Is it a data problem? Duplicate proxyAddresses or userPrincipalName values, invalid characters, and oversized attributes cause most per-object export errors. Fix them on-premises and run Start-ADSyncSyncCycle -PolicyType Delta.

Entra Connect Sync vs Cloud Sync: Which One Are You Running?

Before troubleshooting, confirm which synchronization engine is in place. The two tools serve similar purposes but differ in architecture, capabilities, and where errors surface. The table below reflects Microsoft’s current Connect Sync vs Cloud Sync comparison.

FeatureMicrosoft Entra Connect SyncMicrosoft Entra Cloud Sync
ArchitectureOn-premises server with sync engine and SQL databaseLightweight provisioning agent, configuration lives in the cloud
High availabilityOne active server (plus optional staging server)Multiple active agents with automatic failover
Disconnected forestsNoYes
ScaleNo per-domain object limit; groups up to 250,000 membersUp to 150,000 objects per domain; groups up to 50,000 members
Password hash sync / password writebackYesYes
Pass-through authentication and AD FS setupYesNo (configured separately)
Device sync (hybrid join)YesNo
Advanced custom sync rulesYes (Synchronization Rules Editor)No (expression builder for attribute mapping)
Attribute-based filteringFullLimited
On-demand provisioningNoYes
Sync intervalEvery 30 minutes by defaultEvery two minutes
Where errors surfaceSynchronization Service Manager, event logs, Connect HealthProvisioning logs in the Microsoft Entra admin center

When Connect Sync is still the right tool: device sync for Microsoft Entra hybrid join, complex custom sync rules, cross-forest references, merging attributes from multiple domains, or very large groups.

When to use Cloud Sync: disconnected forests (mergers and acquisitions), environments where you want no single sync server to fail, and most new deployments. Microsoft describes Cloud Sync as its strategic direction for hybrid identity, and new features such as group provisioning to AD ship there first.

Where Are the Entra Connect Sync Logs?

People search for “Entra Connect sync logs” because there is no single log file. Each place answers a different question:

Log locationWhat it tells you
Synchronization Service Manager > OperationsEvery import, sync, and export run, its status (success, completed-export-errors, stopped-server, and so on), and per-object errors. Start here.
Synchronization Service Manager > Connectors > Search Connector SpaceThe state of one object: pending exports, lineage, and which sync rules applied.
Windows Event Viewer > Application logEvents from the ADSync and Directory Synchronization sources, including run profile failures and password hash sync events. From version 2.4.129.0, admin changes are also logged under the Entra Connect Admin Actions source.
%ProgramData%\AADConnecttrace-*.log files written by the Connect wizard during install, upgrade, and configuration changes. Check these when the wizard itself fails.
Microsoft Entra admin center > Entra Connect > Connect HealthThe sync error report and alerts. The sync error report refreshes every 30 minutes.
Microsoft Entra admin center > Entra Connect > Cloud Sync > Provisioning logsPer-object results for Cloud Sync, the equivalent of the Operations tab.

Operations history is kept for 7 days by default (PurgeRunHistoryInterval in Get-ADSyncScheduler), so capture the error details before they age out.

Entra Connect Error Messages and What They Mean

This section covers the exact strings that appear in Synchronization Service Manager, event logs, Connect Health, and the Connect wizard.

”sync-generic-failure” in Azure AD Connect

sync-generic-failure shows up in the Operations tab during a synchronization step, usually against the SyncRulesEngine. It means a sync rule could not be evaluated for that object, and it often hits every object in a run when the cause is environmental rather than one bad user.

Fix:

  1. In Synchronization Service Manager > Operations, select the failing run and click the error on one affected object. The stack trace names the rule or attribute involved.
  2. From the object’s connector space entry, use Preview > Generate Preview to see exactly which rule fails.
  3. If many objects fail at once after a change, review recent edits in the Synchronization Rules Editor. A custom rule with a bad expression or a missing source attribute is the usual culprit.
  4. Check that TLS 1.2 is enabled and outbound port 443 is open. Microsoft lists .NET Framework 4.7.2 and TLS 1.2 as minimum requirements for current Connect Sync builds.
  5. Run a full sync after fixing the rule: Start-ADSyncSyncCycle -PolicyType Initial.

”sync-rule-error-function-triggered”

This means a sync rule deliberately called the Error() function in one of its expressions. Some rules use it to stop an object that is missing required data. Open the error detail to read the message the rule returned, then find that rule in the Synchronization Rules Editor. Fix the source data rather than editing a default rule.

”dn-attributes-failure”

This export error usually appears on groups. It means one or more members of the group could not be exported, often because those member users have their own errors (for example, duplicate proxyAddresses in on-premises AD). Fix the member objects first; the group error clears on the next cycle.

”The import operation from Microsoft Entra Connector has failed”

This is the description of the Connect Health alert Import from Microsoft Entra ID failed. The sync engine could not read from your tenant, so nothing downstream of that import is reliable. Microsoft’s remediation is to “investigate the event log errors of import operation”, which in practice means:

  1. Open Synchronization Service Manager > Operations and find the failed Full Import or Delta Import on the <tenant>.onmicrosoft.com - AAD connector.
  2. Read the status and the connection error detail. Authentication errors point to the sync account; timeouts point to network or proxy issues.
  3. Test connectivity from the Connect server:
Test-NetConnection -ComputerName "login.microsoftonline.com" -Port 443
Test-NetConnection -ComputerName "adminwebservice.microsoftonline.com" -Port 443
  1. If the account is blocked, check the Entra sign-in logs for the sync account and look for Conditional Access failures (see the next section).

”View the management agent run history for details”

This phrase is the tail end of ADSync event log entries and alerts that report a failed run profile. It is not an error on its own. It tells you the detail lives in Synchronization Service Manager > Operations (the run history for that connector, which the sync engine calls a management agent). Find the run with the matching timestamp and open the per-object errors.

”There was an issue obtaining cloud sync intervals”

This error appears in the Connect wizard, typically during the Configure step of an install or upgrade, as System.InvalidOperationException: There was an issue obtaining cloud sync intervals. The wizard could not read the sync schedule from your tenant. Read the inner exception in the newest trace-*.log under %ProgramData%\AADConnect:

  • Inner exception shows AADSTS50079 or AADSTS50076: a Conditional Access or per-user MFA requirement is hitting the account the wizard uses. Exclude the Connect Sync service account (the Directory Synchronization Accounts role) from MFA policies; Microsoft’s Conditional Access guidance treats it as a service account to exclude. Our Conditional Access setup guide covers how to structure those exclusions safely.
  • Inner exception is a DNS or HTTP error: the server cannot reach Microsoft endpoints. Check proxy settings, TLS 1.2, and the required URLs and ports.

”The synchronization service scheduler is suspended until this setup wizard is closed”

This message is expected. When the Connect wizard is open, the scheduler suspends itself so configuration changes can apply. Close the wizard and sync resumes. If Get-ADSyncScheduler still shows SchedulerSuspended : True after an upgrade, re-run the wizard to completion. Microsoft states that only Connect should modify SchedulerSuspended, so do not set it with PowerShell.

”An Azure Active Directory call was made to keep object in sync between Azure Active Directory and Exchange Online”

This is an Exchange Online error, not a Connect Sync error, and it usually includes Microsoft.Online.Workflows.PropertyUpdateNotAllowedException. You tried to change an attribute (often an alias in proxyAddresses) on a mailbox whose source of authority is on-premises AD. The cloud refuses the write because the next sync would overwrite it.

Fix: make the change on-premises (Active Directory Users and Computers, the Exchange management tools, or Set-ADUser) and let Connect Sync carry it to the cloud.

DeletingCloudOnlyObjectNotAllowed (Error Type 114)

Exported as “This synchronization operation, Delete, is not valid. Contact Technical Support.” Microsoft documents this most often during moves from hybrid to cloud-only, or when Connect tries to delete an object that was restored or moved out of sync scope. Microsoft’s fix: identify the object, soft-delete the cloud account, run a delta sync so the deletion imports, then restore the user from the recycle bin and run another delta sync.

InvalidHardMatch (new hard match hardening, July 2026)

Beginning July 1, 2026, Microsoft Entra ID blocks a hard match when the target cloud user already has onPremisesObjectIdentifier set or holds, or is eligible for, a privileged role. You will see messages such as “The cloud user with privileged roles is not allowed to be taken over.” For privileged accounts, temporarily remove the role or eligibility, let the hard match complete, then restore it. Microsoft’s sync errors reference lists the recovery path for each block reason.

SP-AzureImportDataConflicts (not a sync error)

If you landed here searching for SP-AzureImportDataConflicts: that code comes from SharePoint Online migrations, not from Entra Connect. It means an item’s unique ID conflicts with data already migrated into the destination site collection, usually because the same source was migrated to two different locations. Clean up the earlier copy (including both recycle bins) and re-run the migration job incrementally.

Microsoft Azure AD Sync Service Not Starting

If the ADSync service will not start, check the Application event log for the reason before restarting anything. Common causes are a changed or expired password on the service account, a full LocalDB database (the default SQL Express LocalDB has a 10 GB limit), or a failed upgrade that left miiserver.exe.config out of date. Microsoft documents a known issue in versions 2.5.190.0 and 2.6.1.0 where a previously modified miiserver.exe.config causes sync to fail after upgrade with a System.Diagnostics.DiagnosticSource assembly load error.

Common Export Errors and How to Fix Them

Attribute Conflicts and Duplicate Attribute Errors

Symptom: Sync completes but reports errors like “AttributeValueMustBeUnique” or “InvalidSoftMatch.” Objects are not exported to Microsoft Entra ID, or two on-premises accounts map to the same cloud identity.

Cause: Microsoft Entra ID enforces uniqueness on attributes including userPrincipalName, proxyAddresses, mail, and signInName. When two objects share a value, the sync engine cannot export the conflicting object.

This frequently occurs when:

  • A user was previously created directly in the cloud (cloud-only) and then an on-premises account is synced with the same UPN or email.
  • Mailbox migrations leave behind stale proxyAddresses on objects that should not have them.
  • Multiple on-premises forests contain objects with overlapping SMTP addresses.

Fix:

  1. Identify the conflicting objects. In the Microsoft Entra admin center, go to Entra ID > Entra Connect > Connect Health and open the sync error report. Each error includes the source object and the conflicting attribute value.

  2. For duplicate proxyAddresses, use PowerShell on-premises to find all objects sharing the address:

Get-ADObject -Filter 'proxyAddresses -eq "SMTP:user@contoso.com"' -Properties proxyAddresses
  1. Remove the conflicting value from the object that should not have it:
Set-ADUser -Identity "stale-user" -Remove @{proxyAddresses="SMTP:user@contoso.com"}
  1. If the conflict is with a cloud-only object, either delete the cloud object or use hard matching to link the on-premises object to the existing cloud object. Remember the July 2026 hard match hardening described above.

  2. Force a sync cycle to clear the error:

Start-ADSyncSyncCycle -PolicyType Delta

InvalidSoftMatch Errors

Symptom: Error code “InvalidSoftMatch” appears during export. Connect Sync cannot match an on-premises object to an existing cloud object.

Cause: Soft matching pairs an on-premises user with a cloud user by proxyAddresses or userPrincipalName. It fails when the matching cloud object already has an immutableId from a different on-premises object, which tells Entra ID that the cloud account belongs to someone else. Common triggers include duplicate values on-premises, a reinstall of Connect Sync with a different source anchor, or moving a user between forests.

Fix:

  1. Verify the on-premises user’s addresses:
Get-ADUser -Identity "jdoe" -Properties proxyAddresses | Select-Object -ExpandProperty proxyAddresses
  1. Confirm what the cloud object holds:
Connect-MgGraph -Scopes "User.Read.All"
Get-MgUser -UserId "jdoe@contoso.com" -Property ProxyAddresses,OnPremisesImmutableId | Select-Object ProxyAddresses,OnPremisesImmutableId
  1. If the duplicate is genuine, remove the value from the object that should not have it. If the cloud object is the right match and simply needs its anchor set, perform a hard match by setting OnPremisesImmutableId to the Base64 encoding of the on-premises source anchor (by default ms-DS-ConsistencyGuid, which starts out equal to ObjectGUID):
$guid = (Get-ADUser -Identity "jdoe").ObjectGUID
$immutableId = [Convert]::ToBase64String($guid.ToByteArray())
Update-MgUser -UserId "jdoe@contoso.com" -OnPremisesImmutableId $immutableId

This will be blocked if the cloud user holds or is eligible for a privileged role or already has onPremisesObjectIdentifier set.

  1. Run a delta sync, or a full sync if you changed scoping:
Start-ADSyncSyncCycle -PolicyType Initial

ObjectTypeMismatch

Symptom: An object fails to sync with an “ObjectTypeMismatch” error.

Cause: Microsoft Entra ID already contains a different object type (for example a mail-enabled group or mail contact) with the same proxyAddresses value as the user being synced. Because the types differ, the sync engine cannot merge them.

Fix:

  1. Identify the conflicting contact or group in the cloud:
Get-MgContact -Filter "mail eq 'user@contoso.com'"
  1. If the contact is no longer needed (because the on-premises user should take ownership of that address), delete it:
Remove-MgContact -OrgContactId "<contact-object-id>"
  1. Trigger a delta sync:
Start-ADSyncSyncCycle -PolicyType Delta

UPN Mismatch and Non-Routable Domains

Symptom: Users sync successfully but cannot sign in with their expected email address. Their UPN in Entra ID shows as user@contoso.onmicrosoft.com or similar instead of user@contoso.com.

Cause: The on-premises UPN suffix uses a non-routable domain (like .local or .internal). Microsoft Entra ID requires a verified, internet-routable domain as the UPN suffix, so it substitutes the default onmicrosoft.com domain.

Fix:

  1. Add the routable UPN suffix to your on-premises Active Directory. Open Active Directory Domains and Trusts, right-click the root node, and add the new UPN suffix (for example, contoso.com).

  2. Update user UPNs in bulk:

Get-ADUser -Filter {UserPrincipalName -like "*@contoso.local"} | ForEach-Object {
    $newUPN = $_.SamAccountName + "@contoso.com"
    Set-ADUser -Identity $_ -UserPrincipalName $newUPN
}
  1. Verify the domain is listed as verified under Entra ID > Domain names in the Microsoft Entra admin center.

  2. Run a delta sync and confirm the UPNs update correctly in the cloud.

Our Active Directory replication troubleshooting guide covers how to make sure these changes replicate across all domain controllers before sync picks them up.

Export Errors and Stopped-Server Scenarios

Symptom: The sync cycle runs but objects are stuck in a “pending export” state. The Operations tab shows statuses like stopped-server or completed-export-errors, or Connect Health raises “Export to Microsoft Entra ID failed.”

Cause: Export failures typically result from:

  • The sync service account lacking required permissions, or being blocked by Conditional Access.
  • Network connectivity issues between the Connect server and Microsoft endpoints.
  • An expired or revoked credential, or legacy authentication on a version that requires application-based authentication.

Fix:

  1. Open Synchronization Service Manager on the Connect server. Click Connectors, select the Microsoft Entra connector, and click Search Connector Space to inspect pending exports.

  2. Verify network connectivity to the required Microsoft endpoints with the Test-NetConnection commands above.

  3. If the connector credentials have expired, re-run the Connect wizard, select Customize synchronization options, and re-authenticate with a Hybrid Identity Administrator account.

  4. Review the full list of required endpoints and ports and make sure your firewall and proxy allow them.

”Export to Microsoft Entra ID was Stopped. Accidental delete threshold was reached”

Connect Sync stops all exports when a run would delete more objects than the threshold (500 by default). This usually follows an OU filtering change or a moved OU. Check which objects are pending deletion before you do anything else. If the deletions are intended, temporarily disable the threshold, sync, and turn it back on:

Disable-ADSyncExportDeletionThreshold
Start-ADSyncSyncCycle -PolicyType Delta
Enable-ADSyncExportDeletionThreshold -DeletionThreshold 500

Password Hash Sync Failures

Password hash synchronization (PHS) is the most common sign-in method for hybrid environments and a critical fallback if pass-through authentication or federation fails. When PHS breaks, users cannot sign in to cloud resources with their on-premises password.

Symptom: Password changes made on-premises do not reach Entra ID. Sign-ins fail with “incorrect password” even though the on-premises password is correct. Connect Health may raise “Password Hash Synchronization heartbeat was skipped in last 120 minutes” or “Password Hash Synchronization stopped working.”

Diagnosing the issue:

  1. Check the password sync configuration:
Import-Module ADSync
Get-ADSyncAADPasswordSyncConfiguration -SourceConnector "contoso.com"
  1. Check the scheduler:
Get-ADSyncScheduler

Look at SyncCycleEnabled and SchedulerSuspended. Password sync runs on its own scheduler, but a suspended or broken engine still stops it.

  1. Check the Application event log on the Connect server for Event ID 611 (password sync failure) and 656/657 (password change requests and results).

Common fixes:

  • Re-enable password hash sync if it was accidentally disabled, through the Connect wizard or PowerShell:
Set-ADSyncAADPasswordSyncConfiguration -SourceConnector "contoso.com" -TargetConnector "contoso.onmicrosoft.com - AAD" -Enable $true
  • Restart the ADSync service when no sync run is in progress. This is Microsoft’s documented remediation for both PHS alerts:
Restart-Service ADSync
  • Trigger a full password resync if individual password syncs keep failing:
$connectorName = "contoso.com"
$aadConnectorName = "contoso.onmicrosoft.com - AAD"
Import-Module ADSync
$c = Get-ADSyncConnector -Name $connectorName
$p = New-Object Microsoft.IdentityManagement.PowerShell.ObjectModel.ConfigurationParameter "Microsoft.Synchronize.ForceFullPasswordSync", String, ConnectorGlobal, $null, $null, $null
$p.Value = 1
$c.GlobalParameters.Remove($p.Name)
$c.GlobalParameters.Add($p)
$c = Add-ADSyncConnector -Connector $c
Set-ADSyncAADPasswordSyncConfiguration -SourceConnector $connectorName -TargetConnector $aadConnectorName -Enable $false
Set-ADSyncAADPasswordSyncConfiguration -SourceConnector $connectorName -TargetConnector $aadConnectorName -Enable $true

Once PHS is restored, make sure users are also enrolled in multi-factor authentication as a layer on top of password-based sign-in.

Filtering Issues: Objects Syncing (or Not) When They Should Not (or Should)

Filtering determines which on-premises objects are synchronized. Misconfigured filters are a silent source of “Azure AD Connect user not syncing” tickets: objects are either missing from the cloud or syncing when they should be excluded.

OU-Based Filtering

Only objects in selected OUs are synchronized.

Common mistake: creating a new OU for a department and forgetting to include it in the sync scope. All users in that OU are invisible to Entra ID.

How to verify and adjust:

  1. Open the Connect wizard and select Customize synchronization options.
  2. On the Domain and OU Filtering page, expand each domain and verify that the correct OUs are checked.
  3. Filtering changes require a full import. After making changes, run:
Start-ADSyncSyncCycle -PolicyType Initial

Attribute-Based Filtering

Attribute-based filtering uses sync rules to include or exclude objects based on attribute values, for example filtering out all users where extensionAttribute15 equals “NoSync.”

Diagnosing unexpected filtering:

  1. Open the Synchronization Rules Editor on the Connect server.
  2. Review inbound sync rules with scoping filters. Look for rules with a lower precedence number (higher priority) that may override default behavior.
  3. Use Search Connector Space in Synchronization Service Manager to find the object and inspect its lineage.

Tip: to exclude service accounts or shared mailboxes from sync, attribute-based filtering on a custom extension attribute is cleaner than managing dozens of OU exclusions.

Domain-Based Filtering

Domain-based filtering selects which domains in a multi-domain or multi-forest topology are synchronized.

Common mistake in multi-forest environments: adding a new trusted forest but not configuring it in Connect Sync. Objects from the new forest are not synced.

How to add a new forest:

  1. Open the Connect wizard and select Customize synchronization options.
  2. Add the new forest and provide credentials for the AD DS connector account.
  3. Select the OUs to include and complete the wizard.

If the forest is disconnected (no trust, no line of sight to the Connect server), Cloud Sync is usually the simpler answer.

Sync Cycle Management

The Connect Sync scheduler runs a delta cycle every 30 minutes by default. If you change the interval, Microsoft requires a sync cycle at least once every 7 days; going longer can force a full sync to recover.

Check the scheduler status:

Get-ADSyncScheduler

Run a delta sync (only changes since the last cycle):

Start-ADSyncSyncCycle -PolicyType Delta

Run a full sync (re-evaluates all objects and rules):

Start-ADSyncSyncCycle -PolicyType Initial

Stop a running cycle so you can make configuration changes (safe; pending changes run next cycle):

Stop-ADSyncSyncCycle

Temporarily disable and re-enable the scheduler during maintenance:

Set-ADSyncScheduler -SyncCycleEnabled $false
Set-ADSyncScheduler -SyncCycleEnabled $true

Warning: avoid full sync cycles during business hours in large environments. A full sync reprocesses every object in the connector space and can take hours in directories with hundreds of thousands of objects.

Health Monitoring with Microsoft Entra Connect Health

Microsoft Entra Connect Health (formerly Azure AD Connect Health) provides cloud-based monitoring for your on-premises sync infrastructure. It surfaces sync errors, agent problems, and performance issues before they turn into user-facing incidents.

Setting up Connect Health:

  1. You need a Microsoft Entra ID P1 or P2 license (included in Microsoft 365 E3/E5 and Business Premium).
  2. The Connect Health agent for sync is installed with Microsoft Entra Connect Sync. For AD FS and AD DS monitoring, install the agent separately.
  3. Verify the agent is reporting under Entra ID > Entra Connect > Connect Health in the Microsoft Entra admin center.

Connect Health alerts worth acting on immediately (names as they appear in Microsoft’s alert catalog):

  • Microsoft Entra Connect Sync Service isn’t running.
  • Import from Microsoft Entra ID failed and Export to Microsoft Entra ID failed.
  • Connection to Microsoft Entra ID failed due to authentication failure.
  • Password Hash Synchronization stopped working or heartbeat was skipped in last 120 minutes.
  • Export to Microsoft Entra ID was Stopped. Accidental delete threshold was reached.
  • Health service data isn’t up to date (the agent cannot reach the service).

Alerts like “sync errors detected on your Azure AD Connect service” link to the sync error report, which groups errors by type (duplicate attribute, data mismatch, data validation, large attribute, and others).

For organizations following the Microsoft 365 security hardening checklist, route Connect Health alerts into the same monitoring workflow as sign-in risk detections and Conditional Access reporting.

Staging Mode: Safe Testing and Disaster Recovery

Connect Sync supports a staging mode where the server imports and synchronizes data but does not export any changes.

Use cases for staging mode:

  • Pre-upgrade testing. Install the new version on the staging server, verify sync rules produce the expected results, then promote it.
  • Disaster recovery. If the active server fails, promote the staging server to resume sync within minutes instead of hours.
  • Validating sync rule changes. Test custom rules without risking production.

How to promote a staging server:

  1. On the current active server (if accessible), re-run the Connect wizard and enable staging mode.
  2. On the staging server, re-run the wizard and disable staging mode.
  3. Verify that a sync cycle completes successfully and objects export.

Critical rule: never run two active Connect Sync servers against the same tenant. It causes conflicting exports and data corruption.

Upgrading Microsoft Entra Connect Sync

Running an unsupported version is now a direct cause of sync outages, not just a missed bug fix. As of Microsoft’s version history page (updated September 2026):

  • All Connect Sync 1.x versions are unsupported and no longer synchronize.
  • Each 2.x version retires 12 months after a newer version is released. For example, 2.5.79.0 retires on 23 October 2026 and 2.5.190.0 on 2 February 2027.
  • Mandatory upgrade: you must be on version 2.6.84.0 or later and configure application-based authentication by April 7, 2027. Legacy authentication is being retired and sync stops after that date if you have not done both.
  • The installer is only available from the Microsoft Entra admin center (Entra Connect > Get started > Manage), not the old Microsoft Download Center link. Current builds require .NET Framework 4.7.2 and TLS 1.2.

Check your current version:

(Get-ADSyncGlobalSettings).Parameters | Where-Object {$_.Name -eq "Microsoft.Synchronize.ServerConfigurationVersion"} | Select-Object Value

Or open Programs and Features on the Connect server and look for the “Microsoft Azure AD Connect” entry (the installed program still uses the old name).

Upgrade approaches:

  • In-place upgrade. Run the latest installer on the existing server. The wizard preserves your configuration. Automatic upgrade handles this for eligible configurations, but not every release ships through autoupgrade.
  • Swing migration. Build a new server with the latest version in staging mode, verify configuration, then promote it and decommission the old server. Use this when also moving to a new OS or SQL instance.

If you are troubleshooting a specific error, check whether the version history lists a fix for it before spending time on manual remediation.

Migrating from Connect Sync to Cloud Sync

Microsoft’s development focus is on Cloud Sync. Organizations running Connect Sync should evaluate whether Cloud Sync meets their requirements and plan a migration when it does.

Pre-migration checklist:

  • Confirm Cloud Sync supports every feature you use (see the comparison table at the top of this article).
  • If you rely on device sync for hybrid join, advanced custom sync rules, cross-forest references, or groups over 50,000 members, Cloud Sync is not yet a drop-in replacement.
  • Confirm no domain exceeds 150,000 objects.

Migration steps:

  1. Install the Microsoft Entra provisioning agent on at least two domain-joined servers per forest for high availability.
  2. Create the configuration under Entra ID > Entra Connect > Cloud Sync > New configuration.
  3. Set the scope to match your current Connect Sync OU and group filters.
  4. Use Provision on demand to test a handful of users before enabling the configuration.
  5. Migrate a pilot OU first, following Microsoft’s pilot tutorial, and remove that scope from Connect Sync as you go.
  6. Monitor the provisioning logs for at least 48 hours before decommissioning the Connect Sync server.

Warning: do not run Connect Sync and Cloud Sync against the same objects at the same time. Use one or the other for each set of users and groups.

If you are working through this transition while also fixing Azure SSO and AADSTS sign-in errors, sequence the work so you are not debugging two identity changes at once.

Quick Reference: Sync Error Lookup Table

ErrorWhere you see itLikely causeFirst step
AttributeValueMustBeUniqueExport error, Connect HealthDuplicate UPN, mail, or proxyAddressRemove the duplicate value on-premises
InvalidSoftMatchExport errorCloud object already anchored to a different on-premises objectFix the duplicate, or hard match the right object
InvalidHardMatchExport errorHard match blocked by July 2026 hardeningRemove privileged role temporarily or clear onPremisesObjectIdentifier
ObjectTypeMismatchExport errorContact or group in the cloud owns the same addressDelete the stale cloud object
sync-generic-failureOperations tab, sync stepSync rule could not evaluateOpen the error, preview the object, fix the rule or source data
sync-rule-error-function-triggeredOperations tabA rule called Error() on purposeRead the message, fix the source data
dn-attributes-failureExport error on groupsMember objects have their own errorsFix the member objects first
DeletingCloudOnlyObjectNotAllowed (114)Export errorDelete of a restored or out-of-scope objectSoft-delete, sync, restore, sync
LargeObject / ExceededAllowedLengthExport errorToo many certificates (limit 15) or proxyAddressesRemove expired certificates and stale addresses
DataValidationFailedExport errorInvalid characters or format in UPNClean the value on-premises
Import from Microsoft Entra ID failedConnect Health, event logAuthentication or connectivity to the tenantCheck the run detail and sync account sign-ins
There was an issue obtaining cloud sync intervalsConnect wizardMFA/Conditional Access on the account, or networkRead the inner exception in %ProgramData%\AADConnect trace log
Password Hash Synchronization stopped workingConnect HealthSync engine or PHS agent stoppedRestart ADSync when idle

When to Escalate

Not every sync error can be resolved through self-service troubleshooting. Escalate to Microsoft support or your managed services provider when:

  • Sync has been broken for more than one full cycle and you cannot identify the root cause.
  • The Connect server is in a corrupted state and the wizard will not launch.
  • You suspect corruption in the metaverse or connector space databases.
  • An error ends with “Contact Technical Support” and persists after you follow Microsoft’s documented recovery steps.
  • A Microsoft service incident is affecting sync endpoints (check the Microsoft 365 Service Health Dashboard).
  • You need to upgrade to 2.6.84.0 and move to application-based authentication across multiple servers before the April 2027 deadline.

Sync errors left unresolved compound over time. A single attribute conflict today becomes dozens of orphaned objects next month. Treat sync errors with the same urgency as security incidents: investigate immediately, fix at the source, and confirm the fix holds across several sync cycles.

How Exodata Helps

Exodata runs hybrid identity for SMBs and mid-market teams every day: Connect Sync upgrades ahead of retirement dates, Cloud Sync migrations, Connect Health monitoring, and cleanup of the duplicate attributes that cause most export errors. If your sync is broken now or you need a plan for the 2027 deadline, talk to our team.

Frequently Asked Questions

How often does Entra Connect Sync run by default?

Microsoft Entra Connect Sync runs a delta sync cycle every 30 minutes by default. Full sync cycles run when explicitly triggered or after configuration changes. Microsoft Entra Cloud Sync runs every two minutes. If you customize the Connect Sync interval, a sync cycle still has to run at least once every 7 days.

Where are the Azure AD Connect sync logs located?

There is no single log file. Run history and per-object errors are in Synchronization Service Manager on the Operations tab. Service and password sync events are in the Windows Application event log under the ADSync and Directory Synchronization sources. Wizard install and configuration logs are trace files in the ProgramData\AADConnect folder. Cloud-side errors are in the Connect Health sync error report or, for Cloud Sync, the provisioning logs in the Microsoft Entra admin center.

What does sync-generic-failure mean in Azure AD Connect?

It means a synchronization rule could not be evaluated for an object during the sync step. Open the failed run in Synchronization Service Manager, click the error on an affected object to read the stack trace, and use the object preview to see which rule fails. Recent custom rule edits, missing source attributes, and TLS 1.2 or connectivity problems are the most common causes.

What is the minimum supported version of Entra Connect Sync?

All 1.x versions have stopped working. Each 2.x version is supported for 12 months after a newer one is released, and Microsoft requires every server to run version 2.6.84.0 or later with application-based authentication configured by April 7, 2027. Download the latest installer from the Microsoft Entra admin center.

Why are users created on-premises not appearing in Entra ID?

The most common causes are an OU or attribute filter that excludes the user, missing required attributes, an attribute conflict with an existing cloud object, or the user sitting in a sync error state. Search the AD connector space in Synchronization Service Manager for the object and review its lineage. If the object is not in the connector space at all, it is being filtered out before import.

Can I run Entra Connect Sync and Cloud Sync at the same time?

Yes, but never against the same set of objects. You can use Connect Sync for one forest or OU and Cloud Sync for another. Overlapping scopes create conflicting export operations and unpredictable results. Microsoft recommends moving fully to Cloud Sync where its feature set covers your needs.

How do I fix a “directory synchronization is paused” error?

Run Set-ADSyncScheduler -SyncCycleEnabled $true in PowerShell on the Connect server, make sure the Connect wizard is closed, and then trigger a delta sync with Start-ADSyncSyncCycle -PolicyType Delta. If sync was paused deliberately for a cleanup, confirm the cleanup is finished first.

Are sync errors caused by Active Directory replication problems?

Often, yes. If on-premises replication is broken, the sync engine can read stale data from one domain controller while users change passwords against another. Symptoms include attribute changes that revert, group memberships that disappear, and password changes that do not propagate. Run repadmin /replsummary and fix replication before chasing sync errors further.

What is the difference between hard match and soft match?

Soft match links an on-premises object to an existing cloud object by comparing proxyAddresses or userPrincipalName, and it only works if the cloud object has no immutableId yet. Hard match compares the source anchor, ms-DS-ConsistencyGuid by default, against the cloud object’s immutableId. Hard match is more precise, but since July 2026 Microsoft Entra ID blocks hard matches into accounts that hold privileged roles or already have an on-premises object identifier set.