Hi anonymous user • Thank you for reaching out.
The error Dn-Attribute-failure
usually occurs when there are duplicate attribute values exist for 2 or more users/groups/contacts in the on-premises domain but those values cannot be assigned to multiple users in Azure AD. For example, you can have the same SMTP/Proxy address configured for 2 users in local AD, but when you sync those users to Azure AD, you will encounter a Dn-Attribute-failure
error as the value of these attributes must be unique for every user in Azure AD.
To resolve this error, you need to correct/change the duplicate attributes in your on-premises AD.
After making the changes in your local AD, run Start-ADSyncSyncCycle -PolicyType Initial
to run a full sync cycle.
Note: You can try changing duplicate attributes for a very small set of users and confirm that you no longer get the Dn-Attribute-failure
error for those users before making these changes for all the affected users.
Read more: End-to-end troubleshooting of Azure AD Connect objects and attributes
-----------------------------------------------------------------------------------------------------------
Please "Accept the answer" if the information helped you. This will help us and others in the community as well.