Entra Connect Directory Synchronization timing

Billy Kunstek 20 Reputation points
2024-12-18T18:46:51.75+00:00

Our SSPR process has been taking upwards of 7 minutes to update password via the Entra Connect password writeback feature and users were unable to log into their Intune cloud only machines until the password writeback was finished. We identified that we were running an outdated version of Entra Connect and updated to the lastest via a Swing Migration.

Once this migration was completed we appear to still be seeing delays for longer then a minute at times and other times it can be instant for the end user.

Below example:
User initiated SSPR at 5:07:11 PM , on premises domain controller received and updated the password by 5:07:20 PM CST. The user was unable to have a successful log in with Entra until 5:09:05 PM CST for a total login failure delay of 114 seconds.

When looking at the Entra Connect logs and the on premises domain controller the password change was seemingly instant but the Directory Synchronization events didn't report back till the 114 second mark. Is this an event delay from on prem to the Entra Connect server we would need to look into?

User's image

Microsoft Security | Microsoft Entra | Microsoft Entra ID
0 comments No comments
{count} votes

Accepted answer
  1. Andy David - MVP 157.8K Reputation points MVP Volunteer Moderator
    2024-12-18T19:09:57.65+00:00
    1 person found this answer helpful.

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.