Azure AD Connect dn-attributes-failure Sync Error

KRW Admin 10 Reputation points
2023-07-11T19:53:45.5033333+00:00

I'm getting dn-attributes-failure sync errors for AD security groups in Azure AD Connect. From what I could find the two likely causes are disabled AD users being members of the on-prem group and two on-prem AD groups having duplicate attributes. I've removed all disabled AD users from the affected AD groups and done an initial resync though, and that did not resolve the issue, and it looks like none of the groups have any identical properties, so that's not the issue.

Has anyone else had a similar issue?

Active Directory
Active Directory
A set of directory-based technologies included in Windows Server.
6,405 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
21,272 questions
0 comments No comments
{count} votes

2 answers

Sort by: Most helpful
  1. Harpreet Singh Matharoo 7,781 Reputation points Microsoft Employee
    2023-07-12T05:56:29.8266667+00:00

    Hello @KRW Admin

    Thank you for reaching out. The error Dn-Attribute-failure on AD Security Groups usually occurs when there are users with duplicate attribute values in the on-premises domain and are part of the group being sync'd to Azure AD. For example, you can have the same SMTP/Proxy address configured for 2 users in local AD, but when you sync those users to Azure AD, you will encounter a Dn-Attribute-failure error for all the AD Security Group user is part of.

    To resolve this error, you need to correct the duplicate attributes in your on-premises AD all the users who are part of the affected group. After making the changes in your local AD, run Start-ADSyncSyncCycle -PolicyType Initial to run a full sync cycle.

    Read more: End-to-end troubleshooting of Azure AD Connect objects and attributes


    Please "Accept the answer" if the information helped you. This will help us and others in the community as well.

    3 people found this answer helpful.

  2. EME IT 0 Reputation points
    2024-03-19T11:14:05.1+00:00

    Good morning!

    @Harpreet Singh Matharoo
    How do I resolve this error? I have already resolved the user errors, now it appears in the groups.

    https://learn.microsoft.com/pt-br/entra/identity/hybrid/connect/tshoot-connect-sync-errors

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.