Azure AD Connect - cannot configure

Frederico Gil 0 Reputation points
2023-09-05T16:24:33.3666667+00:00

Hello,

I had "successfully" running AD Connect (password hash sync) with my on-premise AD with version 2.0.3.0.

When I try install version 2.1 or above of AD Connect I received this error. Only I can install version 2.0.3.0 or below.

I check all thinks, like permissions of the global admin and enterprise admin and only received this error in specific ad connect version.

[ 27] [ERROR] ConfigSyncDirectoriesPage: Caught exception while creating the connector for directory: "localdomain"

Exception Data (Raw): System.Management.Automation.CmdletInvocationException: Failed to retrieve schema.<error><error><incident><connection-result>failed-authentication</connection-result><date>2023-09-05 15:25:04.318</date><server>localdomain389</server><cd-error><error-code>0x31</error-code>

<error-literal>Invalid Credentials</error-literal>

</cd-error></incident></error></error> ---> Microsoft.IdentityManagement.PowerShell.ObjectModel.SynchronizationConfigurationValidationException: Failed to retrieve schema.<error><error><incident><connection-result>failed-authentication</connection-result><date>2023-09-05 15:25:04.318</date><server>"localdomain":389</server><cd-error><error-code>0x31</error-code>

<error-literal>Invalid Credentials</error-literal>

</cd-error></incident></error></error>

[Image

](https://filestore.community.support.microsoft.com/api/images/32f0c3e8-0c57-4b99-be6e-52eb7fafdd56?upload=true&fud_access=wJJIheezUklbAN2ppeDns8cDNpYs3nCYjgitr%2bfFBh2dqlqMuW7np3F6Utp%2fKMltnRRYFtVjOMO5tpbpW9UyRAwvLeec5emAPixgq9ta07Dgnp2aq5eJbnfd%2fU3qhn540fK1gSUfyTjdnhzETwtRYkb0U7v64nE9%2bu9vstU1NPcQjKxJlSOAxl0kt%2fAck3uBcrthE2k1iS70%2b7Rlog57BsK9Io10mLRWdlk9g8rpGajTkvhdcfW5rcfwAAqhfX6d6ogd3%2frXTKhzhcYkI%2bnSithWQ9Pmy6RIY7IKHGKQixJxJ7GLsFi7lmgiqYUiDemUmDA979YtLI8sJGcFLSQSjbkMZGl3q4EqlXTtYqsv7cIPJDo3xfdd3dImG6%2bhlg0guC734vhqcS6yeHi9EQckrxFvmLsq9mLIh0wUFiC6qiw%3d"filestore.community.support.microsoft.com")

than you for help

Active Directory
Active Directory
A set of directory-based technologies included in Windows Server.
6,658 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
22,171 questions
{count} votes

1 answer

Sort by: Most helpful
  1. Marilee Turscak-MSFT 36,886 Reputation points Microsoft Employee
    2023-09-06T22:56:01.4333333+00:00

    Hi @Frederico Gil ,

    It looks like you are getting the "Invalid Credentials" error right after the other error. Please make sure that you are entering the valid domain user credentials and that the user has read access and MFA enabled. Is the GA account in a federated domain and does the GA account have MFA enabled? Try to check on sign-in logs to see if the Cloud connector account is having any restriction on logging in

    If this does not help, one thing you can try is to create separate enterprise admins for all domains to restore the access.

    Another possibility is that the AD connect server is not able to reach the Active directory domain controllers. This could be because of incorrect routing or because you have ports blocked on the network. Make sure traffic is allowed on ports documented at https://docs.microsoft.com/en-us/azure/active-directory/hybrid/reference-connect-ports#table-1---azure-ad-connect-and-on-premises-ad

    If you still face this issue after checking these variables, let me know.

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.