Failure with Azure AD sync service credentials error.

18203024 0 Reputation points

Now through some digging I found that this can be a result of a mimatch with the AD sync connect user. Now I followed these directions

I have located the MSOL account within the Synchronization service manager. when I highlight my on prem connector, I see the Profile Name ourdomain\AAD_ which IS in our on prem. so is the MSOL username I am seeing when I click properties of the connector and connect to active directory forest just a place holder? Can I just change the username to the AAD and update the password?

Azure Active Directory
Azure Active Directory
An Azure enterprise identity service that provides single sign-on and multi-factor authentication.
16,536 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Sandeep G-MSFT 9,391 Reputation points Microsoft Employee


    Thank you for posting your question in Microsoft Q&A.

    Account which starts with MSOL_ is the account that gets created and used to pull any changes from on-premises. The account is created with a long, complex password that doesn't expire. If you have a password policy in your domain, make sure that long and complex passwords are allowed for this account.

    And account that starts with AAD_ is the service account that gets created under which AD connect service runs. The AAD_ service account is created with a long, complex password that doesn't expire. A user account prefixed with AAD_ is created during installation only when Azure AD Connect is installed on Windows Server 2008 and when it's installed on a domain controller.

    We would suggest not to change the user name to AAD for MSOL account.

    Regarding the accounts in AD connect you can also refer below article,

    Let me know if you have any further questions.

    Please "Accept the answer" if the information helped you. This will help us and others in the community as well.

    0 comments No comments