Problem with Azure Dynamic Group Membership after connect upgrade

James R. Atherton 21 Reputation points
2024-03-27T23:54:40.0266667+00:00

I upgraded my Azure Connect today to the latest version. Now, every time it syncs, all members of my dynamic groups get's wiped out, only to reassign people a few minutes later, sending users a slu of welcome emails, and stopping all SSO access for a short time every 20 or so minutes. As far as the logs show, it seems every other sync causes all members to be removed, and then the next sync re-adds them. What the heck could be going on here?

Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
19,299 questions
{count} votes

Accepted answer
  1. Akhilesh 4,455 Reputation points Microsoft Vendor
    2024-04-08T16:51:30.1233333+00:00

    Hi @James R. Atherton
    I'm glad that you were able to resolve your issue and thank you for posting your solution so that others experiencing the same thing can easily reference this! Since the Microsoft Q&A community has a policy that "The question author cannot accept their own answer. They can only accept answers by others ", I'll repost your solution in case you'd like to "Accept " the answer.Issue:

    I upgraded my Azure Connect today to the latest version. Now, every time it syncs, all members of my dynamic groups get's wiped out, only to reassign people a few minutes later, sending users a slu of welcome emails, and stopping all SSO access for a short time every 20 or so minutes. As far as the logs show, it seems every other sync causes all members to be removed, and then the next sync re-adds them. What the heck could be going on here?

    Solution:

    the mappings for the ExtensionAttributes have changed somewhat, so every other sync it would delete the extensionattribute, then add it, then delete it, then add it. Since my dynamic groups were based on them, they would empty and fill over and over. I found an arcane comment somewhere that uses a different attribute name, so I looked it up, and managed to make everything work.

    If you have any other questions or are still running into more issues, please let me know. Thank you again for your time and patience throughout this issue.

    Thanks,

    Akhilesh.

    Please remember to "Accept Answer" if any answer/reply helped, so that others in the community facing similar issues can easily find the solution.


0 additional answers

Sort by: Most helpful