Unable to create the synchronization service account for Azure Active Directory.

adminmtsaglik 0 Reputation points
2024-03-28T15:54:22.7533333+00:00

Unable to create the synchronization service account for Azure Active Directory.

Active Directory
Active Directory
A set of directory-based technologies included in Windows Server.
6,639 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
22,107 questions
{count} votes

2 answers

Sort by: Most helpful
  1. Thameur-BOURBITA 33,006 Reputation points
    2024-03-28T15:59:38.2533333+00:00

    Hi @adminmtsaglik

    You can refer to the following link to create and configure the service account :

    Microsoft Entra Connect: Accounts and permissions

    Please don't forget to accept helpful answer

    1 person found this answer helpful.

  2. Marilee Turscak-MSFT 36,866 Reputation points Microsoft Employee
    2024-04-03T21:43:16.34+00:00

    Hi @adminmtsaglik ,

    I understand that you are having trouble creating the synchronization service account for Entra ID Connect.

    If you are seeing the error "Unable to create the synchronization service account", the most common root cause would be a Conditional Access/MFA policy which requests registration of your connector account user. To resolve this, you can exclude this user from Conditional Access/MFA policies.

    Other possible things to check:

    • Make sure you check the legacy per-user MFA settings in the Admin Portal as well through the direct link to the relevant portal here. Alternatively, you can search for "MFA" in the top search bar within the M365 admin center and select "Multi-factor authentication" under Settings. If MFA is set to enabled, the account will be blocked from signing in and you will need to set it to "Disabled." Then restart the wizard.
    • To isolate the issue, login with an admin account > check sign-in logs under Monitoring > check the user sign-in logs and non-interactive log to review the failure. You can either remove the service account from any blocking policies or exclude your IP range from the policies.
    • Ensure that TLS 1.2 is enabled to allow successful authentication.

    If you still face an issue after excluding the account, it would help a lot if you could provide any error messages that you face when trying to create the account like Girish requested. With only the information provided it is harder to isolate the root cause.

    If the information helped you, please Accept the answer. This will help us as well as others in the community who may be researching similar questions.

    1 person found this answer helpful.

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.