Promoted Azure AD Connect server to domain controller and now virtual sync account used for service wont start

Thom Scott 26 Reputation points
2021-08-30T23:28:47.787+00:00

Hello,

Someone ended up adding the ADDS role to our Azure ad connect server.

When the server was initially setup, it was using a virtual service account for the Microsoft Azure AD sync service. See link below for details.

https://learn.microsoft.com/en-us/azure/active-directory/hybrid/concept-adsync-service-account

The documentation above says that a virtual service account cannot be used on a domain controller. I'm thinking this is why the service will no longer start.

What is the best way to correct this issue?

Active Directory
Active Directory
A set of directory-based technologies included in Windows Server.
6,244 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
20,629 questions
0 comments No comments
{count} votes

Accepted answer
  1. Andy David - MVP 145.6K Reputation points MVP
    2021-08-31T12:27:47.277+00:00
    1 person found this answer helpful.

2 additional answers

Sort by: Most helpful
  1. Thom Scott 26 Reputation points
    2021-08-31T17:02:11.49+00:00

    NVM the link from below states the only supported method for changing the service account is to reinstall.

    And since It is a DC, would be best to leave it only as a DC and not have multiple services running on it.

    https://learn.microsoft.com/en-us/azure/active-directory/hybrid/concept-adsync-service-account

    1 person found this answer helpful.

  2. Thom Scott 26 Reputation points
    2021-08-31T15:29:56.557+00:00

    why is that? There is nothing in AD Connect documentation stating you cant have AD connect installed on a domain controller.

    0 comments No comments