Promoted Azure AD Connect server to domain controller and now virtual sync account used for service wont start

Thom Scott 26 Reputation points


Someone ended up adding the ADDS role to our Azure ad connect server.

When the server was initially setup, it was using a virtual service account for the Microsoft Azure AD sync service. See link below for details.

The documentation above says that a virtual service account cannot be used on a domain controller. I'm thinking this is why the service will no longer start.

What is the best way to correct this issue?

Active Directory
Active Directory
A set of directory-based technologies included in Windows Server.
6,057 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
20,081 questions
0 comments No comments
{count} votes

Accepted answer
  1. Andy David - MVP 143.6K Reputation points MVP
    1 person found this answer helpful.

2 additional answers

Sort by: Most helpful
  1. Thom Scott 26 Reputation points

    NVM the link from below states the only supported method for changing the service account is to reinstall.

    And since It is a DC, would be best to leave it only as a DC and not have multiple services running on it.

    1 person found this answer helpful.

  2. Thom Scott 26 Reputation points

    why is that? There is nothing in AD Connect documentation stating you cant have AD connect installed on a domain controller.

    0 comments No comments