I would migrate to a new server
https://learn.microsoft.com/en-us/azure/active-directory/hybrid/how-to-connect-import-export-config
This browser is no longer supported.
Upgrade to Microsoft Edge to take advantage of the latest features, security updates, and technical support.
Hello,
Someone ended up adding the ADDS role to our Azure ad connect server.
When the server was initially setup, it was using a virtual service account for the Microsoft Azure AD sync service. See link below for details.
https://learn.microsoft.com/en-us/azure/active-directory/hybrid/concept-adsync-service-account
The documentation above says that a virtual service account cannot be used on a domain controller. I'm thinking this is why the service will no longer start.
What is the best way to correct this issue?
I would migrate to a new server
https://learn.microsoft.com/en-us/azure/active-directory/hybrid/how-to-connect-import-export-config
NVM the link from below states the only supported method for changing the service account is to reinstall.
And since It is a DC, would be best to leave it only as a DC and not have multiple services running on it.
https://learn.microsoft.com/en-us/azure/active-directory/hybrid/concept-adsync-service-account
why is that? There is nothing in AD Connect documentation stating you cant have AD connect installed on a domain controller.