Share via

AADDS104 critical alert without any changes to nsg

Mim Kol 0 Reputation points
2026-02-24T05:00:15.3333333+00:00
Managed domain reporting AADDS104 (Critical) – “Microsoft is unable to reach the domain controllers.”

No NSG, DNS, UDR, or peering changes were made.
Internal connectivity verified:
- LDAP 389 reachable
- DC IPs responding
- Replica set shows Running

Restart option is not available in the current portal UI.

This appears to be a backend connectivity or replica heartbeat issue.
Please perform backend health verification and restart replica set if necessary.
Region: West US 2
Replica Set: aadds-vnet/aadds-subnet
Microsoft Security | Microsoft Entra | Microsoft Entra ID
{count} votes

1 answer

Sort by: Most helpful
  1. Sridevi Machavarapu 22,120 Reputation points Microsoft External Staff Moderator
    2026-02-24T07:13:39.7266667+00:00

    Hello Mim Kol,

    Thank you for the update. I’m glad to hear the alert has cleared.

    No manual restart or refresh was performed from our side. Based on the behavior, the alert appears to have resolved on its own.

    Alerts such as AADDS104 can sometimes appear temporarily during backend service maintenance or internal health checks in Microsoft Entra Domain Services. During this time, the alert may remain visible even though the managed domain continues to function normally. Once the backend health checks complete and connectivity signals stabilize, the alert typically clears automatically.

    Since the alert has now disappeared and there were no reported issues with domain join, authentication, or LDAP connectivity, the managed domain can be considered healthy.

    If you notice the alert again or experience any service impact, please feel free to reach out.

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.