A cloud-based identity and access management service for securing user authentication and resource access
I had this issue and fixed it by turning MFA off for the sync account.
This browser is no longer supported.
Upgrade to Microsoft Edge to take advantage of the latest features, security updates, and technical support.
At the end of the initial configuration wizard, the AAD Connect try to create a aad-sync account (Sync_AZURE-C_....).
After 5 Minutes it terminates with an unspecified error.
The Trace-File says that creation ist successful but 15 seconds later the authorization ist failed.
[11:26:05.687] [ 20] [INFO ] GetServiceAccount: successfully created a service account (Sync_AZURE-C_xxx@xxxxxxxxxxxxx .onmicrosoft.com). Sleeping an initial backoff time to facilitate account propagation.
The wizard try this for 5 minutes every 15s and end in the tracefile with
"[11:31:09.349] [ 20] [WARN ] [ERROR] GetServiceAccount: the retry time limit for service account authorization has been exceeded."
In the Azure-Portal, we can see that the account ist successfully created and some password change events were generated.
We also try to delete the generated sync account an try the whole procedure again- same result.
What should we do?
Cheers,
Steffen
A cloud-based identity and access management service for securing user authentication and resource access
I had this issue and fixed it by turning MFA off for the sync account.