Share via

Azure AD Connect Configuration Error

Steffen Horlbeck 1 Reputation point
2020-08-27T10:31:32.733+00:00

At the end of the initial configuration wizard, the AAD Connect try to create a aad-sync account (Sync_AZURE-C_....).
After 5 Minutes it terminates with an unspecified error.
The Trace-File says that creation ist successful but 15 seconds later the authorization ist failed.
[11:26:05.687] [ 20] [INFO ] GetServiceAccount: successfully created a service account (Sync_AZURE-C_xxx@xxxxxxxxxxxxx .onmicrosoft.com). Sleeping an initial backoff time to facilitate account propagation.

The wizard try this for 5 minutes every 15s and end in the tracefile with
"[11:31:09.349] [ 20] [WARN ] [ERROR] GetServiceAccount: the retry time limit for service account authorization has been exceeded."
In the Azure-Portal, we can see that the account ist successfully created and some password change events were generated.
We also try to delete the generated sync account an try the whole procedure again- same result.
What should we do?
Cheers,
Steffen

Microsoft Security | Microsoft Entra | Microsoft Entra ID

1 answer

Sort by: Most helpful
  1. Dan Jenkin 1 Reputation point
    2021-10-06T20:16:48.023+00:00

    I had this issue and fixed it by turning MFA off for the sync account.

    Was this answer helpful?

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.