Unable to access Sync services, AD FS services, AD DS services with Azure Active Directory P1 licensing

Zach Logsdon 31 Reputation points
2022-05-20T18:24:21.703+00:00

Upon decommissioning a server from Azure AD Connect and moving to all non-synced accounts, we ran into 7 sync errors listed under "Other" within our Azure AD Connect Health blade.

Support chat suggested that I use an Azure Active Directory P1 license to allow for access to Sync services, AD FS services, and AD DS services to remove the decommissioned server from the list to stop the errors. Even after applying the license to my admin account, I do not have access to these sections to do the server removal.

I get the following error message:

The caller is not authorized.

Session ID: (not including for potential identity risk)
Extension: Microsoft_Azure_ADHybridHealth
Resource ID: Not available
Content: CommonServiceListBlade
Error code: 401

My account is listed as a Global administrator in Azure AD and for Role based access control, is listed as an Owner in Azure AD Connect Health.
We have confirm that the Microsoft.ADHybridHealthService resource is registered in our subscription.

Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
19,473 questions
{count} vote

Accepted answer
  1. Cristian SPIRIDON 4,471 Reputation points
    2022-05-22T04:48:20.157+00:00

    Hi,

    If you want to remove a server from AD Sync then you can follow below instructions:

    https://learn.microsoft.com/en-us/azure/active-directory/hybrid/how-to-connect-health-operations#delete-a-server-or-service-instance

    Hope this helps!


0 additional answers

Sort by: Most helpful