Unable to access Sync services, AD FS services, AD DS services with Azure Active Directory P1 licensing

Zach Logsdon 31 Reputation points
2022-05-20T18:24:21.703+00:00

Upon decommissioning a server from Azure AD Connect and moving to all non-synced accounts, we ran into 7 sync errors listed under "Other" within our Azure AD Connect Health blade.

Support chat suggested that I use an Azure Active Directory P1 license to allow for access to Sync services, AD FS services, and AD DS services to remove the decommissioned server from the list to stop the errors. Even after applying the license to my admin account, I do not have access to these sections to do the server removal.

I get the following error message:

The caller is not authorized.

Session ID: (not including for potential identity risk)
Extension: Microsoft_Azure_ADHybridHealth
Resource ID: Not available
Content: CommonServiceListBlade
Error code: 401

My account is listed as a Global administrator in Azure AD and for Role based access control, is listed as an Owner in Azure AD Connect Health.
We have confirm that the Microsoft.ADHybridHealthService resource is registered in our subscription.

Microsoft Security | Microsoft Entra | Microsoft Entra ID
{count} vote

Answer accepted by question author
  1. Cristian SPIRIDON 4,486 Reputation points Volunteer Moderator
    2022-05-22T04:48:20.157+00:00

    Hi,

    If you want to remove a server from AD Sync then you can follow below instructions:

    https://learn.microsoft.com/en-us/azure/active-directory/hybrid/how-to-connect-health-operations#delete-a-server-or-service-instance

    Hope this helps!


0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.