Skip to content

Commit 55338e4

Browse files
committed
Learn Editor: Update troubleshoot-pwd-sync.md
1 parent 1088f97 commit 55338e4

1 file changed

Lines changed: 29 additions & 26 deletions

File tree

support/entra/entra-id/user-prov-sync/troubleshoot-pwd-sync.md

Lines changed: 29 additions & 26 deletions
Original file line numberDiff line numberDiff line change
@@ -6,7 +6,7 @@ ms.reviewer: willfid
66
ms.service: entra-id
77
ms.custom: sap:Microsoft Entra Connect Sync
88
---
9-
# How to troubleshoot password synchronization when using an Azure AD sync appliance
9+
# How to troubleshoot password synchronization when using Microsoft Entra Connect
1010

1111
This article helps you troubleshoot common issues that you may encounter when you synchronize passwords from the on-premises environment to Microsoft Entra ID by using [Microsoft Entra Connect](/azure/active-directory/hybrid/whatis-azure-ad-connect).
1212

@@ -21,9 +21,9 @@ Before you perform the troubleshooting steps, make sure that you have the [lates
2121

2222
Additionally, make sure that directory synchronization is in a healthy state. For more information, see [Troubleshoot object synchronization with Microsoft Entra Connect Sync](/azure/active-directory/hybrid/tshoot-connect-objectsync).
2323

24-
## Some users can't sign in to Office 365, Azure, or Microsoft Intune
24+
## Some users can't sign in to Microsoft 365, Microsoft Entra, or Microsoft Intune
2525

26-
In this scenario, passwords of most users appear to be syncing. However, there are some users whose passwords appear not to sync. The following are scenarios in which a user can't sign in to a Microsoft cloud service, such as Office 365, Azure, or Intune.
26+
In this scenario, passwords of most users appear to be syncing. However, there are some users whose passwords appear not to sync. The following are scenarios in which a user can't sign in to a Microsoft cloud service, such as Microsoft 365, Entra, or Intune.
2727

2828
### Scenario 1: The "User must change password at next logon" check box is selected for the user's account
2929

@@ -32,7 +32,8 @@ To resolve this issue, follow these steps:
3232
1. Take one of the following actions:
3333
- In the user account properties in Active Directory Users and Computers, clear the **User must change password at next logon** check box.
3434
- Have the user change their on-premises user account password.
35-
- Enable the [ForcePasswordChangeOnLogOn](/azure/active-directory/hybrid/how-to-connect-password-hash-synchronization#synchronizing-temporary-passwords-and-force-password-change-on-next-logon) feature on the Microsoft Entra Connect server.
35+
- Enable the [ForcePasswordChangeOnLogOn](/azure/active-directory/hybrid/how-to-connect-password-hash-synchronization#synchronizing-temporary-passwords-and-force-password-change-on-next-logon) feature in Microsoft Entra ID.
36+
3637
2. Wait a few minutes for the change to sync between the on-premises Active Directory Domain Services (AD DS) and Microsoft Entra ID.
3738

3839
### Scenario 2: The user changed their password in the cloud service portal
@@ -42,7 +43,7 @@ To resolve this issue, follow these steps:
4243
1. Have the user change their on-premises user account password.
4344
2. Wait a few minutes for the change to sync between the on-premises AD DS and Microsoft Entra ID.
4445

45-
<a name='scenario-3-some-users-dont-appear-to-be-syncing-to-azure-ad'></a>
46+
<a name='scenario-3-some-users-dont-appear-to-be-syncing-to-azure-ad'></a>To change the password in the cloud service and have Microsoft Entra Connect update the respective on-premises user account password, you can implement [Password Writeback](/entra/identity/authentication/tutorial-enable-sspr-writeback).
4647

4748
### Scenario 3: Some users don't appear to be syncing to Microsoft Entra ID
4849

@@ -52,38 +53,40 @@ To resolve this issue, use the IdFix DirSync Error Remediation Tool (IdFix) to h
5253

5354
For more info about how to troubleshoot this issue, see [One or more objects don't sync when using the Azure Active Directory Sync tool](objects-dont-sync-ad-sync-tool.md)
5455

55-
### Scenario 4: Users are moved between filtered and unfiltered scopes
56+
### Scenario 4: Users are moved between included and excluded sync scopes
5657

5758
In this scenario, the user is moved to a scope that now allows the user to be synced. It could be when filtering is set up for domains, organizational units, or attributes.
5859

59-
To resolve this issue, see the **How to perform a full password sync** section.
60+
To resolve this issue, see the **How to perform an initial sync** section.
6061

6162
### Scenario 5: Users can't sign in by using a new password but they can sign in by using their old password
6263

63-
In this scenario, you're using the Azure AD Sync Service together with password synchronization. After you disable and then re-enable directory synchronization, users can't sign in by using a new password. However, their old password still works.
64+
In this scenario, you're using Microsoft Entra Connect together with password synchronization. After you disable directory synchronization or password synchronization, users can't sign in by using a new password. However, their old password still works.
6465

65-
To resolve this issue, re-enable password synchronization. To do it, start the Azure AD sync appliance Configuration Wizard, and then continue through the screens until you see the option to enable password synchronization.
66+
To resolve this issue, re-enable directory synchronization and password synchronization. To do it, start Microsoft Entra Connect configuration wizard, select **Configure** and **Customize synchronization options**, then continue through the screens until you see the option to enable password synchronization.
6667

6768
### Scenario 6: Users can't sign in by using their password
6869

69-
In this scenario, the password hash doesn't successfully sync to the Azure AD Sync Service. If the user account was created in Active Directory running on a version of Windows Server earlier than Windows Server 2003, the account doesn't have a password hash.
70+
In this scenario, the password hash doesn't successfully sync to Microsoft Entra ID. If the user account was created in on-premsises Active Directory running on a version of Windows Server earlier than Windows Server 2003, the account doesn't have a password hash.
7071

7172
## Directory synchronization is running but passwords of all users aren't synced
7273

7374
In this scenario, passwords of all users appear not to sync. It usually occurs if one of the following conditions is true:
7475

75-
- The **Synchronize now** check box wasn't selected.
76-
- You enabled password synchronization after directory sync already occurred.
76+
- The check box to **Start the synchronization process when configuration completes**, wasn't selected.
77+
78+
- Entra Connect server is in Staging mode.
79+
80+
- Password synchronization is disabled.
81+
7782
- A full directory sync hasn't yet completed.
7883

7984
> [!IMPORTANT]
8085
> Password sync will not start until a full directory sync has completed.
8186
82-
To resolve this issue, first make sure that you enable password synchronization. To do it, start the Azure AD sync appliance Configuration Wizard, and then continue through the screens until you see the option to enable password synchronization.
87+
To resolve this issue, first make sure that you enable password synchronization. To do it, start Microsoft Entra Connect configuration wizard, select **Configure** and **Customize synchronization options**, then continue through the screens until you see the option to enable password synchronization.
8388

84-
After password synchronization is enabled, you must do a full password sync. See How to perform a full password sync section.
85-
86-
For more information, see [Troubleshoot password hash synchronization with Microsoft Entra Connect Sync](/azure/active-directory/hybrid/tshoot-connect-password-hash-synchronization#one-object-is-not-synchronizing-passwords-troubleshoot-by-using-the-troubleshooting-task).
89+
After password synchronization is enabled, you must wait for a full password sync to finish. Check the Windows [Event Viewer logs](/troubleshoot/entra/entra-id/user-prov-sync/troubleshoot-pwd-sync#event-id-messages-in-event-viewer) to monitor the password synchronization process.
8790

8891
## Troubleshoot one user whose password isn't synced
8992

@@ -137,28 +140,28 @@ The following tables list event ID messages in the Application log that are rela
137140

138141
## More information
139142

140-
### How to perform a full password sync
141-
142-
To do a full password sync, follow these steps, as appropriate for the Azure AD Sync appliance that you're using.
143+
### How to perform an initial sync
143144

144-
1. If you're using the Azure Active Directory Sync tool:
145+
To do a full sync, follow these steps, as appropriate on the Microsoft Entra Connect that you're using.
145146

146-
1. On the server where the tool is installed, open PowerShell, and then run the following command:
147+
1. On the server where Microsoft Entra Connect is installed, open PowerShell, and then run the following command:
147148

148149
```powershell
149150
Import-Module DirSync
150151
```
151-
152-
2. Run the following commands:
153-
152+
153+
2. Run the following commands:
154+
154155
```powershell
155156
Set-FullPasswordSync
156157
```
157-
158+
158159
```powershell
159160
Restart-Service FIMSynchronizationService -Force
160161
```
162+
163+
### How to perform a full password sync
161164
162-
2. If you're using the Azure AD Sync Service or Microsoft Entra Connect, run the script that's on this page: [Azure AD Sync: How to Use PowerShell to Trigger a Full Password Sync](/archive/technet-wiki/28433.azure-ad-sync-how-to-use-powershell-to-trigger-a-full-password-sync)
165+
To do a full password sync, run the script that's on this page: [Azure AD Sync: How to Use PowerShell to Trigger a Full Password Sync](/archive/technet-wiki/28433.azure-ad-sync-how-to-use-powershell-to-trigger-a-full-password-sync)
163166
164167
[!INCLUDE [Azure Help Support](../../../includes/azure-help-support.md)]

0 commit comments

Comments
 (0)