Synchronization Service Manager
The Synchronization Service Manager (SSM) is a critical tool for monitoring, configuring, and troubleshooting synchronization between on-premises Active Directory and Azure AD (formerly Entra ID). It provides insights into sync health, error logs, and operational status, enabling administrators to resolve issues proactively. This guide walks through using SSM alongside PowerShell cmdlets to manage sync processes effectively.
Monitoring Sync Status¶
Use SSM to check the synchronization service’s operational status and health.
Check Sync Service Status¶
Run the following PowerShell cmdlet to verify if the sync service is running:
Name : Microsoft Azure AD Sync
Status : Running
LastSyncTime : 2023-10-05 14:30:00
SyncHealthStatus : Healthy
Review Sync Health¶
Use Get-ADSyncHealth to assess overall sync health:
- SyncHealthStatus:
Healthy, Warning, or Error.- SyncErrors: Count of critical errors (e.g., connectivity issues).
- SyncWarnings: Count of non-critical warnings (e.g., attribute mismatches).
Analyze Sync Logs¶
Check detailed logs for errors or warnings:
Configuring Sync Settings¶
Adjust sync schedules, connection settings, and filters via SSM or PowerShell.
Set Sync Schedule¶
Modify the sync schedule using Set-ADSyncScheduler:
Update Connection Settings¶
Modify connection parameters (e.g., proxy settings) with Set-ADSyncConnection:
Configure Sync Filters¶
Adjust filtering rules to exclude specific objects:
Troubleshooting Common Issues¶
SSM and PowerShell cmdlets help identify and resolve sync failures.
Restart Sync Service¶
If sync stalls, restart the service:
Resolve Connectivity Errors¶
Check network connectivity and firewall rules. Use Test-ADSyncConnectivity to validate:
Fix Attribute Mismatches¶
Review attribute mappings in SSM under "Attribute Mappings". Use Get-ADSyncAttribute to audit mappings:
Key takeaways¶
- Use
Get-ADSyncHealthandGet-ADSyncLogto monitor sync status and debug errors. - Adjust sync schedules and filters with
Set-ADSyncSchedulerandSet-ADSyncFilter. - Restart the sync service with
Restart-ADSyncServicefor stalled processes. - Validate connectivity with
Test-ADSyncConnectivityto resolve network-related issues. - Regularly audit attribute mappings to prevent sync mismatches.