Skip to content

Password Hash Sync

Password hash synchronization errors in Entra ID Connect can disrupt identity synchronization between on-premises Active Directory (AD) and Azure AD. These errors often stem from misconfigurations, connectivity issues, or service disruptions. This section outlines methods to diagnose and resolve common password hash sync errors.


1. Verify Sync Service Status and Logs

The Azure AD Connect sync service must be running and healthy. Use PowerShell to check its status and review logs for detailed error messages.

Commands:

# Check sync service status
Get-ADSyncService | Select-Object Status, LastSyncTime

# Restart the sync service if needed
Restart-ADSyncService

Log Location:
Sync logs are stored at:
C:\ProgramData\Microsoft\AzureADSync\Logs
Use Get-ADSyncLog to filter relevant entries. For example:

Get-ADSyncLog -Filter {EventID -eq "SyncError"} | Format-List

Log Level Adjustment (for deeper diagnostics):

Set-ADSyncLogLevel -LogLevel Verbose


2. Test Network Connectivity

Password hash sync relies on secure communication between on-premises AD and Azure AD. Ensure DNS resolution, firewall rules, and port accessibility are correct.

Commands:

# Test connectivity to Azure AD
Test-Connectivity -SyncServiceAccount "[email protected]" -SyncServicePassword "SecurePassword123!"

# Verify DNS resolution for Azure AD endpoints
Resolve-DnsName -Name "globalcatalog.contoso.com" -Type SRV

Firewall Requirements:
Ensure ports 88 (Kerberos), 389 (LDAP), and 636 (LDAPS) are open between on-premises AD and Azure AD.


3. Validate Sync Configuration

Misconfigured sync rules or password policies can trigger errors. Check the following:

  • Password Settings: Ensure on-premises AD passwords meet Azure AD requirements (e.g., length, complexity).
  • Sync Rules: Use Get-ADSyncRule to verify password sync rules are enabled.
  • Sync Account Permissions: Confirm the sync service account has Replicating Directory Changes permissions on the domain controller.

Example:

Get-ADSyncRule -Filter {Name -eq "PasswordHashSyncRule"} | Select-Object Enabled, LastRunStatus


4. Address Account Lockouts

Sync service accounts or user accounts can become locked out, causing sync failures.

Steps:
1. Check for lockouts using Azure AD Connect Health:
- Navigate to Azure AD Connect Health > Sync Health > Account Lockouts.
2. Temporarily disable lockout policies for the sync service account if needed.

Note: Avoid disabling lockout policies permanently; use temporary overrides for troubleshooting.


5. Re-run the Sync Cycle

For intermittent errors, manually trigger a sync cycle to isolate issues:

Start-ADSyncSyncCycle -PolicyType Delta

Monitor the sync status with:

Get-ADSyncSyncCycleCoverage -PolicyType Delta


Key takeaways

  • Check sync service status and logs for actionable error codes.
  • Verify network connectivity and firewall rules for Kerberos/LDAP traffic.
  • Validate sync configurations (rules, passwords, permissions) to align with Azure AD requirements.
  • Monitor for account lockouts using Azure AD Connect Health.
  • Manually trigger sync cycles to test resolution of transient errors.