Jump to content

Recommended Posts

Posted

Hi,

 

I am having difficulty getting my domain to sync accross to Office 365. I have installed the DirSync tools many many times now and keep hitting the same error. The configuration runs great, but when I come to do a sync, two management agents run;

 

Active Directory Connector - SUCCESS

Windows Azure Active Directory Connector - STOPPED-SERVER-DOWN

 

Every article I have found seems to suggest that this happens because the azure account has an expired password, but I have checked and this is not the case. I can use the account to connect to Office365 via Powershell from the same machine and I can login to the portal with no problems at all.

 

Can anyone help?

 

Thanks

Mike

Posted

Try resetting the password for the user in any case, even if it hasn't or isn't due to expire. :)

 

You'll need to run through the DirSync config again just to be on the safe side. I hit this issue the other day, bugged the hell out of me. Resetting the Office 365 user password sorted it.

  • Thanks 1
Posted
Its an existing one, I have come back to it after about 30 days of leaving it (due to summer break) and its not working. It has been working for the better part of 6 months.
Posted (edited)
I have done James, several times... :( I think I have become an expert at resetting the password he he Edited by mbedford
Posted
Its an existing one, I have come back to it after about 30 days of leaving it (due to summer break) and its not working. It has been working for the better part of 6 months.

 

And is DIRSync the only thing you have running on it ?

 

Only reason I ask is I had the same issue a few weeks back. Randomly the service stopped and wouldn't start then when I started looking into groups and security some weren't there. But they were services and accounts set up during the install.

 

So rather than spend ages trying to diagnose I just recreated the DIR Sync server

  • Thanks 1
Posted

That's not a bad shout. Its on an application server at the moment with about 10 other licensing services for things like AutoCAD and SolidWorks etc...

I think I will create a separate VM for it, for the sake of 2 hours work its worth ago.

 

The-Dude - Yes I did that today hoping that it would be fixed by doing that.

 

I will try a new server tomorrow.

 

Thanks

Mike

Posted

Hi,

 

Can you please look at the event log, and give me the IDs that have been logged?

 

You might need to ensure you are running the latest version of the DirSync Software as I am sure you can see from recent threads on here many people have experienced issues recently.

 

Regards,

James.

  • Thanks 1
Posted

hi james

 

I will take a look in the morning and post the events here here. As far as the dirsync versions go, it's the latest version as of today, I noticed that problem in the forum posts around this one, thanks for the suggestion though.

 

Mike

 

sent from my android phone

Posted

Hello,

 

I have a built a new 2012 server today specifically for DirSync. Same error has occurred :-(

 

Please see eventlog entries below

 

ProvisioningServiceAdapter::ExecuteWithRetry: Action: Import, Attempt: 3, Exception: Microsoft.Online.Coexistence.ProvisionRetryException: Unable to communicate with the Windows Azure Active Directory service. Tracking ID: 003fd61a-b71d-4932-83aa-711b0c253d99 See the event log for more details. ---> System.ServiceModel.EndpointNotFoundException: There was no endpoint listening at https://adminwebservice.microsoftonline.com/provisioningservice.svc that could accept the message. This is often caused by an incorrect address or SOAP action. See InnerException, if present, for more details. ---> System.Net.WebException: Unable to connect to the remote server ---> System.Net.Sockets.SocketException: A socket operation encountered a dead network 157.56.55.72:443

at System.Net.Sockets.Socket.DoConnect(EndPoint endPointSnapshot, SocketAddress socketAddress)

at System.Net.ServicePoint.ConnectSocketInternal(Boolean connectFailure, Socket s4, Socket s6, Socket& socket, IPAddress& address, ConnectSocketState state, IAsyncResult asyncResult, Exception& exception)

--- End of inner exception stack trace ---

at System.Net.HttpWebRequest.GetRequestStream(TransportContext& context)

at System.Net.HttpWebRequest.GetRequestStream()

at System.ServiceModel.Channels.HttpOutput.WebRequestHttpOutput.GetOutputStream()

--- End of inner exception stack trace ---

 

Server stack trace:

at System.ServiceModel.Channels.HttpOutput.WebRequestHttpOutput.GetOutputStream()

at System.ServiceModel.Channels.HttpOutput.Send(TimeSpan timeout)

at System.ServiceModel.Channels.HttpChannelFactory`1.HttpRequestChannel.HttpChannelRequest.SendRequest(Message message, TimeSpan timeout)

at System.ServiceModel.Channels.RequestChannel.Request(Message message, TimeSpan timeout)

at System.ServiceModel.Channels.ServiceChannel.Call(String action, Boolean oneway, ProxyOperationRuntime operation, Object[] ins, Object[] outs, TimeSpan timeout)

at System.ServiceModel.Channels.ServiceChannelProxy.InvokeService(IMethodCallMessage methodCall, ProxyOperationRuntime operation)

at System.ServiceModel.Channels.ServiceChannelProxy.Invoke(IMessage message)

 

Exception rethrown at [0]:

at System.Runtime.Remoting.Proxies.RealProxy.HandleReturnMessage(IMessage reqMsg, IMessage retMsg)

at System.Runtime.Remoting.Proxies.RealProxy.PrivateInvoke(MessageData& msgData, Int32 type)

at Microsoft.Online.Coexistence.Schema.IProvisioningWebService.ReadBack(Byte[] inputCookie, Boolean isFullSync)

at Microsoft.Online.Coexistence.ProvisionHelper.InvokeAwsAPI[T](Func`1 awsOperation, String opsLabel)

--- End of inner exception stack trace ---

at Microsoft.Online.Coexistence.ProvisionHelper.CommunicationExceptionHandler(CommunicationException ex)

at Microsoft.Online.Coexistence.ProvisionHelper.InvokeAwsAPI[T](Func`1 awsOperation, String opsLabel)

at Microsoft.Azure.ActiveDirectory.Connector.ProvisioningServiceAdapter.<>c__DisplayClass7.b__6()

at Microsoft.Azure.ActiveDirectory.Connector.ProvisioningServiceAdapter.ExecuteWithRetry(String actionName, Action action).

Posted

Fixed it!

 

Turns out the Forefront TMG 2010 does not like Anonymous traffic on port 443. I had to create a very counter intuitive rule to allow this traffic past our firewall. I'm not going to post it here as its quite complex but if anyone experiences this problem and is using TMG2010, PM me and I will let you know what I did.

 

Thanks everyone for your help,

Mike

  • 9 months later...
  • 7 months later...
Posted

Hi there,

I am facing the same issue now, however I had given *.microsoftonline.com as an exception in the proxy, but still the error persists. Do I need to do anything more?

My 80 and 443 ports are opened on the Sync server.

 

Please help, Thanks in Advance

  • 1 month later...
Posted

Hi Mike

 

I'm have the same issue and tried adding domain sets and allow all users etc and still errors

 

Any help would be appreciated.

 

I hope this post will allow me to PM :0)

 

Kind Regards

 

Andy

Posted
I've run into various troubles with the DIr sync and the Azure Sync (Went back to dirsync) The best and quickest test is that on the same server that runs dirsync is to perform the MSOL-connect and see if it does... I ran into trouble when it told me to update, (which I did dutifully) and the new connector failed! (I'd foolishly thought it was credentials errors and I was troubleshooting on my workstation not the server)
Posted (edited)

Thanks for the reply but my woes are definitely TMG 2010 not allowing anonymous traffic on 443. I can see the authentication request and denies in TMG for DirSync server.

 

I hate TMG, I don't trust it working as it should but its all we have to play with :0(

Edited by AndyBurt
Posted

Finally find a way....

 

For anyone that needs it, this is what I found works for us.

 

Create an outbound Access rule, from the DirSync server to a Domain Name Set (see below domains added) for all users and apply.

 

Domain Name Set

*.microsoft.com

*.verisign.com

*.onmircosoft.com (You may be able to just use this one)

 

Then go to Web Access Policy > Configure HTTPS Inspection > Source Exceptions

and add your DirSync Server.

 

After applying and waiting for TMG to sort itself out, go back to the DirSync server and you should now be able to authenticate and sync.

 

On another note if you're syncing passwords, when DirSync runs make sure the .onmicrosoft.com global admin you're using is a different username than your AD account syncing. The sync through up errors halfway through due to my account syncing and 365 updating to my AD my password. School boy error I know.

 

Also be aware DirSync does not sync any AD updates to UPN. This has to be done with remote powershell. Syntax (I Think) - "Set-MsolUserPrincipalName -newuserprincipalname [email protected] -userprincipalname [email protected]". Please note I've not tried this syntax yet as more TMG woe with remote powershell... the joy! :0)

 

Hope this helps.

 

Cheers

 

Andy

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...