DJ-1701 Posted December 1, 2016 Posted December 1, 2016 Before I bother Exa during my limited time at the Primary, has anyone been having issues with AD and 365 Password Synchronization? I am wondering if this has anything to do with our optional NetASQ/Stormshield box with SSL Interception as the 365 password synchronization it's been working fine at the Secondary on a SWGfL connection.
pete Posted December 1, 2016 Posted December 1, 2016 If you're MITM-ing the connection, I can see Azure/Azure AD Connect going "nope, something dodgy going on here - abort connection". I'd disable interception for that server to the azure endpoints and try again. Has it ever worked? If it's just one person, reset their AD password to the same as it is now, wait two minutes and then try again. 1
DJ-1701 Posted December 1, 2016 Author Posted December 1, 2016 If you're MITM-ing the connection, I can see Azure/Azure AD Connect going "nope, something dodgy going on here - abort connection". I'd disable interception for that server to the azure endpoints and try again. Has it ever worked? If it's just one person, reset their AD password to the same as it is now, wait two minutes and then try again. It has worked, though I have noticed issues with syncing before, which have cleared themselves up. Transferred the Azure AD Connect service to a different server which made no difference and confirmed everything with the setup at the Secondary. Anyway, now it's plum right refusing to sync, been going on for a couple of weeks. I'll see if there is anyway for it to bypass the interception/talk to Exa. Cheers.
ItsOggy Posted December 3, 2016 Posted December 3, 2016 Hi, are you on DirSync or Azure AD Connect? May not be a filtering issue, mine stopped syncing passwords with DirSync so had to upgrade to AD Connect.
mikkydoos Posted December 5, 2016 Posted December 5, 2016 Look at the logs/activity when you run ... C:\Program Files\Microsoft Azure AD Sync\UIShell\miisclient.exe That should tell you whats going on. DirSync shouldn't work anymore. Its all ADConnect now.
DJ-1701 Posted December 5, 2016 Author Posted December 5, 2016 Hi, are you on DirSync or Azure AD Connect? May not be a filtering issue, mine stopped syncing passwords with DirSync so had to upgrade to AD Connect. Running Azure AD Connect, upgraded when I was saw it was going end of life. Look at the logs/activity when you run ... C:\Program Files\Microsoft Azure AD Sync\UIShell\miisclient.exe That should tell you whats going on. DirSync shouldn't work anymore. Its all ADConnect now. Unfortunately no useful information, apparently it is a success... and in part that is true, a new account is created if I set one up in AD, but password changes are no longer updating.
mikkydoos Posted December 5, 2016 Posted December 5, 2016 Log a support ticket in your O365 admin portal. MS's support is surprisingly excellent for Office 365. You'll get a call back within half an hour. 1
DJ-1701 Posted December 6, 2016 Author Posted December 6, 2016 Had Microsoft call, basically going over the Event Viewer and looking for certain event errors which were not visible. Also got me to run a script to turn off and on the password sync, but nothing. They wanted to connect via log me in... but that wouldn't work for them, and it has worked for me previously... Call still logged with Exa from yesterday, but looking on the helpdesk it doesn't appear to be assigned yet so will give them a call.
DJ-1701 Posted December 6, 2016 Author Posted December 6, 2016 Probably blocked on your SWGFL connection. The Primary is the one with the issue, so that's over the Exa connection. Though as I said, Log me in hasn't been an issue before... though before now, neither was Azure AD Connect.
Boredguy Posted December 6, 2016 Posted December 6, 2016 Probably blocked on your SWGFL connection. Na we is good on our site with SWGfL, just the EXA connection the primary is on.
mikkydoos Posted December 6, 2016 Posted December 6, 2016 Na we is good on our site with SWGfL, just the EXA connection the primary is on. Oh yeah. As in the OP
DJ-1701 Posted December 13, 2016 Author Posted December 13, 2016 Contacted Exa who changed the filtering and firewall settings for me. Microsoft could then remote in. After running a few more test syncs, an error was eventually found in the logs under 'Information'. Microsoft said this was due to a firewall blocking a port, sent me a hyperlink with all the ports and domains they needed unblocked. Contacted Exa who confirmed the firewall settings for the server were fine and shouldn't be blocked... so obviously Microsoft was wrong on that one. In the end I completely uninstalled AD Azure again, reconnected... it errored on the AD account used to Sync settings saying it didn't have the right level of access rights... it did... completely deleted the account and set it back up with exactly the same settings. Installed AD Azure yet again, connected successfully and now syncing passwords again! The End
NetworkNinja Posted December 14, 2016 Posted December 14, 2016 Was just about to comment on how we solved this issue. at least its working now We had to do the exact same completely uninstall AD connect and then re-install the whole program and service. 1
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now