william_tropico Posted September 27, 2019 Posted September 27, 2019 Morning, Got a strange one. Had an email at 12:15am which said "Identity synchronization object deletion limit reached". I saw this at 5am and panicked! It looks like over 500 items were attempted to be deleted during the sync between AD and O365. I looked in Active directory and looks like everything is still there. What would have caused this and at such a strange time, and how can I see what was removed?
chazzy2501 Posted September 27, 2019 Posted September 27, 2019 phew, lucky I don't have alerts setup to read at home. 1
meldistrict12 Posted September 27, 2019 Posted September 27, 2019 If you have the Synchronization Service Manager - take a look on there, it should show what it was trying to delete.
MrKJLS Posted September 27, 2019 Posted September 27, 2019 You can turn off the limit and then do the sync, switch it back on https://docs.microsoft.com/en-us/azure/active-directory/hybrid/how-to-connect-sync-feature-prevent-accidental-deletes
william_tropico Posted September 27, 2019 Author Posted September 27, 2019 going though the logs it looks like devices and not users but why would it suddenly try and remove 500+ computers from Azure? They are still all in AD
jdsok Posted September 27, 2019 Posted September 27, 2019 We also had 800+ objects try to delete out of Azure, when they were still alive and active in our on-prem AD system. I did notice they were all Win7 machines.
chaplic Posted October 3, 2019 Posted October 3, 2019 Did azure ad connect update itself? there's a change as to how it decides to sync computer objects if they have a cert (or not)
jdsok Posted October 3, 2019 Posted October 3, 2019 Did azure ad connect update itself? there's a change as to how it decides to sync computer objects if they have a cert (or not) Maybe? Do you have any more information about a change in how it decides to sync computer objects? We have a single on-prem AD domain that we're syncing for hybrid AD join, and as far as I can tell it's just pointed at our computer and user OUs, nothing fancy.
georgeescott Posted October 3, 2019 Posted October 3, 2019 Here’s the Microsoft article on it: https://docs.microsoft.com/en-us/azure/active-directory/hybrid/reference-connect-device-disappearance. I suspect you have automatic upgrade enabled on the Azure AD Connect client which kicked off the deletions when it upgraded to 1.4.xx.x.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now