Azure AD Connect Sync Errors: Troubleshooting Guide
Diagnose stuck sync cycles, duplicate attribute errors and password hash sync issues in Microsoft Entra Connect.
Common Symptoms and Quick Fixes
| Symptom | Likely Cause | Quick Fix |
|---|---|---|
| Sync stuck or not running | Scheduler disabled | Check the scheduler and run a delta sync |
| Duplicate attribute error | Same proxyAddresses on two objects | Remove the duplicate in on-prem AD |
| Passwords not updating in the cloud | Password hash sync not running | Check PHS status and event log |
Method 1: Check and Trigger Sync
Run on the Entra Connect server.
Get-ADSyncScheduler
Set-ADSyncScheduler -SyncCycleEnabled $true
Start-ADSyncSyncCycle -PolicyType Delta
Method 2: Fix Duplicate Attributes
Find the clash, then clean it in on-prem AD.
1
Locate the duplicateOpen Microsoft Entra admin center > Entra Connect Health > Sync errors.
2
Remove the extra valueEdit proxyAddresses or userPrincipalName on the wrong object in AD, then run a delta sync.
Method 3: Check Password Hash Sync
Look for Event ID 656 and 657 in the Application log on the sync server.
Get-ADSyncAADPasswordSyncConfiguration -SourceConnector "contoso.local"
Pro Tip for AdministratorsIf a full password sync is needed, run it only outside business hours.
Frequently Asked Questions (FAQ)
Q: How often does sync run?
Every 30 minutes by default.
Q: Can I force a full sync?
Yes, with Start-ADSyncSyncCycle -PolicyType Initial, but use it sparingly.