Forum Discussion

SteffenHNW's avatar
SteffenHNW
Brass Contributor
Jun 23, 2024

Azure AD Sync Entra ID Sync Connect SSO problem

Hi community,

 

i have an entra id connect sync running with sso.

It is working fine, but if I want to change the configuration (new OU) I'm ending with a failure.

Can somebody tell me what the problem is?

 

Thanks, Greets, Steffen

 

  • LainRobertson's avatar
    LainRobertson
    Silver Contributor

    SteffenHNW 

     

    Hi, Steffen.

     

    I'm afraid I only speak English, so I had to rely on a translator to process the screenshot you included.

     

    Assuming I typed the text from the screenshot correctly, the translator produced (from the top and bottom of the screenshot, respectively):

     

    Enter a domain administrator account to configure your local forest to use single sign-on.

     

    The status for single sign-on cannot be retrieved.

     

    Based on that translation, it's not an issue with the new organisational unit you're selecting.

     

    The things that come to mind are:

     

    1. Ensure you are running the AAD Connect configuration wizard as a domain administrator of the local Active Directory forest you are synchronising;
    2. Ensure the Azure credential you've provided is a member of at least one of the following built-in Azure roles:
      1. Hybrid Identity Administrator;
      2. Global Administrator;
    3. You're running a very old version of AAD Connect and potentially have a firewall issue as noted here: 
      1. Azure AD Connect - Cannot Retrieve Single Sign-on Status - Microsoft Q&A
    4. The Azure "security defaults" policies, conditional access policies or MFA settings on your Azure administration account could be getting in the way:
      1. Mentioned in the above article, as well as this next one:
      2. Unable to set SSO in Azure AD Connect - Microsoft Community Hub
    5. Check that your environment still meets the prerequisites for SSO:
      1. Quickstart: Microsoft Entra seamless single sign-on - Microsoft Entra ID | Microsoft Learn

     

    Cheers,

    Lain