Forum Discussion
Weird Issue with Entra Connect -Cloud Sync HybridIdentityServiceAgentTimeout
Your Cloud Sync agent is running locally, but the timeout and failed Service Bus test point to outbound communication rather than domain join or administrator rights. On FortiGate, allow TCP 443 to the complete resolved destinations behind *.servicebus.windows.net and *.msappproxy.net, including CNAME chains, and exclude those flows from TLS inspection, certificate substitution, authentication, and application proxying. Do not pin one IP because endpoints can change. Test name resolution and TCP connectivity from the agent server under the service context, not only an interactive administrator session. Check the provisioning agent traces under C:\ProgramData\Microsoft\Azure AD Connect Provisioning Agent\Trace and export an AADCloudSyncTools log bundle immediately after reproducing the timeout. Finally, confirm the agent becomes healthy in the Entra admin center. If TCP 443 works but registration still times out, capture FortiGate deny and TLS logs and open Microsoft support with the exact UTC correlation time.