Azure AD Connect -- Attribute Value Must Be Unique

%3CLINGO-SUB%20id%3D%22lingo-sub-1506079%22%20slang%3D%22en-US%22%3EAzure%20AD%20Connect%20--%20Object%20not%20found%20in%20AAD%20Connector%20Space%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1506079%22%20slang%3D%22en-US%22%3E%3CP%3Enew%20to%20Azure%20AD%20Connect.%3C%2FP%3E%3CP%3ESetup%20and%20I%20had%20a%20few%20errors%20getting%20going%2C%20but%20I%20managed%20to%20clear%20all%20but%20one%20out.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20am%20at%20the%20point%20where%20Azure%20AD%20sync%20is%20reporting%20no%20errors%2C%20however%2C%20password%20hash%20sync%20is%20not%20happening.%26nbsp%3B%20%26nbsp%3BWhen%20I%20ran%20the%20troubleshooting%20tool%2C%20I%20ran%20into%20the%20following%3A%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EChecking%20for%20object%20%22CN%3DJohn%20Smith%2C%20OU%3DUsers%2CDC%3Ddomain%2CDC%3Dlocal%22%20in%20sync%20engine...%3CBR%20%2F%3EObject%26nbsp%3B%22CN%3DJohn%20Smith%2C%20OU%3DUsers%2CDC%3Ddomain%2CDC%3Dlocal%22%20is%20found%20in%20AD%20Connector%20Space%20-%20%22domain.local%22%3CBR%20%2F%3EObject%26nbsp%3B%22CN%3DJohn%20Smith%2C%20OU%3DUsers%2CDC%3Ddomain%2CDC%3Dlocal%22%20is%20found%20in%20Metaverse%3CBR%20%2F%3E%3CSTRONG%3EObject%26nbsp%3B%22CN%3DJohn%20Smith%2C%20OU%3DUsers%2CDC%3Ddomain%2CDC%3Dlocal%22%20is%20not%20found%20in%20AAD%20Connector%20Space%3C%2FSTRONG%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20am%20not%20sure%20what%20to%20look%20at%20next.%26nbsp%3B%20As%20an%20aside%2C%20the%20local%20AD%20is%20a%20non-routable%20TLD%20(.local).%26nbsp%3B%20The%20usernames%20are%20also%20different%20between%20AD%20and%20AAD%20(f.lastname%20in%20AD%20vs%20firstname.lastname%20in%20AAD).%26nbsp%3B%20The%20UPN%20suffix%20has%20been%20added%20to%20list%20in%20AD.%26nbsp%3B%20The%20AAD%20username%20(which%20is%20user's%20email%20address)%20has%20been%20added%20to%20AD%20proxy%20address%20as%20SMTP%3Afirstname.lastname%40domain.com%26nbsp%3B%20%26nbsp%3Band%20Email%20attribute%20on%20General%20tab%20has%20been%20entered%20as%20%3CA%20href%3D%22mailto%3Afirstname.lastname%40domain.com%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%22%3Efirstname.lastname%40domain.com%3C%2FA%3E%26nbsp%3B%3CBR%20%2F%3E%3CBR%20%2F%3Eany%20thoughts%20of%20what%20I%20can%20look%20at%20next%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-1506079%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EAzure%20AD%20Connect%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E
New Contributor

-- Updating from my previous message --


I managed to get syncing attempts happening by removing the group filter.   
As my test group, I made a special OU for the test user and am applying the sync only to this OU.

 

I am now a bit further, but stumped again.
Both AD accounts and AAD accounts are pre-existing:

AD Account:   j.smith@domain.com   (actually a .local account, but UPN added to AD)

AAD Account:  john.smith@domain.com

When the sync happens, I am getting "Error:  Attribute Value Must Be Unique"

Looking deeper at the error, it is mentioning the error is in relation to the ProxyAddress.

 

I have already defined the following in AD for the j.smith user:

email (General Tab):   john.smith@domain.com

Proxy Address (Attribute Editor):  SMTP:john.smith@domain.com

 

this does not seem to help though.  I have tested also by removing Proxy Address and still no go.

 

any thoughts?

1 Reply

Fixed this item.

The issue was the test account (my account) was a Global Admin in AzureAD.   I needed to demote the account to user account first, make the sync, and then re-enable global admin for my account.