SOLVED

MS Edge Enterprise Account Syncing

Brass Contributor

It seems it is now enabled for me in Dev channel, but it is showing that "sync has been disabled by the administrator." This is a domain-joined PC. Is this setting looking at the "Sync your settings" area in windows 10 that gets disabled by default if it is a domain-joined PC or is this a group policy somewhere else that I cannot find?

 

Thanks!

 

Transport StateDisabled
Disable Reasons

Enterprise policy, Waiting for sync url, Waiting for access token

 

Actionable Error

Error TypeDISABLED_BY_ADMIN
ActionSTOP_SYNC_FOR_DISABLED_ACCOUNT
37 Replies

@Michael Rennie and this is with the New Edge browser that the rest of your ORG can log into and sync fine with ?

One of my sys admin and myself are testing it out before deploying to the rest of the ORG. But we both are having this sync issue with our work accounts. So as of now, we will not be deploying it out until we can figure this out. 

@Kirby Stuart We are running the new edge with a few users in our org, so far I am the only one with the sync issues.

 

Sync briefly worked for me on a canary version back in the fall but since then it has stopped workign for me across all versions on all platforms. PC, Mac, iOS

@Kirby Stuart  Sorry to hear that you are running into issues with Sync. We absolutely want to ensure that you have a great experience in adopting sync. We will be happy to work alongside with you and assist in removing any issues that you feel are deployment blockers. If you feel that this will be helpful, please message me your contact details so that we can engage.  

@Kirby Stuart @akhator I'm in a similar situation. Myself and about 5 other coworkers are using it before we roll it out org wide and replace Chrome/IE/Old Edge. However the sync isn't working for all of us and we have a lot of users who float between different computers, so that's very important feature for us to have working consistently.

Hey everyone apparently there was a bug in the June 2019 Edge beta 77 that lost your encryption key forever if you tried to sync. You have to request a purge of your Edge cloud server data to fix it. I just opened my case with Microsoft to start the process. Hopefully that goes smoothly and fixes things. FYI... I had to purchase a $499 single incident support plan from Microsoft commercial business support to submit the case.

@akhator 

 

Did this get resolved?

 

I am ready to deploy CrEdge but need account sync to work with our Active Directory accounts with only Azure AD (as opposed to Azure AD Premium).

 

I thought the issue what that a GPO needed to be configured so I pulled down the ADMX but do not see a setting in there so I assume the issue is that... it just doesn't work.  If that is the case, can you tell me/us if this will be corrected in the near future or if we are going to have to stay with Chrome and not deploy CrEdge?

 

Thanks.

 

Same here... on latest MacOS (10.15.3) & Edge (80.0.361.69). Using my AzureAD global admin account. Verified nothing is blocked on my AAD tenant in Azure IP, but still seeing the error:

Error Type DISABLED_BY_ADMIN
Action STOP_SYNC_FOR_DISABLED_ACCOUNT
URL
Error Description Microsoft Information Protection service is disabled

On the edge://sync-internals, the Summary section shows "Disable Reasons: Feature not supported. Waiting for sync URL"

Back to Chrome... :(

@Andrew Connell Sorry to hear that you are running into problems with sync. Can you confirm that you reviewed https://docs.microsoft.com/en-us/deployedge/microsoft-edge-enterprise-sync and ensured that AIP is enabled? 

@akhator did something happen in Edge v81? Sync works for all users on the domain, and only stopped for one when Edge automatically upgraded to v81. Workstations that still had v80 still worked.

@Michael Ries We are not expecting any regression in sync behavior with 81 build. Can you file OCV including all diagnostic data and IM me your email address? Edge 81 has been available for quite some time and we are now nearing rolling out of Edge 83.  

@akhator I cannot sync in Edge v83 with my M365 account on one PC, while it works on another. It says "We can't synchronize to your account since we need to confirm that it's you". edge://sync-internals/ says "EDGE_AUTH_ERROR: 3, 24, 4b0". Trying again over and over, deleting the profile (primary), going for a second profile, un- and reinstalling Edge - nothing helps. My M365 account uses MFA via Auth-app. It has both landline and mobile phone numbers filled in.

Teams login on both machines is fine.

Both PCs are Win 8.1 machines locally AD joined, Windows login with the same roaming AD account. Tenant was M365 Business Basic now upgraded to Business Premium. The difference is that on the erroneous PC I had signed in to Edge vSeventysomething with my local AD account while being on M365 Business Basic (not really knowing what I was doing). So I suppose there is sth wrotten deep down in the user profile. For that reason after uninstalling Edge I deleted the Edge folder in AppData but obviously that was not the cure.

What can be done?

@Michael Rennie 

 

I'm pretty sure this back-end problem is mine too. We have to pay $500 to fix a problem with Azure AD??? That's pretty crazy.

@Roger Buckthal You're not helpful nor was that productive. I assume you don't even understand why we're using this if you're saying stuff like that. Go troll somewhere else.

We also have some users reporting the sync issue. For example for it looks as follows in edge://sync-internals :

Disable Reasons: Feature not supported.

Sync Client ID: Uninitialized

Invalidator Client ID: Uninitialized

Username: user@cantonso.com

Requested Toke: n/a

Has token: false

Error Type: DISABLED_BY_ADMIN
Action: STOP_SYNC_FOR_DISABLED_ACCOUNT
Error: Description Microsoft Information Protection service is disabled

 

Is there any news how to fix it? If there is a fix, is it needed to be fixed per account or per tenant?

 

Best regards

Johannes

@Johannes Goerlich 

 

In short, no fix you can do. You have to open a case with MS and they will fix. Two things of importance:

-It's a pain to get through to the right "department" to fix this, and you will have to jump through lots of "restart your router" type troubleshooting.

-You will lose your Edge profile, so make sure you back it up first.

In the meantime we were told to ask the users to sign-out from their work profile on all their devices, sign-in on one device and reset the sync by selecting Settings and more > Sync > Reset sync with Resume sync after resetting to fix this issue.

 

It seems there is no possibility to determine proactively which users are effected. So we have to wait for every affected one to complain and raise a ticket at our IT support.

 

tw. it was mentioned by MS that the issue might be fixed with v88 stable, but i couldn't verify, yet.

@Johannes Goerlich, Thanks, enterprise sync is working with Edge with my account now. I followed the instructions: Sign out, sign in, Sync > reset synced with resume. Rinse and repeat because the first time it failed. Syncing started after the second time, and now syncs to my phone, other computers.

I had a previous Azure AD / AIP subscription and could not get DISABLED_BY_ADMIN to go away, even after a ticket with M365 Support. I was directed to Edge Beta Support, which prompted for a fee. I did a bit more searching and made it to this post and @Johannes Goerlich had the answer that solved the problem! I created an account just to like it and to say thank you!