On-premises sync for AD users not working

%3CLINGO-SUB%20id%3D%22lingo-sub-2279826%22%20slang%3D%22en-US%22%3EOn-premises%20sync%20for%20AD%20users%20not%20working%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2279826%22%20slang%3D%22en-US%22%3E%3CP%3EHi%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3Ewe%20want%20to%20use%20the%20On-premises%20sync%20of%20AD%20users%20in%20our%20enterprise%20(%26gt%3B%2010.000%20users).%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EUnfortunately%2C%20it%20doesn't%20work.%20The%20error%20message%20in%20%22edge%3A%2F%2Fsync-internals%22%20is%20the%20following%3A%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EError%20Type%3A%26nbsp%3B%3CSPAN%3EDISABLED_BY_ADMIN%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%3CSPAN%3EAction%3A%26nbsp%3BSTOP_SYNC_FOR_DISABLED_ACCOUNT%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%3CSPAN%3EError%20Description%3A%26nbsp%3BMicrosoft%20Information%20Protection%20service%20is%20disabled%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThe%20thing%20is%2C%20the%20feature%20used%20to%20work%20back%20when%20it%20was%20first%20integrated%20into%20Edge.%20At%20some%20point%20(M86%20or%20M87)%20it%20stopped%20working.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWe%20have%20configured%20serveral%20group%20policies%2C%20including%3A%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ERoamingProfileSupportEnabled%3A%201%3C%2FP%3E%3CP%3ERoamingProfileLocation%3A%20Path%20on%20a%20network%20share%3C%2FP%3E%3CP%3EConfigureOnPremisesAccountAutoSignIn%3A%201%3C%2FP%3E%3CP%3ENonRemovableProfileEnabled%3A%201%3C%2FP%3E%3CP%3EForceSync%3A%201%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20tried%20installing%20the%20Microsoft%20Azure%20Information%20Protection%20client.%20Now%2C%20Edge%20sometimes%20says%20that%20sync%20is%20enabled%2C%20but%20a%20profile.pb%20never%20gets%20generated.%20When%20I%20restart%20the%20browser%2C%20sync%20is%20disabled%20again.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-2279826%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EProfiles%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3Eroaming%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3ESync%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2280579%22%20slang%3D%22en-US%22%3ERe%3A%20On-premises%20sync%20for%20AD%20users%20not%20working%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2280579%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F778149%22%20target%3D%22_blank%22%3E%40limonjuice%3C%2FA%3E%26nbsp%3BHi!%26nbsp%3B%20The%20Sync%20Team%20has%20put%20together%20a%20step-by-step%20troubleshooting%20guide%20for%20issues.%26nbsp%3B%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3ESpecifically%20for%20the%20%22%3CSPAN%3EDISABLED_BY_ADMIN%22%20error%20you%20are%20seeing%2C%20please%20see%20the%20following%3A%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fdeployedge%2Fmicrosoft-edge-troubleshoot-enterprise-sync%23issue-sync-is-not-available-for-this-account%22%20target%3D%22_self%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fdeployedge%2Fmicrosoft-edge-troubleshoot-enterprise-sync%23issue-sync-is-not-available-for-this-account%3C%2FA%3E%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSPAN%3EThanks!%26nbsp%3B%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CEM%3E-Kelly%3C%2FEM%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2279841%22%20slang%3D%22en-US%22%3ERe%3A%20On-premises%20sync%20for%20AD%20users%20not%20working%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2279841%22%20slang%3D%22en-US%22%3E%3CP%3EI%20attached%20a%20screenshot%20of%20edge%3A%2F%2Fsync-internals%3C%2FP%3E%3C%2FLINGO-BODY%3E
New Contributor

Hi,

 

we want to use the On-premises sync of AD users in our enterprise (> 10.000 users).

 

Unfortunately, it doesn't work. The error message in "edge://sync-internals" is the following:

 

Error Type: DISABLED_BY_ADMIN

Action: STOP_SYNC_FOR_DISABLED_ACCOUNT

Error Description: Microsoft Information Protection service is disabled

 

The thing is, the feature used to work back when it was first integrated into Edge. At some point (M86 or M87) it stopped working.

 

We have configured serveral group policies, including:

 

RoamingProfileSupportEnabled: 1

RoamingProfileLocation: Path on a network share

ConfigureOnPremisesAccountAutoSignIn: 1

NonRemovableProfileEnabled: 1

ForceSync: 1

 

I tried installing the Microsoft Azure Information Protection client. Now, Edge sometimes says that sync is enabled, but a profile.pb never gets generated. When I restart the browser, sync is disabled again.

2 Replies

I attached a screenshot of edge://sync-internals

@limonjuice Hi!  The Sync Team has put together a step-by-step troubleshooting guide for issues.  

 

Specifically for the "DISABLED_BY_ADMIN" error you are seeing, please see the following: https://docs.microsoft.com/en-us/deployedge/microsoft-edge-troubleshoot-enterprise-sync#issue-sync-i...

 

Thanks! 

 

-Kelly