password not reflecting in Office 365

%3CLINGO-SUB%20id%3D%22lingo-sub-296562%22%20slang%3D%22en-US%22%3Epassword%20not%20reflecting%20in%20Office%20365%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-296562%22%20slang%3D%22en-US%22%3E%3CP%3Epassword%20not%20reflecting%20in%20Office%20365%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ENo%20error%20in%20Azure%20AD%20connect%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3Erecent%20password%20sync%20is%20reflected%20in%20admin%20portal%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3Ewhen%20we%20try%20to%20login%2C%20got%20error%20below%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EUser%20can%20sign%20in%20to%20local%20AD%20using%20the%20password%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20style%3D%22width%3A%20404px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F61955i4733CBE55F60AE15%2Fimage-size%2Flarge%3Fv%3D1.0%26amp%3Bpx%3D999%22%20alt%3D%22Capture.PNG%22%20title%3D%22Capture.PNG%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAny%20known%20issues%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3Ethanks%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-296562%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EOffice%20365%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-297193%22%20slang%3D%22en-US%22%3ERe%3A%20password%20not%20reflecting%20in%20Office%20365%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-297193%22%20slang%3D%22en-US%22%3E%3CP%3EAs%20%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F869%22%20target%3D%22_blank%22%3E%40Chris%20Webb%3C%2FA%3E%20said%2C%20this%20looks%20like%20a%20replication%20issue!%20could%20also%20be%20a%20network%20ports%20issue%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ERun%20dcdiag%20on%20your%20DC..see%20whats%20comes%20up!%3C%2FP%3E%3CP%3EInfo%2C%20how%20to%20use%3A%26nbsp%3B%3C%2FP%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Factivedirectorypro.com%2Fdcdiag-check-domain-controller-health%2F%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Factivedirectorypro.com%2Fdcdiag-check-domain-controller-health%2F%3C%2FA%3E%3C%2FP%3E%3CP%3EI%20usually%20use%26nbsp%3B%3CSPAN%3Edcdiag%20%2Fc%20%2Fv%20%2Fq%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E(%20%3CSPAN%3E%2Fq%20only%20displays%20errors%20which%20can%20be%20preferable%20)%3C%2FSPAN%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAlso%20run%26nbsp%3B%3C%2FP%3E%3CP%3Erepadmin%3CSPAN%3E%20%2Freplsum%20and%3C%2FSPAN%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%3Erepadmin%20%2Fshowrepl%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%3EDownload%20portQry%20and%20run%20the%20domain%20test%3A%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%3CSPAN%3E%3CA%20href%3D%22https%3A%2F%2Fwww.microsoft.com%2Fen-us%2Fdownload%2Fdetails.aspx%3Fid%3D24009%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fwww.microsoft.com%2Fen-us%2Fdownload%2Fdetails.aspx%3Fid%3D24009%3C%2FA%3E%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%3EAlso%20check%20your%20logs%20in%20eventviewer%20for%20more%20errors%20on%20the%20ADconnect%20server%20and%20DC's%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%3E%2F%20Adam%3C%2FSPAN%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-297153%22%20slang%3D%22en-US%22%3ERe%3A%20password%20not%20reflecting%20in%20Office%20365%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-297153%22%20slang%3D%22en-US%22%3E1722%20is%20relocation%20errors.%20You%20may%20need%20to%20do%20some%20searching%20on%20that%20and%20do%20some%20research%20around%20checking%20your%20replication%20health.%20Repladmin%20etc.%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-297152%22%20slang%3D%22en-US%22%3ERe%3A%20password%20not%20reflecting%20in%20Office%20365%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-297152%22%20slang%3D%22en-US%22%3Eam%20using%20password%20sync%20only%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-297151%22%20slang%3D%22en-US%22%3ERe%3A%20password%20not%20reflecting%20in%20Office%20365%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-297151%22%20slang%3D%22en-US%22%3EYou%20never%20did%20confirm%20if%20your%20using%20just%20password%20sync%20or%20pass%20through%20auth.%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-297150%22%20slang%3D%22en-US%22%3ERe%3A%20password%20not%20reflecting%20in%20Office%20365%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-297150%22%20slang%3D%22en-US%22%3E%3CP%3EYes%2C%20restarted%20already%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3Ealso%20with%20EVENT%20error%20611%2C%20RPC%20ERROR%201722%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-297144%22%20slang%3D%22en-US%22%3ERe%3A%20password%20not%20reflecting%20in%20Office%20365%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-297144%22%20slang%3D%22en-US%22%3EHave%20you%20reboot%20you%20ad%20connect%20server%20yet%3F%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-297143%22%20slang%3D%22en-US%22%3ERe%3A%20password%20not%20reflecting%20in%20Office%20365%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-297143%22%20slang%3D%22en-US%22%3E%3CP%3Eaffects%20all%20user%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EGot%20error%20611%20below%20in%20Event%20viewer%20of%20AD%20Connect%20server%3A%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3Eunable%20to%20open%20connection%20to%20domain%3A%20contoso.com%2C%20an%20exeption%20occured%20while%20attempting%20to%20locate%20domain%20controller%20for%20domain%20contoso.com%3B%20system%20security%20authentication%20exception%20the%20username%20password%20is%20incorrect%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAzure%20Ad%20connect%20version%20is%201.1.654.0%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-296930%22%20slang%3D%22en-US%22%3ERe%3A%20password%20not%20reflecting%20in%20Office%20365%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-296930%22%20slang%3D%22en-US%22%3E%3CP%3ESometimes%20the%20sync%20with%20online%20portal%20take%20more%20than%2048%20hrs.%20are%20you%20able%20to%20login%20now%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-296606%22%20slang%3D%22en-US%22%3ERe%3A%20password%20not%20reflecting%20in%20Office%20365%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-296606%22%20slang%3D%22en-US%22%3E%3CP%3EIs%20this%20a%20single%20user%2C%20a%20group%20of%20users%2C%20all%20users%3F%20Any%20errors%20in%20the%20event%20logs%3F%20Have%20you%20run%20a%20full%20password%20sync%20cycle%3F%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EThere's%20a%20very%20detailed%20article%20on%20troubleshooting%20issues%20with%20PHS%20here%3A%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Factive-directory%2Fhybrid%2Ftshoot-connect-password-hash-synchronization%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Factive-directory%2Fhybrid%2Ftshoot-connect-password-hash-synchronization%3C%2FA%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-296605%22%20slang%3D%22en-US%22%3ERe%3A%20password%20not%20reflecting%20in%20Office%20365%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-296605%22%20slang%3D%22en-US%22%3E%3CP%3EIf%20Passthrough%20was%20in%20use%20another%20thing%20to%20check%20is%20to%20see%20if%20you%20are%20actually%20not%20using%20preview%20version%20of%20agents.%20I'm%20not%20sure%20when%20they%20should%20stop%20working%2C%20but%20updating%20them%20is%20a%20must%20anyway%20(for%20security%20and%20compatibility%20concerns).%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Factive-directory%2Fhybrid%2Fhow-to-connect-pta-upgrade-preview-authentication-agents%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Factive-directory%2Fhybrid%2Fhow-to-connect-pta-upgrade-preview-authentication-agents%3C%2FA%3E%3C%2FP%3E%3CP%3EWe%20have%20also%20recently%20switched%20from%20PTA%20to%20Password%20sync%2C%20but%20i%20still%20have%20updated%20the%20agents%20in%20case%20PTA%20will%20be%20needed%20again%20in%20the%20future.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-296567%22%20slang%3D%22en-US%22%3ERe%3A%20password%20not%20reflecting%20in%20Office%20365%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-296567%22%20slang%3D%22en-US%22%3ELast%20time%20i%20had%20this%20happen%2C%20after%20tearing%20my%20hair%20out%20and%20a%20call%20to%20Microsoft%20it%20turned%20out%20to%20be%20that%20I%20actually%20had%20Passthrough%20Authentication%20setup%20and%20the%20agent%20wasn't%20responding%20properly%20until%20I%20reboot%20the%20adsync%20server.%20I%20switched%20to%20Password%20sync%20only%20after%20that.%3CBR%20%2F%3E%3CBR%20%2F%3ECheck%20your%20adconnect%20and%20see%20if%20you%20guys%20might%20have%20Passthrough%20setup%2C%20if%20so%20I'd%20check%20into%20maybe%20rebooting%20so%20the%20agent%20that%20handles%20that%20gets%20reset.%3C%2FLINGO-BODY%3E
Highlighted
Super Contributor

password not reflecting in Office 365

 

No error in Azure AD connect

 

recent password sync is reflected in admin portal

 

when we try to login, got error below

 

User can sign in to local AD using the password

 

Capture.PNG

 

Any known issues?

 

thanks

11 Replies
Highlighted
Last time i had this happen, after tearing my hair out and a call to Microsoft it turned out to be that I actually had Passthrough Authentication setup and the agent wasn't responding properly until I reboot the adsync server. I switched to Password sync only after that.

Check your adconnect and see if you guys might have Passthrough setup, if so I'd check into maybe rebooting so the agent that handles that gets reset.
Highlighted

If Passthrough was in use another thing to check is to see if you are actually not using preview version of agents. I'm not sure when they should stop working, but updating them is a must anyway (for security and compatibility concerns). https://docs.microsoft.com/en-us/azure/active-directory/hybrid/how-to-connect-pta-upgrade-preview-au...

We have also recently switched from PTA to Password sync, but i still have updated the agents in case PTA will be needed again in the future.

Highlighted

Is this a single user, a group of users, all users? Any errors in the event logs? Have you run a full password sync cycle?

 

There's a very detailed article on troubleshooting issues with PHS here: https://docs.microsoft.com/en-us/azure/active-directory/hybrid/tshoot-connect-password-hash-synchron...

Highlighted

Sometimes the sync with online portal take more than 48 hrs. are you able to login now?

Highlighted

affects all user

 

Got error 611 below in Event viewer of AD Connect server:

 

unable to open connection to domain: contoso.com, an exeption occured while attempting to locate domain controller for domain contoso.com; system security authentication exception the username password is incorrect

 

Azure Ad connect version is 1.1.654.0

Highlighted
Have you reboot you ad connect server yet?
Highlighted

Yes, restarted already

 

also with EVENT error 611, RPC ERROR 1722

 

Highlighted
You never did confirm if your using just password sync or pass through auth.
Highlighted
am using password sync only
Highlighted
1722 is relocation errors. You may need to do some searching on that and do some research around checking your replication health. Repladmin etc.
Highlighted

As @Chris Webb said, this looks like a replication issue! could also be a network ports issue

 

Run dcdiag on your DC..see whats comes up!

Info, how to use: 

https://activedirectorypro.com/dcdiag-check-domain-controller-health/

I usually use dcdiag /c /v /q

( /q only displays errors which can be preferable ) 

 

Also run 

repadmin /replsum and 

repadmin /showrepl

 

Download portQry and run the domain test:

https://www.microsoft.com/en-us/download/details.aspx?id=24009

 

Also check your logs in eventviewer for more errors on the ADconnect server and DC's

 

/ Adam