Solved

Active Directory and Office 365 Won't Sync

Posted on 2014-11-04
1
1,842 Views
Last Modified: 2015-01-06
We use Windows Azure Active Directory Sync Service to synchronize the user accounts in our AD with Office 365.  Currently the Azure AD Sync Service is stopped and attempts to restart it have been unsuccessful.  The Event Log says it won't start because the Forefront Identity Manager Synchronization Service is not running and that the Azure AD Sync Service is dependent upon it.

Attempts to restart the FIM Aync Serivce have been unsuccessful. When attempting to start it Event ID 7024 appears in the system log in the event viewer and says "the FIM Synchronization Service failed to start with server specific error %%2149781504".  Event ID 6028 simultaneously appears in the APP log in the event viewer and says, "The server encryption keys could not be accessed.  Verify that the service account has permissions to the following registry key, hkey local machine\microsoft\forefront\2010\synchronization service."  The service account the FIM Sync service uses does have full permissions to that key.

Any information on what we can do to get the FIM Sync Service running so that the Azure AD Sync service will run would be greatly appreciated.  Thanks in advance.
0
Comment
Question by:sswmoore
1 Comment
 
LVL 39

Accepted Solution

by:
Vasil Michev (MVP) earned 500 total points
ID: 40423892
Just reinstall it, or use the newly released AadSync tool: http://msdn.microsoft.com/en-us/library/azure/dn790204.aspx

Otherwise, check the local groups (FIMSyncAdmins and/or ADSyncAdmins) and make sure the account running the service is added .
0

Featured Post

Does Powershell have you tied up in knots?

Managing Active Directory does not always have to be complicated.  If you are spending more time trying instead of doing, then it's time to look at something else. For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

You might have come across a situation when you have Exchange 2013 server in two different sites (Production and DR). After adding the Database copy in ECP console it displays Database copy status unknown for the DR exchange server. Issue is strange…
Is your Office 365 signature not working the way you want it to? Are signature updates taking up too much of your time? Let's run through the most common problems that an IT administrator can encounter when dealing with Office 365 email signatures.
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles to another domain controller. Log onto the new domain controller with a user account t…
This tutorial will walk an individual through the process of configuring their Windows Server 2012 domain controller to synchronize its time with a trusted, external resource. Use Google, Bing, or other preferred search engine to locate trusted NTP …

911 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

23 Experts available now in Live!

Get 1:1 Help Now