Running Full DirSync every night. Recommended?

Occassionally the standard delta dirsync doesn't synchronize all user objects. However, the Full Sync, which in my case can take up to 5 hours to complete, will synchronize the objects. Is it recommended to run a Full Dirsync every night? Is there a Best Practice?

Thank you,
Anthony K O365Asked:
Who is Participating?

[Product update] Infrastructure Analysis Tool is now available with Business Accounts.Learn More

I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

Vasil Michev (MVP)Commented:
Full sync should only be needed if you make changes to the agents/profile runs. Some changes might be omitted simply because dirsync does not recognize the AD object as modified, if this is what happens in your case you can modify your workflow to also update some other attribute, such as extentionattribute5, etc. Another thing that comes to mind is that in some cases you will need multiple syncs to have the changes reflected in O365 (for example provisioning archives). AADSync/AADConnect will take care of this automatically, but if you are still using dirsync, you might need to force another run or wait 3h more.

In any case, you should investigate on what's causing this. If you insist on running Full sync every night, you can certainly do so, but it shouldnt be needed.
Anthony K O365Author Commented:
I get this error on a few accounts (see below) and the only way to fix it or get them synched is via Full DirSync. Some of these accounts were actually disabled, but enabled and would never sync even after a few delta syncs. I set Dirsync to every 60 mins.

"Unable to update this object in Azure Active Directory, because the attribute [AccountEnabled], is not valid. Update the value in your local directory services."

Any thoughts on why?
Anthony K O365Author Commented:
Also, is there a way to automate a Full Dirsync, perhaps via scheduled Task?
The 7 Worst Nightmares of a Sysadmin

Fear not! To defend your business’ IT systems we’re going to shine a light on the seven most sinister terrors that haunt sysadmins. That way you can be sure there’s nothing in your stack waiting to go bump in the night.

Vasil Michev (MVP)Commented:
Are you using dirsync or AADSync?
Anthony K O365Author Commented:
Vasil Michev (MVP)Commented:
For newer dirsync versions, you should be able to run

Start-OnlineCoexistenceSync –FullSync

Open in new window

so just put that in a scheduled task. For older versions, you need to modify the reg key, so you can do a simple scheduled task to run a PS script with both the reg action and the Start-OnlineCoexistenceSync cmdlet.

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
Anthony K O365Author Commented:
Thank you!
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Office 365

From novice to tech pro — start learning today.