Office 365 AAD Sync

Mitch P
Mitch P used Ask the Experts™
We have migrated a SBS 2008 Exchange to Office 365 and have installed AAD Sync on a member server 2008 R2. The initial sync worked Ok but since then we have not been able to complete any change syncs. We found out there was an issue with the sync account passwords created by the install and reset one but the other (Sync_) account generated the following error when we try to change it...

"unexpected exception thrown.; Action:PingProvisioningServiceEndPoint, Exception:"

We have also been getting "stopped-extension-dll-exception" in the status in SSM, as well as the following in the EL

ProvisioningServiceAdapter::ExecuteWithRetry: Action PingProvisioningServiceEndPoint, Unexpected Exception: System.Runtime.InteropServices.COMException (0x80010107)
   at System.Runtime.InteropServices.Marshal.ThrowExceptionForHRInternal(Int32 errorCode, IntPtr errorInfo)
   at System.Management.ManagementObject.Initialize(Boolean getObject)
   at System.Management.ManagementBaseObject.get_Properties()
   at System.Management.ManagementBaseObject.GetPropertyValue(String propertyName)
   at Microsoft.Online.DirSync.Common.PrerequisiteChecks.TryMachineIsDomainControllerCore()
   at Microsoft.Online.Coexistence.ProvisionHelper.IsMachineDomainController()
   at Microsoft.Online.Coexistence.ProvisionHelper.GenerateSyncToken()
   at Microsoft.Online.Coexistence.ProvisionHelper.OpenProxyConnection()
   at Microsoft.Online.Coexistence.ProvisionHelper.InvokeAwsAPI[T](Func`1 awsOperation, String opsLabel)
   at Microsoft.Azure.ActiveDirectory.Connector.ProvisioningServiceAdapter.ExecuteWithRetry(String actionName, Action action).

Any ideas, or can we try to remove and reinstall??
Watch Question

Do more with

Expert Office
EXPERT OFFICE® is a registered trademark of EXPERTS EXCHANGE®
Jian An LimSolutions Architect
Top Expert 2016

you can just remove and reinstall (not this one but AADconnect)
Mitch PDirector


Totally Removed and reinstalled... I am getting a "stopped-server-down" error now... I have checked and double checked the settings. The initial sync works ok but subsequent syncs fail

Any ideas?
Jian An LimSolutions Architect
Top Expert 2016


I have seen that before, it is because the new configuration seems have deleted a large number of object.
better you check out before you do anything.
ONce you confirm, then
Disable the threshold via

Import-Module ADSync
# Disable ADSync export deletion threshold

then sync again.
Mitch PDirector


Will try and let you know
I opened a case with MS and they looked and reported back the following

>>ran port query found 443 not listing on the sync tool server
>>ran netmon
>>but we were not able to trace anything related with inbound and outbound traffic for 443
>>we found that there was event id with error for DCOM permission:-
Event ID:      10016
>>Follow article:-
>>ran full sync
>>now everything working fine  
Cause: Dcom permission issue
Resolution:gave sufficent permison to AAD Account
Here is some more info I thought you might be interested
Microsoft Azure Active Directory Connect
Azure AD Connect: Version Release History

Great help and very concise Not sure why these DCOM errors were there of the user permissions were not as they should be..

Do more with

Expert Office
Submit tech questions to Ask the Experts™ at any time to receive solutions, advice, and new ideas from leading industry professionals.

Start 7-Day Free Trial