Skip to content

Synchronization Service Manager

The Synchronization Service Manager (SSM) is a critical tool for monitoring, configuring, and troubleshooting synchronization between on-premises Active Directory and Azure AD (formerly Entra ID). It provides insights into sync health, error logs, and operational status, enabling administrators to resolve issues proactively. This guide walks through using SSM alongside PowerShell cmdlets to manage sync processes effectively.


Monitoring Sync Status

Use SSM to check the synchronization service’s operational status and health.

Check Sync Service Status

Run the following PowerShell cmdlet to verify if the sync service is running:

Get-ADSyncService
Example Output:
Name             : Microsoft Azure AD Sync
Status           : Running
LastSyncTime     : 2023-10-05 14:30:00
SyncHealthStatus : Healthy

Review Sync Health

Use Get-ADSyncHealth to assess overall sync health:

Get-ADSyncHealth
Key Metrics:
- SyncHealthStatus: Healthy, Warning, or Error.
- SyncErrors: Count of critical errors (e.g., connectivity issues).
- SyncWarnings: Count of non-critical warnings (e.g., attribute mismatches).

Analyze Sync Logs

Check detailed logs for errors or warnings:

Get-ADSyncLog
Filter logs by severity:
Get-ADSyncLog | Where-Object { $_.Severity -eq "Error" }


Configuring Sync Settings

Adjust sync schedules, connection settings, and filters via SSM or PowerShell.

Set Sync Schedule

Modify the sync schedule using Set-ADSyncScheduler:

Set-ADSyncScheduler -Schedule "0 2 * * *"  # Run daily at 2:00 AM

Update Connection Settings

Modify connection parameters (e.g., proxy settings) with Set-ADSyncConnection:

Set-ADSyncConnection -ProxyAddress "http://proxy.example.com:8080"

Configure Sync Filters

Adjust filtering rules to exclude specific objects:

Set-ADSyncFilter -ExcludeObjects "OU=Test,DC=example,DC=com"


Troubleshooting Common Issues

SSM and PowerShell cmdlets help identify and resolve sync failures.

Restart Sync Service

If sync stalls, restart the service:

Restart-ADSyncService

Resolve Connectivity Errors

Check network connectivity and firewall rules. Use Test-ADSyncConnectivity to validate:

Test-ADSyncConnectivity -TargetServer "adfs.example.com"

Fix Attribute Mismatches

Review attribute mappings in SSM under "Attribute Mappings". Use Get-ADSyncAttribute to audit mappings:

Get-ADSyncAttribute | Where-Object { $_.IsMapped -eq $false }


Key takeaways

  • Use Get-ADSyncHealth and Get-ADSyncLog to monitor sync status and debug errors.
  • Adjust sync schedules and filters with Set-ADSyncScheduler and Set-ADSyncFilter.
  • Restart the sync service with Restart-ADSyncService for stalled processes.
  • Validate connectivity with Test-ADSyncConnectivity to resolve network-related issues.
  • Regularly audit attribute mappings to prevent sync mismatches.