Overview
Join John Munjoma as he covers Azure AD authentication and synchronization options.
Recommended Experience
- None
Related Certifications
- Microsoft 365 Certified: Security Administrator
Related Job Functions
- Security administrator
- Security manager
- Security auditor
- Security architect
- Systems administrator
John Munjoma has been a CBT Nuggets trainer since 2020 and holds a variety of CompTIA, Cisco, and Microsoft certifications. His areas of expertise include networking, network security, and Microsoft Azure.
Intro
This Nugget is an introduction to the Microsoft 365 Security Administration certification course.
Azure AD Authentication Options
In this Nugget, we go through the three different authentication options Administrators can choose from to sync their on-prem environments to Microsoft 365.
Knowledge Check
An Administrator wants to use Azure to handle user sign-in to various cloud-based resources. Which of the following authentication methods would the Administrator use?
Monitoring Azure AD Connect
In this Nugget, we learn how to use Azure AD Connect health and Windows Event viewer to Monitor Azure Active Directory Connect.
Knowledge Check
Which tool would you use to monitor your on-premises identity infrastructure from the cloud?
Troubleshooting Azure AD Connect
In this Nugget, we go through the various tools we can use to troubleshoot Azure AD Connect.
Knowledge Check
Which of the following options would be ideal to troubleshoot a group that is not synchronizing between Azure AD and your On-Prem AD?
Conclusion
I hope this has been informative for you and I would like to thank you for consuming.
View Transcript
Intro
0:00[MUSIC PLAYING]
0:05I would like to congratulate you, my friend,
0:08for taking this bold step to pursue the Microsoft 365
0:11Security Administration certification.
0:12Now, most of the times, when [INAUDIBLE] begin a new course,
0:15we spend countless hours online trying
0:17to figure out whether that course is the best fit for us.
0:20And it is important for us, definitely,
0:21as we begin this course to figure out whether we are
0:24the perfect fit for the course.
0:25Apart from that, we also simply want
0:27to know what exactly is covered in the course, what
0:30is the content of the course.
0:32And perhaps are there any prerequisites for us
0:35to actually have prior to us taking these particular course?
0:37Now if you're going to take the exam, which
0:39is the Microsoft-500 exam, for this particular course,
0:44it is important that you have a few things or a few tools
0:47in your kit prior to you going for this particular exam.
0:50I would recommend strongly that you should be
0:52familiar with Microsoft Azure.
0:54It becomes a very important tool as you go further.
0:57It may also be very, very important for you
0:59to be familiar with the various tools and services
1:02that we run on-prem.
1:03And other than that, yes, Microsoft 365
1:06becomes very important, your SharePoint, your OneDrive,
1:09your Teams, and everything else that comes
1:11with this particular package.
1:13Now, am I the rightful fit?
1:15Well, you actually could be very excited
1:16as I am in this particular course.
1:18But, definitely, it's important for us
1:20to know what exactly are we currently doing.
1:22Are you somebody who is dealing with Microsoft systems?
1:24Perhaps managing or administering some Microsoft
1:27365 services or some Azure services?
1:30And if you are, it becomes very important for you
1:32to know how you can go about securing that environment.
1:35And this is where the MS-500 becomes very important for us
1:38to simply delve into.
1:40Well, if you're currently maybe in a space where you hardly
1:43work with all the Azure stuff but you've
1:44been working with some Windows environment on-prem,
1:47could be an Active Directory or any other on-premise service,
1:49it's important, too, that you begin familiarizing yourself
1:52with the various tools with which you could secure
1:54the most important resources that you
1:56may have within the cloud.
1:57Now, for the exam and the course in particular,
2:00there are four different domains that we
2:01have to cover as part of the content.
2:03We have the first domain, which is known as the implement
2:06and manage identity domain.
2:07And, actually, in this particular domain
2:09are many subdomains or other skills
2:11that are covered therein.
2:13So we are going to cover things such as securing
2:15identities, implementing authentication
2:17methods, et cetera.
2:18So this is the section we are going
2:19to look at how we can configure multifactor authentication, how
2:22we can work with SSPR, and many of the things
2:25that are very important for the security of the users
2:27that we have within our environment.
2:29We'll also look at implementing and managing
2:31threat protection, a very important part that
2:33actually looks at how we can use tools such as Microsoft
2:36Defender.
2:38And if you're still doubtful or skeptical of Microsoft Defender
2:40capabilities like I used to be in the past,
2:42you would actually be amazed or impressed by the virus
2:45solutions that it actually provides
2:47from the various endpoint solutions
2:49to Defender Application Guard and Defender Application
2:51Control and many of the tools where
2:53there are features that we can use
2:55to protect our devices from various cloud-based threats.
2:59Once we've covered that part, we are
3:00going to look at implementing and managing
3:03information protection.
3:04Now, this is one domain that is near and dear to my heart.
3:07Why do I say so?
3:08Simply because I am also concerned
3:10with how any organization out there is
3:12going to be handling my personal identifiable information.
3:14If your organization is going to be handling anything
3:17from my age, my name, my Social Security number to my driver's
3:21license, details, and everything else,
3:23I would be concerned with how you're
3:24going to be securing that type of data.
3:27And in this particular domain, we
3:29are going to look at how we can go about configuring
3:31sensitivity levels and various types of policies that
3:33would simply position our systems
3:35and various administrators who are actually handling
3:38this data to be in such an environment, whereby
3:40this kind of information is regarded as sensitive so
3:44that in any event of communicating
3:46with various stakeholders and other users who would actually
3:48not be part of our organization, these users who are handling
3:51this type of data could actually be notified to say,
3:53hey, you are about to share something that
3:55is regarded as very sensitive.
3:57We're also going to look at how we can configure data loss
3:59prevention.
4:00OK, very important stuff that is actually
4:02covered in this particular domain.
4:04The final domain that we're going to look at
4:05is managing governance and compliance features
4:09within Microsoft 365.
4:10Now this is very important, friends.
4:12This is where we're going to look
4:13at how we can do our audit logs, how we can do our reports.
4:17And if you actually thought that this is an entirely technical
4:20course, well, you're actually mistaken because the report
4:23section could actually be done by various stakeholders who
4:25could be in different departments, who simply want
4:28this kind of information for various types of legal reports
4:31or maybe submission of various compliance,
4:34regulatory forms, and everything else that needs to be shown
4:36as proof that we are compliant with the various regulations
4:40and requirements that actually need us to continue operating
4:43in the space that we operate as an organization.
4:45So these are the various domains that we have to cover.
4:47And I cannot wait, to be honest, to work with you through
4:50the various demos that we have to do as we delve into this
4:53particular course.
4:54And, of course, like I said earlier on,
4:55it is important for you to actually
4:57be familiar with the various features such as Azure Active
5:00Directory and the various Microsoft 365 features.
5:02However, this is not really a hard-coded requirement.
5:05You could still actually tag along as we go through it
5:07and be able to pick those pieces as we proceed.
5:10Now without further ado, let's dive into our first Nugget.
Azure AD Authentication Options
0:06Thank you for joining me in this Nugget
0:07as we look at Azure Active Directory authentication
0:10options.
0:11Now, if you would like to come along with me
0:13and go through each and every part
0:15as I would be actually doing these demonstrations,
0:18I would highly recommend you to get a free Microsoft 365
0:21subscription, which is a trial version, which
0:23you can try out these things.
0:24However, you'll also realize that the MS-500
0:28exam or the Microsoft 365 Security administration course
0:32focuses more on ensuring that users
0:34are familiar with both Azure, as well
0:37as the various on-prem environments that you
0:39may simply have in your environment.
0:41In short, this course is actually
0:43ideal for users who are managing a hybrid environment.
0:47So as much as we would like to do things
0:49in Azure and Microsoft 365, it is important for you
0:53to have some form of on-prem environment
0:55that you can create.
0:56And this could be your virtual machines in Hyper-V
1:00or if you're running a VM environment with ESXi,
1:03let's say, version 6.5 or version 7,
1:05and you're able to simply spin some virtual machines in there.
1:08That would actually become ideal.
1:10So what I would simply want to do in that case
1:12is to simply spin up one virtual machine
1:14that we can use as a domain controller for the environment.
1:16It doesn't matter how [INAUDIBLE] are used really,
1:18how everyone comes to the operating system.
1:20I would recommend that you use Windows Server 2016 or later.
1:25You'll also need to have access to a domain
1:27that you can administer and make changes to,
1:30and this is the domain that you would
1:32need to register with Microsoft 365 in the cloud.
1:35And at the same time, the domain should also
1:37be in your domain controller.
1:38And like I said, it isn't really very important
1:42that you stick to a particular hypervisor,
1:44but if you're able to stick with, let's say, Hyper-V,
1:48I'm pretty sure that would work great.
1:49So like in my case, I have Hyper-V over here.
1:52You would simply have to go and create
1:54your new virtual machine.
1:55And from that virtual machine, you then
1:57go ahead and run your server operating system.
2:00Like I said, the hypervisor you're going to be using
2:03is not a big issue, so you'll notice
2:04that most of the demos that will be running
2:06will be in VMware ESXi.
2:09And in this environment, I have my Windows Server 2022.
2:12Don't worry much about the version.
2:13If you can't get hold of Windows Server 2022, 2019 and 2016
2:17still have very similar features,
2:19and you'll be able to follow along using those versions
2:21of Windows Server.
2:22So in this particular environment,
2:25the most important thing is for you to ensure that whatever
2:27server that you have, which is going
2:29to be running as a domain controller,
2:31has the same domain as the one that you're
2:33having within your Microsoft 365 environment.
2:36So the main objective over here is
2:37for us to be able to link these two environments, our cloud
2:41environment, as well as our on-prem environment.
2:43So in this case, we could have a domain controller over here,
2:46and we definitely have our Active Directory.
2:49And we have various resources that we have over here.
2:51So all the identities that we have in this environment
2:55should actually be able to be accessed from our Azure
2:59environment using the Azure Active Directory.
3:01So this becomes very important as it allows our users
3:04to benefit from the various Azure services
3:07that they wouldn't actually be able to access
3:09had their only continued to run on prem.
3:11For example, SSPR, which simply allows our users
3:14to reset their passwords, this is a very important tool
3:17that users can actually leverage upon each and every time
3:19they've forgotten their passwords
3:21or they simply suspect something is happening
3:23and they want to reset their passwords, et cetera.
3:25This will give our users access to an Azure service
3:27to perform tasks that they previously
3:29couldn't complete without the help of an administrator.
3:32And this actually becomes a win-win situation
3:35as the user is now able to reset passwords
3:37to their own convenience without having
3:38to call the administrator.
3:40And the administrator, on the other hand,
3:42can now focus on more important tasks
3:44other than repeatedly resetting passwords for users.
3:48And for this kind of communication
3:49to actually happen in a secure way where [INAUDIBLE]
3:51are identities on the on-prem servers
3:53that we have are actually reflected in our Azure Active
3:57Directory, et cetera, we have to plan well.
4:00There are actually three ways in which we can accomplish that.
4:03And for us to be able to set that in place,
4:05we could opt to configure password hash synchronization
4:09within our environment.
4:10Another option we can make use of
4:12is the pass through authentication.
4:14There has to be the rightful type of authentication
4:17between these two environments in order for us
4:20to ensure that we can actually have
4:22all the identities reflecting within our Azure Active
4:24Directory.
4:24The third option that we can make use of is Federation.
4:28We are making use of Active Directory Federation services.
4:31I would like us to take some time and focus on each of these
4:34so that we can be able to make the best decision whenever
4:37we are planning for Azure Active Directory authentication.
4:41All right.
4:41So let us set some things straight over here.
4:43I would like us to think of these as two separate entities.
4:46As always, of course, these are two different parts.
4:48So we have our on-prem over here, OK?
4:52And there is our cloud.
4:53So everything beyond this line is just the cloud section.
4:58So let's look at these differently.
5:00The objective is for us to be able to connect whatever
5:02we have on-prem to the various services
5:05that we simply want to actually use within the cloud.
5:08This could be our applications, that
5:10could be Microsoft 365 services, or many other interesting Azure
5:15services, such as Azure Active Directory.
5:18All right.
5:18So for us to be able to link our on-prem environment
5:20to our Azure cloud environment, we
5:23have to make use of a tool that is known as the Azure Active
5:26Directory Connect or AD Connect.
5:28Now, before that, AD Connect was known as DirSync
5:31or directory synchronization.
5:33And I remember like yesterday when
5:35we used to create user accounts within our on-prem Active
5:38Directory.
5:38And users would go like, can I begin accessing my Microsoft
5:41365 for Office 365 services?
5:43And be like, oh, give me a couple
5:44of minutes or five minutes.
5:45I'm still waiting for DirSync to complete synchronization.
5:48So this was actually what was required in order for us
5:51to have the various accounts that are actually
5:53stored on our on-prem to reflect within the various Azure
5:57and Microsoft 365 services that we're simply using.
5:59And prior to that--
6:00actually Microsoft does this so many times
6:02with this issue of renaming services.
6:03This was also known as Azure Active Directory
6:06synchronization services.
6:07Now, the main point here is that we
6:09need to understand how AD Connect plays
6:12this important role in ensuring that there
6:14is a proper connectivity between our Active Directory on prem
6:17and the various services that we have in the cloud.
6:19So let's [INAUDIBLE] for example,
6:21that we'd like to authenticate the various identities that we
6:23have within our environment using password hash
6:26authentication.
6:27And in fact, this explains what exactly
6:29used to happen in the background each and every time I
6:32as an administrator was telling the various users whose
6:34accounts were just created to say
6:36they should wait a bit for DirSync
6:38to complete synchronization.
6:39Now what happens in the background is as follows.
6:42The first thing that you're going to do
6:43is to install your AD Connect on your domain controller.
6:46So you have that application running,
6:48and your domain controller on-prem
6:50has AD Connect installed.
6:52Once that has been done, the synchronization agent
6:54that runs in AD Connect is going to request
6:57for password hash values that are stored in your domain
7:01controller.
7:02And each and every tank this happens,
7:04the AD Connect is simply trying to query
7:07if there has been any update, if there
7:09has been any new identity whose password has to be updated
7:12to Azure Active Directory.
7:13So this happens each and every two minutes.
7:15This querying happens every two minutes.
7:17And then when the synchronization agent
7:19has run that request, your domain controller
7:22is going to do the second thing, which
7:24is to respond by retrieving those hash values.
7:27And please take note here that it isn't retrieving
7:29passwords in plain text.
7:31It's actually retrieving the hash value
7:33of each and every password.
7:34And once that hash value has been retrieved,
7:36it is going to sort it by adding additional characters
7:40and simply increasing its complexity.
7:42And once that hash value has been sorted,
7:45it is now going to respond by sending that hash value
7:48to the synchronization agent.
7:50So the synchronization agent now has the hash value
7:53that has been sorted and sent to each from the domain
7:56controller.
7:56The third thing is that the agent
7:59is going to decrypt this particular hash.
8:02Remember that this hash was actually sorted prior to it
8:05being sent to the agent.
8:06So what's going to happen is that the agent
8:08is going to remove every additional character that
8:10was added during sorting as to maintain
8:12the original state of the hash prior to it being sorted.
8:15So once it has been decrypted, then it
8:17will actually rehash it again.
8:19So when it's rehashes it, it will actually
8:21put it in the secure hash algorithm 256.
8:25And once it has done that, it's now
8:27going to pass it over securely using SSL to the Azure Active
8:31Directory database.
8:32So in this case, we simply want to ensure that the hash is
8:35stored in the Azure database.
8:37Now what is going to happen is that each and every time
8:39a user tries to access the Azure resources
8:42or any of these services from Microsoft 365, the Azure Active
8:45Directory database is going to have
8:47that hash as a condition with which
8:50is going to verify and authenticate
8:52users who require access to various Azure services.
8:55So in the event that the user keys
8:57in a password and that password's hash value
8:59is equivalent to the hash value stored within the Azure
9:02database, then that user will be granted access.
9:05In the event that this condition is not met or it's not true,
9:08then that user won't actually be granted access
9:10to any of those Azure services that require access to.
9:13So with PHS, or password hash authentication,
9:15you'd actually give your users the ability
9:17to use the same username and password that they'll
9:20use to sign into various resources
9:21that they have on-prem to sign into various resources
9:24that you now have in the cloud or in Azure.
9:26It is fairly easy to deploy as well
9:28and doesn't require any additional infrastructure
9:30for you to actually carry this out.
9:32As long as you're comfortable with storing all those password
9:35hash values in the cloud, then everything
9:37should actually be perfect for you.
9:38And in this case, you wouldn't actually
9:40require any additional or high-end functionalities
9:43in order for you to deploy it or even for your users
9:46to be able to work with it.
9:48It's actually a very easy type of authentication
9:51as you shall see in the coming skills
9:53when you get to configure this type of authentication.
9:56Now, if your organization isn't comfortable
9:58or their policies that negate your organization
10:00to directly synchronize your on-prem environment
10:02to your cloud services like Microsoft 365,
10:05well, Microsoft has a solution to that.
10:07You would actually use the Pass-through Authentication.
10:11Now, the Pass-through Authentication,
10:13unlike the password hash authentication,
10:15doesn't store all those values in the cloud.
10:18Users, in this case, are not authenticated
10:21by the hash value stored in the cloud
10:22rather they are authenticated by the very on-prem environment
10:26that they have using their domain controllers.
10:29So in this case, if we have whatever other services
10:31that you're running and we have a domain
10:32controller in this area, it will simply
10:34check what identities do we have within our Active Directory.
10:37All right, these are the identities.
10:39What are their passwords and their values?
10:41OK, these are their values.
10:43And thereby carry out authentication on-prem.
10:46So all of the authentication is going
10:47to happen on-prem unlike when we use password hash
10:51authentication.
10:52The caveat may arise when we have authentication issues
10:54to do with the service that we are using on-prem
10:56to authenticate our users.
10:57In this scenario, all we'll simply need
10:59is a lightweight agent installed on those domain controllers.
11:03If you have multiple domain controllers that we're using
11:05or it's a single domain controller,
11:06that would still function well.
11:09The advantage still is that you're not
11:10going to store any of those passwords
11:12in the cloud that would remain on prem for security
11:14reasons or any other reasons that your organization may
11:16simply have.
11:17Another option that could be ideal for your organization
11:20is when you're making use of a federated authentication
11:23system.
11:23So this would actually need to make use of your Active
11:26Directory Federation services.
11:27A Federation will usually have two or more domains that
11:31actually trust each other, and these domains
11:34have access to resources across the organization.
11:37So again, instead of any of those domains directly
11:40synchronizing to your cloud environment,
11:42you would simply want the authentication
11:44to happen on-prem.
11:45So you simply want to authenticate your user
11:47in a slightly similar manner to what you'd
11:49experience if you had passed through authentication.
11:51Now, federated authentication can be great,
11:53especially if you have multi-factor authentication
11:56that is being handled by different organizations.
11:58And you simply don't want that kind of authentication
12:01be done with maybe your Microsoft 365,
12:03and you want to maintain that organization.
12:05Then you could actually look no further but
12:07to implement this type of a solution.
12:09So while this may be great for organizations that simply want
12:12to authenticate their users on-prem
12:14and make use of certificates or third-party multi-factor
12:16authentication organization, this actually
12:19would require a lot of management.
12:20It will actually have a lot of overheads
12:22in terms of you maintaining the infrastructure that
12:25will be needed in order for you to make
12:27use of a federated authentication system.
12:30So in certain circumstances, you might end up
12:31having to deploy more than one authentication method.
12:34For example, you might want to have
12:36a part of what you'd see in the password hash authentication
12:39or maybe have another domain controller configured
12:41with Pass-through Authentication in order for you
12:43to benefit from the features that are contained
12:45in Pass-through Authentication.
12:47However, it is here that administrators will actually
12:49be able to decide what authentication method is
12:52the best for the environment.
12:53Well, for now, my friend, I hope this has been informative
12:56for you, and I would like to thank you for viewing.
Monitoring Azure AD Connect
0:00[OPENING JINGLE]
0:05Hello, and thank you for joining me in this Nugget,
0:08as we look at monitoring Azure AD Connect.
0:11Now we have so far looked at how we can install Azure AD
0:14Connect, and we understand its importance
0:16when it comes to managing our hybrid environment,
0:19especially when it comes to identities.
0:20Now, of course, when talking about hybrid environments,
0:23we are referring to both our cloud
0:24environment, as well as our own on-prem infrastructure,
0:27and what connects, or the links the two
0:29is our Azure AD Connect.
0:31So that is its key and important role.
0:33And we cannot just overlook such an important factor within
0:36our environment, without putting in place various solutions that
0:38will help us to keep an eye on what exactly is happening.
0:41And what are the things we could do to remain
0:43informed, in terms of how it's operating?
0:45How well it is synchronizing?
0:47And if at all, there is anything that we
0:49need to do to ensure that everything is running smoothly.
0:51All right.
0:52So what are those things that we can do within our environment
0:54to simply ensure that we have an understanding of what is going
0:57on with our Azure AD Connect?
0:58One of them is the Azure AD Connect Health Analytics.
1:01Now, this is a very important service
1:03by Microsoft, which simply gives us
1:05an overview in terms of how this tool is functioning
1:08within an environment, where there has been some errors
1:10and synchronization, where there's been any anomalies that
1:13are actually making these to not function properly.
1:16Now, this doesn't actually solve anything.
1:18It's not your troubleshooting tool
1:20that is going to give you step 1 to 10,
1:22on how you can resolve something,
1:23but it gives you insight in terms of what you can do.
1:26Although this may not be something
1:27that you'll be doing every day as an administrator,
1:29but whenever there is an issue that you're
1:31failing to understand, it is always
1:32important to look at what the real issue is
1:35by looking at all these alerts, which would help you
1:38in a troubleshooting process to resolve the problem.
1:41Another solution that we have to look at is the Event Viewer.
1:43As old as it may seem, this becomes very handy because,
1:46on that server where you're running your AD Connect,
1:49you can also have logs informing you
1:51when the device was turned off.
1:53Maybe there was an upgrade of your RAM on that server
1:55infrastructure or anything else that required the hardware
1:58to be turned off and AD Connect couldn't sync anymore.
2:00You would simply need to have an understanding of what exactly
2:03happened in the past and be able to track that and see
2:06if you could use some of that information that
2:08has been monitored previously to actually resolve any issues.
2:12Now without further ado, I want us to get into the Azure portal
2:15and look at how we can make use of the Azure AD Connect Health
2:18Analytics.
2:19And later on, look at the Event Viewer.
2:21See you there.
2:22All right, folks.
2:23So here we are within Microsoft 365 Admin Center
2:26and from the dashboard, we already
2:27can see that we have Azure AD Connect in place.
2:30So over here, we simply get an update
2:32in terms of our sync status, as well as
2:33password sync, et cetera.
2:35So if you would like to keep an eye
2:36to see that your Azure AD Connect is live,
2:39then this is one quick area you can always keep an eye on.
2:42But to have more information, then we
2:43can simply go and open our Azure portal.
2:45There are many ways to get there.
2:46And over here, I have Azure Active Directory.
2:48So I simply click over there.
2:50And once I am in here, then we can access our AAD again.
2:54And within our Azure Active Directory,
2:56we simply have to scroll down and access Azure AD Connect.
3:01So once we click on that one, we simply
3:02have more information here we have Troubleshoot.
3:04We have Refresh, et cetera.
3:05So this simply gives us an insight
3:07in terms of the health status of our Azure AD Connect.
3:10So we have quite a lot of information
3:12here from provision from Active Directory.
3:14We have managed Azure AD Cloud Sync,
3:16but our interest is mainly towards the end, where
3:19we have Health and Analytics.
3:21So if we click over here, this simply gives us
3:23information aligned with our own on-prem identity infrastructure
3:26and synchronization services to Azure.
3:28And in this case, identity is definitely
3:30referring to our users, et cetera.
3:32So let's go ahead and click over there.
3:34So over here, we have information
3:36regarding the latest features.
3:37We can add additional tools if we
3:39would like to have more information regarding
3:41AD Connect Health agents for Active Directory, et cetera.
3:44We can also provide feedback to Microsoft if we need to,
3:47or simply learn more about it too.
3:48And to our left-hand side, we have Sync Errors.
3:51And if we go and click over there,
3:53you'll notice that we can have more information regarding
3:55the various types of errors that could have actually
3:57been happening within the environment.
3:59And this is the area as an administrator, that
4:01could prove very helpful if you're carrying out
4:03some troubleshooting of our Azure AD Connect.
4:05For example, here, we have duplicate attribute.
4:07You may have a data mismatch, you
4:08have data validation failure, et cetera.
4:10And you could simply look at these
4:12and be able to carry out your troubleshooting based
4:14on any recorded errors in this section.
4:17Now the primary goal of this tool
4:19is to simply inform us when the last synchronization took
4:22place.
4:22And this is between our Azure Active
4:24Directory and our on-prem Active Directory.
4:27And it is important for us to make
4:28use of the various notifications that we can
4:30stay abreast of the situation.
4:31We would like to be informed each and every time
4:34there is something critical or an error of any sort
4:36that has stopped this synchronization.
4:39And if you look at the top section,
4:40we have Notification Settings.
4:42We click over there.
4:43We can actually enable this feature here.
4:46So that each and every time there is something critical,
4:48all our global administrators are informed that there
4:51is something that is going on.
4:53And they can receive emails, timely,
4:55informing them that there is normal synchronization going
4:58on, and the error is X,Y, Z.
5:00Now, this becomes very important as it
5:02allows us to see those errors as soon as synchronization stops,
5:05even if I was away from work, I would at least
5:07be in position to know what is going on
5:09and be able to begin resolving that error as soon as possible.
5:14So over here, we can simply go ahead and click on Save.
5:16And if you go back to the Azure Active Directory Connect
5:19Health, we can still benefit from other features.
5:21Over here under Configure, if we go and access our settings,
5:24we have a feature that allows us to always remain up
5:27to date with our Azure AD Connect Health agents.
5:30So by enabling this, we are simply
5:31ensuring that each and every time there's
5:33a new release of the Azure Active Directory Connect
5:35Health, would also be updated.
5:37And if it all we benefit as an organization
5:39from the various Microsoft services, when
5:41it comes to support, et cetera, and we simply
5:43want to give them access to our tenant's,
5:44then this can be very helpful.
5:46Turning these on would simply allow Microsoft Access
5:48to our tenants Health Data.
5:50So if that's something that I would like to have,
5:52then we can turn that on.
5:53Now, apart from working with Azure AD Connect Health
5:56to monitor and troubleshoot the various issues that
5:58could arise with the environment,
6:00it is important for us to also investigate
6:02what could be happening on the host,
6:03where AD Connect is installed.
6:05And based on my past experience, the most cases when
6:07AD Connect wouldn't synchronize, would
6:09be as a result of a power outage,
6:11where the host server had to switch
6:12from the primary source of power to the secondary one
6:15or in the event that there is a planned hardware upgrading that
6:17is to be done on the host server.
6:19Now for us to assert that, we need
6:21to make use of Event Viewer within our host server
6:23and be able to prove that.
6:25However, for the sake of your exam,
6:26it may be important for you to be aware of the various steps
6:29that you have to take in order for you
6:30to access the Azure Active Directory Connect health.
6:34Now here we are within our host server,
6:36Azure AD Connect in its integration with our cloud
6:38resources, does leave logs on a host server
6:41that we can use to have an understanding of what exactly
6:43could be happening within our environment.
6:45So if we search Event View over there,
6:48and would simply want to understand what exactly
6:50could be happening.
6:51We could use the Windows Logs feature.
6:53And over here, we can access applications.
6:55And from the applications area, we
6:56can do quite a number of things to simply read
6:58through and track those logs.
7:01For example, we can already see there is ADSync 405,
7:04and this is happening on the server.
7:06And if we wanted to, we could simply go and search.
7:09So in the search area, we could simply
7:11say AD Connect if we want.
7:13Or would simply say ADSync.
7:15And we can carry out that search to continue
7:17having more information that tells us what exactly has
7:21been happening on our device.
7:23Now over here, we can also see the level of these events
7:25that most of them are simply informational.
7:27But if we had something that was saying Error or Warning,
7:30then it would be something that really requires our attention.
7:33Apart from that, we can also see the debt and time
7:35on which this was happening.
7:37We can see the Source's Directory Synchronization,
7:39Event ID, et cetera.
7:40And we can also have more information
7:42regarding the various events that are being generated.
7:44From here, we have the general area and the details area,
7:47which could simply give us more information regarding
7:49this particular event.
7:50So all this have to do with our own on-prem
7:51Active Directory failing to synchronize with our Azure
7:54Active Directory.
7:55And if we simply wanted to get into details of all these,
7:57we could also try and make use of the future features
8:00over here.
8:01Filter Current Log, for example.
8:03Let's just deselect that and go straight
8:05to Filter Current Logs over here.
8:06And let's say we would like to see something
8:08that is Error-wise and Warning.
8:10So if you click OK, we'll have all that information
8:13displayed for us.
8:13And over here, we can see quite a lot of information
8:16regarding all this.
8:17Now, if we just go and select the Directory one,
8:19let's just select the first one.
8:20We can also begin picking up information regarding
8:23what has been happening.
8:24For example, Azure AD Connect scheduler
8:26is unable to start a new sync cycle
8:28since that particular day.
8:29And all these could be been informative for us.
8:31We would also look at the Errors if there
8:33is anything that is to do with AD Connect throwing errors
8:35at us.
8:36And fundamentally, anything that is hindering it
8:38from synchronizing within our environment
8:40would be very useful for us.
8:42So, my friend, this is how we can
8:43make use of the Azure AD Connect Health Analytics tool,
8:47as well as the Event Viewer to simply ensure
8:50that we are keeping an eye on Azure AD Connect.
8:53And that the synchronization is happening in time.
8:55So that our users who are working from various locations
8:58can access all our applications and everything
9:01that is within our Azure Active Directory.
9:03And our on-prem identities are updated in synchronizing
9:06to Azure and all the objects are synchronized by means
9:09of the Azure AD Connect.
9:11So in conclusion, these are the tools among many others
9:14that you may rely on to monitor your Azure AD Connect
9:17within your environment.
9:18For now, my friend, I hope this has been informative for you,
9:21and I would like to thank you for viewing.
Troubleshooting Azure AD Connect
0:00[AUDIO LOGO]
0:05Hello and thank you for joining me on this Nugget
0:08as we look at troubleshooting AzureAD Connect.
0:12Now each and every time we're looking at AzureAD Connect,
0:14we need to understand that this is an entity that
0:17is responsible for linking our on-prem services to AzureAD.
0:22And it is important for us to always ensure
0:24that the synchronization between these two environments
0:27are actually functioning well.
0:28Because the moment synchronization stops,
0:31then whatever we do on our on-prem,
0:33whether we are adding users or making certain edits,
0:35would actually not synchronize in AzureAD.
0:39In the previous Nugget, we looked
0:40at how we can go about keeping an eye on monitoring AzureAD
0:43Connect and look at the various important areas
0:45where that information could be found.
0:47However for this particular Nugget,
0:49I want us to take some time and look
0:50at what we can do in the event that AD Connect simply
0:53stops to synchronize or we simply keep on seeing errors
0:57and warnings, and we simply want to find a solution
0:59to permanently resolve that.
1:01I tell you the truth, there is nothing
1:03that is horrifying than coming to work every day
1:06and seeing that same ticket or that same error
1:08because you would know that, at a certain point,
1:10it is going to bomb and affect the rest of the infrastructure.
1:13So let us take some time and look at some of those areas
1:16that we can begin looking at in the event
1:18that we are troubleshooting AzureAD Connect.
1:21One of them is the Microsoft Services.
1:23Yes, the good old Microsoft Services
1:25is very key and important in helping
1:28us understand whether there is any service that
1:30is dependent on AzureAD Connect that isn't running.
1:33If any of those services are not running,
1:35you can simply go to the host server
1:37where AzureAD Connect is installed and check.
1:39Sometimes they could actually be running,
1:41but we simply have to restart them in order for them
1:44to be refreshed so that they can actually
1:47start anew and ensure that each and every service is running.
1:49This is one of the basic things we can do for those services.
1:52There are other times when you have
1:53to install those services anew, but that is
1:56something that is very serious.
1:57But if it actually becomes very important
1:59that we should go ahead and do that,
2:01we can run quite a number of scripts within PowerShell
2:04to install those services.
2:06Another aspect that we can also look at
2:08is the synchronization manager.
2:10Now the synchronization manager comes as part of the package
2:12when installing AzureAD Connect on the on-prem server.
2:16And in this case, there are other features
2:18that are actually contained in there, which you can tweak
2:20and fine tune to ensure that synchronization is happening.
2:24As the name suggests, this is simply
2:25the management of the synchronization between the two
2:28environments.
2:29And lastly, we have the AD Connect troubleshoot.
2:31Now this is something that would come embedded
2:33within AzureAD Connect itself.
2:36So we have to launch AzureAD Connect,
2:38and once we have launched it, we have the troubleshoot area.
2:41And there are quite a lot of features and options
2:44that we have to maybe select and ensure
2:46that we can also resolve that error based
2:48on the options provided and the trouble we are experiencing
2:52within our environment.
2:53And of course, we can still rely on some of the information
2:55that Microsoft provides, especially
2:57when it comes to all those tips that pop up within the health
3:00analytics area.
3:01We can also leverage on that information
3:03to ensure that we have as much information
3:05as we can to timely resolve any issue that
3:09may arise as a result of AzureAD Connect
3:11not syncing within an environment.
3:13Without further ado, I want us to dive into Microsoft 365
3:16and look at how we can go about troubleshooting AzureAD
3:20Connect.
3:20All right folks, so here we are within the Microsoft 365 admin
3:23center.
3:24And if we go to the user management AzureAD Connect,
3:27already we can see sync status--
3:29last seen 35 minutes ago.
3:32Now the AzureAD Connect feature that we actually
3:35rely on to ensure that everything
3:36is functioning properly is the Azure Synchronization Service
3:41Manager.
3:42This happens every 30 minutes automatically.
3:45Every 30 minutes an update has to take place.
3:48Now this is a synchronization update.
3:49So if, for example, I'm adding a user over here in this area--
3:54if that user is added, when that synchronization takes place,
3:57then that information must be transferred
3:58from our on-prem environment to our Azure environment.
4:02Now it doesn't necessarily take 30 minutes for a single user
4:05that we are creating on on-prem AD to be updated to AzureAD.
4:09However, this synchronization is specified for 30 minutes
4:12to ensure that if there is anything-- any user,
4:15any object, or anything that has been done
4:17on our on-prem infrastructure-- then
4:18all of those configurations and updates that have been done
4:21can synchronize and be updated into our cloud environment.
4:25Therefore, this is very important in ensuring
4:28that at the time of this synchronization
4:30every piece of data or object we configure on our on-prem server
4:33can now be integrated and updated into Azure.
4:36And each and every user who needs
4:38to make use of that service from the cloud
4:40would now be able to access it without having
4:42any difficulties.
4:43And you can actually look into Synchronization Manager
4:47and look at how you can go about manually updating this,
4:50if you have issues that have to do with users who are not
4:53able to access their resources or are not able to sign
4:56into their Azure tenant, or they're simply
4:58having challenges accessing these services.
5:01But in the event that doesn't happen automatically,
5:04like I said previously, we can come over here and manually
5:07restart that service.
5:09So here, we are already notified that this service hasn't been
5:13able to sync in that past time.
5:15And if we head to our Azure Active Directory,
5:18so that we can access the AzureAD Health Analytics,
5:21you'll also be able to see that there
5:22is information already informing us that something isn't right.
5:26So here we are within AzureAD.
5:28If we access our AzureAD Connect over here and access the Health
5:33Analytics, you'll be able to see that-- over here--
5:36if you've go to sync errors--
5:38OK, we don't really have anything in the error section.
5:40How about sync services?
5:42Oops, there we go.
5:43All right, so over here we can see
5:45that this is the service name that is affected
5:47and we can see that there are two active alerts--
5:49the time when this happened-- and this
5:51is simply a warning that there is an unhealthy service
5:54of some sort.
5:55There we go.
5:55There's a warning over there.
5:57If we have to resolve that, we have
6:00to pick the bits and pieces together and begin
6:02looking at what we can do in order for us to resolve that.
6:05So we can see over here there are also two counts there.
6:08And we can actually expand that over here with health service
6:11data is not up to date.
6:12All right, so that is one warning.
6:14And we have synchronization has stopped.
6:16Now I have said it in the previous Nugget,
6:18in most cases this could actually
6:20be as a result of maybe a power outage.
6:23The server is simply off.
6:25But as you can see from the Microsoft 365 AD Connect area,
6:28password synchronization is happening.
6:30It's just the syncing status that is telling us
6:32that something isn't right.
6:33So already this nullifies that this
6:36could be a power-related issue.
6:37Or maybe there was some outage of some sort
6:39that rendered your server to completely go off.
6:42So over here we can also see that, if we click over there,
6:45we can get more information regarding what we can do.
6:47There are also additional links that we can click on
6:49to simply ensure that we understand and can troubleshoot
6:52that issue correctly.
6:53If we go back there, we can also do the same over here.
6:56Now sometimes, due to regulatory stipulations, that
6:59prevents organizations from collecting AD Connect health
7:03information or we could simply have this service
7:05off within our environment.
7:07And if we head back to the Azure Active Directory Sync area
7:10and check the other alert that we have here,
7:12this one is an error type and it's actually
7:15a synchronization-related error.
7:17There isn't any communication anymore
7:19that is happening between our on-prem server and our Azure
7:22Active Directory.
7:23And this shows us that the scope is covering that account
7:26and was raised on that particular date.
7:28And then we have all the information, et cetera.
7:30And if we click on it over here, we
7:32can also now have detailed information regarding
7:35this particular alert.
7:36We can see what the issue is.
7:38It's a synchronization-related issue and we are unable
7:40to update this information or the data in AzureAD--
7:43over there-- and we have a suggested fix.
7:46Over here we're notified that AzureAD Connect may
7:48fail to schedule its next sync if AzureAD is actually
7:52open in the background.
7:53And we may simply have to ensure that it
7:55is closed in order for it to schedule
7:57the following synchronization.
7:58We may also have other features that would simply
8:00allow us to make use of all the available tools on our Windows
8:03devices to ensure that this service is running properly.
8:06Over here we can see that we have services
8:08and we can go and restart all the services
8:10that have something to do with the Microsoft AzureAD sync.
8:13However, when we do this we have be very careful,
8:16as resetting this will interrupt any other service that depends
8:19on the Microsoft AzureAD sync--
8:21right there.
8:21Also additional links that we can follow over here.
8:24There is quite a lot that we can rely on
8:26as we continue hunting for the solutions that
8:28have to do with us resolving the errors that we are experiencing
8:32within our environment.
8:33All right so the low hanging fruit for us,
8:35when troubleshooting this error is to begin with services.
8:39If we go and check services, or you could simply say run
8:42and you do services with MSC, then you
8:44should be able to have a view into what exactly
8:47could be happening within your environment.
8:49We would be, in our scenario, looking for anything that
8:51is to do with AzureAD Connect.
8:54We can see here, AzureAD Connect AD DS Insight Services
8:57is running.
8:58We have the Health AD DS Diagnostic Services.
9:01We have quite a lot of them that have to do with AzureAD Connect
9:04so we could manually go and maybe
9:08try to do a restart of each one of them,
9:10or simply stop them and start them afresh.
9:13However if there are a lot like this,
9:15the quickest way in which we could go about that
9:17is to simply go and open up PowerShell.
9:19And over here, we could go and do a restart service.
9:24And then we can specify that anything
9:26that has to do with AzureAD Connect within our environment
9:29should actually be restarted.
9:31Simply add an asterisk over here so
9:33that everything that has that at its end
9:35can simply be restarted.
9:36Press enter over there and it will restart those services
9:40within our environment.
9:41Let's just see there.
9:42OK, those are warnings to say restarting this would actually
9:46have some implications on any other service that
9:49depends on AzureAD Connect.
9:52They should actually go off, all of them.
9:54And later on be restarted.
9:57That on its own should help us to refresh or correct
10:01any other errors that pertain to this problem
10:04that we are facing within our environment.
10:06And if that in any instance does not work or doesn't resolve
10:09our scenario, then would have to escalate this and look
10:12at how best we could look at other features and tools that
10:15could help us resolve this particular error.
10:18All right, so another tool that we can rely on
10:20is the Azure Active Directory Connect Synchronization Service
10:24Manager.
10:25Over here we have Synchronization Service.
10:27If we click over there to open it we have in this area
10:30the names, the profile, and the status, including
10:33the time and end time of all the synchronization that
10:35actually took place.
10:36Over here, we can simply have an insight
10:39into any sync that wasn't successful--
10:41if at all there was any.
10:43And if you'd like to do a manual synchronization,
10:45we could use our connectors in this area--
10:47if we click on connectors over there.
10:49And from here, you can see the two domains
10:51that we have-- the M365 domain and the junction technology
10:55domain.
10:55And if we needed to actually go ahead and do
10:58a manual synchronization of any of these domains,
11:01we can simply click on the domain
11:02and we have connectors in here-- or we can simply right
11:04click on that-- and do a restart of this.
11:07We could either stop it and try to run it
11:10or if we are having trouble maybe synchronizing
11:13certain objects within our environment,
11:15then we can go and select the properties area.
11:17Let's go and click on properties over here.
11:19And we have the connector designer
11:21in this section and the various menus.
11:23And here we have select object types.
11:26If we click over there, we have to ensure
11:28that the feature that you're looking for, for instance,
11:30is a group that is in synchronizing,
11:32then we'll have to verify whether group is selected.
11:34Now by de-selecting this option, you
11:36understand that the replication would be in the synchronization
11:39process.
11:40It will not include these deselected feature.
11:43And there are other features that may not appear over here.
11:45If in case we wanted to see that we can simply
11:48go to select all over there and we can view the various
11:51features that we may simply want to add
11:53in this particular domain.
11:55Now all this becomes very important
11:56because, in the synchronization process, anything that is not
11:59included and may be useful for users, in the event
12:02that they try to access it from the cloud
12:04that feature won't actually be there.
12:06All right, so other than the Synchronization Service
12:08Manager, we also can go to AD Connect itself.
12:12And when we open AD Connect there
12:13is a feature that allows us to begin the troubleshooting
12:16process.
12:16I'm just reposition this for us.
12:18All right, so there we go.
12:20Now if you notice here, we have the configure area-- just
12:23at the bottom here.
12:24If we go and click on configure, at the very bottom of the tasks
12:27that we have in here we have troubleshoot.
12:30Go and click on troubleshoot over there and click next.
12:32And once we have done that, we can launch the troubleshooting
12:35tool.
12:36And right away it'll open PowerShell
12:38with a number of options.
12:40Over here we have options from one until six
12:44and Q is for us to quit and go out of this particular area.
12:48And we have the first one, where we simply
12:50want to troubleshoot an object synchronization.
12:52So take, for example, that you created a group and that group
12:55after--
12:56let's say an hour or two-- it isn't still
12:58popping up within Azure.
12:59You can actually begin to look at what
13:01could be causing that group from not showing within the cloud
13:05environment.
13:06That would simply help you to begin troubleshooting
13:09of such particular objects.
13:11You also have troubleshooting password hash synchronization
13:14for identities that aren't going to be able to synchronize.
13:17You have collecting general diagnostics information.
13:19Configure AzureAD DS Connect to account permissions.
13:23You have test AzureAD connectivity.
13:25You have test active directory connectivity.
13:28All these could be very helpful.
13:29And if you're thinking in our scenario we are actually
13:31unable to connect, this will become very important.
13:35The fifth option-- just for us to begin testing
13:37for connectivity issues and also verify
13:40that our active directory is perfectly connected.
13:43All right, so let us start with the first one, which
13:45is the fifth one, when we are testing
13:48active directory connectivity.
13:50Let's go ahead and select five over there.
13:52When you press five, it should run a test.
13:54It says we're testing Azure connectivity
13:56for connector M365.
13:58That's our domain, right?
13:59And then it actually gives us a printout
14:01here of true and no connectivity issues have been detected.
14:05This looks good on this end.
14:07All right, so how about our active directory connectivity?
14:10Let's go ahead and select option number six over there.
14:14If we select option number six and press enter?
14:16OK, it says current configuration status.
14:18Would you like to test a forest that already
14:20has a connector configured?
14:21Oh yes, we would like to.
14:22We have junction technology, right?
14:24So if we press A over there and press enter--
14:26configured active directory connectors--
14:28we have one over there, which is junction technology.
14:30That's the name.
14:31Let's just go ahead and specify junction technology.
14:35All right, .co.za and press enter.
14:38If there are any issues with this--
14:39you can see that already it is picking up that information
14:42to do with our FQDN and all the data that is required.
14:45And finally, it gives a printout output
14:48of no connectivity issues detected.
14:50So far everything looks good, but we can also
14:52still make use of various options
14:55in here, depending on the scenario
14:57we are trying to resolve.
14:58If you are dealing with an identity issue
15:00or if you are dealing with an object issue,
15:02we could also rely on these options over here.
15:04So how about object synchronization, option number
15:07one?
15:07Let's try that out and see how it turns out.
15:10If you press enter over there, that simply
15:12gives you access to your active directory objects
15:15within that domain.
15:16Now in this case, your object could be users,
15:18or they could be shared folders or applications-- whatever
15:21it is-- if that isn't syncing, then
15:22you can simply specify the name of that object over here.
15:27And once you have specified the name of the object over there,
15:29then you can initialize the synchronization
15:31for that particular object.
15:32Now there are times when certain objects are not
15:34accessible because of the privileges or the role
15:36that a particular administrator has within the environment.
15:39So if there is need for you to maybe key in some admin
15:42credentials, then you have to key in those admin
15:45credentials prior to you synchronizing those objects.
15:48For now, I want us to head back to Microsoft 365
15:51and look at whether our AD Connect has been resolved
15:53by the various troubleshooting tools
15:54that we have implemented so far.
15:56All right, so here we are within Microsoft 365 Admin Center
15:59and this is our AzureAD Connect new status over here.
16:03I simply had to give it a bit of time in order for it
16:05to complete the synchronization.
16:07And ensure that at the moment you are doing this,
16:09your AzureAD Connect on your host server
16:12should be turned off.
16:13There shouldn't be anything that is actually running
16:16or any other service that is still
16:17having its application open in the taskbar, et cetera.
16:21There we have it.
16:22Now in conclusion, let us look at the things
16:23that we consider are vital when we
16:26are troubleshooting our AzureAD Connect within our environment.
16:30Now we spoke earlier of the role that the Microsoft Services
16:33plays in restarting and re-initializing
16:36the various services that are running
16:37that have to do with AzureAD Connect synchronization
16:40in the environment.
16:41Therefore it is important for us to keep an eye on this feature.
16:44But the moment we actually realize
16:45that there's something wrong with the synchronization
16:47or the monitoring of the various services
16:49that we have to ensure that everything is running smoothly.
16:52And once we have verified that and made sure
16:55that nothing really isn't stuck in this area,
16:57then we can begin looking at the tools that
16:59are provided by the Synchronization Service
17:02Management.
17:02Now in this area we have seen how
17:04we can use the connectors to restart and stop
17:06the various domains that we have to simply aid
17:09the configuration.
17:09And if at all there is something that we suspect
17:11could have happened in the background,
17:13we can use the features that are contained
17:15within here to manually start synchronization.
17:17And finally, we looked at the various PowerShell
17:20scripts and options that are provided within the AD Connect
17:23troubleshooting tool that we've actually seen,
17:25we could use to troubleshoot objects,
17:27to troubleshoot synchronization, to also
17:29verify that we have connectivity to an active directory.
17:32With this, my friend, I hope this has been informative
17:34for you and I would like to thank you for viewing.
Team training path
Turn this skill into assignable team training
This free skill is a preview of the courses your team can assign, track, and report on with CBT Nuggets.
$708
seat / year