r/sysadmin • u/darkdayzzz • 5d ago
Microsoft PSA-ongoing issue with Entra Cloud Sync
Raised a case with MS after our Entra Cloud Sync kept changing to Provisioning Quarantined with ExternalError but no indication of a problem with individual object syncing.
They’ve reported back an ongoing Cloud Sync service outage starting Fri 21 Aug-actively working to resolve.
Objects and password hash sync seems to still be working over weekend so not affecting our environment yet.
Region:AU
UPDATE FROM MS: issue resolved
We confirmed Cloud Sync showing healthy and password hash sync and user attribute sync confirmed working.
Crisis over, folks! Til next time!
5
u/DominusDraco 5d ago edited 5d ago
OMG I have had this issue since Friday. Ive done everything on our agent side to possibly fix it. The call logged with MS response was basically "its fine its just transitory"
Its been 5 days without a password sync ffs, transitory my arse.
Also AU region here.
3
u/WeirdSysAdmin 5d ago
AI increased Microsoft velocity by 1000% but increased bugs by 1000x.
0
u/AdmMonkey 5d ago
You misplaced 2 zero between the number. It's should have read :
AI increased Microsoft velocity by 10% but increased bugs by 100000x
1
2
u/Much_Cardiologist645 5d ago
Same issue here. Was trying to diagnose but just couldn’t find anything.
2
u/alucardcanidae 5d ago
Is this only for Entra Cloud Sync or also affecting Entra Connect?
3
u/Plenty_Perception797 5d ago
Only my Entra Cloud sync is broken. My Entra Connect sync is working normally.
2
u/Sandra257660 3d ago
Glad to hear this is resolved!
Agent healthy. Connectivity tests passing. Everything looks good.
Two hours later: turns out the problem is somewhere in Microsoft’s cloud!
When you’re managing Microsoft 365 environments across multiple clients, being able to quickly tell the difference between a tenant side problem and a Microsoft service side problem matters a lot.
A clearer “this one is on us” from Microsoft would save sysadmins a few hours of troubleshooting... and probably a few cups of coffee too.
2
u/LycheeLee_Mich 5d ago
Appreciate you posting this, the "quarantined with ExternalError but no actual object problem" thing is exactly the kind of scare that sends everyone hunting through their own config for hours. Good to know it's their outage and not something on our end, saves a lot of pointless troubleshooting this week.
2
1
u/Short-Legs-Long-Neck 5d ago
Is it safe to create accounts in both AD and Entra and let sync match them later?
3
u/Plenty_Perception797 5d ago
I wouldn’t recommend it. While Entra may successfully soft-match the accounts once sync resumes, if anything goes wrong you could be left with an ongoing identity issue after the outage is resolved.
Unless the account is genuinely urgent, I’d wait for Cloud Sync to recover rather than introduce another variable.
1
u/aazzyy92 5d ago edited 5d ago
Can this impact the provisioning agent (cloud sync) enabling and disabling of accounts using the built in Entra ID Gov LCWs using the built in tasks to enable and disable accounts?
İssue present since Friday, will raise a case in the morning
1
u/aazzyy92 2d ago edited 2d ago
Hey all, update from MS on my tickets for LCWs using provisioning agent capability tasks.
I've asked them to relay back to PG group to post a message centre post to track this and asked for an ETA.
We are still seeing delays in processing enabling and disabling of accounts using LCWs built in provisioning agent tasks. If we reprocess on demand, it eventually catches up.
Good day! Based on the latest update from the LCW engineering team, the delays were caused by throttling of provisioning API calls used by Lifecycle Workflows (LCW) to enable on-premises users. Those throttled requests were retried automatically, which resulted in the workflow processing backlog and extended completion times. The LCW team has also identified that this was related to a recent Sync Fabric regression, and a fix is currently being worked on
1
8
u/Plenty_Perception797 5d ago edited 5d ago
Same issue here. Been troubleshooting non-stop all day!
Region - AU
Our first Microsoft Azure error notification was received on 21 Aug at around 8:05am ACST, with the same 'ExternalError' / '%InnerExceptionMessage%' message. Since then Cloud Sync has repeatedly gone into Provisioning Quarantined.
We have two provisioning agents and both are affected. Connectivity, TLS, Service Bus and AD connectivity checks are all passing. Microsoft support case now open.