When the integration is automatically disabled or the sync is not running, it might be due to one of the following reasons.
These errors will be displayed in the Integration Card and will also appear in the Sync Report.
a. When there is no error message in the Azure AD User Sync card
We have a 20,000 user limit for sync via Azure AD User Sync. Once this limit is exceeded, the integration will be disabled automatically.
Kindly drop an email to the support team to verify the same.
b. User sync stopped because the Org Admin role has been revoked from the admin who enabled this integration. Please re-enable the integration to resume user sync.
The OrgAdmin role is necessary for the sync to function.
If the OrgAdmin role is downgraded for the user who enabled the integration, the sync will stop running.
This error will be shown in the Integration Card.
Re-enabling the integration with the required role will fix this.
c. User sync stopped because the Org Admin who enabled this integration has been removed from the application. Please re-enable the integration to resume user sync.
The user who enabled the sync must be present in the instance for it to work.
If the user is deleted, the sync will stop, and this error will be displayed in the Integration Card.
Re-enabling the integration with the required permissions will fix this.
d. User sync stopped because the token has been invalidated. Please re-enable the integration to resume user sync.
Re-enabling the integration will fix this.
The token used to add users in IAM is either not stored correctly or has been invalidated for some reason.
In this case, the sync will stop, and this error will appear in the Integration Card.
By default, 1000 login slots are provided by IAM. Once this limit is reached, no more users can be added to ESM, and this error will be displayed during sync. Kindly contact the SDP Cloud support team to increase the count.
- Once increased, the sync will resume during the next scheduled run.
- If user space is available but the error still appears, please advise the user to trigger a Restart Sync.