Users not added/updated to SDP - Azure AD User Sync

Users not added/updated to SDP - Azure AD User Sync

a. Check whether Initial Sync is completed

When Azure AD has a large set of users, it might take time to process and sync all of them. Once the Initial Sync is completed, all users would have been processed, and you can check whether a specific user has been added or not after that.

Info

If the sync interval is 2 minutes, it indicates that the Initial Sync is running.It will continue until all users are fetched from Azure.
Once all users are fetched and processed, the Incremental Sync will begin, which runs every 'x' days as configured in the sync settings.

b. Check whether any error is shown in Microsoft Azure card

If Microsoft Azure is enabled using Privliged Access Admin or Global Admin credentials, the sync process will use that account’s token to fetch users from Azure.
If any issues occur with that token, the sync may fail. In such cases, an error will be displayed on the Microsoft Azure Integration card

c. Check for the error in Sync Report/System Log

Search using the user's Email ID or Object ID in all the sync reports. If the user sync failed, the cause will be printed in the report.

If the sync report is not enabled, or if the data is not available in the report, check for the user add failure in the System Log, and trigger a Restart Sync once the necessary action is taken.

d. Check whether users are manually deleted (For user add failure)



We will process previously deleted users only when the option "Re-sync Deleted Users" is selected for the configuration:

"Select an action to be performed during the next sync cycle for users that are deleted from ServiceDesk Plus Cloud."

1. If the Re-sync Deleted Users option is not selected, check the Sync Report or System Logs for a user delete log to confirm if the user was previously deleted.
2. If the user was deleted manually, ensure the correct option is set in the configuration.
  1. Any change in those user accounts in Azure AD will bring them back into SDP.
  1. If no changes are expected, users can be manually imported via the Import from Azure option.
  1. If the list of users is large, it is recommended to suggest the user trigger a Restart Sync.

e. Check whether criteria matches with user details

Check the criteria in the Azure configuration popup. If they have enabled the sync report, please verify the users' details match the criteria.


  1. If the saved criteria is not proper, change it.
  2. Then any change in the skipped user accounts in Azure AD will bring those users in to SDP.
  3. If no changes will be made, they can manually import the users via the Import from Azure option.
  4. If the list is huge, then we can suggest the user trigger Restart Sync.

f. If the issue is not resolved

Contact Support with the following details:
  1. Affected user's Email ID and Object ID
    (The Object ID can be found in the Azure profile. If the user is deleted, it can be found in the Azure Audit Logs.)
  2. Available Sync Reports
  3. The following System Logs exported as CSV or XLS

                  New to ADSelfService Plus?

                    • Related Articles

                    • Azure AD User Sync – Overview

                      Helpguide --> https://help.sdpondemand.com/azure-ad-user-sync Azure AD User Sync, when enabled, gets users from Azure periodically and adds/updates/deletes them in SDP. The sync flow is mainly categorized into 2 parts: Initial Sync and Incremental ...
                    • Common Errors During Azure User Sync and Their Resolutions

                      Helpguide --> https://help.sdpondemand.com/azure-ad-user-sync a. IAMError:U123 This indicates that the user is part of a different organization. A user can be part of only one organization account. If the user belongs to another valid account, they ...
                    • Azure AD User Sync integration is getting disabled / Error message shown in Azure AD User Sync card

                      Helpguide --> https://help.sdpondemand.com/azure-ad-user-sync When the integration is automatically disabled or the sync is not running, it might be due to one of the following reasons. These errors will be displayed in the Integration Card and will ...
                    • Users are not deleted/login revoked - Azure AD User Sync

                      Ensure the configurations are selected correctly by navigating to: Setup → Apps and Add-ons → Integrations → Azure AD User Sync. Also, verify that the user has been synced at least once previously through Azure AD User Sync or Import from Azure. This ...
                    • Microsoft Azure Integration and its benefits

                      Kindly refer to this link for more info about this integration, https://help.sdpondemand.com/azure_integration Why does this integration have to be enabled separately? This is an additional authentication step implemented to enhance the existing ...