Microsoft Entra Cloud Sync error codes and descriptions
The AzureActiveDirectoryInvalidCredential and AzureActiveDirectoryExpiredCredentials entries no longer reference the cloud service-account repair cmdlet.
Daily.Entra.NewsA cross-product view of Microsoft Entra changes related to Troubleshooting.
The AzureActiveDirectoryInvalidCredential and AzureActiveDirectoryExpiredCredentials entries no longer reference the cloud service-account repair cmdlet.
The troubleshooting article no longer documents the Repair-AADCloudSyncToolsAccount cmdlet or its usage steps.
The Linux device registration troubleshooting documentation now shows a different tenant ID in its example output.
The example Tenant ID was changed from 12345678-90ab-cdef-1234-567890abcdef to aaaabbbb-0000-cccc-1111-dddd2222eeee.
The documentation now states that the “Users may join devices to Microsoft Entra ID” setting applies to Windows 10 or newer, macOS, and Linux. It also adds troubleshooting guidance to verify registration or join settings when users encounter errors.
The troubleshooting documentation now directs administrators to the Hard match scenarios and recovery paths when DataValidationFailed occurs during a hard match operation, while retaining guidance to validate userPrincipalName characters and format.
The troubleshooting guide now covers DataValidationFailed alongside IdentityDataValidationFailed, including cases where onPremisesObjectIdentifier changes during hard match operations. It also adds guidance for checking userPrincipalName formatting and using the documented hard match recovery paths.
The documentation now uses clearer commands to enable and verify `AllowOnPremUpdateOfOnPremisesObjectIdentifierEnabled`, and explicitly shows how to set it back to `$false` after remediation to re-enable hard match protection.
- The object or property isn't supported for preview in the current release.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to MX3 Diagnostics Connector.
> Error code 1002013 indicates an expected (and successful) interrupt of the sign-up flow. [Learn more](howto-troubleshoot-sign-up-errors.md#sign-up-error-codes)
A Microsoft Entra documentation page was updated: Customer intent: As an IT administrator, I want to learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to MX3 Diagnostics so that I can streamline the user management process and ensure that users have the appropriate access to MX3 Diagnostics..
Troubleshoot the Global Secure Access client using the health check tab in the advanced diagnostics utility.
Troubleshoot the Global Secure Access client using the Health check tab in the Advanced diagnostics utility.
Learn what a mismatched directory error means and how to resolve it in Microsoft Entra Domain Services
Learn how to monitor and troubleshoot private application access scenarios that require the Microsoft Entra Private Access connector, using Microsoft Entra Health monitoring tools.
Learn how to monitor and troubleshoot remote network connectivity using Microsoft Entra Health monitoring.
Understand critical IP address ranges to consider when configuring and troubleshooting internet over remote network connectivity.
Learn how to troubleshoot and resolve network security group configuration alerts for Microsoft Entra Domain Services
Learn how to troubleshoot and resolve common alerts with secure LDAP for Microsoft Entra Domain Services.
Learn how to troubleshoot service principal configuration alerts for Microsoft Entra Domain Services
Learn how to troubleshoot application access problems with the Global Secure Access Windows client.
This article covers how to use the output from the Device Registration command tool on Linux to understand the state of devices in Microsoft Entra ID.
A Microsoft Entra documentation page was updated: Troubleshoot devices by using the dsregcmd command.
This document provides troubleshooting guidance for the Global Secure Access client when it shows the "disabled by your organization" error message.
Troubleshoot the macOS Global Secure Access client using the Health check tab in the Advanced diagnostics utility.
ai-usage: ai-assisted
Diagnose and resolve common errors when using the High Scale Compatibility (HSC) API for migrating from Azure AD B2C to Microsoft Entra External ID.
A Microsoft Entra documentation page was updated: Troubleshoot Hybrid Join Windows Legacy.
This article helps to troubleshoot deploying the Microsoft Enterprise SSO plug-in on Apple devices
Reduce risk from malicious or manipulated prompts sent to generative AI sites and apps with prompt injection protection policies in Global Secure Access.
Learn if a device can communicate with the Global Secure Access service and tunnel traffic, by using the health check utility.
Learn how to troubleshoot and resolve Transport Layer Security (TLS) inspection errors in Global Secure Access.
A Microsoft Entra documentation page was updated: Troubleshooting Enterprise State Roaming settings in Microsoft Entra ID.
Learn why some apps may exceed the limits on configured permissions and how to address this issue.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to MX3 Diagnostics Connector.
Learn how to troubleshoot user update issues with HR provisioning
The portal verifies that `did.json` is reachable and correct when you select **Refresh registration status**. You should also consider verifying that you can request that URL in a browser to avoid errors like not using HTTPS, a bad TLS/SSL certificate, or the URL not being public. If the `did.json` file can't be requested anonymously in a browser or via tools such as `curl`, without warnings or errors, the portal won't be able to complete the **Refresh registration status** step.
If you still can't resolve your problem, contact ServiceNow support, and ask them to turn on SOAP debugging to help troubleshoot.
If you're experiencing issues with Privileged Identity Management (PIM) in Microsoft Entra ID, the information included in this article can help you resolve these issues.
Learn how to configure user self-remediation and manually remediate risky users in Microsoft Entra ID Protection.
View performance, experience, and availability insights for Microsoft 365 apps routed through Microsoft Entra Internet Access. Integrate enriched log data with Log Analytics or Microsoft Sentinel for network diagnostics and security analysis.
Monitor and troubleshoot configuration changes in Global Secure Access using deployment logs. Learn how to view logs, configure settings, and analyze fields.

The proposed workaround for the above-mentioned scenario is as follows.
1. In the system tray, right-click **Global Secure Access Client** and then select **Advanced Diagnostics**. Select the **Traffic** tab and select **Start collecting**.
A Microsoft Entra documentation page was updated: Troubleshoot Global Secure Access Client Ios Health Check Utility.
Learn if a device can communicate with the Global Secure Access service and tunnel traffic, by using the health check utility.
View performance, experience, and availability insights for Microsoft 365 apps routed through Microsoft Entra Internet Access. Integrate enriched log data with Log Analytics or Microsoft Sentinel for network diagnostics and security analysis.
In the [Microsoft Intune admin center](https://intune.microsoft.com/), confirm the following criteria:
Upon successful onboarding, Domain Services back fills synchronized users and groups with the onboarded custom attribute values. The custom attribute values appear gradually, depending on the size of the tenant. To check the backfill status, go to [Domain Services Health](check-health.md) and verify the **Synchronization with Microsoft Entra ID** monitor timestamp has updated within the last hour.
A troubleshooting article that includes a workaround for a case where a Distributed File System (DFS) doesn't operate correctly with Global Secure Access.
Troubleshoot problems installing the Microsoft Entra private network connector.
Learn how to troubleshoot common errors and configuration problems with Microsoft Entra application proxy.
Troubleshoot problems installing the Microsoft Entra private network connector.
Troubleshoot the Global Secure Access client using the Health check tab in the Advanced diagnostics utility.
Learn how to configure user self-remediation and manually remediate risky users in Microsoft Entra ID Protection.
A troubleshooting article that includes a workaround for a case where a Distributed File System (DFS) doesn't operate correctly with Global Secure Access.
Learn how to troubleshoot application access problems with the Global Secure Access Windows client.
Troubleshoot the Global Secure Access client using the health check tab in the advanced diagnostics utility.
This document provides troubleshooting guidance for the Global Secure Access client when it shows the "disabled by your organization" error message.
Discover how to use advanced diagnostics to resolve issues with the Global Secure Access mobile client for Android and iOS.
Troubleshoot the macOS Global Secure Access client using the Health check tab in the Advanced diagnostics utility.
Troubleshoot the Global Secure Access client using the Health check tab in the Advanced diagnostics utility.
Learn how to troubleshoot and resolve Transport Layer Security (TLS) inspection errors in Global Secure Access.
Monitor and troubleshoot configuration changes in Global Secure Access using deployment logs. Learn how to view logs, configure settings, and analyze fields.
Troubleshoot problems with broken links in application proxy apps that are integrated with Microsoft Entra ID.
Describes how to troubleshoot various issues you might encounter when you install and use the ECMA Connector Host.
Learn how to check the status of automatic user account provisioning jobs, and how to troubleshoot the provisioning of individual users.
Learn how to troubleshoot errors in Microsoft Entra application proxy.
Learn how to troubleshoot attribute retrieval issues with HR provisioning
Learn how to troubleshoot InsufficientAccessRights error when provisioning to on-premises Active Directory.
This article provides potential issues and resolutions that guide you in how to troubleshoot issues with the inbound provisioning API.
Learn how to troubleshoot a Kerberos constrained delegation (KCD) configuration in Microsoft Entra application proxy.
This article provides potential issues and resolutions that show you how to troubleshoot manager update issues with HR provisioning
How to troubleshoot common issues faced when configuring user provisioning to an application already listed in the Microsoft Entra application gallery.
Learn how to troubleshoot user creation issues with HR provisioning
Learn how to troubleshoot user update issues with HR provisioning
This article provides potential issues and resolutions so you can troubleshoot writeback issues with HR provisioning.
Troubleshoot common issues faced when a user isn't appearing in a Microsoft Entra Gallery Application configured for user provisioning with Microsoft Entra ID.
Troubleshoot problems with broken links in application proxy apps that are integrated with Microsoft Entra ID.
author: shlipsey3
author: HULKsmashGithub
author: HULKsmashGithub
Learn how to troubleshoot sign-up errors using Microsoft Entra reports in the Microsoft Entra admin center
Understand critical IP address ranges to consider when configuring and troubleshooting internet over remote network connectivity.
Learn about currently known issues and errors encountered when using the Microsoft Entra Agent ID preview.
Learn how to troubleshoot application access problems with the Global Secure Access Windows client.
Learn how to troubleshoot errors in Microsoft Entra application proxy.
A troubleshooting article that includes a workaround for a case where a Distributed File System (DFS) doesn't operate correctly with Global Secure Access.
Learn about some items you should check to help you troubleshoot Microsoft Entra entitlement management.
author: HULKsmashGithub