3 million user on Local AD to be synchronized with Office 365 FID issue

Hello everyone,

I have a customer (University) Who has an issue with DirSync. They have 3 million users on Local AD they want to synchronize with Office 365 to enable these users for Exchange online. 

Now they have users "Students" enabled for Exchange online and management and staff are enabled on the On-premises Exchange servers. 

Dirsync during the day synchronize 2 times fine without any error and again 2 times doesn't synchronize and gives error with no details. the error is "Stopped Extension-dll exception" 

More errors shown as below 
Directory Synchronization:
An unknown error occurred with the Microsoft Online Services Sign-in Assistant. Contact Technical Support. SetCredential() failed. Contact Technical Support.  (0x8009000B)

I am attaching other errors as well

   at Microsoft.Online.Coexistence.ProvisionHelper.GetLiveCompactToken(String userName, String userPassword)
   at Microsoft.Azure.ActiveDirectory.Connector.ProvisioningServiceAdapter.Initialize()
   at Microsoft.Azure.ActiveDirectory.Connector.ProvisioningServiceAdapter.Import(Byte[] syncCookie, Boolean isFullImport)
   at Microsoft.Azure.ActiveDirectory.Connector.Connector.GetImportEntriesCore()
   at Microsoft.Azure.ActiveDirectory.Connector.Connector.GetImportEntries(GetImportEntriesRunStep getImportEntriesRunStep)
Forefront Identity Manager 4.1.3465.0"

FIMSynchronizationService:
The management agent "Windows Azure Active Directory Connector" failed on run profile "Delta Import Delta Sync" because the server encountered errors.

FIMSynchronizationService:
The management agent "Windows Azure Active Directory Connector" step execution completed on run profile "Delta Import Delta Sync" but the watermark was not saved.
 
 Additional Information
 Discovery Errors       : "0"
 Synchronization Errors : "0"
 Metaverse Retry Errors : "0"
 Export Errors          : "0"
 Warnings               : "0"
 
 User Action
 View the management agent run history for details.

Directory Synchronization:
The Management Agent Windows Azure Active Directory Connector failed on execution. Error returned is 'stopped-extension-dll-exception'.  If the problem persists, contact Technical Support.

Customer have tried to involve Microsoft with them through a third party technical support company but microsoft was not able to apply anything since they have tried to apply some scripts but those scripts would take 3 days without finishing.


The first time the Dirsync was applied it took 1 week without finishing until now they were not able to apply a full import and export sync.

What have really got me interested is that Microsoft did not suggest to the customer to upgrade his FIM (ForeFront Identity Manager)'s old version to the latest one. 

Customer is using Full SQL deployment on a dedicated server and DirSync (FID) on a separate server too. The deployed servers are virtual and have 32 GB ram and 200 GB HDD size and 4 cores.


I have recommended to this customer that we do not touch this current deployment since Microsoft themselves couldn't do anything in regard, but what we could do is take a virtual snapshot and then apply the upgrade and see if this resolves the issue or not?

Note:

Microsoft talked to them about a limited number of synchronized items to their Azure site per week! I am not sure about this but what the customer said is that they change approximately about 25,000 user object per day. 
Could this issue happens because of this limit?


Thanks



  • Edited by moh10ly Friday, January 16, 2015 2:25 PM
January 16th, 2015 2:23pm

Besides the large number of objects in the system, which I am not sure DirSync can handle, I suggest you separate the failing step from other steps in the RunProfile.

So, if you have a step that does Delta Import and Delta Sync, separate into 2 steps;

Best,

Nosh

Free Windows Admin Tool Kit Click here and download it now
January 22nd, 2015 12:33am

Hi Nosh, the problem was solved by uninstall DirSync after taking a full backup of the SQL server and taking a backup of the service encryption key for Dirsync and reinstalling it. 

You can lookup here for the steps

https://www.microsoft.com/en-us/download/details.aspx?id=42524

Microsoft has enabled syncing more than 25 thousand objects per day to the client's tenant on O365 so they can Sync unlimited objects per day. now they have no issues.

Thanks for your comment.

June 8th, 2015 9:26am

Glad you got it solved and thanks for the update.
Free Windows Admin Tool Kit Click here and download it now
June 8th, 2015 9:36am

This topic is archived. No further replies will be accepted.

Other recent topics Other recent topics