Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion docs/global-secure-access/how-to-configure-connectors.md
Original file line number Diff line number Diff line change
Expand Up @@ -53,7 +53,7 @@ The Microsoft Entra private network connector requires a server running Windows
> ```

> [!WARNING]
> If you've deployed Microsoft Entra Password Protection Proxy, do not install Microsoft Entra application proxy and Microsoft Entra Password Protection Proxy together on the same machine. Microsoft Entra application proxy and Microsoft Entra Password Protection Proxy install different versions of the Microsoft Entra Connect Agent Updater service. These different versions are incompatible when installed together on the same machine.
> If you've deployed Microsoft Entra Password Protection Proxy, do not install Microsoft Entra application proxy and Microsoft Entra Password Protection Proxy together on the same machine. Microsoft Entra application proxy and Microsoft Entra Password Protection Proxy install different versions of the Microsoft Azure AD Connect Agent Updater service. These different versions are incompatible when installed together on the same machine.

#### Transport Layer Security (TLS) requirements

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -154,8 +154,8 @@ You can also check whether all the required ports are open.
1. Sign in to the Windows server where the provisioning agent is installed.
2. Go to **Control Panel** > **Uninstall or Change a Program**.
3. Uninstall the following programs:
- Microsoft Entra Connect Provisioning Agent
- Microsoft Entra Connect Agent Updater
- Microsoft Azure AD Connect Provisioning Agent
- Microsoft Azure AD Connect Agent Updater
- Microsoft Entra Connect Provisioning Agent Package

## Provisioning agent history
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -19,7 +19,7 @@ After you configure the provisioning agent and the Extensible Connectivity(ECMA)

1. Check that the agent and ECMA host are running:
1. On the server with the agent installed, open **Services** by going to **Start** > **Run** > **Services.msc**.
2. Under **Services**, make sure the **Microsoft Entra Connect Provisioning Agent**, and **Microsoft ECMA2Host** services are present and their status is *Running*.
2. Under **Services**, make sure the **Microsoft Azure AD Connect Provisioning Agent**, and **Microsoft ECMA2Host** services are present and their status is *Running*.

![Screenshot that shows that the ECMA service is running.](./media/on-premises-ecma-troubleshoot/tshoot-1.png)

Expand All @@ -41,7 +41,7 @@ After you configure the provisioning agent and the Extensible Connectivity(ECMA)
1. Ensure that you've assigned one or more agents to the application in the Azure portal.
1. After you assign an agent, you need to wait 10 to 20 minutes for the registration to complete. The connectivity test won't work until the registration completes.
1. Ensure that you're using a valid certificate that has not expired. Go to the **Settings** tab of the ECMA host to view the certificate expiration date. If the certificate has expired, click `Generate certificate` to generate a new certificate.
1. Restart the provisioning agent by going to the taskbar on your VM by searching for the Microsoft Entra Connect provisioning agent. Right-click **Stop**, and then select **Start**.
1. Restart the provisioning agent by going to the taskbar on your VM by searching for the Microsoft Azure AD Connect Provisioning Agent. Right-click **Stop**, and then select **Start**.
1. If you continue to see `The ECMA host is currently importing data from the target application` even after restarting the ECMA Connector Host and the provisioning agent, and waiting for the initial import to complete, then you may need to cancel and start over configuring provisioning to the application in the Azure portal.

1. When you provide the tenant URL in the Azure portal, ensure that it follows the following pattern. You can replace `localhost` with your host name, but it isn't required. Replace `connectorName` with the name of the connector you specified in the ECMA host. The error message 'invalid resource' generally indicates that the URL does not follow the expected format.
Expand Down Expand Up @@ -211,15 +211,15 @@ You might experience the following error scenarios.

You might receive an error message that states:

"Service 'Microsoft Entra Connect Provisioning Agent' failed to start. Check that you have sufficient privileges to start the system services."
"Service 'Microsoft Azure AD Connect Provisioning Agent' failed to start. Check that you have sufficient privileges to start the system services."

This problem is typically caused by a group policy that prevented permissions from being applied to the local NT Service sign-in account created by the installer (NT SERVICE\AADConnectProvisioningAgent). These permissions are required to start the service.

To resolve this problem:

1. Sign in to the server with an administrator account.
2. Open **Services** by either navigating to it or by going to **Start** > **Run** > **Services.msc**.
3. Under **Services**, double-click **Microsoft Entra Connect Provisioning Agent**.
3. Under **Services**, double-click **Microsoft Azure AD Connect Provisioning Agent**.
4. On the **Log On** tab, change **This account** to a domain admin. Then restart the service.

This test verifies that your agents can communicate with Azure over port 443. Open a browser, and go to the previous URL from the server where the agent is installed.
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -301,7 +301,7 @@ Follow these steps to confirm that the connector host is started and has identif

3. Enter the **Secret Token** value that you defined when you created the connector.
>[!NOTE]
>If you just assigned the agent to the application, please wait 10 minutes for the registration to complete. The connectivity test won't work until the registration completes. Forcing the agent registration to complete by restarting the provisioning agent on your server can speed up the registration process. Go to your server, search for **services** in the Windows search bar, identify the **Microsoft Entra Connect Provisioning Agent** service, right-select the service, and restart.
>If you just assigned the agent to the application, please wait 10 minutes for the registration to complete. The connectivity test won't work until the registration completes. Forcing the agent registration to complete by restarting the provisioning agent on your server can speed up the registration process. Go to your server, search for **services** in the Windows search bar, identify the **Microsoft Azure AD Connect Provisioning Agent** service, right-select the service, and restart.
4. Select **Test Connection**, and wait one minute.
5. After the connection test is successful and indicates that the supplied credentials are authorized to enable provisioning, select **Save**.</br>
[![Screenshot that shows testing an agent.](~/includes/media/app-provisioning-sql/configure-9.png)](~/includes/media/app-provisioning-sql/configure-9.png#lightbox)
Expand Down Expand Up @@ -467,7 +467,7 @@ Now that your attributes are mapped and an initial user is assigned, you can tes

1. On the server the running the Microsoft Entra ECMA Connector Host, select **Start**.
2. Enter **run** and enter **services.msc** in the box.
3. In the **Services** list, ensure that both the **Microsoft Entra Connect Provisioning Agent** service and the **Microsoft ECMA2Host** services are running. If not, select **Start**.
3. In the **Services** list, ensure that both the **Microsoft Azure AD Connect Provisioning Agent** service and the **Microsoft ECMA2Host** services are running. If not, select **Start**.


1. In the Azure portal, select **Enterprise applications**.
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -284,7 +284,7 @@ Follow these steps to confirm the connector host is started and has identified a
1. Enter the **Secret Token** value that you defined when you created the connector.

> [!NOTE]
> If you just assigned the agent to the application, please wait 10 minutes for the registration to complete. The connectivity test won't work until the registration completes. Forcing the agent registration to complete by restarting the provisioning agent on your server can speed up the registration process. Go to your server, search for **services** in the Windows search bar, identify the **Microsoft Entra Connect Provisioning Agent** service, right-select the service, and restart.
> If you just assigned the agent to the application, please wait 10 minutes for the registration to complete. The connectivity test won't work until the registration completes. Forcing the agent registration to complete by restarting the provisioning agent on your server can speed up the registration process. Go to your server, search for **services** in the Windows search bar, identify the **Microsoft Azure AD Connect Provisioning Agent** service, right-select the service, and restart.

1. Select **Test Connection**, and wait one minute.
1. After the connection test is successful and indicates that the supplied credentials are authorized to enable provisioning, select **Save**.
Expand All @@ -310,7 +310,7 @@ Return to the web browser window where you were configuring the application prov
1. Enter the **Secret Token** value that you defined when you created the connector.

> [!NOTE]
> If you just assigned the agent to the application, please wait 10 minutes for the registration to complete. The connectivity test won't work until the registration completes. Forcing the agent registration to complete by restarting the provisioning agent on your server can speed up the registration process. Go to your server, search for **services** in the Windows search bar, identify the **Microsoft Entra Connect Provisioning Agent Service**, right-select the service, and restart.
> If you just assigned the agent to the application, please wait 10 minutes for the registration to complete. The connectivity test won't work until the registration completes. Forcing the agent registration to complete by restarting the provisioning agent on your server can speed up the registration process. Go to your server, search for **services** in the Windows search bar, identify the **Microsoft Azure AD Connect Provisioning Agent Service**, right-select the service, and restart.

1. Select **Test Connection**, and wait one minute.
1. After the connection test is successful and indicates that the supplied credentials are authorized to enable provisioning, select **Save**.
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -234,7 +234,7 @@ To connect the Microsoft Entra provisioning agent with your application, follow

5. Enter the **Secret Token** value that you defined when you created the connector.
>[!NOTE]
>If you just assigned the agent to the application, please wait 10 minutes for the registration to complete. The connectivity test won't work until the registration completes. Forcing the agent registration to complete by restarting the provisioning agent on your server can speed up the registration process. Go to your server, search for **services** in the Windows search bar, identify the **Microsoft Entra Connect Provisioning Agent Service**, right-select the service, and restart.
>If you just assigned the agent to the application, please wait 10 minutes for the registration to complete. The connectivity test won't work until the registration completes. Forcing the agent registration to complete by restarting the provisioning agent on your server can speed up the registration process. Go to your server, search for **services** in the Windows search bar, identify the **Microsoft Azure AD Connect Provisioning Agent Service**, right-select the service, and restart.
1. Select **Test Connection**, and wait one minute.

1. After the connection test is successful and indicates that the supplied credentials are authorized to enable provisioning, select **Save**.
Expand Down
4 changes: 2 additions & 2 deletions docs/identity/hybrid/cloud-sync/how-to-automatic-upgrade.md
Original file line number Diff line number Diff line change
Expand Up @@ -32,8 +32,8 @@ To verify your version, right-click the executable and select properties and the
## Uninstall the agent
To remove the agent, go to **Uninstall or change a program** and uninstall the following:

- **Microsoft Entra Connect Agent Updater**
- **Microsoft Entra Provisioning Agent**
- **Microsoft Azure AD Connect Agent Updater**
- **Microsoft Azure AD Connect Agent Provisioning Agent**
- **Microsoft Entra Provisioning Agent Package**

![Agent removal](media/how-to-automatic-upgrade/agent-3.png)
Expand Down
4 changes: 2 additions & 2 deletions docs/identity/hybrid/cloud-sync/how-to-troubleshoot.md
Original file line number Diff line number Diff line change
Expand Up @@ -75,7 +75,7 @@ However, during the name resolution, the CNAME records might contain DNS records
To verify that the agent is running, follow these steps:

1. On the server with the agent installed, open **Services**. Do this by going to **Start** > **Run** > **Services.msc**.
1. Under **Services**, make sure **Microsoft Entra Connect Agent Updater** and **Microsoft Entra Provisioning Agent** are there. Also confirm that their status is *Running*.
1. Under **Services**, make sure **Microsoft Azure AD Connect Agent Updater** and **Microsoft Azure AD Connect Agent** are there. Also confirm that their status is *Running*.

![Screenshot of local services and their status.](media/how-to-troubleshoot/troubleshoot-1.png)

Expand All @@ -87,7 +87,7 @@ The following sections describe some common agent installation problems, and typ

You might receive an error message that states:

*Service 'Microsoft Entra Provisioning Agent' failed to start. Verify that you have sufficient privileges to start the system services.*
*Service 'Microsoft Azure AD Connect Agent' failed to start. Verify that you have sufficient privileges to start the system services.*

This problem is typically caused by a group policy. The policy prevented permissions from being applied to the local NT Service sign-in account created by the installer (`NT SERVICE\AADConnectProvisioningAgent`). These permissions are required to start the service.

Expand Down
2 changes: 1 addition & 1 deletion docs/identity/hybrid/connect/how-to-connect-health-adfs.md
Original file line number Diff line number Diff line change
Expand Up @@ -106,7 +106,7 @@ At this point, the agent services should start to automatically allow the agent

To verify that the agent was installed, look for the following services on the server. If you completed the configuration, they should already be running. Otherwise, they're stopped until the configuration is complete.

- Microsoft Entra Connect Agent Updater
- Microsoft Azure AD Connect Agent Updater
- Microsoft Entra Connect Health Agent

:::image type="content" source="media/how-to-connect-health-agent-install/install5.png" alt-text="Screenshot that shows Microsoft Entra Connect Health AD FS services.":::
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -87,7 +87,7 @@ The Microsoft Entra Connect Health agent for sync is installed automatically in

To verify that the agent has been installed, look for the following services on the server. If you completed the configuration, the services should already be running. Otherwise, the services are stopped until the configuration is complete.

- Microsoft Entra Connect Agent Updater
- Microsoft Azure AD Connect Agent Updater
- Microsoft Entra Connect Health Agent

:::image type="content" source="media/how-to-connect-health-agent-install/install5.png" alt-text="Screenshot that shows the running Microsoft Entra Connect Health for sync services on the server.":::
Expand Down Expand Up @@ -137,7 +137,7 @@ At this point, the agent services should start to automatically allow the agent

To verify that the agent was installed, look for the following services on the server. If you completed the configuration, they should already be running. Otherwise, they're stopped until the configuration is complete.

- Microsoft Entra Connect Agent Updater
- Microsoft Azure AD Connect Agent Updater
- Microsoft Entra Connect Health Agent

:::image type="content" source="media/how-to-connect-health-agent-install/install5.png" alt-text="Screenshot that shows Microsoft Entra Connect Health AD DS services.":::
Expand Down
2 changes: 1 addition & 1 deletion docs/identity/hybrid/connect/how-to-connect-pta-faq.yml
Original file line number Diff line number Diff line change
Expand Up @@ -142,7 +142,7 @@ sections:
- question: |
How do I remove a Pass-through Authentication Agent?
answer: |
As long as a Pass-through Authentication Agent is running, it remains active and continually handles user sign-in requests. If you want to uninstall an Authentication Agent, go to **Control Panel -> Programs -> Programs and Features**. Uninstall both the **Microsoft Entra Connect Authentication Agent** and the **Microsoft Entra Connect Agent Updater** programs.
As long as a Pass-through Authentication Agent is running, it remains active and continually handles user sign-in requests. If you want to uninstall an Authentication Agent, go to **Control Panel -> Programs -> Programs and Features**. Uninstall both the **Microsoft Entra Connect Authentication Agent** and the **Microsoft Azure AD Connect Agent Updater** programs.

If you check the Pass-through Authentication blade on the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Hybrid Identity Administrator](~/identity/role-based-access-control/permissions-reference.md#hybrid-identity-administrator). You should see the Authentication Agent showing as **Inactive**. This is *expected*. The Authentication Agent is automatically dropped from the list after 10 days.

Expand Down
4 changes: 2 additions & 2 deletions docs/includes/app-provisioning-ldap.md
Original file line number Diff line number Diff line change
Expand Up @@ -336,7 +336,7 @@ Follow these steps to confirm that the connector host has started and has read a

3. Enter the **Secret Token** value that you defined when you created the connector.
>[!NOTE]
>If you just assigned the agent to the application, please wait 10 minutes for the registration to complete. The connectivity test won't work until the registration completes. Forcing the agent registration to complete by restarting the provisioning agent on your server can speed up the registration process. Go to your server, search for **services** in the Windows search bar, identify the **Microsoft Entra Connect Provisioning Agent** service, right-click the service, and restart.
>If you just assigned the agent to the application, please wait 10 minutes for the registration to complete. The connectivity test won't work until the registration completes. Forcing the agent registration to complete by restarting the provisioning agent on your server can speed up the registration process. Go to your server, search for **services** in the Windows search bar, identify the **Microsoft Azure AD Connect Provisioning Agent** service, right-click the service, and restart.
4. Select **Test Connection**, and wait one minute.
5. After the connection test is successful and indicates that the supplied credentials are authorized to enable provisioning, select **Save**.</br>
[![Screenshot that shows testing an agent.](.\media\app-provisioning-sql\configure-9.png)](.\media\app-provisioning-sql\configure-9.png#lightbox)
Expand Down Expand Up @@ -494,7 +494,7 @@ Now that your attributes are mapped and an initial user is assigned, you can tes

1. On the server the running the Microsoft Entra ECMA Connector Host, select **Start**.
2. Enter **run** and enter **services.msc** in the box.
3. In the **Services** list, ensure that both the **Microsoft Entra Connect Provisioning Agent** service and the **Microsoft ECMA2Host** services are running. If not, select **Start**.
3. In the **Services** list, ensure that both the **Microsoft Azure AD Connect Provisioning Agent** service and the **Microsoft ECMA2Host** services are running. If not, select **Start**.


1. In the Azure portal, select **Enterprise applications**.
Expand Down
Loading