You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: articles/active-directory/hybrid/reference-connect-health-faq.yml
+37-27Lines changed: 37 additions & 27 deletions
Original file line number
Diff line number
Diff line change
@@ -26,7 +26,7 @@ sections:
26
26
- question: |
27
27
I manage multiple Azure AD directories. How do I switch to the one that has Azure Active Directory Premium?
28
28
answer: |
29
-
To switch between different Azure AD tenants, select the currently signed-in **User Name** on the upper-right corner, and then choose the appropriate account. If the account is not listed here, select **Sign out**, and then use the global admin credentials of the directory that has Azure Active Directory Premium (P1 or P2) enabled to sign in.
29
+
To switch between different Azure AD tenants, select the currently signed-in **User Name** on the upper-right corner, and then choose the appropriate account. If the account isn't listed here, select **Sign out.** Next, use the global admin credentials of the directory that has Azure Active Directory Premium (P1 or P2) enabled to sign in.
30
30
31
31
- question: |
32
32
What version of identity roles are supported by Azure AD Connect Health?
@@ -39,17 +39,17 @@ sections:
39
39
|Azure AD Connect | Version 1.0.9125 or higher|
40
40
|Active Directory Domain Services (AD DS)| <ul><li> Windows Server 2012 </li> <li>Windows Server 2012 R2 </li> <li> Windows Server 2016 </li> <li> Windows Server 2019 </li> </ul>|
41
41
42
-
Windows Server Core installations are not supported.
42
+
Windows Server Core installations aren't supported.
43
43
44
-
Note that the features provided by the service may differ based on the role and the operating system. In other words, all the features may not be available for all operating system versions. See the feature descriptions for details.
44
+
The features provided by the service may differ based on the role and the operating system. All of the features may not be available, for all operating system versions. See the feature descriptions for details.
45
45
46
46
- question: |
47
47
How many licenses do I need to monitor my infrastructure?
48
48
answer: |
49
49
* The first Connect Health Agent requires at least one Azure AD Premium (P1 or P2) license.
50
-
* Each additional registered agent requires 25 additional Azure AD Premium (P1 or P2) licenses.
50
+
* Each additional registered agent requires 25 more Azure AD Premium (P1 or P2) licenses.
51
51
* Agent count is equivalent to the total number of agents that are registered across all monitored roles (AD FS, Azure AD Connect, and/or AD DS).
52
-
* AAD Connect Health licensing does not require you to assign the license to specific users. You only need to have the requisite number of valid licenses.
52
+
* Azure AD Connect Health licensing doesn't require you to assign the license to specific users. You only need to have the requisite number of valid licenses.
53
53
54
54
Licensing information is also found on the [Azure AD Pricing page](https://aka.ms/aadpricing).
55
55
@@ -66,19 +66,29 @@ sections:
66
66
- question: |
67
67
Does Azure AD Connect Health support Azure Germany Cloud?
68
68
answer: |
69
-
Azure AD Connect Health is not supported in Germany Cloud except for the [sync errors report feature](how-to-connect-health-sync.md#object-level-synchronization-error-report).
69
+
Azure AD Connect Health isn't supported in Germany Cloud except for the [sync errors report feature](how-to-connect-health-sync.md#object-level-synchronization-error-report).
70
70
71
71
| Roles | Features | Supported in German Cloud |
72
72
| ------ | --------------- | --- |
73
73
| Connect Health for Sync | Monitoring / Insight / Alerts / Analysis | No |
74
74
| | Sync error report | Yes |
75
-
| Connect Health for ADFS | Monitoring / Insight / Alerts / Analysis | No |
76
-
| Connect Health for ADDS | Monitoring / Insight / Alerts / Analysis | No |
75
+
| Connect Health for AD FS | Monitoring / Insight / Alerts / Analysis | No |
76
+
| Connect Health for AD DS | Monitoring / Insight / Alerts / Analysis | No |
77
77
78
-
To ensure the agent connectivity of Connect Health for sync, please configure the [installation requirement](how-to-connect-health-agent-install.md#outbound-connectivity-to-the-azure-service-endpoints) accordingly.
78
+
To ensure the agent connectivity of Connect Health for sync, configure the [installation requirement](how-to-connect-health-agent-install.md#outbound-connectivity-to-the-azure-service-endpoints) accordingly.
79
79
80
80
- name: Installation questions
81
81
questions:
82
+
- question: |
83
+
Does my agent installation get updated automatically when there's a new version of the agent?
84
+
answer: |
85
+
Yes, all agents will get updated automatically when there's a new version of the agent.
86
+
87
+
- question: |
88
+
Can I opt out or disable automatic upgrade of the agent?
89
+
answer: |
90
+
No, automatic upgrade is mandatory. If you don't want the agent to be upgraded when a new version is released, you should uninstall the agent.
91
+
82
92
- question: |
83
93
What is the impact of installing the Azure AD Connect Health Agent on individual servers?
84
94
answer: |
@@ -119,7 +129,7 @@ sections:
119
129
- question: |
120
130
Does Azure AD Connect Health support Basic authentication when connecting to HTTP proxies?
121
131
answer: |
122
-
No. A mechanism to specify an arbitrary user name and password for Basic authentication is not currently supported.
132
+
No. A mechanism to specify an arbitrary user name and password for Basic authentication isn't currently supported.
123
133
124
134
- question: |
125
135
What firewall ports do I need to open for the Azure AD Connect Health Agent to work?
@@ -129,7 +139,7 @@ sections:
129
139
- question: |
130
140
Why do I see two servers with the same name in the Azure AD Connect Health portal?
131
141
answer: |
132
-
When you remove an agent from a server, the server is not automatically removed from the Azure AD Connect Health portal. If you manually remove an agent from a server or remove the server itself, you need to manually delete the server entry from the Azure AD Connect Health portal.
142
+
When you remove an agent from a server, the server isn't automatically removed from the Azure AD Connect Health portal. If you manually remove an agent from a server or remove the server itself, you need to manually delete the server entry from the Azure AD Connect Health portal.
133
143
134
144
You might reimage a server or create a new server with the same details (such as machine name). If you did not remove the already registered server from the Azure AD Connect Health portal, and you installed the agent on the new server, you might see two entries with the same name.
135
145
@@ -138,7 +148,7 @@ sections:
138
148
- question: |
139
149
Can I install the Azure AD Connect health agent on Windows Server Core?
140
150
answer: |
141
-
No. Installation on Server Core is not supported.
151
+
No. Installation on Server Core isn't supported.
142
152
143
153
- name: Health Agent registration and data freshness
144
154
questions:
@@ -147,33 +157,33 @@ sections:
147
157
answer: |
148
158
The health agent can fail to register due to the following possible reasons:
149
159
150
-
* The agent cannot communicate with the required endpoints because a firewall is blocking traffic. This is particularly common on web application proxy servers. Make sure that you have allowed outbound communication to the required endpoints and ports. See the [requirements section](how-to-connect-health-agent-install.md#requirements) for details.
151
-
* Outbound communication is subjected to an TLS inspection by the network layer. This causes the certificate that the agent uses to be replaced by the inspection server/entity, and the steps to complete the agent registration fail.
152
-
* The user does not have access to perform the registration of the agent. Global admins have access by default. You can use [Azure role-based access control (Azure RBAC)](how-to-connect-health-operations.md#manage-access-with-azure-rbac) to delegate access to other users.
160
+
* The agent cannot communicate with the required endpoints because a firewall is blocking traffic. This issue is common on web application proxy servers. Make sure that you have allowed outbound communication to the required endpoints and ports. See the [requirements section](how-to-connect-health-agent-install.md#requirements) for details.
161
+
* Outbound communication is subjected to a TLS inspection by the network layer. This causes the certificate that the agent uses to be replaced by the inspection server/entity, and the steps to complete the agent registration fail.
162
+
* The user doesn't have access to perform the registration of the agent. Global admins have access by default. You can use [Azure role-based access control (Azure RBAC)](how-to-connect-health-operations.md#manage-access-with-azure-rbac) to delegate access to other users.
153
163
154
164
- question: |
155
-
I am getting alerted that "Health Service data is not up to date." How do I troubleshoot the issue?
165
+
I am getting alerted that "Health Service data isn't up to date." How do I troubleshoot the issue?
156
166
answer: |
157
-
Azure AD Connect Health generates the alert when it does not receive all the data points from the server in the last two hours. [Read more](how-to-connect-health-data-freshness.md).
167
+
Azure AD Connect Health generates the alert when it doesn't receive all the data points from the server in the last two hours. [Read more](how-to-connect-health-data-freshness.md).
158
168
159
169
- name: Operations questions
160
170
questions:
161
171
- question: |
162
172
Do I need to enable auditing on the web application proxy servers?
163
173
answer: |
164
-
No, auditing does not need to be enabled on the web application proxy servers.
174
+
No, auditing doesn't need to be enabled on the web application proxy servers.
165
175
166
176
- question: |
167
177
How do Azure AD Connect Health Alerts get resolved?
168
178
answer: |
169
-
Azure AD Connect Health alerts get resolved on a success condition. Azure AD Connect Health Agents detect and report the success conditions to the service periodically. For a few alerts, the suppression is time-based. In other words, if the same error condition is not observed within 72 hours from alert generation, the alert is automatically resolved.
179
+
Azure AD Connect Health alerts get resolved on a success condition. Azure AD Connect Health Agents detect and report the success conditions to the service periodically. For a few alerts, the suppression is time-based. In other words, if the same error condition isn't observed within 72 hours from alert generation, the alert is automatically resolved.
170
180
171
181
- question: |
172
182
I am getting alerted that "Test Authentication Request (Synthetic Transaction) failed to obtain a token." How do I troubleshoot the issue?
173
183
answer: |
174
-
Azure AD Connect Health for AD FS generates this alert when the Health Agent installed on an AD FS server fails to obtain a token as part of a synthetic transaction initiated by the Health Agent. The Health agent uses the local system context and attempts to get a token for a self relying party. This is a catch-all test to ensure that AD FS is in a state of issuing tokens.
184
+
Azure AD Connect Health for AD FS generates this alert when the Health Agent installed on an AD FS server fails to obtain a token as part of a synthetic transaction initiated by the Health Agent. The Health agent uses the local system context and attempts to get a token for a self relying party. This behavior is a catch-all test to ensure that AD FS is in a state of issuing tokens.
175
185
176
-
Most often this test fails because the Health Agent is unable to resolve the AD FS farm name. This can happen if the AD FS servers are behind a network load balancers and the request gets initiated from a node that's behind the load balancer (as opposed to a regular client that is in front of the load balancer). This can be fixed by updating the "hosts" file located under "C:\Windows\System32\drivers\etc" to include the IP address of the AD FS server or a loopback IP address (127.0.0.1) for the AD FS farm name (such as sts.contoso.com). Adding the host file will short-circuit the network call, thus allowing the Health Agent to get the token.
186
+
Most often this test fails because the Health Agent is unable to resolve the AD FS farm name. This state can happen if the AD FS servers are behind a network load balancers and the request gets initiated from a node that's behind the load balancer (as opposed to a regular client that is in front of the load balancer). This issue can be fixed by updating the "hosts" file located under "C:\Windows\System32\drivers\etc" to include the IP address of the AD FS server or a loopback IP address (127.0.0.1) for the AD FS farm name (such as sts.contoso.com). Adding the host file will short-circuit the network call, thus allowing the Health Agent to get the token.
177
187
178
188
- question: |
179
189
I got an email indicating my machines are NOT patched for the recent ransomware attacks. Why did I receive this email?
@@ -207,19 +217,19 @@ sections:
207
217
```
208
218
209
219
- question: |
210
-
Why does the PowerShell cmdlet 'Get-MsolDirSyncProvisioningError' show less sync errors in the result?
220
+
Why does the PowerShell cmdlet 'Get-MsolDirSyncProvisioningError' show fewer sync errors in the result?
211
221
answer: |
212
-
<i>Get-MsolDirSyncProvisioningError</i> will only return DirSync provisioning errors. Besides that, Connect Health portal also shows other sync error types such as export errors. This is consistent with Azure AD Connect delta result. Read more about [Azure AD Connect Sync errors](./tshoot-connect-sync-errors.md).
222
+
<i>Get-MsolDirSyncProvisioningError</i> will only return DirSync provisioning errors. The Connect Health portal also shows other sync error types such as export errors. Read more about [Azure AD Connect Sync errors](./tshoot-connect-sync-errors.md).
213
223
214
224
- question: |
215
-
Why are my ADFS audits not being generated?
225
+
Why are my AD FS audits not being generated?
216
226
answer: |
217
-
Please use PowerShell cmdlet <i>Get-AdfsProperties -AuditLevel</i> to ensure audit logs is not in disabled state. Read more about [ADFS audit logs](/windows-server/identity/ad-fs/technical-reference/auditing-enhancements-to-ad-fs-in-windows-server#auditing-levels-in-ad-fs-for-windows-server-2016). Notice if there are advanced audit settings pushed to the ADFS server, any changes with auditpol.exe will be overwritten (event if Application Generated is not configured). In this case, please set the local security policy to log Application Generated failures and success.
227
+
Please use the PowerShell cmdlet <i>Get-AdfsProperties -AuditLevel</i> to ensure audit logs aren't in disabled state. Read more about [AD FS audit logs](/windows-server/identity/ad-fs/technical-reference/auditing-enhancements-to-ad-fs-in-windows-server#auditing-levels-in-ad-fs-for-windows-server-2016). Notice if there are advanced audit settings pushed to the AD FS server, any changes with auditpol.exe will be overwritten (event if Application Generated isn't configured). In this case, set the local security policy to log Application Generated failures and success.
218
228
219
229
- question: |
220
-
When will the agent certificate be automatic renewed before expiration?
230
+
When will the agent certificate be automatically renewed before expiration?
221
231
answer: |
222
-
The agent certification will be automatic renewed **6 months** before its expiration date. If it is not renewed, please ensure the network connection of the agent is stable. Restart the agent services or update to the latest version may also solve the issue.
232
+
The agent certification will be automatically renewed **6 months** before its expiration date. If it isn't renewed, ensure the network connection of the agent is stable. Restart the agent services or update to the latest version may also solve the issue.
0 commit comments