You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: articles/active-directory/hybrid/reference-connect-health-faq.yml
+17-17Lines changed: 17 additions & 17 deletions
Original file line number
Diff line number
Diff line change
@@ -26,7 +26,7 @@ sections:
26
26
- question: |
27
27
I manage multiple Azure AD directories. How do I switch to the one that has Azure Active Directory Premium?
28
28
answer: |
29
-
To switch between different Azure AD tenants, select the currently signed-in **User Name** on the upper-right corner, and then choose the appropriate account. If the account is not listed here, select **Sign out.** Next, use the global admin credentials of the directory that has Azure Active Directory Premium (P1 or P2) enabled to sign in.
29
+
To switch between different Azure AD tenants, select the currently signed-in **User Name** on the upper-right corner, and then choose the appropriate account. If the account isn't listed here, select **Sign out.** Next, use the global admin credentials of the directory that has Azure Active Directory Premium (P1 or P2) enabled to sign in.
30
30
31
31
- question: |
32
32
What version of identity roles are supported by Azure AD Connect Health?
@@ -39,7 +39,7 @@ sections:
39
39
|Azure AD Connect | Version 1.0.9125 or higher|
40
40
|Active Directory Domain Services (AD DS)| <ul><li> Windows Server 2012 </li> <li>Windows Server 2012 R2 </li> <li> Windows Server 2016 </li> <li> Windows Server 2019 </li> </ul>|
41
41
42
-
Windows Server Core installations are not supported.
42
+
Windows Server Core installations aren't supported.
43
43
44
44
The features provided by the service may differ based on the role and the operating system. All of the features may not be available, for all operating system versions. See the feature descriptions for details.
45
45
@@ -49,7 +49,7 @@ sections:
49
49
* The first Connect Health Agent requires at least one Azure AD Premium (P1 or P2) license.
50
50
* Each additional registered agent requires 25 more Azure AD Premium (P1 or P2) licenses.
51
51
* Agent count is equivalent to the total number of agents that are registered across all monitored roles (AD FS, Azure AD Connect, and/or AD DS).
52
-
* AAD Connect Health licensing does not require you to assign the license to specific users. You only need to have the requisite number of valid licenses.
52
+
* AAD Connect Health licensing doesn't require you to assign the license to specific users. You only need to have the requisite number of valid licenses.
53
53
54
54
Licensing information is also found on the [Azure AD Pricing page](https://aka.ms/aadpricing).
55
55
@@ -66,7 +66,7 @@ sections:
66
66
- question: |
67
67
Does Azure AD Connect Health support Azure Germany Cloud?
68
68
answer: |
69
-
Azure AD Connect Health is not supported in Germany Cloud except for the [sync errors report feature](how-to-connect-health-sync.md#object-level-synchronization-error-report).
69
+
Azure AD Connect Health isn't supported in Germany Cloud except for the [sync errors report feature](how-to-connect-health-sync.md#object-level-synchronization-error-report).
70
70
71
71
| Roles | Features | Supported in German Cloud |
72
72
| ------ | --------------- | --- |
@@ -80,14 +80,14 @@ sections:
80
80
- name: Installation questions
81
81
questions:
82
82
- question: |
83
-
Does my agent installation get updated automatically when there is a new version of the agent?
83
+
Does my agent installation get updated automatically when there's a new version of the agent?
84
84
answer: |
85
-
Yes, all agents will get updated automatically when there is a new version of the agent.
85
+
Yes, all agents will get updated automatically when there's a new version of the agent.
86
86
87
87
- question: |
88
88
Can I opt out or disable automatic upgrade of the agent?
89
89
answer: |
90
-
No, automatic upgrade is mandatory. If you do not want the agent to be upgraded when a new version is released, you should uninstall the agent.
90
+
No, automatic upgrade is mandatory. If you don't want the agent to be upgraded when a new version is released, you should uninstall the agent.
91
91
92
92
- question: |
93
93
What is the impact of installing the Azure AD Connect Health Agent on individual servers?
@@ -129,7 +129,7 @@ sections:
129
129
- question: |
130
130
Does Azure AD Connect Health support Basic authentication when connecting to HTTP proxies?
131
131
answer: |
132
-
No. A mechanism to specify an arbitrary user name and password for Basic authentication is not currently supported.
132
+
No. A mechanism to specify an arbitrary user name and password for Basic authentication isn't currently supported.
133
133
134
134
- question: |
135
135
What firewall ports do I need to open for the Azure AD Connect Health Agent to work?
@@ -139,7 +139,7 @@ sections:
139
139
- question: |
140
140
Why do I see two servers with the same name in the Azure AD Connect Health portal?
141
141
answer: |
142
-
When you remove an agent from a server, the server is not automatically removed from the Azure AD Connect Health portal. If you manually remove an agent from a server or remove the server itself, you need to manually delete the server entry from the Azure AD Connect Health portal.
142
+
When you remove an agent from a server, the server isn't automatically removed from the Azure AD Connect Health portal. If you manually remove an agent from a server or remove the server itself, you need to manually delete the server entry from the Azure AD Connect Health portal.
143
143
144
144
You might reimage a server or create a new server with the same details (such as machine name). If you did not remove the already registered server from the Azure AD Connect Health portal, and you installed the agent on the new server, you might see two entries with the same name.
145
145
@@ -148,7 +148,7 @@ sections:
148
148
- question: |
149
149
Can I install the Azure AD Connect health agent on Windows Server Core?
150
150
answer: |
151
-
No. Installation on Server Core is not supported.
151
+
No. Installation on Server Core isn't supported.
152
152
153
153
- name: Health Agent registration and data freshness
154
154
questions:
@@ -159,24 +159,24 @@ sections:
159
159
160
160
* The agent cannot communicate with the required endpoints because a firewall is blocking traffic. This issue is common on web application proxy servers. Make sure that you have allowed outbound communication to the required endpoints and ports. See the [requirements section](how-to-connect-health-agent-install.md#requirements) for details.
161
161
* Outbound communication is subjected to an TLS inspection by the network layer. This causes the certificate that the agent uses to be replaced by the inspection server/entity, and the steps to complete the agent registration fail.
162
-
* The user does not have access to perform the registration of the agent. Global admins have access by default. You can use [Azure role-based access control (Azure RBAC)](how-to-connect-health-operations.md#manage-access-with-azure-rbac) to delegate access to other users.
162
+
* The user doesn't have access to perform the registration of the agent. Global admins have access by default. You can use [Azure role-based access control (Azure RBAC)](how-to-connect-health-operations.md#manage-access-with-azure-rbac) to delegate access to other users.
163
163
164
164
- question: |
165
-
I am getting alerted that "Health Service data is not up to date." How do I troubleshoot the issue?
165
+
I am getting alerted that "Health Service data isn't up to date." How do I troubleshoot the issue?
166
166
answer: |
167
-
Azure AD Connect Health generates the alert when it does not receive all the data points from the server in the last two hours. [Read more](how-to-connect-health-data-freshness.md).
167
+
Azure AD Connect Health generates the alert when it doesn't receive all the data points from the server in the last two hours. [Read more](how-to-connect-health-data-freshness.md).
168
168
169
169
- name: Operations questions
170
170
questions:
171
171
- question: |
172
172
Do I need to enable auditing on the web application proxy servers?
173
173
answer: |
174
-
No, auditing does not need to be enabled on the web application proxy servers.
174
+
No, auditing doesn't need to be enabled on the web application proxy servers.
175
175
176
176
- question: |
177
177
How do Azure AD Connect Health Alerts get resolved?
178
178
answer: |
179
-
Azure AD Connect Health alerts get resolved on a success condition. Azure AD Connect Health Agents detect and report the success conditions to the service periodically. For a few alerts, the suppression is time-based. In other words, if the same error condition is not observed within 72 hours from alert generation, the alert is automatically resolved.
179
+
Azure AD Connect Health alerts get resolved on a success condition. Azure AD Connect Health Agents detect and report the success conditions to the service periodically. For a few alerts, the suppression is time-based. In other words, if the same error condition isn't observed within 72 hours from alert generation, the alert is automatically resolved.
180
180
181
181
- question: |
182
182
I am getting alerted that "Test Authentication Request (Synthetic Transaction) failed to obtain a token." How do I troubleshoot the issue?
@@ -224,12 +224,12 @@ sections:
224
224
- question: |
225
225
Why are my ADFS audits not being generated?
226
226
answer: |
227
-
Please use PowerShell cmdlet <i>Get-AdfsProperties -AuditLevel</i> to ensure audit logs is not in disabled state. Read more about [ADFS audit logs](/windows-server/identity/ad-fs/technical-reference/auditing-enhancements-to-ad-fs-in-windows-server#auditing-levels-in-ad-fs-for-windows-server-2016). Notice if there are advanced audit settings pushed to the ADFS server, any changes with auditpol.exe will be overwritten (event if Application Generated is not configured). In this case, set the local security policy to log Application Generated failures and success.
227
+
Please use the PowerShell cmdlet <i>Get-AdfsProperties -AuditLevel</i> to ensure audit logs aren't in disabled state. Read more about [ADFS audit logs](/windows-server/identity/ad-fs/technical-reference/auditing-enhancements-to-ad-fs-in-windows-server#auditing-levels-in-ad-fs-for-windows-server-2016). Notice if there are advanced audit settings pushed to the ADFS server, any changes with auditpol.exe will be overwritten (event if Application Generated isn't configured). In this case, set the local security policy to log Application Generated failures and success.
228
228
229
229
- question: |
230
230
When will the agent certificate be automatic renewed before expiration?
231
231
answer: |
232
-
The agent certification will be automatic renewed **6 months** before its expiration date. If it is not renewed, ensure the network connection of the agent is stable. Restart the agent services or update to the latest version may also solve the issue.
232
+
The agent certification will be automatic renewed **6 months** before its expiration date. If it isn't renewed, ensure the network connection of the agent is stable. Restart the agent services or update to the latest version may also solve the issue.
0 commit comments