Microsoft Entra ID
Troubleshooting

Diagnose and remediate duplicated attribute sync errors

In brief

The article now documents the guided workflow for duplicate-attribute errors, including finding affected objects, opening Error Details, using Troubleshoot, reviewing proposed resolutions, and applying supported fixes. Status descriptions and diagnostic images were also updated.

What Entra admins need to know

Administrators troubleshooting synchronization errors should follow the updated workflow in Connect Health; unsupported cases continue to require manual resolution.

This editorial summary was generated by AI from the documentation changes. Verify important details in the full Microsoft Learn article.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Diagnose and remediate duplicated attribute sync errors

Use this article to understand common duplicated attribute synchronization scenarios and follow the diagnostic workflow in Microsoft Entra Connect Health.

Overview

Taking one step farther to highlight sync errors, Microsoft Entra Connect Health introduces self-service remediation. It troubleshoots duplicated attribute sync errors and fixes objects that are orphaned from Microsoft Entra ID. The diagnosis feature has these benefits: When QuarantinedAttributeValueMustBeUnique and AttributeValueMustBeUnique sync errors happen, it's common to see a UserPrincipalName or Proxy Addresses conflict in Microsoft Entra ID. You might solve the sync errors by updating the conflicting source object from the on-premises side. The sync error will be resolved after the next sync. For example, this image indicates that two users have a conflict of their UserPrincipalName. Both are [email protected]. The conflicting objects are quarantined in Microsoft Entra ID.

Diagnose sync error common scenarioDiagram that shows a common duplicated attribute synchronization error scenario.

Orphaned object scenario

Occasionally, you might find that an existing user loses the Source Anchor. The deletion of the source object happened in on-premises Active Directory. But the change of deletion signal never got synchronized to Microsoft Entra ID. This loss happens for reasons like sync engine issues or domain migration. When the same object gets restored or recreated, logically, an existing user should be the user to sync from the Source Anchor.

As an example, the existing object in Microsoft Entra ID preserves the license of Joe. A newly synchronized object with a different Source Anchor occurs in a duplicated attribute state in Microsoft Entra ID. Changes for Joe in on-premises Active Directory won't be applied to Joe’s original user (existing object) in Microsoft Entra ID.

Diagnose sync error orphaned object scenarioDiagram that shows an orphaned object synchronization error scenario.

Diagnostic and troubleshooting steps in Connect Health

The diagnose feature supports user objects with the following duplicated attributes:

| Attribute name | Synchronization error types|

Follow the steps from the Microsoft Entra admin center to narrow down the sync error details and provide more specific solutions:

Sync error diagnosis steps

From the Microsoft Entra admin center, take a few steps to identify specific fixable scenarios:

  1. CheckIn Microsoft Entra Connect Health, select Sync errors, and then select the Diagnose statusDuplicate Attribute column. The status shows if there's a possible waycategory.
  2. Find the affected object. Expand the row to fix a syncreview its details.
  3. Select Fix this error directly from Microsoft Entra ID. In other words, a troubleshooting flow exists that can narrow down to open Error Details. This action is available only for supported duplicate-attribute errors.
  4. Compare the error caseconflicting and potentially fix it.existing objects, and then select Troubleshoot to open the Fix Synchronization Error diagnostic wizard.

The wizard provides a directory query to help verify the affected user, asks diagnostic questions, and provides expandable guidance before you continue to a proposed resolution.

:::image type="content" source="media/how-to-connect-health-diagnose-sync-errors/connect-health-sync-diagnostic-wizard.png" alt-text="Screenshot of the Connect Health Fix Synchronization Error wizard with callouts for the suggested directory query, diagnostic answer choices, and guidance." lightbox="media/how-to-connect-health-diagnose-sync-errors/connect-health-sync-diagnostic-wizard.png":::

The panel can show the following statuses:

Status What does it mean?
Not Started You haven't visited this diagnosiscompleted the guided process. Depending on the diagnostic result, there's a potential wayyou might be able to fix the sync error directly from the portal.Microsoft Entra ID.
Manual Fix Required The error doesn't fitmeet the criteria offor an available fixes fromportal fix. For example, the portal. Either conflicting object typesobjects aren't users,supported user objects or you already went through the diagnostic steps, andguided process found no fix resolution was available from the portal. In the latter case, a fix from the on-premises side is still one of the solutions.applicable fix. Read more about on-premises fixes.
Pending Sync A fix was applied. The portalapplied, and the service is waiting for the next sync cycle to clear the error.
  1. In the Identity Verification step, answer the questions about the on-premises and Microsoft Entra objects. The answers help identify an orphaned object case.

  2. Review the proposed resolution in Review & Apply. If no portal fix is available based on your answers, close the panel and use the displayed manual resolution guidance. The status changes to Manual Fix Required for the current sync cycle.

  3. If the panel identifies a supported orphaned object case, select Apply Fix. The status changes to Pending Sync.

  4. After the next sync cycle, the error should be removed from the list.

In these examples, the question tries to identify whether Joe Jackson still exists in on-premises Active Directory. For the common scenario, both users Joe Johnson and Joe Jackson are present in on-premises Active Directory. The quarantined objects are two different users.

Diagram that shows a common duplicated attribute synchronization error scenario.

For the orphaned object scenario, only the single user Joe Johnson is present in on-premises Active Directory:

Diagram that shows the does-user-exist question for an orphaned object synchronization error scenario.

Do both of these accounts belong to the same user?

This question checks an incoming conflicting user and the existing user object in Microsoft Entra ID to see if they belong to the same user.

In the following example, the two objects belong to the same user Joe Johnson.

Diagram that shows the same-user question for an orphaned object synchronization error scenario.

What happens after the fix is applied in the orphaned object scenario

  1. Updates the Source Anchor to the correct object in Microsoft Entra ID.
  2. Deletes the conflicting object in Microsoft Entra ID if it's present.

Diagram that shows the synchronization error scenario after the fix is applied.

Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…