Microsoft Entra ID
General

Microsoft Entra Connect Health operations

In brief

The article updates navigation and steps for email notifications, server or service deletion, and role-based access control, with new screenshots.

What Entra admins need to know

Administrators have current portal paths and clearer guidance for managing notifications, removing resources, and assigning access.

This editorial summary was generated by AI from the documentation changes. Verify important details in the full Microsoft Learn article.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Microsoft Entra Connect Health operations

This topic describes the various operations you can perform by using Microsoft Entra Connect Health.

Enable email notifications

You can configure the Microsoft Entra Connect Health service to send email notifications when alerts indicate that your identity infrastructure isn't healthy. This occurs when an alert is generated, and when it is resolved.

Screenshot of Microsoft Entra Connect Health email notification settings

To enable Microsoft Entra Connect Health email notifications

  1. In the Microsoft Entra admin centerOpen Microsoft Entra Connect Health, search for Microsoft Entra Connect Health
  2. Selectand then select Sync errors.
  3. Select Notification Settingssettings on the command bar.
  4. For Get email notification for alerts, select Yes.
  5. At the email notification switch,Under Recipients, select ONAll global administrators.
  6. Select the check box if you want all Global Administrators to receive email notifications.
  7. If you want to receive email notifications atUnder Custom notification emails, add any other email addresses, specify them in theaddresses that should receive notifications. Use Additional Email RecipientsRemove email box. Toto remove an email address from this list, right-select the entry and select Delete.address.
  8. To finalize the changes, selectSelect Save. Changes take effect only after you save.save them.

:::image type="content" source="media/how-to-connect-health-operations/connect-health-notification-settings.png" alt-text="Screenshot of the Connect Health notification settings panel with callouts for enabling email, choosing recipients, and saving changes." lightbox="media/how-to-connect-health-operations/connect-health-notification-settings.png":::

  • This action doesn't delete the data already collected from this server. That data is deleted in accordance with the Azure data retention policy.
  • After performing this action, if you want to start monitoring the same server again, you must uninstall and reinstall the Health Agent on this server.

The service overview separates the two deletion paths. Select a server to open its details before deleting only that server. Use Delete on the service-level command bar only when you intend to delete the entire monitored service instance.

:::image type="content" source="media/how-to-connect-health-operations/connect-health-delete-server-or-service.png" alt-text="Screenshot of the Connect Health service overview with callouts for selecting an individual server and using the service-level Delete action." lightbox="media/how-to-connect-health-operations/connect-health-delete-server-or-service.png":::

Delete a server from the Microsoft Entra Connect Health service

Microsoft Entra Connect Health for Active Directory Federation Services (AD FS) and Microsoft Entra Connect (Sync):

  1. Open Microsoft Entra Connect Health, select the Server blade fromapplicable service type, and then select the Server List blade by selectingservice.
  2. In the servers section, select the server namethat you want to be removed.remove. For AD FS, select View all servers first.
  3. OnSelect Delete on the Server blade, from the action bar, select Delete. Screenshot of Microsoft Entra Connect Health delete servercommand bar.
  4. Confirm by typing the server name in the confirmation box.
  5. Select Delete.

Microsoft Entra Connect Health for AD Domain Services:

To delete a service instance from the Microsoft Entra Connect Health service

  1. Open Microsoft Entra Connect Health, and select the Service blade from the Service List blade by selectingapplicable service type.
  2. Select the service identifier (farm name)identifier, such as the farm name, that you want to remove.
  3. OnSelect Delete on the Service blade, from the action bar, select Delete. Screenshot of Microsoft Entra Connect Health delete servicecommand bar.
  4. Confirm by typing the service name in the confirmation box (for example: box, such as sts.contoso.com)com.
  5. Select Delete.

Manage access with Azure RBAC

Allow users or groups access to Microsoft Entra Connect Health

The following steps show how to allow access.

Step 1: Select the appropriate access scope

To allow a user access at the all service instances level within Microsoft Entra Connect Health,level, open Microsoft Entra Connect Health, and then select Role based access control (IAM).

To manage access for an individual service instance, open the main blade in Microsoft Entraservice and select Access Control where available.

The IAM page lets you check existing access, review role assignments and roles, or create an assignment at the selected Connect Health.
Health scope.

:::image type="content" source="media/how-to-connect-health-operations/connect-health-role-based-access-control.png" alt-text="Screenshot of the Connect Health role-based access control page with callouts for adding an assignment, reviewing role information, and granting access at the current scope." lightbox="media/how-to-connect-health-operations/connect-health-role-based-access-control.png":::

Step 2: Add users and groups, and assign roles

  1. From theSelect ConfigureAdd section,, and then select UsersAdd role assignment.
    Screenshot of Microsoft Entra Connect Health resource sidebar
  2. Select a role, such as AddOwner, Contributor, or Reader.
  3. In the Select a role pane, select a role (for example, Owner).
    Screenshot of Microsoft Entra Connect Health and Azure RBAC configure menu
  4. Type the name or identifier of the targeted user or group. You canSearch for and select one or more users or groups atgroups.
  5. Confirm the same time. Select Select. Screenshot of Microsoft Entra Connect Health and Azure role list
  6. Select OK.
    role assignment.
  7. After the role assignment is complete, the users and groups appear in the role assignments list.
    Screenshot of Microsoft Entra Connect Health and Azure RBAC and new users highlighted

Now the listed users and groups have access, according to their assigned roles.

Step 3: Share the bladeConnect Health location with users or groups

  1. After you assign permissions, a user can access Microsoft Entra Connect Health by goingshare the Microsoft Entra Connect Health.

  2. On link with the blade,users or groups.

    Remove users or groups

    To remove access, select the user can pinor group in the blade, or different parts of it, to the dashboard. Select therole assignments list, and then select Pin to dashboardRemove icon.
    Screenshot of Microsoft Entra Connect Health and Azure RBAC pin blade, with pin icon highlighted

Remove users or groups

You can remove a user or a group added to Microsoft Entra Connect Health and Azure RBAC. Simply right-select the user or group, and select Remove.
Screenshot of Microsoft Entra Connect Health and Azure RBAC with Remove highlighted

.

Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…