Microsoft Entra ID
Monitoring

Using Microsoft Entra Connect Health with AD DS

In brief

The guide now documents the updated service overview, alert details and search, domain controller filtering and column options, replication error details, and 24-hour authentication performance charts.

What Entra admins need to know

Administrators can follow the revised navigation and workflows when monitoring AD DS health and investigating alerts, replication issues, and authentication trends.

This editorial summary was generated by AI from the documentation changes. Verify important details in the full Microsoft Learn article.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Using Microsoft Entra Connect Health with AD DS

The following documentation is specific to monitoring Active Directory Domain Services with Microsoft Entra Connect Health. The supported versions of AD DS are Windows Server 2016, 2019, 2022, and 2025.

For more information on monitoring AD FS with Microsoft Entra Connect Health, see Using Microsoft Entra Connect Health with AD FS. Additionally, for information on monitoring Microsoft Entra Connect (Sync) with Microsoft Entra Connect Health see Using Microsoft Entra Connect Health for Sync.

Microsoft Entra Connect Health for AD DSOpen Microsoft Entra Connect Health, select AD DS services, and then select a service. The service page provides:

  • An Essentials section with forest and monitoring information.
  • Summary cards for domain controllers, replication status, and alerts.
  • Performance charts for LDAP successful binds, NTLM authentications, and Kerberos authentications.

:::image type="content" source="media/how-to-connect-health-adds/connect-health-adds-overview.png" alt-text="Screenshot of the Connect Health AD DS service overview with callouts for forest details, the domain controller list, and replication status." lightbox="media/how-to-connect-health-adds/connect-health-adds-overview.png":::

Alerts for Microsoft Entra Connect Health for AD DS

The Alerts section within Microsoft Entra Connect Health for AD DS, provides you a list of page lists active and resolved alerts,alerts related to your domain controllers. SelectingSelect an active or resolved alert opens a new blade with additional information, along with resolution steps, and links to supporting documentation. Each alert type can have one or more instances, which correspond to each of the domain controllers affected by that particular alert. Near the bottom of the alert blade, you can double-click an affected domain controllerrow to open an additional blade with morethe details about thatpanel, which contains alert instance.metadata, affected servers, resolution guidance, related documentation, and a feedback option.

Within this blade, you can enable email notifications for alerts andUse the command bar to refresh the list, change the time range in view. Expandingto include older resolved alerts, or open notification settings. You can also search the time range allows you to see prior resolved alerts.

Microsoft Entra Connect Sync erroralert list.

Domain Controllers Dashboard

This dashboard provides a topological view of your environment, along with keyOn the service page, select View all domain controllers to open the domain controllers list. The list shows operational metrics and the health status of each of your monitored domain controllers. The presented metrics help

Use Group by domain or Group by site to quickly identify, any domain controllers that might require further investigation. By default, only a subset of the columns is displayed. However, you can find the entire set of available columns, by double-clicking the columns command. Selecting the columns that you most care about turns this dashboard into a single and easy place to view the health of your AD DS environment.

Domain Controllers

Domain controllers can be grouped by their respective domain or site, which is helpful for understandingunderstand the environment topology. Lastly, if you double-clickYou can search by domain controller name, domain, site, role, or status; include or exclude monitored and not-monitored domain controllers; and use Choose columns to customize the blade header, the dashboard maximizes to utilize the available screen real-estate. This larger view is helpful when multiple columns are displayed.table.

Replication Status Dashboard

This dashboard provides aOn the service page, select View replication details to view of the replication status and replication topology of your monitored domain controllers. The page shows the status of the most recent replication attempt is listed, along with helpful documentation for any error that is found. Youand can double-clickbe grouped by domain or site. Use search to find a domain controller with an error,controller, and expand groups to review source and destination domain controllers, naming context, status, and the last attempted replication.

Select a replication error to open the Replication Error Details panel. The panel includes the source and target domain controllers, naming context, site, domain, last attempted and successful synchronization times, recommended fix, and related troubleshooting link when available.

Monitoring

The service page shows 24-hour graphical trends for three default performance counters: LDAP successful binds, NTLM authentications, and Kerberos authentications. Compare the charts to identify authentication-volume changes, and then select View detailed monitoring for a metric to open a new bladelarger view and change the time range.

:::image type="content" source="media/how-to-connect-health-adds/connect-health-adds-performance-monitoring.png" alt-text="Screenshot of Connect Health AD DS monitoring with information such as: details aboutcallouts for comparing LDAP, NTLM, and Kerberos trends and opening detailed monitoring." lightbox="media/how-to-connect-health-adds/connect-health-adds-performance-monitoring.png":::

Select View all Performance Metrics to open the error, recommended resolution steps,full collection. Use Manage counters to select the metrics you want to display, drag charts to reorder them, and linksselect a chart to troubleshooting documentation.

Replication Status

Monitoring

This feature provides graphical trends of different performance counters, which are continuously collected from each of the monitored domain controllers. Performance of a domain controller can easily be compared across all othercompare data for monitored domain controllers in your forest. Additionally, you can see various performance counters side by side, which is helpful when troubleshooting issues in your environment.

Monitoring

By default, we have preselected four performance counters; however, you can include others by clickingover the filter command and selecting or deselecting any desired performance counters. Additionally, you can double-click a performance counter graph to open a new blade, which includes data points for each of the monitored domain controllers.available time ranges.

Related links

Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…