Issue with Entra Connect wizard setup and MFA requirements/conditional access

Taio Ray 20 Reputation points
2025-01-06T20:36:40.05+00:00

Hi all,

Our company is moving from an on-prem AD to a hybrid AAD setup and we want to utilize intune to manage a few policies. The issue I am having is with the initial Entra connect setup, the installation wizard fails each time with this error.

User's image

and in the Entra failed logs User's image

I have researched this and it seems to be a conditional access issue. What is the best way around this? Do I have to create a policy for the service account associated? We have assigned the hybrid administrator role to myself and the service account. Any help is greatly appreciated,

Thanks

Active Directory
Active Directory
A set of directory-based technologies included in Windows Server.
6,823 questions
Microsoft Intune
Microsoft Intune
A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.
5,475 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
23,012 questions
0 comments No comments
{count} votes

Accepted answer
  1. Akhilesh Vallamkonda 11,355 Reputation points Microsoft Vendor
    2025-01-08T17:49:57.66+00:00

    Hi @Taio Ray

    Thank you for reaching Microsoft Q&A Forum!

    If you are seeing the error "Unable to create the synchronization service account", the most common root cause would be a Conditional Access/MFA policy which requests registration of your connector account user. To resolve this, you can exclude this user from Conditional Access/MFA policies.
    Also, ensure that TLS 1.2 is enabled to allow successful authentication.

    Reference: https://learn.microsoft.com/en-us/answers/questions/1840734/unable-to-create-the-synchronization-service-accou
    https://learn.microsoft.com/en-us/answers/questions/622694/unable-to-create-the-synchronization-service-accou
    Hope this helps. Do let us know if you any further queries by responding in the comments section.

    Thanks,

    Akhilesh V.


    If this answers your query, do click Accept Answer and Yes for was this answer helpful. And, if you have any further query do let us know.

    1 person found this answer helpful.

1 additional answer

Sort by: Most helpful
  1. Marcin Policht 32,660 Reputation points MVP
    2025-01-06T20:42:13.89+00:00

    Try excluding the Entra Connect sync account from the CA policy that apparently applies in this case

    More at https://www.alitajran.com/conditional-access-mfa-breaks-azure-ad-connect-synchronization/


    If the above response helps answer your question, remember to "Accept Answer" so that others in the community facing similar issues can easily find the solution. Your contribution is highly appreciated.

    hth

    Marcin

    1 person found this answer helpful.

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.