We have an existing Azure AD Connect synchronization with Microsoft 365 tenant. We did create…
Azure AD Connect Synchronization Service Manager shows the status completed-export-errors. However, when we want to look into the details, we only find that it shows the export error dn-attributes-failure. In this article, you will learn why this is happening and the solution for the export error dn-attributes-failure in Azure AD Connect Synchronization Services.
Table of contents
To find the export error dn-attributes-failure in Azure AD Connect, follow these steps:
- Sign in to the Azure AD Connect server
- Start Synchronization Service Manager
- Click on the tab Operations
- Click in the list on completed-export-errors
- Click on the Export Error
In our example, the security group SG_Azure_A is pending export and can’t update successfully.
The Export Error tab only shows the error: dns-attributes-failure, nothing more.
Solution for dn-attributes-failure
While we go back to the Synchronization Service Manager and look into the Export Errors, we also see the error DataValidationFailed.
The solution is to address the DataValidationFailed export errors first. After that, you don’t have to do anything for the dn-attributes-failure export errors, and it will automatically resolve.
In our example, the security group SG_Azure_A got members with invalid characters. Once we fix that, the group can update, and the dn-attribute-failure export error will not appear anymore.
The best to check and address the DataValidationFailed export errors is with the IdFix tool.
Run IdFix tool
Go through the article IdFix – Directory synchronization error remediation tool and fix all the AD objects that show up with an error.
This is how it looks when querying the Active Directory on-premises with IdFix.
This is how it looks after fixing the AD objects and querying.
Force Azure AD sync
Force a delta sync with PowerShell on the AD Connect server.
PS C:\> Start-ADSyncSyncCycle -PolicyType Delta Result ------ Success
Verify Azure AD Connect sync status
Six steps will happen when you apply a synchronization, and they all will show the success status.
Everything looks great!
Read more: Upgrade Azure AD Connect »
You learned why the export error dn-attributes-failure appears. The solution is to run ldFix tool and fix all the issues. After that, Azure AD Connect will synchronize all AD objects, and no more error appears.
Did you enjoy this article? You may also like Create AD DS Connector account. Don’t forget to follow us and share this article.