We like to allow users to reset their Microsoft 365/Office 365 password. The feature we…
Find Azure AD Connect accounts
Azure AD Connect uses 3 accounts to synchronize information between Windows Server Active Directory and Azure Active Directory. You sometimes want to check if these Azure AD Connect accounts have the correct permission or write them down before migrating Azure AD Connect to another server. In this article, you will learn how to find Azure AD Connect service accounts.
Table of contents
Azure AD Connect accounts
Azure AD Connect uses the following 3 accounts to synchronize data between Active Directory (on-premises) and Azure Active Directory (cloud):
- AD DS Connector account: Read/write information to Windows Server Active Directory
- ADSync Service account: Run the synchronization service and access the SQL database
- Azure AD Connector account: Write information to Azure AD
Let’s find all 3 Azure AD service accounts and note them down.
Find AD DS Connector account
The AD DS Connector account, which reads/writes information to Windows Server Active Directory, can be found in these two places.
Method 1: Synchronization Service Manager
Find the AD DS Connector account in Synchronization Service Manager:
- Sign in on the Azure AD Connect Server.
- Start Synchronization Service Manager.
- Click on Connectors.
- Select the internal domain.
- Click on Properties.
In our example, it’s the internal domain exoip.local.
- Click Connect to Active Directory Forest.
- The user name field shows the AD DS Connector account.
In our example, the AD DS Connector account is MSOL_b3c27fcc1296.
Note: If the user name has the prefix MSOL_, Azure AD Connect created the account in Azure AD Connect setup.
Read more in the articles Create AD DS Connector account and Change AD DS Connector account.
Method 2: Azure Active Directory Connect
Another way to check the AD DS Connector account is in Azure Active Directory Connect:
- Sign in on the Azure AD Connect Server.
- Start Azure AD Connect.
- Click View or export current configuration.
- Click Next.
- The ACCOUNT property shows the AD DS Connector account.
In our example, the AD DS Connector account is MSOL_b3c27fcc1296.
Find ADSync Service account
The ADSync service account, which runs the synchronization service and accesses the SQL database, can be found in the following place:
- Sign in on the Azure AD Connect Server.
- Start Services (services.msc).
- Double-click the service name Microsoft Azure AD Sync to open the properties.
- Click on the tab Log On.
- The this account field shows the ADSync Service account.
In our example, the ADSync Service account is ADSync.
Note: If the account name is ADSync or starts with ADSync, Azure AD Connect created the account in Azure AD Connect setup.
Find Azure AD Connector account
The Azure AD Connector account, which writes information to Azure AD, can be found in the following two places.
Method 1: Synchronization Service Manager
- Sign in to the Azure AD Connect server.
- Start Synchronization Service Manager.
- Click on Connectors.
- Select the Microsoft domain (.onmicrosoft.com)
- Click on Properties.
In our example, it’s the Microsoft domain M365x333525.onmicrosoft.com – AAD.
- Click on Connectivity.
- The UserName field shows the Azure AD Connector account.
In our example, the Azure AD Connector account starts with Sync_AAD01-2012.
Read more in the articles Change Azure AD Connector account and How to Remove On-Premises Directory Synchronization Service Account.
Method 2: Microsoft 365 admin center
Another way to check the Azure AD Connector account is in Microsoft 365 admin center:
- Sign in to Microsoft 365 admin center.
- Expand Health and click on Directory sync status.
- The Directory sync service account field shows the Azure AD Connector account.
In our example, the Azure AD Connector account starts with Sync_AAD01-2012.
Did this help you to check the Azure AD Connect service accounts?
Keep reading: Upgrade Azure AD Connect »
Conclusion
You learned how to find Azure AD Connect accounts. There are 3 accounts, and it’s good to know where you can find them before you migrate Azure AD Connect to a new server or if there are synchronization issues.
Did you enjoy this article? You may also like Configure Azure AD Multi-Factor Authentication. Don’t forget to follow us and share this article.
Hi Ali,
Thanks for the article. Where can I find this account “Sync_AAD01-2012” in the server as it stated that “Synced from on-premises”?
You can’t find it in on-premises Active Directory. I know that it’s weird because Microsoft 365 shows that it’s synced from on-premises, but you should ignore that.
If you ever need to change or remove the account:
– Change Azure AD Connector account
– How to Remove On-Premises Directory Synchronization Service Account.