立即与支持人员聊天
与支持团队交流

Active Administrator 8.8.1 - User Guide

Active Administrator Overview User Provisioning Certificates Security & Delegation  Active Directory Health
Switching to Active Directory Health Using the Active Directory Health landing page Installing Active Directory Health Analyzer agents Using the Active Directory Health Analyzer agent configuration utility Excluding domain controllers Managing the Remediation Library Analyzing Active Directory health Analyzing Microsoft Entra ID Managing Active Directory Health Analyzer alerts Managing alert notifications Pushing alerts to System Center Operations Manager and SNMP managers Managing monitored domain controllers Managing data collectors Active Directory Health Templates Managing Active Directory Health Analyzer agents Using the Troubleshooter Recovering Active Directory Health data
Auditing & Alerting Group Policy Active Directory Recovery Active Directory Infrastructure DC Management DNS Management Configuration
Using the Configuration landing page Managing tasks Defining role-based access Setting email server options Configuring SCOM and SNMP Settings Setting notification options Setting Active Template options Setting agent installation options Setting recovery options Setting GPO history options Setting certificate configuration Setting service monitoring policy Managing archive databases Migrating data to another database Setting a preferred domain controller Setting up workstation logon auditing Managing configuration settings Setting user options Managing the Active Directory server
Diagnostic Console Alerts Appendix
Domain controller alerts
Active Directory Certificate Services service is not running Active Directory Domain Services is not running Active Directory Web Services service is not running Consecutive replication failures DC cache hits DC DIT disk space DC DIT log file disk space DC LDAP load DC LDAP response too slow DC Memory Usage DC properties dropped DC RID pool low DC SMB connections DC SYSVOL disk space DC time sync lost Detected NO_CLIENT_SITE record DFS Replication service not running DFS service is not running DFSR conflict area disk space DFSR conflict files generated DFSR RDC not enabled DFSR sharing violation DFSR staged file age DFSR staging area disk space DFSR USN records accepted DFSRS CPU load DFSRS unresponsive DFSRS virtual memory DFSRS working set DNS Client Service is not running Domain controller CPU load Domain controller page faults Domain controller unresponsive File Replication Service is not running File replication (NTFRS) staging space free in kilobytes GC response too slow Group policy object inconsistent Hard disk drive Intersite Messaging Service is not running Invalid primary DNS domain controller address Invalid secondary DNS domain controller address KDC service is not running LSASS CPU load LSASS virtual memory LSASS working set Missing SRV DNS record for either the primary or secondary DNS server NETLOGON not shared NetLogon service is not running Orphaned group policy objects exist Physical memory Power supply Primary DNS resolver is not responding Secondary DNS resolver is not responding Security Accounts Manager Service is not running SRV record is not registered in DNS SYSVOL not shared W32Time service is not running Workstation Service is not running
Domain alerts Site alerts Forest alerts Microsoft Entra Connect alerts
Event Definitions PowerShell cmdlets

Setting up the Microsoft Entra Connect application

Previous Next


 Active Directory Health > Analyzing Microsoft Entra ID > Setting up the Microsoft Entra Connect application

Setting up the Microsoft Entra Connect application

Setting up the Microsoft Entra Connect application is a two-step process. First create the Microsoft Entra Connect application through the Microsoft Entra admin center, and then configure settings in Active Administrator.

The default port to use for Microsoft Entra Connect is 15604. The AADCAgentPortNumber property is set in the AADCSettings.xml file located in ProgramData\Quest\ActiveAdministrator\AADCAgent folder.

Topics 

Adding the Microsoft Entra Connect application

Previous Next



Adding the Microsoft Entra Connect application

Refer to Microsoft documentation for details on how to create a Microsoft Entra application.

For Active Administrator, ensure that you enable the following permissions for the application:

Application: Read directory data
Delegated: Access the directory as the signed-in user
Delegated: Sign in and read user profile

The next step is to configure the Microsoft Entra Connect app settings in Active Administrator. See Configuring Microsoft Entra Connect application settings.

Configuring Microsoft Entra Connect application settings

Previous Next



Configuring Microsoft Entra Connect application settings

To configure Microsoft Entra Connect application settings
1
Select Active Directory Health | Microsoft Entra Connect.
3
Open the Agents tab.
4
Click Microsoft Entra App Settings.
5
In the Tenant box, enter the fully qualified name of the Microsoft Entra domain.
6
In the Application Name box, enter AAADConnectApp as the display name.
7
In the Application ID box, enter the Application ID that you recorded from the Microsoft Entra admin center.
8
In the Security Key box, enter the Security key that you copied from the Microsoft Entra admin center.
9

Viewing Microsoft Entra Connect status

Previous Next


 Active Directory Health > Analyzing Microsoft Entra ID > Viewing Microsoft Entra Connect status

Viewing Microsoft Entra Connect status

On the Summary tab you can view a summary of the output of the Synchronization Service Manager and manage the Microsoft Entra Connect Scheduler on each computer where you installed the Microsoft Entra Connect Health Monitoring Agent. See Installing the Microsoft Entra Connect Health Monitoring Agent.

To view Microsoft Entra Connect status
1
Select Active Directory Health | Microsoft Entra Connect.
3
Open the Summary tab, if necessary.

The date and time of the last sync and the results of the sync display, as well as the date and time the display was last updated.

The Summary tab is divided into six sections:

Microsoft Entra Connect Environment

Table 43. Microsoft Entra Connet Environment indicators

Indicator

Description

Computer name

Name of the computer where the Microsoft Entra Connect agent is installed.

Operating system

Operating system on the computer where the Microsoft Entra Connect agent is installed

Microsoft Entra Connect version

Version of Microsoft Entra Connect that is running.

SQL server name

Name of the database server where the Microsoft Entra Connect database is installed

Database name

Name of the Microsoft Entra database

Database size

Size of the Microsoft Entra Connect database.

Last connectivity test completed

Indicates if the last connectivity test was successful or failed at the time and date shown. The connectivity test runs automatically every 15 minutes.

To view details about the test, click Test Details. You can copy the information to a text file.
Running Connectors

Indicates the date and time when the connectors last ran and if any connectors are currently running. To rerun the connectors, click Refresh.

Synchronization Status

Table 44. Synchronization status indicators

Indicator

Description

Last sync

Indicates the date and time of the last synchronization.

Next sync

Indicates the date and time of the next synchronization.

Allowed sync cycle interval

Displays the minimum amount of time (30 minutes) between synchronization cycles allowed by Microsoft Entra ID.

Effective sync cycle interval

Displays the synchronization cycle schedule currently in effect.

Sync cycle enabled

Indicates if the synchronization cycle is enabled. To disable or enable the synchronization cycle, click Synchronization Settings.

Customized sync cycle interval

Displays the amount of time between synchronization cycles. To set the time interval, click Synchronization Settings.

Next sync cycle policy type

Indicates if the next run will process delta changes (Delta), or run a full import and sync (Initial).

Purge run history interval

Displays the amount of time that operation logs are kept. The default is to keep these logs for 7 days. To set the amount of time to keep the logs, click Maintenance Settings.

Maintenance enabled

Indicates if the maintenance process is enabled. The maintenance process updates the certificates/keys and purges the operations log. To disable or enable maintenance, click Maintenance Settings.

Staging mode enabled

Indicates if staging mode is enabled. If enabled, suppresses exports from running, but import and synchronization still run.

Scheduler suspended

Indicates if the scheduler is blocked from running, which may happen during an upgrade.

Sync cycle in progress

Indicates if the scheduler is running the import, sync, and export processes.

Table 45. Synchronization status options

Option

Description

Start Synchronization

Start the synchronization process.

Synchronization Settings

Enable/disable synchronization. Set the time interval between synchronization cycles.

Maintenance Settings

Enable/disable maintenance. Set the amount of time to keep the operation logs,

View Configuration

View the Microsoft Entra Connect agent configuration. Click Copy to copy the list to the clipboard.

Service Status

Indicates the status of the services that run for Microsoft Entra Connect. You can restart, start, and stop the services. If you restart or start a service, you are asked for credentials.

Connector Statistics

Indicates the number of exports added, updated, and deleted, and the total number of connectors.

Microsoft Entra Connect events

Lists the last five Microsoft Entra Connect warnings and errors and the last five events. To view the events over the last 24 hours, open the Events tab. See Viewing Microsoft Entra Connect events.

相关文档

The document was helpful.

选择评级

I easily found the information I needed.

选择评级