Operations and troubleshooting

How to follow a run of the directory agent: event log, state in Conbool, held runs, missing people and addresses counted twice.

Where a run can be read

On the server every run is written to the event log, with counts of objects read, people taken over and groups synchronised. In Conbool the same run appears under Settings, Directory, Directory agent, along with the time each agent last reported in.

Per person the people view shows the source, the path in the directory, the time it last changed in the directory and, on request, the raw values exactly as the directory delivered them. That view is meant for support cases.

The run wrote nothing

If more than ten percent of the people would disappear, the agent holds the run. Almost always the cause is a scope set too narrowly, a changed filter, or a domain controller that returned only part of the directory at the time of the run. First confirm the people really are gone, then approve.

The agent has written nothing since a change

After every change to the scope the agent runs dry until it is approved. The state is shown on the same page.

A person is missing

Accounts without an email address are not taken over, nor are accounts outside the configured scopes or excluded by the filter. Disabled accounts are not missing, they are kept marked as disabled.

A person is counted twice

If the same address arrives from two sources, for example from Entra ID and from local Active Directory, it counts as one person. If somebody is still counted twice, the secondary addresses are usually missing: without proxyAddresses a second address counts as a person of its own. See Attribute mapping.

Shared mailboxes take seats

Without local Exchange the directory carries no attribute for shared mailboxes. One of the other rules belongs in the scope then, based on a scope or an attribute, otherwise every shared mailbox takes a seat.

The service does not start

preflight names each point separately: reachability, encryption, authentication, read access, replication rights and recycle bin. Missing replication rights are a note, not an error, and the agent then runs without incremental sync.

If an agent never reports in, check the outbound path on port 443 and whether the agent is still valid in Conbool. A revoked agent needs a new join key.