<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Entra Connect &#8211; Miroslav Šraga</title>
	<atom:link href="https://www.sraga.cz/tag/entra-connect/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.sraga.cz</link>
	<description>Sdílím své zkušenosti s Microsoft 365 a Azure</description>
	<lastBuildDate>Sun, 15 Sep 2024 15:13:37 +0000</lastBuildDate>
	<language>cs</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.9</generator>
	<item>
		<title>Entra Troubleshooting: permission-issue error code 8344</title>
		<link>https://www.sraga.cz/entra-troubleshooting-permission-issue-error-code-8344/</link>
					<comments>https://www.sraga.cz/entra-troubleshooting-permission-issue-error-code-8344/#respond</comments>
		
		<dc:creator><![CDATA[Miroslav Šraga]]></dc:creator>
		<pubDate>Sun, 15 Sep 2024 15:10:18 +0000</pubDate>
				<category><![CDATA[Azure AD / Entra ID]]></category>
		<category><![CDATA[AD Sync]]></category>
		<category><![CDATA[Azure AD Connect]]></category>
		<category><![CDATA[Entra Connect]]></category>
		<category><![CDATA[Entra ID]]></category>
		<guid isPermaLink="false">https://www.sraga.cz/?p=766</guid>

					<description><![CDATA[Synchronizační služba Azure AD Connect (Entra AD Connect) nepřenáší (některé) objekty z Active Directory a zobrazuje chybu permission-issue. Po kliknutí na chybu se zobrazí: &#8222;Přístupová práva jsou nedostatečná k provedení operace&#8220; s kódem chyby 8344. Když navíc kliknete na tlačítko &#8222;Log&#8220;, zobrazí se chyba &#8222;Nerozpoznaný formát GUID&#8220;. Proč k tomu dochází a jaké je řešení? ... <a title="Entra Troubleshooting: permission-issue error code 8344" class="read-more" href="https://www.sraga.cz/entra-troubleshooting-permission-issue-error-code-8344/" aria-label="Číst více o Entra Troubleshooting: permission-issue error code 8344">Číst dál</a>]]></description>
										<content:encoded><![CDATA[		<div data-elementor-type="wp-post" data-elementor-id="766" class="elementor elementor-766" data-elementor-post-type="post">
				<div class="elementor-element elementor-element-5233097 e-flex e-con-boxed e-con e-parent" data-id="5233097" data-element_type="container">
					<div class="e-con-inner">
				<div class="elementor-element elementor-element-8a05c3a elementor-widget elementor-widget-text-editor" data-id="8a05c3a" data-element_type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p>Synchronizační služba Azure AD Connect (Entra AD Connect) nepřenáší (některé) objekty z Active Directory a zobrazuje chybu <strong>permission-issue</strong>. Po kliknutí na chybu se zobrazí: &#8222;Přístupová práva jsou nedostatečná k provedení operace&#8220; s kódem chyby 8344. Když navíc kliknete na tlačítko &#8222;Log&#8220;, zobrazí se chyba &#8222;Nerozpoznaný formát GUID&#8220;.</p><p>Proč k tomu dochází a jaké je řešení? V tomto článku se dozvíte, jak opravit chybu Entra/Azure AD Connect permission-issue s kódem 8344.</p>								</div>
				</div>
				<div class="elementor-element elementor-element-8460ad5 elementor-toc--minimized-on-tablet elementor-widget elementor-widget-table-of-contents" data-id="8460ad5" data-element_type="widget" data-settings="{&quot;exclude_headings_by_selector&quot;:[],&quot;headings_by_tags&quot;:[&quot;h2&quot;,&quot;h3&quot;,&quot;h4&quot;,&quot;h5&quot;,&quot;h6&quot;],&quot;marker_view&quot;:&quot;numbers&quot;,&quot;no_headings_message&quot;:&quot;No headings were found on this page.&quot;,&quot;minimize_box&quot;:&quot;yes&quot;,&quot;minimized_on&quot;:&quot;tablet&quot;,&quot;hierarchical_view&quot;:&quot;yes&quot;,&quot;min_height&quot;:{&quot;unit&quot;:&quot;px&quot;,&quot;size&quot;:&quot;&quot;,&quot;sizes&quot;:[]},&quot;min_height_tablet&quot;:{&quot;unit&quot;:&quot;px&quot;,&quot;size&quot;:&quot;&quot;,&quot;sizes&quot;:[]},&quot;min_height_mobile&quot;:{&quot;unit&quot;:&quot;px&quot;,&quot;size&quot;:&quot;&quot;,&quot;sizes&quot;:[]}}" data-widget_type="table-of-contents.default">
				<div class="elementor-widget-container">
									<div class="elementor-toc__header">
						<h4 class="elementor-toc__header-title">
				Obsah			</h4>
										<div class="elementor-toc__toggle-button elementor-toc__toggle-button--expand" role="button" tabindex="0" aria-controls="elementor-toc__8460ad5" aria-expanded="true" aria-label="Open table of contents"><svg aria-hidden="true" class="e-font-icon-svg e-fas-chevron-down" viewBox="0 0 448 512" xmlns="http://www.w3.org/2000/svg"><path d="M207.029 381.476L12.686 187.132c-9.373-9.373-9.373-24.569 0-33.941l22.667-22.667c9.357-9.357 24.522-9.375 33.901-.04L224 284.505l154.745-154.021c9.379-9.335 24.544-9.317 33.901.04l22.667 22.667c9.373 9.373 9.373 24.569 0 33.941L240.971 381.476c-9.373 9.372-24.569 9.372-33.942 0z"></path></svg></div>
				<div class="elementor-toc__toggle-button elementor-toc__toggle-button--collapse" role="button" tabindex="0" aria-controls="elementor-toc__8460ad5" aria-expanded="true" aria-label="Close table of contents"><svg aria-hidden="true" class="e-font-icon-svg e-fas-chevron-up" viewBox="0 0 448 512" xmlns="http://www.w3.org/2000/svg"><path d="M240.971 130.524l194.343 194.343c9.373 9.373 9.373 24.569 0 33.941l-22.667 22.667c-9.357 9.357-24.522 9.375-33.901.04L224 227.495 69.255 381.516c-9.379 9.335-24.544 9.317-33.901-.04l-22.667-22.667c-9.373-9.373-9.373-24.569 0-33.941L207.03 130.525c9.372-9.373 24.568-9.373 33.941-.001z"></path></svg></div>
					</div>
				<div id="elementor-toc__8460ad5" class="elementor-toc__body">
			<div class="elementor-toc__spinner-container">
				<svg class="elementor-toc__spinner eicon-animation-spin e-font-icon-svg e-eicon-loading" aria-hidden="true" viewBox="0 0 1000 1000" xmlns="http://www.w3.org/2000/svg"><path d="M500 975V858C696 858 858 696 858 500S696 142 500 142 142 304 142 500H25C25 237 238 25 500 25S975 237 975 500 763 975 500 975Z"></path></svg>			</div>
		</div>
						</div>
				</div>
				<div class="elementor-element elementor-element-a339a90 elementor-widget elementor-widget-heading" data-id="a339a90" data-element_type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h2 class="elementor-heading-title elementor-size-default">Chyba: permission-issue</h2>				</div>
				</div>
				<div class="elementor-element elementor-element-d9fff9a elementor-alert-info elementor-widget elementor-widget-alert" data-id="d9fff9a" data-element_type="widget" data-widget_type="alert.default">
				<div class="elementor-widget-container">
							<div class="elementor-alert" role="alert">

						<span class="elementor-alert-title">Error: permission-issue</span>
			
						<span class="elementor-alert-description">Connected data source error code: 8344<br />
Connected data source error: Insufficient access rights to perform the operation.</span>
			
			
		</div>
						</div>
				</div>
				<div class="elementor-element elementor-element-c4b1bee elementor-widget elementor-widget-text-editor" data-id="c4b1bee" data-element_type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p>Proč se tato chyba zobrazuje  a jaké je řešení nedostatečných přístupových práv?</p>								</div>
				</div>
				<div class="elementor-element elementor-element-d09ea37 elementor-widget elementor-widget-image" data-id="d09ea37" data-element_type="widget" data-widget_type="image.default">
				<div class="elementor-widget-container">
																<a href="https://www.sraga.cz/wp-content/uploads/2024/09/entra-permission-issue-8344-1.png" data-elementor-open-lightbox="yes" data-elementor-lightbox-title="entra-permission-issue-8344-1" data-e-action-hash="#elementor-action%3Aaction%3Dlightbox%26settings%3DeyJpZCI6NzY4LCJ1cmwiOiJodHRwczpcL1wvd3d3LnNyYWdhLmN6XC93cC1jb250ZW50XC91cGxvYWRzXC8yMDI0XC8wOVwvZW50cmEtcGVybWlzc2lvbi1pc3N1ZS04MzQ0LTEucG5nIn0%3D">
							<img fetchpriority="high" decoding="async" width="768" height="503" src="https://www.sraga.cz/wp-content/uploads/2024/09/entra-permission-issue-8344-1-768x503.png" class="attachment-medium_large size-medium_large wp-image-768" alt="Microsoft Entra Connect permission-issue" srcset="https://www.sraga.cz/wp-content/uploads/2024/09/entra-permission-issue-8344-1-768x503.png 768w, https://www.sraga.cz/wp-content/uploads/2024/09/entra-permission-issue-8344-1-300x196.png 300w, https://www.sraga.cz/wp-content/uploads/2024/09/entra-permission-issue-8344-1.png 802w" sizes="(max-width: 768px) 100vw, 768px" />								</a>
															</div>
				</div>
				<div class="elementor-element elementor-element-e30a979 elementor-widget elementor-widget-image" data-id="e30a979" data-element_type="widget" data-widget_type="image.default">
				<div class="elementor-widget-container">
																<a href="https://www.sraga.cz/wp-content/uploads/2024/09/entra-permission-issue-8344-2.png" data-elementor-open-lightbox="yes" data-elementor-lightbox-title="entra-permission-issue-8344-2" data-e-action-hash="#elementor-action%3Aaction%3Dlightbox%26settings%3DeyJpZCI6NzY5LCJ1cmwiOiJodHRwczpcL1wvd3d3LnNyYWdhLmN6XC93cC1jb250ZW50XC91cGxvYWRzXC8yMDI0XC8wOVwvZW50cmEtcGVybWlzc2lvbi1pc3N1ZS04MzQ0LTIucG5nIn0%3D">
							<img decoding="async" width="662" height="519" src="https://www.sraga.cz/wp-content/uploads/2024/09/entra-permission-issue-8344-2.png" class="attachment-medium_large size-medium_large wp-image-769" alt="entra permission issue 8344 2" srcset="https://www.sraga.cz/wp-content/uploads/2024/09/entra-permission-issue-8344-2.png 662w, https://www.sraga.cz/wp-content/uploads/2024/09/entra-permission-issue-8344-2-300x235.png 300w" sizes="(max-width: 662px) 100vw, 662px">								</a>
															</div>
				</div>
				<div class="elementor-element elementor-element-96fa399 elementor-widget elementor-widget-image" data-id="96fa399" data-element_type="widget" data-widget_type="image.default">
				<div class="elementor-widget-container">
																<a href="https://www.sraga.cz/wp-content/uploads/2024/09/entra-permission-issue-8344-3.png" data-elementor-open-lightbox="yes" data-elementor-lightbox-title="entra-permission-issue-8344-3" data-e-action-hash="#elementor-action%3Aaction%3Dlightbox%26settings%3DeyJpZCI6NzcwLCJ1cmwiOiJodHRwczpcL1wvd3d3LnNyYWdhLmN6XC93cC1jb250ZW50XC91cGxvYWRzXC8yMDI0XC8wOVwvZW50cmEtcGVybWlzc2lvbi1pc3N1ZS04MzQ0LTMucG5nIn0%3D">
							<img decoding="async" width="662" height="520" src="https://www.sraga.cz/wp-content/uploads/2024/09/entra-permission-issue-8344-3.png" class="attachment-medium_large size-medium_large wp-image-770" alt="entra permission issue 8344 3" srcset="https://www.sraga.cz/wp-content/uploads/2024/09/entra-permission-issue-8344-3.png 662w, https://www.sraga.cz/wp-content/uploads/2024/09/entra-permission-issue-8344-3-300x236.png 300w" sizes="(max-width: 662px) 100vw, 662px">								</a>
															</div>
				</div>
				<div class="elementor-element elementor-element-90718c8 elementor-widget elementor-widget-heading" data-id="90718c8" data-element_type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h2 class="elementor-heading-title elementor-size-default">Způsoby řešení chyby 8344 Entra AD Connect</h2>				</div>
				</div>
				<div class="elementor-element elementor-element-e8e4959 elementor-widget elementor-widget-text-editor" data-id="e8e4959" data-element_type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p>Účet konektoru Entra/Azure AD DS nemá k dispozici všechna oprávnění, a proto se v Entra/Azure AD Connect při exportu objektů AD zobrazí chybový kód 8344 permission-issue. Otázkou je, <strong>kde</strong> tato oprávnění chybí.</p>								</div>
				</div>
				<div class="elementor-element elementor-element-af1407a elementor-alert-warning elementor-widget elementor-widget-alert" data-id="af1407a" data-element_type="widget" data-widget_type="alert.default">
				<div class="elementor-widget-container">
							<div class="elementor-alert" role="alert">

						<span class="elementor-alert-title">Pozor</span>
			
						<span class="elementor-alert-description">Entra / Azure AD Connect používá k synchronizaci informací mezi službou Windows Server Active Directory a Entra ID <b>3 účty</b>.<br /><br />

<b>AD DS Connector account:</b> Čtení/zápis informací do služby Windows Server Active Directory<br />
<b>ADSync Service account:</b>  Spuštění synchronizační služby a přístup k databázi SQL<br />
<b>Azure AD Connector account:</b> Zápis informací do služby Entra ID (Azure AD)
</span>
			
			
		</div>
						</div>
				</div>
				<div class="elementor-element elementor-element-513ca1e elementor-widget elementor-widget-heading" data-id="513ca1e" data-element_type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h5 class="elementor-heading-title elementor-size-default">Způsob 1. Nastavení správných oprávnění pro účet konektoru služby AD DS</h5>				</div>
				</div>
				<div class="elementor-element elementor-element-eff8dea elementor-widget elementor-widget-text-editor" data-id="eff8dea" data-element_type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p>1. Spustťe aplikaci &#8222;<strong>Azure AD Connect</strong>&#8222;</p><p>2. Klikněte na tlačítko &#8222;<strong>Konfigurovat</strong>&#8222;</p>								</div>
				</div>
				<div class="elementor-element elementor-element-607b993 elementor-widget elementor-widget-image" data-id="607b993" data-element_type="widget" data-widget_type="image.default">
				<div class="elementor-widget-container">
																<a href="https://www.sraga.cz/wp-content/uploads/2024/09/entra-connect-configure.png" data-elementor-open-lightbox="yes" data-elementor-lightbox-title="entra-connect-configure" data-e-action-hash="#elementor-action%3Aaction%3Dlightbox%26settings%3DeyJpZCI6NzgwLCJ1cmwiOiJodHRwczpcL1wvd3d3LnNyYWdhLmN6XC93cC1jb250ZW50XC91cGxvYWRzXC8yMDI0XC8wOVwvZW50cmEtY29ubmVjdC1jb25maWd1cmUucG5nIn0%3D">
							<img loading="lazy" decoding="async" width="768" height="543" src="https://www.sraga.cz/wp-content/uploads/2024/09/entra-connect-configure-768x543.png" class="attachment-medium_large size-medium_large wp-image-780" alt="Microsoft Entra Connect - konfigurovat" srcset="https://www.sraga.cz/wp-content/uploads/2024/09/entra-connect-configure-768x543.png 768w, https://www.sraga.cz/wp-content/uploads/2024/09/entra-connect-configure-300x212.png 300w, https://www.sraga.cz/wp-content/uploads/2024/09/entra-connect-configure.png 842w" sizes="(max-width: 768px) 100vw, 768px" />								</a>
															</div>
				</div>
				<div class="elementor-element elementor-element-41ad994 elementor-widget elementor-widget-text-editor" data-id="41ad994" data-element_type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p>3. Klikněte na &#8222;<strong>Řešení potíží</strong>&#8222;</p><p>4. Klikněte na tlačítko &#8222;<strong>Další</strong>&#8222;</p>								</div>
				</div>
				<div class="elementor-element elementor-element-7c20661 elementor-widget elementor-widget-image" data-id="7c20661" data-element_type="widget" data-widget_type="image.default">
				<div class="elementor-widget-container">
																<a href="https://www.sraga.cz/wp-content/uploads/2024/09/entra-connect-troubleshooting.png" data-elementor-open-lightbox="yes" data-elementor-lightbox-title="entra-connect-troubleshooting" data-e-action-hash="#elementor-action%3Aaction%3Dlightbox%26settings%3DeyJpZCI6NzgxLCJ1cmwiOiJodHRwczpcL1wvd3d3LnNyYWdhLmN6XC93cC1jb250ZW50XC91cGxvYWRzXC8yMDI0XC8wOVwvZW50cmEtY29ubmVjdC10cm91Ymxlc2hvb3RpbmcucG5nIn0%3D">
							<img loading="lazy" decoding="async" width="844" height="595" src="https://www.sraga.cz/wp-content/uploads/2024/09/entra-connect-troubleshooting.png" class="attachment-large size-large wp-image-781" alt="Microsoft Entra Connect - řešení potíží" srcset="https://www.sraga.cz/wp-content/uploads/2024/09/entra-connect-troubleshooting.png 844w, https://www.sraga.cz/wp-content/uploads/2024/09/entra-connect-troubleshooting-300x211.png 300w, https://www.sraga.cz/wp-content/uploads/2024/09/entra-connect-troubleshooting-768x541.png 768w" sizes="(max-width: 844px) 100vw, 844px" />								</a>
															</div>
				</div>
				<div class="elementor-element elementor-element-1ca7bfb elementor-widget elementor-widget-text-editor" data-id="1ca7bfb" data-element_type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p>5. Klikněte na tlačítko &#8222;<strong>Spustit</strong>&#8222;</p>								</div>
				</div>
				<div class="elementor-element elementor-element-a810bbe elementor-widget elementor-widget-image" data-id="a810bbe" data-element_type="widget" data-widget_type="image.default">
				<div class="elementor-widget-container">
																<a href="https://www.sraga.cz/wp-content/uploads/2024/09/entra-connect-launch.png" data-elementor-open-lightbox="yes" data-elementor-lightbox-title="entra-connect-launch" data-e-action-hash="#elementor-action%3Aaction%3Dlightbox%26settings%3DeyJpZCI6Nzg1LCJ1cmwiOiJodHRwczpcL1wvd3d3LnNyYWdhLmN6XC93cC1jb250ZW50XC91cGxvYWRzXC8yMDI0XC8wOVwvZW50cmEtY29ubmVjdC1sYXVuY2gucG5nIn0%3D">
							<img loading="lazy" decoding="async" width="843" height="594" src="https://www.sraga.cz/wp-content/uploads/2024/09/entra-connect-launch.png" class="attachment-large size-large wp-image-785" alt="Microsoft Entra Connect - spustit" srcset="https://www.sraga.cz/wp-content/uploads/2024/09/entra-connect-launch.png 843w, https://www.sraga.cz/wp-content/uploads/2024/09/entra-connect-launch-300x211.png 300w, https://www.sraga.cz/wp-content/uploads/2024/09/entra-connect-launch-768x541.png 768w" sizes="(max-width: 843px) 100vw, 843px" />								</a>
															</div>
				</div>
				<div class="elementor-element elementor-element-41f1d40 elementor-widget elementor-widget-text-editor" data-id="41f1d40" data-element_type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p>6. Spustí se nové PowerShell okno. V tomto okně <strong>zadejte 4</strong> (Configure AD DS Connector Account Permissions) a stiskněte <strong>Enter</strong></p>								</div>
				</div>
				<div class="elementor-element elementor-element-9e0e2d5 elementor-widget elementor-widget-code-block-for-elementor" data-id="9e0e2d5" data-element_type="widget" data-widget_type="code-block-for-elementor.default">
				<div class="elementor-widget-container">
					<pre class='theme-okaidia' data-show-toolbar='yes'><code class='language-powershell'>----------------------------------------AADConnect Troubleshooting------------------------------------------


        Enter &#039;1&#039; - Troubleshoot Object Synchronization
        Enter &#039;2&#039; - Troubleshoot Password Hash Synchronization
        Enter &#039;3&#039; - Collect General Diagnostics
        Enter &#039;4&#039; - Configure AD DS Connector Account Permissions
        Enter &#039;5&#039; - Test Azure Active Directory Connectivity
        Enter &#039;6&#039; - Test Active Directory Connectivity
        Enter &#039;Q&#039; - Quit


        Please make a selection:</code></pre>				</div>
				</div>
				<div class="elementor-element elementor-element-470ff41 elementor-widget elementor-widget-text-editor" data-id="470ff41" data-element_type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p>7. V dalším okně <strong>zadejte 12</strong> (Set default AD Connector account permissions) a stiskněte <strong>Enter</strong></p>								</div>
				</div>
				<div class="elementor-element elementor-element-92655e8 elementor-widget elementor-widget-code-block-for-elementor" data-id="92655e8" data-element_type="widget" data-widget_type="code-block-for-elementor.default">
				<div class="elementor-widget-container">
					<pre class='theme-okaidia' data-show-toolbar='yes'><code class='language-powershell'>--------------------------------------------Configure Permissions------------------------------------------


        Enter &#039;1&#039; - Get AD Connector account
        Enter &#039;2&#039; - Get objects with inheritance disabled
        Enter &#039;3&#039; - Set basic read permissions
        Enter &#039;4&#039; - Set Exchange Hybrid permissions
        Enter &#039;5&#039; - Set Exchange mail public folder permissions
        Enter &#039;6&#039; - Set MS-DS-Consistency-Guid permissions
        Enter &#039;7&#039; - Set password hash sync permissions
        Enter &#039;8&#039; - Set password writeback permissions
        Enter &#039;9&#039; - Set restricted permissions
        Enter &#039;10&#039; - Set unified group writeback permissions
        Enter &#039;11&#039; - Show AD object permissions
        Enter &#039;12&#039; - Set default AD Connector account permissions
        Enter &#039;13&#039; - Compare object read permissions when running in context of AD Connector account vs Admin account
        Enter &#039;B&#039; - Go back to main troubleshooting menu
        Enter &#039;Q&#039; - Quit


        Please make a selection: </code></pre>				</div>
				</div>
				<div class="elementor-element elementor-element-69f27ac elementor-widget elementor-widget-text-editor" data-id="69f27ac" data-element_type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p>8. V dalším okně potvrďte akci zadáním &#8222;<strong>Y</strong>&#8220; a stiskněte <strong>Enter</strong></p>								</div>
				</div>
				<div class="elementor-element elementor-element-f9846b8 elementor-widget elementor-widget-code-block-for-elementor" data-id="f9846b8" data-element_type="widget" data-widget_type="code-block-for-elementor.default">
				<div class="elementor-widget-container">
					<pre class='theme-okaidia' data-show-toolbar='yes'><code class='language-powershell'>This option will set permissions required for the following:
    Password Hash Sync
    Password Writeback
    Hybrid Exchange
    Exchange Mail Public Folder
    MsDsConsistencyGuid
It will then restrict permissions

Confirm
Would you like to continue with these options?
[Y] Yes  [N] No  [?] Help (default is &quot;Y&quot;): </code></pre>				</div>
				</div>
				<div class="elementor-element elementor-element-db9a8a4 elementor-widget elementor-widget-text-editor" data-id="db9a8a4" data-element_type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p>9. V dalším okně zadejte &#8222;<strong>E</strong>&#8220; (Existing Connector Account) a stiskněte <strong>Enter</strong></p>								</div>
				</div>
				<div class="elementor-element elementor-element-889c68f elementor-widget elementor-widget-code-block-for-elementor" data-id="889c68f" data-element_type="widget" data-widget_type="code-block-for-elementor.default">
				<div class="elementor-widget-container">
					<pre class='theme-okaidia' data-show-toolbar='yes'><code class='language-powershell'>Account to Configure
Would you like to configure an existing connector account or a custom account?
[E] Existing Connector Account  [C] Custom Account  [?] Help (default is &quot;E&quot;): </code></pre>				</div>
				</div>
				<div class="elementor-element elementor-element-9a04691 elementor-widget elementor-widget-text-editor" data-id="9a04691" data-element_type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p>10. V okně se zobrazí název konektoru, forest a účet konektoru</p>								</div>
				</div>
				<div class="elementor-element elementor-element-9f7496b elementor-widget elementor-widget-image" data-id="9f7496b" data-element_type="widget" data-widget_type="image.default">
				<div class="elementor-widget-container">
															<img loading="lazy" decoding="async" width="795" height="148" src="https://www.sraga.cz/wp-content/uploads/2024/09/entra-connect-configured-connectors.png" class="attachment-large size-large wp-image-792" alt="Microsoft Entra Connect - configured connectors" srcset="https://www.sraga.cz/wp-content/uploads/2024/09/entra-connect-configured-connectors.png 795w, https://www.sraga.cz/wp-content/uploads/2024/09/entra-connect-configured-connectors-300x56.png 300w, https://www.sraga.cz/wp-content/uploads/2024/09/entra-connect-configured-connectors-768x143.png 768w" sizes="(max-width: 795px) 100vw, 795px" />															</div>
				</div>
				<div class="elementor-element elementor-element-28a7fd6 elementor-widget elementor-widget-text-editor" data-id="28a7fd6" data-element_type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p>11. Zadejte <strong>název konektoru </strong><em>(viz sloupec</em><strong> ADConnectorName</strong>) a stiskněte <strong>Enter</strong></p>								</div>
				</div>
				<div class="elementor-element elementor-element-9d0a61c elementor-widget elementor-widget-code-block-for-elementor" data-id="9d0a61c" data-element_type="widget" data-widget_type="code-block-for-elementor.default">
				<div class="elementor-widget-container">
					<pre class='theme-okaidia' data-show-toolbar='yes'><code class='language-powershell'>Name of the connector who&#039;s account to configure: xxx.cz</code></pre>				</div>
				</div>
				<div class="elementor-element elementor-element-ec1ff3e elementor-widget elementor-widget-text-editor" data-id="ec1ff3e" data-element_type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p>12. Zobrazí se požadavek na ověření účtem správce. Zadejte účet Administrátora místní domény</p>								</div>
				</div>
				<div class="elementor-element elementor-element-a1de132 elementor-widget elementor-widget-image" data-id="a1de132" data-element_type="widget" data-widget_type="image.default">
				<div class="elementor-widget-container">
																<a href="https://www.sraga.cz/wp-content/uploads/2024/09/entra-connect-credential-request.png" data-elementor-open-lightbox="yes" data-elementor-lightbox-title="entra-connect-credential-request" data-e-action-hash="#elementor-action%3Aaction%3Dlightbox%26settings%3DeyJpZCI6NzkzLCJ1cmwiOiJodHRwczpcL1wvd3d3LnNyYWdhLmN6XC93cC1jb250ZW50XC91cGxvYWRzXC8yMDI0XC8wOVwvZW50cmEtY29ubmVjdC1jcmVkZW50aWFsLXJlcXVlc3QucG5nIn0%3D">
							<img loading="lazy" decoding="async" width="483" height="434" src="https://www.sraga.cz/wp-content/uploads/2024/09/entra-connect-credential-request.png" class="attachment-medium_large size-medium_large wp-image-793" alt="Microsoft Entra Connect - credential request" srcset="https://www.sraga.cz/wp-content/uploads/2024/09/entra-connect-credential-request.png 483w, https://www.sraga.cz/wp-content/uploads/2024/09/entra-connect-credential-request-300x270.png 300w" sizes="(max-width: 483px) 100vw, 483px" />								</a>
															</div>
				</div>
				<div class="elementor-element elementor-element-e9ffce2 elementor-widget elementor-widget-text-editor" data-id="e9ffce2" data-element_type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p>13. Povolte všechny následující požadavky o přidělení oprávnění.  Přidělení oprávnění provedete tak, že u každého dotazu zadáte &#8222;<strong>A</strong>&#8220; a stisknete <strong>Enter</strong>.</p><ol><li>Grant Password Hash Synchronization permissions</li><li>Grant Password Writeback permissions</li><li>Grant Password Writeback permission for Unexpire Password extended right</li><li>Grant Exchange Hybrid permissions</li><li>Grant Exchange Mail Public Folder permissions</li><li>Grant mS-DS-ConsistencyGuid permissions</li><li>Set restricted permissions</li></ol>								</div>
				</div>
				<div class="elementor-element elementor-element-ac50bea elementor-widget elementor-widget-image" data-id="ac50bea" data-element_type="widget" data-widget_type="image.default">
				<div class="elementor-widget-container">
																<a href="https://www.sraga.cz/wp-content/uploads/2024/09/entra-connect-grant-permissions.png" data-elementor-open-lightbox="yes" data-elementor-lightbox-title="entra-connect-grant-permissions" data-e-action-hash="#elementor-action%3Aaction%3Dlightbox%26settings%3DeyJpZCI6Nzk3LCJ1cmwiOiJodHRwczpcL1wvd3d3LnNyYWdhLmN6XC93cC1jb250ZW50XC91cGxvYWRzXC8yMDI0XC8wOVwvZW50cmEtY29ubmVjdC1ncmFudC1wZXJtaXNzaW9ucy5wbmcifQ%3D%3D">
							<img loading="lazy" decoding="async" width="768" height="62" src="https://www.sraga.cz/wp-content/uploads/2024/09/entra-connect-grant-permissions-768x62.png" class="attachment-medium_large size-medium_large wp-image-797" alt="Microsoft Entra Connect - grant permissions" srcset="https://www.sraga.cz/wp-content/uploads/2024/09/entra-connect-grant-permissions-768x62.png 768w, https://www.sraga.cz/wp-content/uploads/2024/09/entra-connect-grant-permissions-300x24.png 300w, https://www.sraga.cz/wp-content/uploads/2024/09/entra-connect-grant-permissions.png 936w" sizes="(max-width: 768px) 100vw, 768px" />								</a>
															</div>
				</div>
				<div class="elementor-element elementor-element-013ab55 elementor-widget elementor-widget-text-editor" data-id="013ab55" data-element_type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p>14. Pokud jste potvrdili přidělení oprávnění ve všech 7 krocích, zavřete okno PowerShell a také okno Entra/Azure AD Connect</p><p>15. Spusťe PowerShell s zadejte příkaz pro <a href="https://www.sraga.cz/uzitecne-prikazy-pro-azure-ad-connect-entra-connect/" target="_blank" rel="noopener">plnou (iniciání) synchronizaci</a></p><p> </p>								</div>
				</div>
				<div class="elementor-element elementor-element-be9098e elementor-widget elementor-widget-code-block-for-elementor" data-id="be9098e" data-element_type="widget" data-widget_type="code-block-for-elementor.default">
				<div class="elementor-widget-container">
					<pre class='line-numbers theme-okaidia' data-show-toolbar='yes'><code class='language-powershell'>Start-ADSyncSyncCycle -PolicyType Initial</code></pre>				</div>
				</div>
				<div class="elementor-element elementor-element-48f4aa3 elementor-widget elementor-widget-text-editor" data-id="48f4aa3" data-element_type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p>16. Počkejte několik minut, než bude synchronizace dokončena.</p><p>17. Znovu spusťte &#8222;AD Connect Synchronization Service&#8220; a zkontrolujte, zda-li se chyba &#8222;permission-issue&#8220; stále opakuje, nebo byla vyřešena.</p><p>Pokud se chyba stále opakuje, pokračujde dál v tomto návodu.</p>								</div>
				</div>
				<div class="elementor-element elementor-element-bda8112 elementor-widget elementor-widget-heading" data-id="bda8112" data-element_type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h5 class="elementor-heading-title elementor-size-default">Způsob 2. msDS-KeyCredentialLink</h5>				</div>
				</div>
				<div class="elementor-element elementor-element-fe14ebb elementor-widget elementor-widget-text-editor" data-id="fe14ebb" data-element_type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p>V některých případech se mi stalo, že chyba &#8222;permission-issue&#8220; se vyskytovala jen u těch uživatelů, kterým se změnila hodnota Active Directory atributu <strong>msDS-KeyCredentialLink.</strong></p>								</div>
				</div>
				<div class="elementor-element elementor-element-ac0311b elementor-alert-info elementor-widget elementor-widget-alert" data-id="ac0311b" data-element_type="widget" data-widget_type="alert.default">
				<div class="elementor-widget-container">
							<div class="elementor-alert" role="alert">

						<span class="elementor-alert-title">Atribut msDS-KeyCredentialLink</span>
			
						<span class="elementor-alert-description"> se v Active Directory používá k ukládání pověření veřejného klíče přidruženého k objektu počítače nebo uživatele. Tento atribut je důležitý zejména pro scénáře zahrnující Windows Hello for Business a další metody ověřování založené na veřejných klíčích.</span>
			
			
		</div>
						</div>
				</div>
				<div class="elementor-element elementor-element-196e573 elementor-widget elementor-widget-image" data-id="196e573" data-element_type="widget" data-widget_type="image.default">
				<div class="elementor-widget-container">
																<a href="https://www.sraga.cz/wp-content/uploads/2024/09/entra-connect-msDS-KeyCredentialLink.png" data-elementor-open-lightbox="yes" data-elementor-lightbox-title="entra-connect-msDS-KeyCredentialLink" data-e-action-hash="#elementor-action%3Aaction%3Dlightbox%26settings%3DeyJpZCI6ODAxLCJ1cmwiOiJodHRwczpcL1wvd3d3LnNyYWdhLmN6XC93cC1jb250ZW50XC91cGxvYWRzXC8yMDI0XC8wOVwvZW50cmEtY29ubmVjdC1tc0RTLUtleUNyZWRlbnRpYWxMaW5rLnBuZyJ9">
							<img loading="lazy" decoding="async" width="658" height="519" src="https://www.sraga.cz/wp-content/uploads/2024/09/entra-connect-msDS-KeyCredentialLink.png" class="attachment-medium_large size-medium_large wp-image-801" alt="Microsoft Entra Connect - msDS-KeyCredentialLink" srcset="https://www.sraga.cz/wp-content/uploads/2024/09/entra-connect-msDS-KeyCredentialLink.png 658w, https://www.sraga.cz/wp-content/uploads/2024/09/entra-connect-msDS-KeyCredentialLink-300x237.png 300w" sizes="(max-width: 658px) 100vw, 658px" />								</a>
															</div>
				</div>
				<div class="elementor-element elementor-element-a03b1e1 elementor-alert-danger elementor-widget elementor-widget-alert" data-id="a03b1e1" data-element_type="widget" data-widget_type="alert.default">
				<div class="elementor-widget-container">
							<div class="elementor-alert" role="alert">

						<span class="elementor-alert-title">Upozornění</span>
			
						<span class="elementor-alert-description">Funkce Windows Hello pro firmy je vázána mezi uživatelem a zařízením. Uživatel i zařízení musí být synchronizovány mezi Microsoft Entra ID a Active Directory. Zpětný zápis zařízení se používá k aktualizaci atributu msDS-KeyCredentialLink na objektu počítače.</span>
			
			
		</div>
						</div>
				</div>
				<div class="elementor-element elementor-element-55985af elementor-widget elementor-widget-text-editor" data-id="55985af" data-element_type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p>V případě, že používáte <strong>zpětný zápis</strong> do Active Directory (Writeback), může <a href="https://learn.microsoft.com/en-us/windows/security/identity-protection/hello-for-business/deploy/hybrid-cert-trust" target="_blank" rel="noopener">problém vyřešit</a>, když účet AADSync přidáte do skupiny &#8222;<strong>Enterprise Key Admins</strong>&#8222;.</p><p><strong>Relevantní zdroje:</strong></p><ul><li><a href="https://learn.microsoft.com/en-us/windows/security/identity-protection/hello-for-business/deploy/hybrid-cert-trust" target="_blank" rel="noopener">https://learn.microsoft.com/en-us/windows/security/identity-protection/hello-for-business/deploy/hybrid-cert-trust</a></li><li><a href="https://learn.microsoft.com/en-us/windows/security/identity-protection/hello-for-business/hello-hybrid-aadj-sso" target="_blank" rel="noopener">https://learn.microsoft.com/en-us/windows/security/identity-protection/hello-for-business/hello-hybrid-aadj-sso</a></li><li><a href="https://learn.microsoft.com/en-us/openspecs/windows_protocols/ms-adts/f70afbcc-780e-4d91-850c-cfadce5bb15c" target="_blank" rel="noopener">https://learn.microsoft.com/en-us/openspecs/windows_protocols/ms-adts/f70afbcc-780e-4d91-850c-cfadce5bb15c</a></li></ul>								</div>
				</div>
				<div class="elementor-element elementor-element-0019a73 elementor-widget elementor-widget-image" data-id="0019a73" data-element_type="widget" data-widget_type="image.default">
				<div class="elementor-widget-container">
																<a href="https://www.sraga.cz/wp-content/uploads/2024/09/entra-connect-enterprise-admin-keys.png" data-elementor-open-lightbox="yes" data-elementor-lightbox-title="entra-connect-enterprise-admin-keys" data-e-action-hash="#elementor-action%3Aaction%3Dlightbox%26settings%3DeyJpZCI6ODA4LCJ1cmwiOiJodHRwczpcL1wvd3d3LnNyYWdhLmN6XC93cC1jb250ZW50XC91cGxvYWRzXC8yMDI0XC8wOVwvZW50cmEtY29ubmVjdC1lbnRlcnByaXNlLWFkbWluLWtleXMucG5nIn0%3D">
							<img loading="lazy" decoding="async" width="495" height="492" src="https://www.sraga.cz/wp-content/uploads/2024/09/entra-connect-enterprise-admin-keys.png" class="attachment-medium_large size-medium_large wp-image-808" alt="Microsoft Entra Connect - Enterprise Admin Keys" srcset="https://www.sraga.cz/wp-content/uploads/2024/09/entra-connect-enterprise-admin-keys.png 495w, https://www.sraga.cz/wp-content/uploads/2024/09/entra-connect-enterprise-admin-keys-300x298.png 300w, https://www.sraga.cz/wp-content/uploads/2024/09/entra-connect-enterprise-admin-keys-150x150.png 150w" sizes="(max-width: 495px) 100vw, 495px" />								</a>
															</div>
				</div>
				<div class="elementor-element elementor-element-464372d elementor-alert-warning elementor-widget elementor-widget-alert" data-id="464372d" data-element_type="widget" data-widget_type="alert.default">
				<div class="elementor-widget-container">
							<div class="elementor-alert" role="alert">

						<span class="elementor-alert-title">Upozornění</span>
			
						<span class="elementor-alert-description">V internetových diskusích najdete doporučení přidat účet konektoru (MSOL_xxx) do AD skupiny Administrators. Toto řešení může být funkční, avšak do zbytečného přidělování takto vysokých oprávnění bych se nepouštěl.</span>
			
						<button type="button" class="elementor-alert-dismiss" aria-label="Zavřít toto upozornění.">
									<span aria-hidden="true">&times;</span>
							</button>
			
		</div>
						</div>
				</div>
				<div class="elementor-element elementor-element-62305d0 elementor-widget elementor-widget-text-editor" data-id="62305d0" data-element_type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p>Po nastavení oprávnění znovu spusťte synchronizaci.</p>								</div>
				</div>
				<div class="elementor-element elementor-element-5c9fbfa elementor-widget elementor-widget-code-block-for-elementor" data-id="5c9fbfa" data-element_type="widget" data-widget_type="code-block-for-elementor.default">
				<div class="elementor-widget-container">
					<pre class='line-numbers theme-okaidia' data-show-toolbar='yes'><code class='language-powershell'>Start-ADSyncSyncCycle -PolicyType Initial</code></pre>				</div>
				</div>
				<div class="elementor-element elementor-element-ab3ba60 elementor-widget elementor-widget-heading" data-id="ab3ba60" data-element_type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h5 class="elementor-heading-title elementor-size-default">Způsob 3. Udělení individuálních oprávnění</h5>				</div>
				</div>
				<div class="elementor-element elementor-element-ddb1adc elementor-widget elementor-widget-text-editor" data-id="ddb1adc" data-element_type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p>Setkal jsem se případy, kdy byl (po nespecifikovaném zásahu do Active Directory) <strong>znemožněn přístup</strong> k některým objektům z důvodu <strong>chybějícího oprávnění</strong> (opravdu <strong>per</strong> AD <strong>objekt</strong>). Viděl jsem to zejména v případech, kdy došlo k <a href="https://www.sraga.cz/entra-ad-connect-presun-na-novy-server/" target="_blank" rel="noopener">re-instalaci</a> nebo <a href="https://www.sraga.cz/entra-ad-sync-in-place-upgrade-health-agent/" target="_blank" rel="noopener">aktualizaci Entra Connect</a> a byl znovu vytvořen další účet pro synchrnonizaci (MSOL_xxx).</p><p>V takovém případě postupujte následujícím způsobem:</p><p>1. Spusťte &#8222;<strong>Entra/Azure AD Connect</strong>&#8222;</p><p>2. Klikněte na tlačítko &#8222;<strong>Konfigurovat</strong>&#8222;</p>								</div>
				</div>
				<div class="elementor-element elementor-element-5cc1788 elementor-widget elementor-widget-image" data-id="5cc1788" data-element_type="widget" data-widget_type="image.default">
				<div class="elementor-widget-container">
																<a href="https://www.sraga.cz/wp-content/uploads/2024/09/entra-connect-configure.png" data-elementor-open-lightbox="yes" data-elementor-lightbox-title="entra-connect-configure" data-e-action-hash="#elementor-action%3Aaction%3Dlightbox%26settings%3DeyJpZCI6NzgwLCJ1cmwiOiJodHRwczpcL1wvd3d3LnNyYWdhLmN6XC93cC1jb250ZW50XC91cGxvYWRzXC8yMDI0XC8wOVwvZW50cmEtY29ubmVjdC1jb25maWd1cmUucG5nIn0%3D">
							<img loading="lazy" decoding="async" width="768" height="543" src="https://www.sraga.cz/wp-content/uploads/2024/09/entra-connect-configure-768x543.png" class="attachment-medium_large size-medium_large wp-image-780" alt="Microsoft Entra Connect - konfigurovat" srcset="https://www.sraga.cz/wp-content/uploads/2024/09/entra-connect-configure-768x543.png 768w, https://www.sraga.cz/wp-content/uploads/2024/09/entra-connect-configure-300x212.png 300w, https://www.sraga.cz/wp-content/uploads/2024/09/entra-connect-configure.png 842w" sizes="(max-width: 768px) 100vw, 768px" />								</a>
															</div>
				</div>
				<div class="elementor-element elementor-element-49241c0 elementor-widget elementor-widget-text-editor" data-id="49241c0" data-element_type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p>3. Vyberte možnost &#8222;<strong>Zobrazit nebo exportovat aktuální konfiguraci</strong>&#8220; a klikněte na tlačítko &#8222;<strong>Další</strong>&#8222;</p>								</div>
				</div>
				<div class="elementor-element elementor-element-b70a554 elementor-widget elementor-widget-image" data-id="b70a554" data-element_type="widget" data-widget_type="image.default">
				<div class="elementor-widget-container">
																<a href="https://www.sraga.cz/wp-content/uploads/2024/09/entra-connect-current-config.png" data-elementor-open-lightbox="yes" data-elementor-lightbox-title="entra-connect-current-config" data-e-action-hash="#elementor-action%3Aaction%3Dlightbox%26settings%3DeyJpZCI6ODI0LCJ1cmwiOiJodHRwczpcL1wvd3d3LnNyYWdhLmN6XC93cC1jb250ZW50XC91cGxvYWRzXC8yMDI0XC8wOVwvZW50cmEtY29ubmVjdC1jdXJyZW50LWNvbmZpZy5wbmcifQ%3D%3D">
							<img loading="lazy" decoding="async" width="768" height="542" src="https://www.sraga.cz/wp-content/uploads/2024/09/entra-connect-current-config-768x542.png" class="attachment-medium_large size-medium_large wp-image-824" alt="Microsoft Entra Connect - aktuální konfigurace" srcset="https://www.sraga.cz/wp-content/uploads/2024/09/entra-connect-current-config-768x542.png 768w, https://www.sraga.cz/wp-content/uploads/2024/09/entra-connect-current-config-300x212.png 300w, https://www.sraga.cz/wp-content/uploads/2024/09/entra-connect-current-config.png 845w" sizes="(max-width: 768px) 100vw, 768px" />								</a>
															</div>
				</div>
				<div class="elementor-element elementor-element-b7e374f elementor-widget elementor-widget-text-editor" data-id="b7e374f" data-element_type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p>4. Podívejte se, pod jakým účtem se spouští konektor a tento účet si zapamatujte nebo poznačte</p>								</div>
				</div>
				<div class="elementor-element elementor-element-7f65012 elementor-widget elementor-widget-image" data-id="7f65012" data-element_type="widget" data-widget_type="image.default">
				<div class="elementor-widget-container">
																<a href="https://www.sraga.cz/wp-content/uploads/2024/09/entra-connect-current-config-account.png" data-elementor-open-lightbox="yes" data-elementor-lightbox-title="entra-connect-current-config-account" data-e-action-hash="#elementor-action%3Aaction%3Dlightbox%26settings%3DeyJpZCI6ODI4LCJ1cmwiOiJodHRwczpcL1wvd3d3LnNyYWdhLmN6XC93cC1jb250ZW50XC91cGxvYWRzXC8yMDI0XC8wOVwvZW50cmEtY29ubmVjdC1jdXJyZW50LWNvbmZpZy1hY2NvdW50LnBuZyJ9">
							<img loading="lazy" decoding="async" width="768" height="542" src="https://www.sraga.cz/wp-content/uploads/2024/09/entra-connect-current-config-account-768x542.png" class="attachment-medium_large size-medium_large wp-image-828" alt="entra connect current config account" srcset="https://www.sraga.cz/wp-content/uploads/2024/09/entra-connect-current-config-account-768x542.png 768w, https://www.sraga.cz/wp-content/uploads/2024/09/entra-connect-current-config-account-300x212.png 300w, https://www.sraga.cz/wp-content/uploads/2024/09/entra-connect-current-config-account.png 844w" sizes="(max-width: 768px) 100vw, 768px">								</a>
															</div>
				</div>
				<div class="elementor-element elementor-element-dccf4fe elementor-widget elementor-widget-text-editor" data-id="dccf4fe" data-element_type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p>5. Okno Entra Connect zavřete kliknutím na tlačítko &#8222;<strong>Konec</strong>&#8222;</p><p>6. Otevřete si &#8222;Active Directory Users and Coputers / <strong>Uživatelé a počítače služby Active Directory</strong>&#8222;</p><p>7. Klikněte na menu &#8222;<strong>Zobrazit</strong>&#8220; a aktivujte volbu &#8222;<strong>Upřesňující funkce</strong>&#8222;</p>								</div>
				</div>
				<div class="elementor-element elementor-element-bdbbf3d elementor-widget elementor-widget-image" data-id="bdbbf3d" data-element_type="widget" data-widget_type="image.default">
				<div class="elementor-widget-container">
																<a href="https://www.sraga.cz/wp-content/uploads/2024/09/aduc-advanced-features.png" data-elementor-open-lightbox="yes" data-elementor-lightbox-title="aduc-advanced-features" data-e-action-hash="#elementor-action%3Aaction%3Dlightbox%26settings%3DeyJpZCI6ODQxLCJ1cmwiOiJodHRwczpcL1wvd3d3LnNyYWdhLmN6XC93cC1jb250ZW50XC91cGxvYWRzXC8yMDI0XC8wOVwvYWR1Yy1hZHZhbmNlZC1mZWF0dXJlcy5wbmcifQ%3D%3D">
							<img loading="lazy" decoding="async" width="505" height="413" src="https://www.sraga.cz/wp-content/uploads/2024/09/aduc-advanced-features.png" class="attachment-medium_large size-medium_large wp-image-841" alt="ADUC Advanced features" srcset="https://www.sraga.cz/wp-content/uploads/2024/09/aduc-advanced-features.png 505w, https://www.sraga.cz/wp-content/uploads/2024/09/aduc-advanced-features-300x245.png 300w" sizes="(max-width: 505px) 100vw, 505px" />								</a>
															</div>
				</div>
				<div class="elementor-element elementor-element-bb59bde elementor-widget elementor-widget-text-editor" data-id="bb59bde" data-element_type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p>8. Najděte objekt (uživatele), u kterého se zobrazuje chyba 8344 permission-issue a rozklikněte jeho vlastnosti</p><p>9. Přejděte na kartu &#8222;<strong>Zabezpečení</strong>&#8222;</p><p>10. Zkontrolujte, jaké účty <strong>MSOL_xxx</strong> mají oprávnění na objekt uživatele a zkontrolujte, zda-li je přidělen správný účet. <strong>Ověřte</strong>, zda-li je zde <strong>uveden účet</strong>, který jste si poznačili v kroku 4.</p>								</div>
				</div>
				<div class="elementor-element elementor-element-48bef7a elementor-widget elementor-widget-image" data-id="48bef7a" data-element_type="widget" data-widget_type="image.default">
				<div class="elementor-widget-container">
																<a href="https://www.sraga.cz/wp-content/uploads/2024/09/aduc-user-security.png" data-elementor-open-lightbox="yes" data-elementor-lightbox-title="aduc-user-security" data-e-action-hash="#elementor-action%3Aaction%3Dlightbox%26settings%3DeyJpZCI6ODQ4LCJ1cmwiOiJodHRwczpcL1wvd3d3LnNyYWdhLmN6XC93cC1jb250ZW50XC91cGxvYWRzXC8yMDI0XC8wOVwvYWR1Yy11c2VyLXNlY3VyaXR5LnBuZyJ9">
							<img loading="lazy" decoding="async" width="395" height="533" src="https://www.sraga.cz/wp-content/uploads/2024/09/aduc-user-security.png" class="attachment-medium_large size-medium_large wp-image-848" alt="ADUS - User - security - permissions" srcset="https://www.sraga.cz/wp-content/uploads/2024/09/aduc-user-security.png 395w, https://www.sraga.cz/wp-content/uploads/2024/09/aduc-user-security-222x300.png 222w" sizes="(max-width: 395px) 100vw, 395px" />								</a>
															</div>
				</div>
				<div class="elementor-element elementor-element-436c3e5 elementor-widget elementor-widget-text-editor" data-id="436c3e5" data-element_type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p>11. Klikněte na tlačítko &#8222;<strong>Přidat</strong>&#8222;</p><p>12. Do pole &#8222;<strong>Název objektu</strong>&#8220; zadejte &#8222;<strong>MSOL</strong>&#8222;</p><p>13. klikněte na tlačítko &#8222;<strong>Kontrola názvů</strong>&#8222;</p>								</div>
				</div>
				<div class="elementor-element elementor-element-e8394a1 elementor-widget elementor-widget-image" data-id="e8394a1" data-element_type="widget" data-widget_type="image.default">
				<div class="elementor-widget-container">
																<a href="https://www.sraga.cz/wp-content/uploads/2024/09/aduc-user-security-add.png" data-elementor-open-lightbox="yes" data-elementor-lightbox-title="aduc-user-security-add" data-e-action-hash="#elementor-action%3Aaction%3Dlightbox%26settings%3DeyJpZCI6ODQ5LCJ1cmwiOiJodHRwczpcL1wvd3d3LnNyYWdhLmN6XC93cC1jb250ZW50XC91cGxvYWRzXC8yMDI0XC8wOVwvYWR1Yy11c2VyLXNlY3VyaXR5LWFkZC5wbmcifQ%3D%3D">
							<img loading="lazy" decoding="async" width="449" height="546" src="https://www.sraga.cz/wp-content/uploads/2024/09/aduc-user-security-add.png" class="attachment-medium_large size-medium_large wp-image-849" alt="ADUS - User - security - permissions" srcset="https://www.sraga.cz/wp-content/uploads/2024/09/aduc-user-security-add.png 449w, https://www.sraga.cz/wp-content/uploads/2024/09/aduc-user-security-add-247x300.png 247w" sizes="(max-width: 449px) 100vw, 449px" />								</a>
															</div>
				</div>
				<div class="elementor-element elementor-element-f4b42bb elementor-widget elementor-widget-text-editor" data-id="f4b42bb" data-element_type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p>14. Pokud se zobrazí <strong>okno s více účty</strong>, znamená to, že při re-instalaci nebo aktualizaci došlo k vytvoření dalšího účtu. vybere účet, který jste si poznamenali v kroku 4</p><p>15. Klikněte na tlačítko &#8222;<strong>OK</strong>&#8222;</p><p>16. Volbu opět potvrďte kliknutím na tlačítko &#8222;<strong>OK</strong>&#8222;</p>								</div>
				</div>
				<div class="elementor-element elementor-element-beef2e7 elementor-widget elementor-widget-image" data-id="beef2e7" data-element_type="widget" data-widget_type="image.default">
				<div class="elementor-widget-container">
																<a href="https://www.sraga.cz/wp-content/uploads/2024/09/aduc-user-security-add-objects.png" data-elementor-open-lightbox="yes" data-elementor-lightbox-title="aduc-user-security-add-objects" data-e-action-hash="#elementor-action%3Aaction%3Dlightbox%26settings%3DeyJpZCI6ODUzLCJ1cmwiOiJodHRwczpcL1wvd3d3LnNyYWdhLmN6XC93cC1jb250ZW50XC91cGxvYWRzXC8yMDI0XC8wOVwvYWR1Yy11c2VyLXNlY3VyaXR5LWFkZC1vYmplY3RzLnBuZyJ9">
							<img loading="lazy" decoding="async" width="549" height="339" src="https://www.sraga.cz/wp-content/uploads/2024/09/aduc-user-security-add-objects.png" class="attachment-medium_large size-medium_large wp-image-853" alt="ADUS - User - security - permissions" srcset="https://www.sraga.cz/wp-content/uploads/2024/09/aduc-user-security-add-objects.png 549w, https://www.sraga.cz/wp-content/uploads/2024/09/aduc-user-security-add-objects-300x185.png 300w" sizes="(max-width: 549px) 100vw, 549px" />								</a>
															</div>
				</div>
				<div class="elementor-element elementor-element-1afb2ce elementor-widget elementor-widget-text-editor" data-id="1afb2ce" data-element_type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p>17. Oprávnění pro nově přidaný účet nastavte stejně, jak jsou nastavena u původního účtu &#8211; klikněte na tlačítko &#8222;<strong>Upřesnit</strong>&#8222;</p>								</div>
				</div>
				<div class="elementor-element elementor-element-f6d153a elementor-widget elementor-widget-image" data-id="f6d153a" data-element_type="widget" data-widget_type="image.default">
				<div class="elementor-widget-container">
																<a href="https://www.sraga.cz/wp-content/uploads/2024/09/aduc-user-security-advanced.png" data-elementor-open-lightbox="yes" data-elementor-lightbox-title="aduc-user-security-advanced" data-e-action-hash="#elementor-action%3Aaction%3Dlightbox%26settings%3DeyJpZCI6ODU3LCJ1cmwiOiJodHRwczpcL1wvd3d3LnNyYWdhLmN6XC93cC1jb250ZW50XC91cGxvYWRzXC8yMDI0XC8wOVwvYWR1Yy11c2VyLXNlY3VyaXR5LWFkdmFuY2VkLnBuZyJ9">
							<img loading="lazy" decoding="async" width="396" height="534" src="https://www.sraga.cz/wp-content/uploads/2024/09/aduc-user-security-advanced.png" class="attachment-medium_large size-medium_large wp-image-857" alt="aduc-user-security-add-objects" srcset="https://www.sraga.cz/wp-content/uploads/2024/09/aduc-user-security-advanced.png 396w, https://www.sraga.cz/wp-content/uploads/2024/09/aduc-user-security-advanced-222x300.png 222w" sizes="(max-width: 396px) 100vw, 396px" />								</a>
															</div>
				</div>
				<div class="elementor-element elementor-element-09268c0 elementor-widget elementor-widget-text-editor" data-id="09268c0" data-element_type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p>18. <strong>Vyberte</strong> jakýkoliv <strong>záznam</strong>, který odpovídá <strong>účtu</strong> z kroku 4 (MSOL_xxx) a klikněte na tlačítko &#8222;<strong>Upravit</strong>&#8222;</p>								</div>
				</div>
				<div class="elementor-element elementor-element-adf1ed6 elementor-widget elementor-widget-image" data-id="adf1ed6" data-element_type="widget" data-widget_type="image.default">
				<div class="elementor-widget-container">
																<a href="https://www.sraga.cz/wp-content/uploads/2024/09/aduc-user-security-advanced-edit.png" data-elementor-open-lightbox="yes" data-elementor-lightbox-title="aduc-user-security-advanced-edit" data-e-action-hash="#elementor-action%3Aaction%3Dlightbox%26settings%3DeyJpZCI6ODU4LCJ1cmwiOiJodHRwczpcL1wvd3d3LnNyYWdhLmN6XC93cC1jb250ZW50XC91cGxvYWRzXC8yMDI0XC8wOVwvYWR1Yy11c2VyLXNlY3VyaXR5LWFkdmFuY2VkLWVkaXQucG5nIn0%3D">
							<img loading="lazy" decoding="async" width="738" height="502" src="https://www.sraga.cz/wp-content/uploads/2024/09/aduc-user-security-advanced-edit.png" class="attachment-medium_large size-medium_large wp-image-858" alt="ADUC - User - security - permissions" srcset="https://www.sraga.cz/wp-content/uploads/2024/09/aduc-user-security-advanced-edit.png 738w, https://www.sraga.cz/wp-content/uploads/2024/09/aduc-user-security-advanced-edit-300x204.png 300w" sizes="(max-width: 738px) 100vw, 738px" />								</a>
															</div>
				</div>
				<div class="elementor-element elementor-element-bcdbfb6 elementor-widget elementor-widget-text-editor" data-id="bcdbfb6" data-element_type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p>19. V následujícím okne vyberte tato oprávnění:</p><ul><li>Read all properties</li><li>Write all properties</li><li>Read msDS-OperationsForAzTaskBL</li><li>Read msDS-parentdistname</li></ul><p>20. Nastavení potvrďte kliknutím na tlačítko &#8222;<strong>OK</strong>&#8222;</p><p>21. Vlastnosti uživatele také zavřete kliknutím na tlačítko &#8222;<strong>OK</strong>&#8222;</p>								</div>
				</div>
				<div class="elementor-element elementor-element-1e9c2d7 elementor-widget elementor-widget-image" data-id="1e9c2d7" data-element_type="widget" data-widget_type="image.default">
				<div class="elementor-widget-container">
																<a href="https://www.sraga.cz/wp-content/uploads/2024/09/permission-entry-dialog-box.png" data-elementor-open-lightbox="yes" data-elementor-lightbox-title="permission-entry-dialog-box" data-e-action-hash="#elementor-action%3Aaction%3Dlightbox%26settings%3DeyJpZCI6ODYzLCJ1cmwiOiJodHRwczpcL1wvd3d3LnNyYWdhLmN6XC93cC1jb250ZW50XC91cGxvYWRzXC8yMDI0XC8wOVwvcGVybWlzc2lvbi1lbnRyeS1kaWFsb2ctYm94LnBuZyJ9">
							<img loading="lazy" decoding="async" width="768" height="500" src="https://www.sraga.cz/wp-content/uploads/2024/09/permission-entry-dialog-box-768x500.png" class="attachment-medium_large size-medium_large wp-image-863" alt="permission entry dialog box" srcset="https://www.sraga.cz/wp-content/uploads/2024/09/permission-entry-dialog-box-768x500.png 768w, https://www.sraga.cz/wp-content/uploads/2024/09/permission-entry-dialog-box-300x195.png 300w, https://www.sraga.cz/wp-content/uploads/2024/09/permission-entry-dialog-box.png 926w" sizes="(max-width: 768px) 100vw, 768px">								</a>
															</div>
				</div>
				<div class="elementor-element elementor-element-4b4ab12 elementor-widget elementor-widget-image" data-id="4b4ab12" data-element_type="widget" data-widget_type="image.default">
				<div class="elementor-widget-container">
																<a href="https://www.sraga.cz/wp-content/uploads/2024/09/permission-entry-dialog-box-2.png" data-elementor-open-lightbox="yes" data-elementor-lightbox-title="permission-entry-dialog-box-2" data-e-action-hash="#elementor-action%3Aaction%3Dlightbox%26settings%3DeyJpZCI6ODYyLCJ1cmwiOiJodHRwczpcL1wvd3d3LnNyYWdhLmN6XC93cC1jb250ZW50XC91cGxvYWRzXC8yMDI0XC8wOVwvcGVybWlzc2lvbi1lbnRyeS1kaWFsb2ctYm94LTIucG5nIn0%3D">
							<img loading="lazy" decoding="async" width="768" height="494" src="https://www.sraga.cz/wp-content/uploads/2024/09/permission-entry-dialog-box-2-768x494.png" class="attachment-medium_large size-medium_large wp-image-862" alt="ADUC - User - security - permissions" srcset="https://www.sraga.cz/wp-content/uploads/2024/09/permission-entry-dialog-box-2-768x494.png 768w, https://www.sraga.cz/wp-content/uploads/2024/09/permission-entry-dialog-box-2-300x193.png 300w, https://www.sraga.cz/wp-content/uploads/2024/09/permission-entry-dialog-box-2.png 880w" sizes="(max-width: 768px) 100vw, 768px" />								</a>
															</div>
				</div>
				<div class="elementor-element elementor-element-cd5810a elementor-widget elementor-widget-text-editor" data-id="cd5810a" data-element_type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p>22. Po nastavení oprávnění znovu spusťte synchronizaci.</p>								</div>
				</div>
				<div class="elementor-element elementor-element-2818c58 elementor-widget elementor-widget-code-block-for-elementor" data-id="2818c58" data-element_type="widget" data-widget_type="code-block-for-elementor.default">
				<div class="elementor-widget-container">
					<pre class='line-numbers theme-okaidia' data-show-toolbar='yes'><code class='language-powershell'>Start-ADSyncSyncCycle -PolicyType Initial</code></pre>				</div>
				</div>
				<div class="elementor-element elementor-element-63bc012 elementor-widget elementor-widget-text-editor" data-id="63bc012" data-element_type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p>23. Počkejte několik minut, než bude synchronizace dokončena.</p><p>24. Znovu spusťte &#8222;AD Connect Synchronization Service&#8220; a zkontrolujte, zda-li se chyba &#8222;permission-issue&#8220; stále opakuje, nebo byla vyřešena.</p>								</div>
				</div>
				<div class="elementor-element elementor-element-a89be82 elementor-widget elementor-widget-image" data-id="a89be82" data-element_type="widget" data-widget_type="image.default">
				<div class="elementor-widget-container">
																<a href="https://www.sraga.cz/wp-content/uploads/2024/09/entra-no-issue.png" data-elementor-open-lightbox="yes" data-elementor-lightbox-title="entra-no-issue" data-e-action-hash="#elementor-action%3Aaction%3Dlightbox%26settings%3DeyJpZCI6ODY0LCJ1cmwiOiJodHRwczpcL1wvd3d3LnNyYWdhLmN6XC93cC1jb250ZW50XC91cGxvYWRzXC8yMDI0XC8wOVwvZW50cmEtbm8taXNzdWUucG5nIn0%3D">
							<img loading="lazy" decoding="async" width="768" height="379" src="https://www.sraga.cz/wp-content/uploads/2024/09/entra-no-issue-768x379.png" class="attachment-medium_large size-medium_large wp-image-864" alt="Entra Connect - success sync" srcset="https://www.sraga.cz/wp-content/uploads/2024/09/entra-no-issue-768x379.png 768w, https://www.sraga.cz/wp-content/uploads/2024/09/entra-no-issue-300x148.png 300w, https://www.sraga.cz/wp-content/uploads/2024/09/entra-no-issue-1024x506.png 1024w, https://www.sraga.cz/wp-content/uploads/2024/09/entra-no-issue.png 1112w" sizes="(max-width: 768px) 100vw, 768px" />								</a>
															</div>
				</div>
				<div class="elementor-element elementor-element-7ddc802 elementor-widget elementor-widget-text-editor" data-id="7ddc802" data-element_type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p><strong>Relevantní zdroje:</strong></p><ul><li><a href="https://learn.microsoft.com/en-us/troubleshoot/azure/entra/entra-id/user-prov-sync/troubleshoot-permission-issue-sync-service-manager#solution-3-grant-permissions-by-using-the-active-directory-users-and-computers-snap-in" target="_blank" rel="noopener">Grant permissions by using the Active Directory Users and Computers snap-in</a></li><li><a href="https://learn.microsoft.com/en-us/troubleshoot/azure/entra/entra-id/user-prov-sync/password-writeback-access-rights-permissions" target="_blank" rel="noopener">Troubleshoot password writeback access rights and permissions</a></li></ul>								</div>
				</div>
				<div class="elementor-element elementor-element-eb71c7e elementor-widget elementor-widget-heading" data-id="eb71c7e" data-element_type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h2 class="elementor-heading-title elementor-size-default">Další kroky</h2>				</div>
				</div>
				<div class="elementor-element elementor-element-d38998d elementor-widget elementor-widget-text-editor" data-id="d38998d" data-element_type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p>Pokud nasazujete Microsoft Entra Connect, poprvé, mohou se vám hodit následující informace:</p><ul><li><a href="https://www.sraga.cz/entra-connect-troubleshooting-unable-to-validate-credentials/" target="_blank" rel="noopener">Entra Troubleshooting: unable to validate credentials</a></li><li><a href="https://www.sraga.cz/jak-synchronizovat-on-prem-ad-ucty-s-existujicimi-ucty-v-entra-id/" target="_blank" rel="noopener">Jak synchronizovat on-prem AD účty s existujícími účty v Entra ID</a></li><li><a href="https://www.sraga.cz/jak-zjistit-verzi-microsoft-azure-ad-connect-entra-id-connect/" target="_blank" rel="noopener">Jak zjistit aktuální verzi Microsoft Azure AD Connect / Entra ID Connect</a></li></ul>								</div>
				</div>
					</div>
				</div>
				</div>
		]]></content:encoded>
					
					<wfw:commentRss>https://www.sraga.cz/entra-troubleshooting-permission-issue-error-code-8344/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Entra Troubleshooting: unable to validate credentials</title>
		<link>https://www.sraga.cz/entra-connect-troubleshooting-unable-to-validate-credentials/</link>
					<comments>https://www.sraga.cz/entra-connect-troubleshooting-unable-to-validate-credentials/#respond</comments>
		
		<dc:creator><![CDATA[Miroslav Šraga]]></dc:creator>
		<pubDate>Sun, 15 Sep 2024 10:23:12 +0000</pubDate>
				<category><![CDATA[Azure AD / Entra ID]]></category>
		<category><![CDATA[Entra]]></category>
		<category><![CDATA[Entra Connect]]></category>
		<category><![CDATA[TLS]]></category>
		<guid isPermaLink="false">https://www.sraga.cz/?p=725</guid>

					<description><![CDATA[Nastává období, kdy sousta správců IT provádí upgrade služby Microsoft Entra Active Directory Connect. Obrátilo se na mne několik klientů, kteří se, při pokusu o aktualizaci Entra AD Connect, setkali s chybami.  V průvodci setkali s hlášením typu &#8222;nemůžeme se připojit k Azure AD pomocí vašehopověření globálního správce Azure AD&#8220;. Zobrazí se chyba, že nelze ... <a title="Entra Troubleshooting: unable to validate credentials" class="read-more" href="https://www.sraga.cz/entra-connect-troubleshooting-unable-to-validate-credentials/" aria-label="Číst více o Entra Troubleshooting: unable to validate credentials">Číst dál</a>]]></description>
										<content:encoded><![CDATA[		<div data-elementor-type="wp-post" data-elementor-id="725" class="elementor elementor-725" data-elementor-post-type="post">
				<div class="elementor-element elementor-element-44b17cd e-flex e-con-boxed e-con e-parent" data-id="44b17cd" data-element_type="container">
					<div class="e-con-inner">
				<div class="elementor-element elementor-element-14e40e7 elementor-widget elementor-widget-text-editor" data-id="14e40e7" data-element_type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p>Nastává období, kdy sousta správců IT provádí <a href="https://www.sraga.cz/entra-ad-sync-in-place-upgrade-health-agent/" target="_blank" rel="noopener">upgrade služby Microsoft Entra Active Directory Connect</a>. Obrátilo se na mne několik klientů, kteří se, při pokusu o aktualizaci Entra AD Connect, setkali s chybami.  V průvodci setkali s hlášením typu &#8222;nemůžeme se připojit k Azure AD pomocí vašehopověření globálního správce Azure AD&#8220;. Zobrazí se chyba, že nelze ověřit pověření kvůli očekávané chybě.</p><p>V tomto článku se pokusím přiblížit, proč k tomu dochází, a řešení problému &#8222;Azure AD Connect unable to validate credentials.</p>								</div>
				</div>
				<div class="elementor-element elementor-element-6f86ce2 elementor-toc--minimized-on-tablet elementor-widget elementor-widget-table-of-contents" data-id="6f86ce2" data-element_type="widget" data-settings="{&quot;exclude_headings_by_selector&quot;:[],&quot;headings_by_tags&quot;:[&quot;h2&quot;,&quot;h3&quot;,&quot;h4&quot;,&quot;h5&quot;,&quot;h6&quot;],&quot;marker_view&quot;:&quot;numbers&quot;,&quot;no_headings_message&quot;:&quot;No headings were found on this page.&quot;,&quot;minimize_box&quot;:&quot;yes&quot;,&quot;minimized_on&quot;:&quot;tablet&quot;,&quot;hierarchical_view&quot;:&quot;yes&quot;,&quot;min_height&quot;:{&quot;unit&quot;:&quot;px&quot;,&quot;size&quot;:&quot;&quot;,&quot;sizes&quot;:[]},&quot;min_height_tablet&quot;:{&quot;unit&quot;:&quot;px&quot;,&quot;size&quot;:&quot;&quot;,&quot;sizes&quot;:[]},&quot;min_height_mobile&quot;:{&quot;unit&quot;:&quot;px&quot;,&quot;size&quot;:&quot;&quot;,&quot;sizes&quot;:[]}}" data-widget_type="table-of-contents.default">
				<div class="elementor-widget-container">
									<div class="elementor-toc__header">
						<h4 class="elementor-toc__header-title">
				Obsah			</h4>
										<div class="elementor-toc__toggle-button elementor-toc__toggle-button--expand" role="button" tabindex="0" aria-controls="elementor-toc__6f86ce2" aria-expanded="true" aria-label="Open table of contents"><svg aria-hidden="true" class="e-font-icon-svg e-fas-chevron-down" viewBox="0 0 448 512" xmlns="http://www.w3.org/2000/svg"><path d="M207.029 381.476L12.686 187.132c-9.373-9.373-9.373-24.569 0-33.941l22.667-22.667c9.357-9.357 24.522-9.375 33.901-.04L224 284.505l154.745-154.021c9.379-9.335 24.544-9.317 33.901.04l22.667 22.667c9.373 9.373 9.373 24.569 0 33.941L240.971 381.476c-9.373 9.372-24.569 9.372-33.942 0z"></path></svg></div>
				<div class="elementor-toc__toggle-button elementor-toc__toggle-button--collapse" role="button" tabindex="0" aria-controls="elementor-toc__6f86ce2" aria-expanded="true" aria-label="Close table of contents"><svg aria-hidden="true" class="e-font-icon-svg e-fas-chevron-up" viewBox="0 0 448 512" xmlns="http://www.w3.org/2000/svg"><path d="M240.971 130.524l194.343 194.343c9.373 9.373 9.373 24.569 0 33.941l-22.667 22.667c-9.357 9.357-24.522 9.375-33.901.04L224 227.495 69.255 381.516c-9.379 9.335-24.544 9.317-33.901-.04l-22.667-22.667c-9.373-9.373-9.373-24.569 0-33.941L207.03 130.525c9.372-9.373 24.568-9.373 33.941-.001z"></path></svg></div>
					</div>
				<div id="elementor-toc__6f86ce2" class="elementor-toc__body">
			<div class="elementor-toc__spinner-container">
				<svg class="elementor-toc__spinner eicon-animation-spin e-font-icon-svg e-eicon-loading" aria-hidden="true" viewBox="0 0 1000 1000" xmlns="http://www.w3.org/2000/svg"><path d="M500 975V858C696 858 858 696 858 500S696 142 500 142 142 304 142 500H25C25 237 238 25 500 25S975 237 975 500 763 975 500 975Z"></path></svg>			</div>
		</div>
						</div>
				</div>
				<div class="elementor-element elementor-element-fd5e24e elementor-widget elementor-widget-heading" data-id="fd5e24e" data-element_type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h2 class="elementor-heading-title elementor-size-default">EntraAD Connect: chyba ověření</h2>				</div>
				</div>
				<div class="elementor-element elementor-element-7002056 elementor-alert-info elementor-widget elementor-widget-alert" data-id="7002056" data-element_type="widget" data-widget_type="alert.default">
				<div class="elementor-widget-container">
							<div class="elementor-alert" role="alert">

						<span class="elementor-alert-title">Unable to validate credentials due to an unexpected error</span>
			
						<span class="elementor-alert-description">Restart Azure AD Connect with the / InteractiveAuth option to further diagnose this issue. (extendedMessage: An error occurred while sending the request. | The underlying connection was closed: An unexpected error occurred on a send. | Unable to read data from the transport connection: An existing connection was forcibly closed by the remote host. | An existing connection was forcibly closed by the remote host
webException: The underlying connection was closed: An unexpected error occurred on a send.
STS endpoint:
HTTPS://LOGIN.MICROSOFTONLINE.COM/xxx.CZ)</span>
			
			
		</div>
						</div>
				</div>
				<div class="elementor-element elementor-element-c7c8f67 elementor-widget elementor-widget-image" data-id="c7c8f67" data-element_type="widget" data-widget_type="image.default">
				<div class="elementor-widget-container">
																<a href="https://www.sraga.cz/wp-content/uploads/2024/09/entra-connect-unable-to-validate-credentials.png" data-elementor-open-lightbox="yes" data-elementor-lightbox-title="entra-connect-unable-to-validate-credentials" data-e-action-hash="#elementor-action%3Aaction%3Dlightbox%26settings%3DeyJpZCI6NzMwLCJ1cmwiOiJodHRwczpcL1wvd3d3LnNyYWdhLmN6XC93cC1jb250ZW50XC91cGxvYWRzXC8yMDI0XC8wOVwvZW50cmEtY29ubmVjdC11bmFibGUtdG8tdmFsaWRhdGUtY3JlZGVudGlhbHMucG5nIn0%3D">
							<img loading="lazy" decoding="async" width="684" height="515" src="https://www.sraga.cz/wp-content/uploads/2024/09/entra-connect-unable-to-validate-credentials.png" class="attachment-medium_large size-medium_large wp-image-730" alt="Entra - unable to validate credentials due to an unexpected error" srcset="https://www.sraga.cz/wp-content/uploads/2024/09/entra-connect-unable-to-validate-credentials.png 684w, https://www.sraga.cz/wp-content/uploads/2024/09/entra-connect-unable-to-validate-credentials-300x226.png 300w" sizes="(max-width: 684px) 100vw, 684px" />								</a>
															</div>
				</div>
				<div class="elementor-element elementor-element-94c8009 elementor-widget elementor-widget-text-editor" data-id="94c8009" data-element_type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p>Když kliknete na odkaz &#8222;Learn more&#8220;, nebo si otevřete napřímo Entra AD Connect log (C:\<span data-teams="true"><span class="ui-provider a b c d e f g h i j k l m n o p q r s t u v w x y z ab ac ae af ag ah ai aj ak" dir="ltr">program data\aadconnect\trace***** .log</span></span>), obdržíte přibližně takový výpis:</p>								</div>
				</div>
				<div class="elementor-element elementor-element-2ae3715 elementor-widget elementor-widget-code-highlight" data-id="2ae3715" data-element_type="widget" data-widget_type="code-highlight.default">
				<div class="elementor-widget-container">
							<div class="prismjs-default copy-to-clipboard word-wrap">
			<pre data-line="" class="highlight-height language-javascript line-numbers">
				<code readonly="true" class="language-javascript">
					<xmp>[07:58:56.609] [ 16] [ERROR] Authenticate-MSAL: unexpected exception [Unspecified-Authentication-Failure] - extendedMessage: An error occurred while sending the request. | The underlying connection was closed: An unexpected error occurred on a send. | Unable to read data from the transport connection: An existing connection was forcibly closed by the remote host. | An existing connection was forcibly closed by the remote host webException: The underlying connection was closed: An unexpected error occurred on a send.
STS endpoint: HTTPS://LOGIN.MICROSOFTONLINE.COM/xxx.CZ
[07:58:56.612] [ 16] [ERROR] Authenticate-MSAL: exception details: System.Net.Http.HttpRequestException: An error occurred while sending the request. ---> System.Net.WebException: The underlying connection was closed: An unexpected error occurred on a send. ---> System.IO.IOException: Unable to read data from the transport connection: An existing connection was forcibly closed by the remote host. ---> System.Net.Sockets.SocketException: An existing connection was forcibly closed by the remote host</xmp>
				</code>
			</pre>
		</div>
						</div>
				</div>
				<div class="elementor-element elementor-element-c1abbfc elementor-widget elementor-widget-heading" data-id="c1abbfc" data-element_type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h2 class="elementor-heading-title elementor-size-default">Error parsing WS-Trust-response from endpoint</h2>				</div>
				</div>
				<div class="elementor-element elementor-element-2a41b93 elementor-widget elementor-widget-text-editor" data-id="2a41b93" data-element_type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p>Další chyba, která se ke mě dostala je velmi podobná, ale trochu jiná.</p>								</div>
				</div>
				<div class="elementor-element elementor-element-9f41369 elementor-alert-info elementor-widget elementor-widget-alert" data-id="9f41369" data-element_type="widget" data-widget_type="alert.default">
				<div class="elementor-widget-container">
							<div class="elementor-alert" role="alert">

						<span class="elementor-alert-title">Unable to validate credentials due to an unexpected error</span>
			
						<span class="elementor-alert-description">Restart Azure AD Connect with the / InteractiveAuth option to further diagnose this issue. (extendedMessage: There was an error parsing WS-Trust-response from the endpoint. This may occur if there is an issue with your ADFS configuration. See https://aka.ms/msal-net-iwa-troubleshooting for more details. Error Message: Federated service ad https://autologon.microsoftazuread-sso.com/xxxxxx/winauth/trust/2005/usernamemixed?client-request-id=xxxxx returned error: Authentication Failure </span>
			
			
		</div>
						</div>
				</div>
				<div class="elementor-element elementor-element-7c07989 elementor-widget elementor-widget-image" data-id="7c07989" data-element_type="widget" data-widget_type="image.default">
				<div class="elementor-widget-container">
																<a href="https://www.sraga.cz/wp-content/uploads/2024/09/entra-connect-unable-to-validate-credentials-2.png" data-elementor-open-lightbox="yes" data-elementor-lightbox-title="entra-connect-unable-to-validate-credentials-2" data-e-action-hash="#elementor-action%3Aaction%3Dlightbox%26settings%3DeyJpZCI6NzMxLCJ1cmwiOiJodHRwczpcL1wvd3d3LnNyYWdhLmN6XC93cC1jb250ZW50XC91cGxvYWRzXC8yMDI0XC8wOVwvZW50cmEtY29ubmVjdC11bmFibGUtdG8tdmFsaWRhdGUtY3JlZGVudGlhbHMtMi5wbmcifQ%3D%3D">
							<img loading="lazy" decoding="async" width="742" height="523" src="https://www.sraga.cz/wp-content/uploads/2024/09/entra-connect-unable-to-validate-credentials-2.png" class="attachment-medium_large size-medium_large wp-image-731" alt="Entra - unable to validate credentials due to an unexpected error" srcset="https://www.sraga.cz/wp-content/uploads/2024/09/entra-connect-unable-to-validate-credentials-2.png 742w, https://www.sraga.cz/wp-content/uploads/2024/09/entra-connect-unable-to-validate-credentials-2-300x211.png 300w" sizes="(max-width: 742px) 100vw, 742px" />								</a>
															</div>
				</div>
				<div class="elementor-element elementor-element-f6fb072 elementor-widget elementor-widget-heading" data-id="f6fb072" data-element_type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h2 class="elementor-heading-title elementor-size-default">Při provádění úlohy Configure AAD Sync došlo k chybě</h2>				</div>
				</div>
				<div class="elementor-element elementor-element-fe6e696 elementor-widget elementor-widget-text-editor" data-id="fe6e696" data-element_type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p>Poslední chyba, která se ke mě dostala, byla trochu jiná. Klient udělal tu věc, že na server, na kterém běžela služba Entra AD Connect, naistaloval roli &#8222;Active Directory Domain Services&#8220; a tím mu celá Entra spadla a řešilo se několik věcí. První věc, která se musela vyřešit, byla <strong>oprava oprávnění</strong>, protože na doménovém řadiči samozřejmě přestaly fungovat lokální účty. Kompletní odinstalace a opětovná instalace s obnovou konfigurace vyřešila první část a to problém s oprávněním, které bylo nutné jak pro spuštění samotné služby ADSync, ale také pro běh databáze a dalších komponent.</p><p>Nastal ale jiný problém, protože služba nešla korektně nastartovat a synchronizace neprobíhala. Začaly se objevoval další chyby:</p>								</div>
				</div>
				<div class="elementor-element elementor-element-2b30672 elementor-alert-info elementor-widget elementor-widget-alert" data-id="2b30672" data-element_type="widget" data-widget_type="alert.default">
				<div class="elementor-widget-container">
							<div class="elementor-alert" role="alert">

						<span class="elementor-alert-title">Configure AAD Sync</span>
			
						<span class="elementor-alert-description">Při provádění úlohy Configure AAD Sync došlo k chybě: Při odesílání požadavku došlo k chybě..

Jak postupovat dál:
nejsou dostupné žádné konkrétní informace o této chybě. Podrobnosti najdete v protokolu.

V opačném případě zkontrolujte protokol, kde najdete podrobnější informace:
C:\ProgramData\AADConnect\trace-xxxxxx.log</span>
			
			
		</div>
						</div>
				</div>
				<div class="elementor-element elementor-element-054170c elementor-widget elementor-widget-image" data-id="054170c" data-element_type="widget" data-widget_type="image.default">
				<div class="elementor-widget-container">
															<img loading="lazy" decoding="async" width="889" height="625" src="https://www.sraga.cz/wp-content/uploads/2024/09/configure-aad-sync.png" class="attachment-large size-large wp-image-735" alt="Při provádění úlohy Configure AAD Sync došlo k chybě" srcset="https://www.sraga.cz/wp-content/uploads/2024/09/configure-aad-sync.png 889w, https://www.sraga.cz/wp-content/uploads/2024/09/configure-aad-sync-300x211.png 300w, https://www.sraga.cz/wp-content/uploads/2024/09/configure-aad-sync-768x540.png 768w" sizes="(max-width: 889px) 100vw, 889px" />															</div>
				</div>
				<div class="elementor-element elementor-element-9fd1e3a elementor-widget elementor-widget-text-editor" data-id="9fd1e3a" data-element_type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p>V trace logu toho moc nebylo. Nicméně, Event logy mi naštěstí řekly o trochu víc a nasměrovaly mne správným směrem.</p>								</div>
				</div>
				<div class="elementor-element elementor-element-c947637 elementor-widget elementor-widget-image" data-id="c947637" data-element_type="widget" data-widget_type="image.default">
				<div class="elementor-widget-container">
																<a href="https://www.sraga.cz/wp-content/uploads/2024/09/getsecuritytoken.png" data-elementor-open-lightbox="yes" data-elementor-lightbox-title="getsecuritytoken" data-e-action-hash="#elementor-action%3Aaction%3Dlightbox%26settings%3DeyJpZCI6NzM2LCJ1cmwiOiJodHRwczpcL1wvd3d3LnNyYWdhLmN6XC93cC1jb250ZW50XC91cGxvYWRzXC8yMDI0XC8wOVwvZ2V0c2VjdXJpdHl0b2tlbi5wbmcifQ%3D%3D">
							<img loading="lazy" decoding="async" width="768" height="284" src="https://www.sraga.cz/wp-content/uploads/2024/09/getsecuritytoken-768x284.png" class="attachment-medium_large size-medium_large wp-image-736" alt="getsecuritytoken" srcset="https://www.sraga.cz/wp-content/uploads/2024/09/getsecuritytoken-768x284.png 768w, https://www.sraga.cz/wp-content/uploads/2024/09/getsecuritytoken-300x111.png 300w, https://www.sraga.cz/wp-content/uploads/2024/09/getsecuritytoken-1024x378.png 1024w, https://www.sraga.cz/wp-content/uploads/2024/09/getsecuritytoken.png 1224w" sizes="(max-width: 768px) 100vw, 768px">								</a>
															</div>
				</div>
				<div class="elementor-element elementor-element-a33aa93 elementor-alert-info elementor-widget elementor-widget-alert" data-id="a33aa93" data-element_type="widget" data-widget_type="alert.default">
				<div class="elementor-widget-container">
							<div class="elementor-alert" role="alert">

						<span class="elementor-alert-title">GetSecurityToken:</span>
			
						<span class="elementor-alert-description">unable to retrieve a security token for the provisioning web service (AWS). Při odesílání požadavku došlo k chybě. | Nadřízené připojení bylo uzavřeno: Došlo k neočekávané chybě při příjmu. | Klient nemůže komunikovat se serverem, protože nepoužívají žádný společný algoritmus. extendedMessage: Při odesílání požadavku došlo k chybě. | Nadřízené připojení bylo uzavřeno: Došlo k neočekávané chybě při příjmu. | Klient nemůže komunikovat se serverem, protože nepoužívají žádný společný algoritmus
webException: Nadřízené připojení bylo uzavřeno: Došlo k neočekávané chybě při příjmu.
STS endpoint: HTTPS://LOGIN.MICROSOFTONLINE.COM/xxx.ONMICROSOFT.COM</span>
			
			
		</div>
						</div>
				</div>
				<div class="elementor-element elementor-element-42c7af6 elementor-alert-info elementor-widget elementor-widget-alert" data-id="42c7af6" data-element_type="widget" data-widget_type="alert.default">
				<div class="elementor-widget-container">
							<div class="elementor-alert" role="alert">

						<span class="elementor-alert-title">Authenticate-MSAL:</span>
			
						<span class="elementor-alert-description">unexpected exception [Unspecified-Authentication-Failure] - extendedMessage: Při odesílání požadavku došlo k chybě. | Nadřízené připojení bylo uzavřeno: Došlo k neočekávané chybě při příjmu. | Klient nemůže komunikovat se serverem, protože nepoužívají žádný společný algoritmus
webException: Nadřízené připojení bylo uzavřeno: Došlo k neočekávané chybě při příjmu.
STS endpoint: HTTPS://LOGIN.MICROSOFTONLINE.COM/xxx.ONMICROSOFT.COM</span>
			
			
		</div>
						</div>
				</div>
				<div class="elementor-element elementor-element-2a5d8bd elementor-widget elementor-widget-heading" data-id="2a5d8bd" data-element_type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h2 class="elementor-heading-title elementor-size-default">Jak postupovat</h2>				</div>
				</div>
				<div class="elementor-element elementor-element-adb2b39 elementor-widget elementor-widget-text-editor" data-id="adb2b39" data-element_type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p>Pokud patříte mezi ty &#8222;šťastlivce&#8220;, které některá z těchto chyb také potkala, nezoufejte, řešení existuje (a to hned několik):</p><ol><li>Ověřte, zda-li máte <a href="https://www.sraga.cz/jak-zjistit-verzi-microsoft-azure-ad-connect-entra-id-connect/" target="_blank" rel="noopener">aktuální verzi Entra AD Conenct</a></li><li><strong>Interactive authentication</strong> &#8211; Vypněte službu ADSync a nastartuje ji znovu s parametrem <a href="https://learn.microsoft.com/en-us/answers/questions/886773/unable-to-connect-to-azure-ad-connect" target="_blank" rel="noopener">/InteractiveAuth</a></li><li><strong>Ověřte, zda operační systém podporuje TLS 1.2</strong></li></ol>								</div>
				</div>
				<div class="elementor-element elementor-element-b0c857a elementor-widget elementor-widget-heading" data-id="b0c857a" data-element_type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Entra AD Connect - Interactive authentication</h4>				</div>
				</div>
				<div class="elementor-element elementor-element-9ad6ba2 elementor-widget elementor-widget-text-editor" data-id="9ad6ba2" data-element_type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p>Jedním z možných řešení jak vyřešit problém služby Entra AD Connect, která se nemůže ověřit kvůli neočekávané chybě může být spuštěni služby v InteractiveAuth módu.</p><p>Chcete-li opravit chybu Azure AD Connect unable to validate credentials due to an unexpected error, postupujte podle následujících kroků:</p><p>1. Spusťte příkazový řádek jako správce.</p><p>2. Přejděte do složky Microsoft Azure Active Directory Connect.</p>								</div>
				</div>
				<div class="elementor-element elementor-element-4971248 elementor-widget elementor-widget-code-block-for-elementor" data-id="4971248" data-element_type="widget" data-widget_type="code-block-for-elementor.default">
				<div class="elementor-widget-container">
					<pre class='line-numbers theme-okaidia' data-show-toolbar='yes'><code class='language-powershell'>cd &quot;C:\Program Files\Microsoft Azure Active Directory Connect&quot;</code></pre>				</div>
				</div>
				<div class="elementor-element elementor-element-abaedff elementor-widget elementor-widget-text-editor" data-id="abaedff" data-element_type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p>3. Spusťte následující příkaz</p>								</div>
				</div>
				<div class="elementor-element elementor-element-4a3466f elementor-widget elementor-widget-code-block-for-elementor" data-id="4a3466f" data-element_type="widget" data-widget_type="code-block-for-elementor.default">
				<div class="elementor-widget-container">
					<pre class='line-numbers theme-okaidia' data-show-toolbar='yes'><code class='language-powershell'>AzureADConnect.exe /InteractiveAuth</code></pre>				</div>
				</div>
				<div class="elementor-element elementor-element-b2a89d4 elementor-widget elementor-widget-text-editor" data-id="b2a89d4" data-element_type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p>4. Zobrazí se průvodce aktualizací a konfogurací Azure Active Directory Connect, průvodcem projděte běžným způspobem, třeba podle <a href="https://www.sraga.cz/entra-ad-sync-in-place-upgrade-health-agent/" target="_blank" rel="noopener">tohoto návodu</a>.<strong><br /></strong></p>								</div>
				</div>
				<div class="elementor-element elementor-element-1dfa372 elementor-widget elementor-widget-text-editor" data-id="1dfa372" data-element_type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p>Musím přiznat, že ani v jednom z těchto tří případů mi výše uvedený postup nepomohl.</p><p>Co mne na těchto chybových hláškách ale zaujalo, bylo &#8222;<em>Klient nemůže komunikovat se serverem, protože nepoužívají žádný společný algoritmus</em>&#8222;.</p><p>Když jsem v únoru psal článek o <a href="https://www.sraga.cz/entra-ad-connect-presun-na-novy-server/" target="_blank" rel="noopener">přesunu Entra AD Connect na nový server</a>, vypsal jsem do něj všechny pre-rekvizity, které je potřeba pro Entra V2 splnit.</p><p>Všechna chybová hlášení měla stejný základ &#8211; klient nemůže komunikovat s protistranou. Na vině můtže být firewall či proxy (nebyl tento příkald) nebo se nemohou domluvit z jiného důvodu, protože třwba každý mluví jiným jazykem.</p><p><strong>Ve všech třech případech byla na vině chyba v chybějící podpoře TLS 1.2</strong></p>								</div>
				</div>
				<div class="elementor-element elementor-element-8976c25 elementor-widget elementor-widget-heading" data-id="8976c25" data-element_type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">Ověření, zda server podporuje TLS 1.2</h4>				</div>
				</div>
				<div class="elementor-element elementor-element-bbabf3d elementor-widget elementor-widget-text-editor" data-id="bbabf3d" data-element_type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p>Pomocí následujícího <a href="https://www.sraga.cz/tag/powershell/" target="_blank" rel="noopener">PowerShell</a> skriptu můžete zkontrolovat aktuální nastavení protokolu TLS 1.2 na serveru, kde provozujete <a href="https://www.sraga.cz/tag/entra-connect/" target="_blank" rel="noopener">Microsoft Entra Connect</a>.</p>								</div>
				</div>
				<div class="elementor-element elementor-element-259fe77 elementor-widget elementor-widget-code-block-for-elementor" data-id="259fe77" data-element_type="widget" data-widget_type="code-block-for-elementor.default">
				<div class="elementor-widget-container">
					<pre class='line-numbers theme-okaidia' data-show-toolbar='yes'><code class='language-powershell'>Function Get-ADSyncToolsTls12RegValue
{
    [CmdletBinding()]
    Param
    (
        # Registry Path
        [Parameter(Mandatory=$true,
                   Position=0)]
        [string]
        $RegPath,

# Registry Name
        [Parameter(Mandatory=$true,
                   Position=1)]
        [string]
        $RegName
    )
    $regItem = Get-ItemProperty -Path $RegPath -Name $RegName -ErrorAction Ignore
    $output = &quot;&quot; | select Path,Name,Value
    $output.Path = $RegPath
    $output.Name = $RegName

If ($regItem -eq $null)
    {
        $output.Value = &quot;Not Found&quot;
    }
    Else
    {
        $output.Value = $regItem.$RegName
    }
    $output
}

$regSettings = @()
$regKey = &#039;HKLM:\SOFTWARE\WOW6432Node\Microsoft\.NETFramework\v4.0.30319&#039;
$regSettings += Get-ADSyncToolsTls12RegValue $regKey &#039;SystemDefaultTlsVersions&#039;
$regSettings += Get-ADSyncToolsTls12RegValue $regKey &#039;SchUseStrongCrypto&#039;

$regKey = &#039;HKLM:\SOFTWARE\Microsoft\.NETFramework\v4.0.30319&#039;
$regSettings += Get-ADSyncToolsTls12RegValue $regKey &#039;SystemDefaultTlsVersions&#039;
$regSettings += Get-ADSyncToolsTls12RegValue $regKey &#039;SchUseStrongCrypto&#039;

$regKey = &#039;HKLM:\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\TLS 1.2\Server&#039;
$regSettings += Get-ADSyncToolsTls12RegValue $regKey &#039;Enabled&#039;
$regSettings += Get-ADSyncToolsTls12RegValue $regKey &#039;DisabledByDefault&#039;

$regKey = &#039;HKLM:\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\TLS 1.2\Client&#039;
$regSettings += Get-ADSyncToolsTls12RegValue $regKey &#039;Enabled&#039;
$regSettings += Get-ADSyncToolsTls12RegValue $regKey &#039;DisabledByDefault&#039;

$regSettings</code></pre>				</div>
				</div>
				<div class="elementor-element elementor-element-1b51a3d elementor-widget elementor-widget-text-editor" data-id="1b51a3d" data-element_type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p>Výstup skriptu bude přibližně takový:</p>								</div>
				</div>
				<div class="elementor-element elementor-element-b441831 elementor-widget elementor-widget-image" data-id="b441831" data-element_type="widget" data-widget_type="image.default">
				<div class="elementor-widget-container">
																<a href="https://www.sraga.cz/wp-content/uploads/2024/09/tls-1-2-check.png" data-elementor-open-lightbox="yes" data-elementor-lightbox-title="tls-1-2-check" data-e-action-hash="#elementor-action%3Aaction%3Dlightbox%26settings%3DeyJpZCI6NzUyLCJ1cmwiOiJodHRwczpcL1wvd3d3LnNyYWdhLmN6XC93cC1jb250ZW50XC91cGxvYWRzXC8yMDI0XC8wOVwvdGxzLTEtMi1jaGVjay5wbmcifQ%3D%3D">
							<img loading="lazy" decoding="async" width="768" height="127" src="https://www.sraga.cz/wp-content/uploads/2024/09/tls-1-2-check-768x127.png" class="attachment-medium_large size-medium_large wp-image-752" alt="Kontrola TLS 1.2 pomocí PowerShell" srcset="https://www.sraga.cz/wp-content/uploads/2024/09/tls-1-2-check-768x127.png 768w, https://www.sraga.cz/wp-content/uploads/2024/09/tls-1-2-check-300x50.png 300w, https://www.sraga.cz/wp-content/uploads/2024/09/tls-1-2-check.png 945w" sizes="(max-width: 768px) 100vw, 768px" />								</a>
															</div>
				</div>
				<div class="elementor-element elementor-element-86aba4b elementor-widget elementor-widget-text-editor" data-id="86aba4b" data-element_type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p>Ověřte, zda-li je tedy TLS 1.2 na vašem serveru aktivní. Pokud aktivní není, bude výstup podobný, jako na uvedeném obrázku, tedy u jednotlivých komponent bude uvedeno &#8222;Not Found&#8220; nebo &#8222;0&#8220;.</p>								</div>
				</div>
				<div class="elementor-element elementor-element-f095a28 elementor-widget elementor-widget-heading" data-id="f095a28" data-element_type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">PowerShell script pro zapnutí podpory TLS 1.2</h4>				</div>
				</div>
				<div class="elementor-element elementor-element-fd7175a elementor-widget elementor-widget-text-editor" data-id="fd7175a" data-element_type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p>K vynucení podpory protokolu TLS 1.2 na serveru s Microsoft Entra Connect můžete použít následující PowerShell skript.</p>								</div>
				</div>
				<div class="elementor-element elementor-element-1dfe1ec elementor-widget elementor-widget-code-block-for-elementor" data-id="1dfe1ec" data-element_type="widget" data-widget_type="code-block-for-elementor.default">
				<div class="elementor-widget-container">
					<pre class='line-numbers theme-okaidia' data-show-toolbar='yes'><code class='language-powershell'>If (-Not (Test-Path &#039;HKLM:\SOFTWARE\WOW6432Node\Microsoft\.NETFramework\v4.0.30319&#039;))
{
    New-Item &#039;HKLM:\SOFTWARE\WOW6432Node\Microsoft\.NETFramework\v4.0.30319&#039; -Force | Out-Null
}
New-ItemProperty -Path &#039;HKLM:\SOFTWARE\WOW6432Node\Microsoft\.NETFramework\v4.0.30319&#039; -Name &#039;SystemDefaultTlsVersions&#039; -Value &#039;1&#039; -PropertyType &#039;DWord&#039; -Force | Out-Null
New-ItemProperty -Path &#039;HKLM:\SOFTWARE\WOW6432Node\Microsoft\.NETFramework\v4.0.30319&#039; -Name &#039;SchUseStrongCrypto&#039; -Value &#039;1&#039; -PropertyType &#039;DWord&#039; -Force | Out-Null

If (-Not (Test-Path &#039;HKLM:\SOFTWARE\Microsoft\.NETFramework\v4.0.30319&#039;))
{
    New-Item &#039;HKLM:\SOFTWARE\Microsoft\.NETFramework\v4.0.30319&#039; -Force | Out-Null
}
New-ItemProperty -Path &#039;HKLM:\SOFTWARE\Microsoft\.NETFramework\v4.0.30319&#039; -Name &#039;SystemDefaultTlsVersions&#039; -Value &#039;1&#039; -PropertyType &#039;DWord&#039; -Force | Out-Null
New-ItemProperty -Path &#039;HKLM:\SOFTWARE\Microsoft\.NETFramework\v4.0.30319&#039; -Name &#039;SchUseStrongCrypto&#039; -Value &#039;1&#039; -PropertyType &#039;DWord&#039; -Force | Out-Null

If (-Not (Test-Path &#039;HKLM:\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\TLS 1.2\Server&#039;))
{
    New-Item &#039;HKLM:\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\TLS 1.2\Server&#039; -Force | Out-Null
}
New-ItemProperty -Path &#039;HKLM:\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\TLS 1.2\Server&#039; -Name &#039;Enabled&#039; -Value &#039;1&#039; -PropertyType &#039;DWord&#039; -Force | Out-Null
New-ItemProperty -Path &#039;HKLM:\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\TLS 1.2\Server&#039; -Name &#039;DisabledByDefault&#039; -Value &#039;0&#039; -PropertyType &#039;DWord&#039; -Force | Out-Null

If (-Not (Test-Path &#039;HKLM:\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\TLS 1.2\Client&#039;))
{
    New-Item &#039;HKLM:\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\TLS 1.2\Client&#039; -Force | Out-Null
}
New-ItemProperty -Path &#039;HKLM:\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\TLS 1.2\Client&#039; -Name &#039;Enabled&#039; -Value &#039;1&#039; -PropertyType &#039;DWord&#039; -Force | Out-Null
New-ItemProperty -Path &#039;HKLM:\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\TLS 1.2\Client&#039; -Name &#039;DisabledByDefault&#039; -Value &#039;0&#039; -PropertyType &#039;DWord&#039; -Force | Out-Null

Write-Host &#039;TLS 1.2 has been enabled. You must restart the Windows Server for the changes to take affect.&#039; -ForegroundColor Cyan</code></pre>				</div>
				</div>
				<div class="elementor-element elementor-element-7642837 elementor-widget elementor-widget-text-editor" data-id="7642837" data-element_type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p>Výstupem skriptu by pak měla být tato hláška:</p>								</div>
				</div>
				<div class="elementor-element elementor-element-4a447e7 elementor-widget elementor-widget-image" data-id="4a447e7" data-element_type="widget" data-widget_type="image.default">
				<div class="elementor-widget-container">
															<img loading="lazy" decoding="async" width="900" height="41" src="https://www.sraga.cz/wp-content/uploads/2024/09/tls-1-2-enabled.png" class="attachment-large size-large wp-image-753" alt="tls 1 2 enabled" srcset="https://www.sraga.cz/wp-content/uploads/2024/09/tls-1-2-enabled.png 959w, https://www.sraga.cz/wp-content/uploads/2024/09/tls-1-2-enabled-300x14.png 300w, https://www.sraga.cz/wp-content/uploads/2024/09/tls-1-2-enabled-768x35.png 768w" sizes="(max-width: 900px) 100vw, 900px">															</div>
				</div>
				<div class="elementor-element elementor-element-3a7c8dd elementor-alert-warning elementor-widget elementor-widget-alert" data-id="3a7c8dd" data-element_type="widget" data-widget_type="alert.default">
				<div class="elementor-widget-container">
							<div class="elementor-alert" role="alert">

						<span class="elementor-alert-title">Upozornění</span>
			
						<span class="elementor-alert-description">Po aktivaci podpory TLS 1.2 restartujte server.</span>
			
						<button type="button" class="elementor-alert-dismiss" aria-label="Zavřít toto upozornění.">
									<span aria-hidden="true">&times;</span>
							</button>
			
		</div>
						</div>
				</div>
				<div class="elementor-element elementor-element-147f7f3 elementor-widget elementor-widget-heading" data-id="147f7f3" data-element_type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">PowerShell script pro vypnutí podpory TLS 1.2</h4>				</div>
				</div>
				<div class="elementor-element elementor-element-bdbb55b elementor-widget elementor-widget-text-editor" data-id="bdbb55b" data-element_type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p>Ačkoliv deaktivaci podpory TLS 1.2 <strong>nedoporučuji</strong>, v ojedinělých případech může být potřeba. Pokud tedy nutně potřebujede <strong>deaktivovat</strong> podporu TLS 1.2 na vašem serveru, použijte následující skript:</p>								</div>
				</div>
				<div class="elementor-element elementor-element-c98e602 elementor-widget elementor-widget-code-block-for-elementor" data-id="c98e602" data-element_type="widget" data-widget_type="code-block-for-elementor.default">
				<div class="elementor-widget-container">
					<pre class='line-numbers theme-okaidia' data-show-toolbar='yes'><code class='language-powershell'>If (-Not (Test-Path &#039;HKLM:\SOFTWARE\WOW6432Node\Microsoft\.NETFramework\v4.0.30319&#039;))
{
    New-Item &#039;HKLM:\SOFTWARE\WOW6432Node\Microsoft\.NETFramework\v4.0.30319&#039; -Force | Out-Null
}
New-ItemProperty -Path &#039;HKLM:\SOFTWARE\WOW6432Node\Microsoft\.NETFramework\v4.0.30319&#039; -Name &#039;SystemDefaultTlsVersions&#039; -Value &#039;0&#039; -PropertyType &#039;DWord&#039; -Force | Out-Null
New-ItemProperty -Path &#039;HKLM:\SOFTWARE\WOW6432Node\Microsoft\.NETFramework\v4.0.30319&#039; -Name &#039;SchUseStrongCrypto&#039; -Value &#039;0&#039; -PropertyType &#039;DWord&#039; -Force | Out-Null

If (-Not (Test-Path &#039;HKLM:\SOFTWARE\Microsoft\.NETFramework\v4.0.30319&#039;))
{
    New-Item &#039;HKLM:\SOFTWARE\Microsoft\.NETFramework\v4.0.30319&#039; -Force | Out-Null
}
New-ItemProperty -Path &#039;HKLM:\SOFTWARE\Microsoft\.NETFramework\v4.0.30319&#039; -Name &#039;SystemDefaultTlsVersions&#039; -Value &#039;0&#039; -PropertyType &#039;DWord&#039; -Force | Out-Null
New-ItemProperty -Path &#039;HKLM:\SOFTWARE\Microsoft\.NETFramework\v4.0.30319&#039; -Name &#039;SchUseStrongCrypto&#039; -Value &#039;0&#039; -PropertyType &#039;DWord&#039; -Force | Out-Null

If (-Not (Test-Path &#039;HKLM:\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\TLS 1.2\Server&#039;))
{
    New-Item &#039;HKLM:\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\TLS 1.2\Server&#039; -Force | Out-Null
}
New-ItemProperty -Path &#039;HKLM:\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\TLS 1.2\Server&#039; -Name &#039;Enabled&#039; -Value &#039;0&#039; -PropertyType &#039;DWord&#039; -Force | Out-Null
New-ItemProperty -Path &#039;HKLM:\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\TLS 1.2\Server&#039; -Name &#039;DisabledByDefault&#039; -Value &#039;1&#039; -PropertyType &#039;DWord&#039; -Force | Out-Null

If (-Not (Test-Path &#039;HKLM:\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\TLS 1.2\Client&#039;))
{
    New-Item &#039;HKLM:\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\TLS 1.2\Client&#039; -Force | Out-Null
}
New-ItemProperty -Path &#039;HKLM:\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\TLS 1.2\Client&#039; -Name &#039;Enabled&#039; -Value &#039;0&#039; -PropertyType &#039;DWord&#039; -Force | Out-Null
New-ItemProperty -Path &#039;HKLM:\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\TLS 1.2\Client&#039; -Name &#039;DisabledByDefault&#039; -Value &#039;1&#039; -PropertyType &#039;DWord&#039; -Force | Out-Null

Write-Host &#039;TLS 1.2 has been disabled. You must restart the Windows Server for the changes to take affect.&#039; -ForegroundColor Cyan</code></pre>				</div>
				</div>
				<div class="elementor-element elementor-element-d608111 elementor-widget elementor-widget-heading" data-id="d608111" data-element_type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h2 class="elementor-heading-title elementor-size-default">Další kroky
</h2>				</div>
				</div>
				<div class="elementor-element elementor-element-8df86c0 elementor-widget elementor-widget-text-editor" data-id="8df86c0" data-element_type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p>Pokud nasazujete Microsoft Entra Connect, poprvé, mohou se vám hodit následující informace:</p><ul><li><a href="https://www.sraga.cz/entra-troubleshooting-permission-issue-error-code-8344/" target="_blank" rel="noopener">Entra Troubleshooting: permission-issue error code 8344</a></li><li><a href="https://www.sraga.cz/jak-synchronizovat-on-prem-ad-ucty-s-existujicimi-ucty-v-entra-id/" target="_blank" rel="noopener">Jak synchronizovat on-prem AD účty s existujícími účty v Entra ID</a></li><li><a href="https://www.sraga.cz/jak-zjistit-verzi-microsoft-azure-ad-connect-entra-id-connect/" target="_blank" rel="noopener">Jak zjistit aktuální verzi Microsoft Azure AD Connect / Entra ID Connect</a></li></ul>								</div>
				</div>
					</div>
				</div>
				</div>
		]]></content:encoded>
					
					<wfw:commentRss>https://www.sraga.cz/entra-connect-troubleshooting-unable-to-validate-credentials/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Entra AD Connect &#8211; přesun na nový server</title>
		<link>https://www.sraga.cz/entra-ad-connect-presun-na-novy-server/</link>
					<comments>https://www.sraga.cz/entra-ad-connect-presun-na-novy-server/#respond</comments>
		
		<dc:creator><![CDATA[c]]></dc:creator>
		<pubDate>Wed, 07 Feb 2024 09:45:05 +0000</pubDate>
				<category><![CDATA[Azure AD / Entra ID]]></category>
		<category><![CDATA[AD Sync]]></category>
		<category><![CDATA[Azure AD Connect]]></category>
		<category><![CDATA[Entra Connect]]></category>
		<category><![CDATA[PowerShell]]></category>
		<guid isPermaLink="false">https://www.sraga.cz/?p=130</guid>

					<description><![CDATA[S dříve publikovaným článkem (Entra AD Sync (Azure AD Sync) – In-place upgrade) souvisí jedna věc. Verze operačních systémů, které Entra Connect V2 podporuje. Oproti Azure AD Connect došlo k některým změnám v podpoře a s tím u mnohých klientů souvisí potřeba přesunu Entra Connect na nový server. V tomto videu je zaznamenán postup, jak ... <a title="Entra AD Connect &#8211; přesun na nový server" class="read-more" href="https://www.sraga.cz/entra-ad-connect-presun-na-novy-server/" aria-label="Číst více o Entra AD Connect &#8211; přesun na nový server">Číst dál</a>]]></description>
										<content:encoded><![CDATA[		<div data-elementor-type="wp-post" data-elementor-id="130" class="elementor elementor-130" data-elementor-post-type="post">
				<div class="elementor-element elementor-element-b905736 e-flex e-con-boxed e-con e-parent" data-id="b905736" data-element_type="container">
					<div class="e-con-inner">
				<div class="elementor-element elementor-element-d626439 elementor-widget elementor-widget-text-editor" data-id="d626439" data-element_type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p>S dříve publikovaným článkem (<a href="/entra-ad-sync-in-place-upgrade-health-agent/" target="_blank" rel="noopener">Entra AD Sync (Azure AD Sync) – In-place upgrade</a>) souvisí jedna věc. Verze operačních systémů, které Entra Connect V2 podporuje. Oproti Azure AD Connect došlo k některým změnám v podpoře a s tím u mnohých klientů souvisí potřeba přesunu Entra Connect na nový server.</p><p>V tomto videu je zaznamenán postup, jak ze starého serveru přesunout Microsoft Entra Connect na server nový.</p><p>Migrace probíhala z Azure AD Connect verze 1.6 na nový Microsoft Entra Connect V2.</p>								</div>
				</div>
				<div class="elementor-element elementor-element-2a9241d elementor-widget elementor-widget-video" data-id="2a9241d" data-element_type="widget" data-settings="{&quot;youtube_url&quot;:&quot;https:\/\/youtu.be\/pybMDiFyVnI&quot;,&quot;video_type&quot;:&quot;youtube&quot;,&quot;controls&quot;:&quot;yes&quot;}" data-widget_type="video.default">
				<div class="elementor-widget-container">
							<div class="elementor-wrapper elementor-open-inline">
			<div class="elementor-video"></div>		</div>
						</div>
				</div>
				<div class="elementor-element elementor-element-43e9a66 elementor-widget elementor-widget-heading" data-id="43e9a66" data-element_type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h2 class="elementor-heading-title elementor-size-default">Entra Connect V2: Podpora a hlavní změny</h2>				</div>
				</div>
				<div class="elementor-element elementor-element-dcf38fa elementor-alert-info elementor-widget elementor-widget-alert" data-id="dcf38fa" data-element_type="widget" data-widget_type="alert.default">
				<div class="elementor-widget-container">
							<div class="elementor-alert" role="alert">

						<span class="elementor-alert-title">Toto je upozornění</span>
			
						<span class="elementor-alert-description">Služba Azure AD Connect V1 byla k 31. srpnu 2022 vyřazena a již není podporována. Instalace Azure AD Connect V1 může neočekávaně přestat fungovat. Pokud stále používáte Azure AD Connect V1, musíte provést upgrade nebo zvážit přechod na Microsoft Entra Cloud Sync.</span>
			
						<button type="button" class="elementor-alert-dismiss" aria-label="Zavřít toto upozornění.">
									<span aria-hidden="true">&times;</span>
							</button>
			
		</div>
						</div>
				</div>
				<div class="elementor-element elementor-element-3b050cd elementor-widget elementor-widget-text-editor" data-id="3b050cd" data-element_type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p><strong>Systémy Windows Server 2012 a Windows Server 2012 R2 již nejsou podporovány.</strong></p><p>SQL Server 2019 vyžaduje jako serverový <strong>operační systém Windows Server 2016 nebo</strong> novější. Vzhledem k tomu, že Microsoft Entra Connect v2 obsahuje komponenty SQL Serveru 2019, nejsou již podporovány starší verze Windows Server.</p><p><strong>SQL Server 2019 LocalDB</strong></p><p>Předchozí verze Microsoft Entra Connect byly dodávány s SQL Server 2012 LocalDB. Verze V2.0 se dodává s SQL Server 2019 LocalDB, která slibuje vyšší stabilitu a výkon a obsahuje několik oprav chyb souvisejících se zabezpečením. SQL Server 2012 ukončila rozšířenou podporu v červenci 2022.</p><p><strong>Visual C++ Redist 14</strong></p><p>SQL Server 2019 vyžaduje prostředí Visual C++ Redist 14. Tento Redistributable je nainstalován spolu s balíčkem Microsoft Entra Connect V2, takže pro aktualizaci prostředí C++ nemusíte podnikat žádné kroky.</p><p><strong>TLS 1.2</strong></p><p><strong>Protokoly TLS1.0 a TLS 1.1 jsou považovány za nebezpečné</strong>. Společnost Microsoft je vyřazuje. Tato verze <strong>Microsoft Entra Connect podporuje pouze protokol TLS 1.2</strong>. Všechny verze systému Windows Server, které jsou podporovány pro Microsoft Entra Connect V2, již standardně používají protokol TLS 1.2. Pokud váš server nepodporuje protokol TLS 1.2, budete jej muset před nasazením aplikace Microsoft Entra Connect V2 povolit.</p><p><strong>PowerShell 5.0</strong></p><p>Tato verze Microsoft Entra Connect obsahuje několik rutin, které vyžadují PowerShell 5.0, takže tento požadavek je novou podmínkou pro Microsoft Entra Connect.</p><p><strong>Požadavky na Active Directory</strong></p><ul><li>Verze schématu služby Active Directory a <strong>funkční úroveň</strong> doménové struktury musí být <strong>Windows Server 2003 nebo novější</strong>.</li><li>Řadiče domény mohou používat libovolnou verzi, pokud jsou splněny požadavky na verzi schématu a úroveň doménové struktury. Pokud potřebujete provozovat Active Dorectory se systémem Windows Server 2016 nebo starším, může být zapotřebí <a href="https://learn.microsoft.com/en-us/lifecycle/policies/fixed#extended-support" target="_blank" rel="noopener">placený program podpory</a>.</li><li><strong>Řadič domény</strong> používaný nástrojem Microsoft Entra ID <strong>musí být zapisovatelný</strong>. Použití řadiče domény pouze pro čtení (RODC) není podporováno.</li><li>Používání lokálních doménových struktur nebo domén pomocí &#8222;tečkovaných&#8220; (název obsahuje tečku &#8222;.&#8220;) názvů NetBIOS není podporováno.</li><li>Doporučuje se povolit koš služby Active Directory.</li></ul>								</div>
				</div>
				<div class="elementor-element elementor-element-8f4b231 elementor-widget elementor-widget-heading" data-id="8f4b231" data-element_type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h2 class="elementor-heading-title elementor-size-default">Užitečné odkazy
</h2>				</div>
				</div>
				<div class="elementor-element elementor-element-817e2ee elementor-icon-list--layout-traditional elementor-list-item-link-full_width elementor-widget elementor-widget-icon-list" data-id="817e2ee" data-element_type="widget" data-widget_type="icon-list.default">
				<div class="elementor-widget-container">
							<ul class="elementor-icon-list-items">
							<li class="elementor-icon-list-item">
											<a href="http://Consider%20moving%20to%20Microsoft%20Entra%20Cloud%20Sync" target="_blank">

												<span class="elementor-icon-list-icon">
							<svg aria-hidden="true" class="e-font-icon-svg e-fas-dot-circle" viewBox="0 0 512 512" xmlns="http://www.w3.org/2000/svg"><path d="M256 8C119.033 8 8 119.033 8 256s111.033 248 248 248 248-111.033 248-248S392.967 8 256 8zm80 248c0 44.112-35.888 80-80 80s-80-35.888-80-80 35.888-80 80-80 80 35.888 80 80z"></path></svg>						</span>
										<span class="elementor-icon-list-text">Consider moving to Microsoft Entra Cloud Sync</span>
											</a>
									</li>
								<li class="elementor-icon-list-item">
											<a href="https://learn.microsoft.com/en-us/entra/identity/hybrid/connect/how-to-connect-install-prerequisites" target="_blank" rel="noopener">

												<span class="elementor-icon-list-icon">
							<svg aria-hidden="true" class="e-font-icon-svg e-fas-dot-circle" viewBox="0 0 512 512" xmlns="http://www.w3.org/2000/svg"><path d="M256 8C119.033 8 8 119.033 8 256s111.033 248 248 248 248-111.033 248-248S392.967 8 256 8zm80 248c0 44.112-35.888 80-80 80s-80-35.888-80-80 35.888-80 80-80 80 35.888 80 80z"></path></svg>						</span>
										<span class="elementor-icon-list-text">Prerequisites for Microsoft Entra Connect</span>
											</a>
									</li>
						</ul>
						</div>
				</div>
					</div>
				</div>
				</div>
		]]></content:encoded>
					
					<wfw:commentRss>https://www.sraga.cz/entra-ad-connect-presun-na-novy-server/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Entra AD Sync (Azure AD Sync) &#8211; In-place upgrade + Health Agent</title>
		<link>https://www.sraga.cz/entra-ad-sync-in-place-upgrade-health-agent/</link>
					<comments>https://www.sraga.cz/entra-ad-sync-in-place-upgrade-health-agent/#respond</comments>
		
		<dc:creator><![CDATA[c]]></dc:creator>
		<pubDate>Wed, 07 Feb 2024 09:35:56 +0000</pubDate>
				<category><![CDATA[Azure AD / Entra ID]]></category>
		<category><![CDATA[AD Sync]]></category>
		<category><![CDATA[Azure AD Connect]]></category>
		<category><![CDATA[Entra Connect]]></category>
		<guid isPermaLink="false">https://www.sraga.cz/?p=122</guid>

					<description><![CDATA[V posledním týdnu se mi ozvalo několik klientů, kterým přestala fungovat synchronizace. Ve všech případech se jednalo to problém staré verze AD Connect, kdy Microsoft oznámil, že v říjnu 2023 již nebude staré verze podporovat a evidentně v posledních dnech a týdnech začal podporu zastaralých aplikací také skutečně vypínat. V tomto návodu krok po kroku ... <a title="Entra AD Sync (Azure AD Sync) &#8211; In-place upgrade + Health Agent" class="read-more" href="https://www.sraga.cz/entra-ad-sync-in-place-upgrade-health-agent/" aria-label="Číst více o Entra AD Sync (Azure AD Sync) &#8211; In-place upgrade + Health Agent">Číst dál</a>]]></description>
										<content:encoded><![CDATA[		<div data-elementor-type="wp-post" data-elementor-id="122" class="elementor elementor-122" data-elementor-post-type="post">
				<div class="elementor-element elementor-element-8c24ef9 e-flex e-con-boxed e-con e-parent" data-id="8c24ef9" data-element_type="container">
					<div class="e-con-inner">
				<div class="elementor-element elementor-element-78645fb elementor-widget elementor-widget-text-editor" data-id="78645fb" data-element_type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p>V posledním týdnu se mi ozvalo několik klientů, kterým přestala fungovat synchronizace. Ve všech případech se jednalo to problém staré verze AD Connect, kdy Microsoft oznámil, že v říjnu 2023 již nebude staré verze podporovat a evidentně v posledních dnech a týdnech začal podporu zastaralých aplikací také skutečně vypínat.</p><p>V tomto návodu krok po kroku ukazuji, jak</p><ul><li>provést inplace upgrade na poslední verzi Entra AD Sync</li><li>zkontrolovat stav synchronizace</li><li>zkontrolovat stav Health Agenta</li><li>registrace Healts agenta</li><li>ruční spuštění rozdílové synchronizace (Delta )</li></ul>								</div>
				</div>
				<div class="elementor-element elementor-element-0feab94 elementor-alert-info elementor-widget elementor-widget-alert" data-id="0feab94" data-element_type="widget" data-widget_type="alert.default">
				<div class="elementor-widget-container">
							<div class="elementor-alert" role="alert">

						<span class="elementor-alert-title">Informace</span>
			
						<span class="elementor-alert-description">Synchronizace přestane fungovat 1. října 2023 pro všechny zákazníky, kteří stále používají Microsoft Entra Connect V1 (a starší AD Connect).  Zákazníci používající cloudovou synchronizaci Microsoft Entra Connect nebo Microsoft Entra Connect V2 zůstanou plně funkční bez nutnosti jakékoli akce.</span>
			
						<button type="button" class="elementor-alert-dismiss" aria-label="Zavřít toto upozornění.">
									<span aria-hidden="true">&times;</span>
							</button>
			
		</div>
						</div>
				</div>
				<div class="elementor-element elementor-element-2ce0c21 elementor-alert-warning elementor-widget elementor-widget-alert" data-id="2ce0c21" data-element_type="widget" data-widget_type="alert.default">
				<div class="elementor-widget-container">
							<div class="elementor-alert" role="alert">

						<span class="elementor-alert-title">Toto je upozornění</span>
			
						<span class="elementor-alert-description">In-place funguje při přechodu z Azure AD Sync nebo Microsoft Entra Connect. Nefunguje při přechodu z DirSync.</span>
			
						<button type="button" class="elementor-alert-dismiss" aria-label="Zavřít toto upozornění.">
									<span aria-hidden="true">&times;</span>
							</button>
			
		</div>
						</div>
				</div>
				<div class="elementor-element elementor-element-a707779 elementor-widget elementor-widget-text-editor" data-id="a707779" data-element_type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p>Tato metoda je vhodná, pokud máte jeden server a méně než 100 000 objektů. Pokud používáte vlastní pravidla pro synchronizaci, doporučuji udělat jejich zálohu, neboť upgrade může tato pravidla resetovat do výchozího nastavení.</p>								</div>
				</div>
				<div class="elementor-element elementor-element-c3fcfd6 elementor-widget elementor-widget-video" data-id="c3fcfd6" data-element_type="widget" data-settings="{&quot;youtube_url&quot;:&quot;https:\/\/youtu.be\/MrmG8gkpo18?si=vhi-1AqtAGeMBMqb&quot;,&quot;video_type&quot;:&quot;youtube&quot;,&quot;controls&quot;:&quot;yes&quot;}" data-widget_type="video.default">
				<div class="elementor-widget-container">
							<div class="elementor-wrapper elementor-open-inline">
			<div class="elementor-video"></div>		</div>
						</div>
				</div>
					</div>
				</div>
				</div>
		]]></content:encoded>
					
					<wfw:commentRss>https://www.sraga.cz/entra-ad-sync-in-place-upgrade-health-agent/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Užitečné příkazy pro Azure AD Connect / Entra connect</title>
		<link>https://www.sraga.cz/uzitecne-prikazy-pro-azure-ad-connect-entra-connect/</link>
					<comments>https://www.sraga.cz/uzitecne-prikazy-pro-azure-ad-connect-entra-connect/#respond</comments>
		
		<dc:creator><![CDATA[c]]></dc:creator>
		<pubDate>Wed, 07 Feb 2024 09:14:49 +0000</pubDate>
				<category><![CDATA[Nezařazené]]></category>
		<category><![CDATA[AD Sync]]></category>
		<category><![CDATA[Azure AD Connect]]></category>
		<category><![CDATA[Entra Connect]]></category>
		<category><![CDATA[PowerShell]]></category>
		<guid isPermaLink="false">https://www.sraga.cz/?p=102</guid>

					<description><![CDATA[Zjištění aktuální verze AD Connect / Entra Connect Ruční spuštění rozdílové synchronizace Vynucení kompletní synchronizace (full sync) Plnou synchronizaci služby provádějte jen zřídka. Úplná synchronizace služby Entra ID (Azure AD) trvá dlouho, protože prochází všechny objekty služby Active Directory a znovu je synchronizuje. Snad jediným případem použití, kdy je třeba provést úplnou synchronizaci, je změna ... <a title="Užitečné příkazy pro Azure AD Connect / Entra connect" class="read-more" href="https://www.sraga.cz/uzitecne-prikazy-pro-azure-ad-connect-entra-connect/" aria-label="Číst více o Užitečné příkazy pro Azure AD Connect / Entra connect">Číst dál</a>]]></description>
										<content:encoded><![CDATA[		<div data-elementor-type="wp-post" data-elementor-id="102" class="elementor elementor-102" data-elementor-post-type="post">
				<div class="elementor-element elementor-element-9d4bf01 e-flex e-con-boxed e-con e-parent" data-id="9d4bf01" data-element_type="container">
					<div class="e-con-inner">
				<div class="elementor-element elementor-element-5a4f631 elementor-widget elementor-widget-heading" data-id="5a4f631" data-element_type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h2 class="elementor-heading-title elementor-size-default">Zjištění aktuální verze AD Connect / Entra Connect</h2>				</div>
				</div>
				<div class="elementor-element elementor-element-86eaff8 elementor-widget elementor-widget-code-highlight" data-id="86eaff8" data-element_type="widget" data-widget_type="code-highlight.default">
				<div class="elementor-widget-container">
							<div class="prismjs-default copy-to-clipboard ">
			<pre data-line="" class="highlight-height language-javascript line-numbers">
				<code readonly="true" class="language-javascript">
					<xmp>(Get-ADSyncGlobalSettingsParameter | Where-Object { $_.Name -eq 'Microsoft.Synchronize.ServerConfigurationVersion'}).Value</xmp>
				</code>
			</pre>
		</div>
						</div>
				</div>
				<div class="elementor-element elementor-element-a641ceb elementor-widget elementor-widget-heading" data-id="a641ceb" data-element_type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h2 class="elementor-heading-title elementor-size-default">Ruční spuštění rozdílové synchronizace</h2>				</div>
				</div>
				<div class="elementor-element elementor-element-44f3c38 elementor-widget elementor-widget-code-highlight" data-id="44f3c38" data-element_type="widget" data-widget_type="code-highlight.default">
				<div class="elementor-widget-container">
							<div class="prismjs-default copy-to-clipboard ">
			<pre data-line="" class="highlight-height language-javascript line-numbers">
				<code readonly="true" class="language-javascript">
					<xmp>Start-ADSyncSyncCycle -PolicyType Delta
</xmp>
				</code>
			</pre>
		</div>
						</div>
				</div>
				<div class="elementor-element elementor-element-444c87a elementor-widget elementor-widget-heading" data-id="444c87a" data-element_type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h2 class="elementor-heading-title elementor-size-default">Vynucení kompletní synchronizace (full sync)</h2>				</div>
				</div>
				<div class="elementor-element elementor-element-33981c0 elementor-widget elementor-widget-text-editor" data-id="33981c0" data-element_type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p>Plnou synchronizaci služby provádějte jen zřídka. Úplná synchronizace služby Entra ID (Azure AD) <strong>trvá dlouho</strong>, protože prochází všechny objekty služby Active Directory a znovu je synchronizuje. Snad jediným případem použití, kdy je třeba provést úplnou synchronizaci, je změna konfigurace služby Entra Connect (Azure AD Connect).</p><p>Nicméně v případě, že opravdu chcete spustit úplnou synchronizaci, použijte tento příkaz:</p>								</div>
				</div>
				<div class="elementor-element elementor-element-6ac3622 elementor-widget elementor-widget-code-highlight" data-id="6ac3622" data-element_type="widget" data-widget_type="code-highlight.default">
				<div class="elementor-widget-container">
							<div class="prismjs-default copy-to-clipboard ">
			<pre data-line="" class="highlight-height language-javascript line-numbers">
				<code readonly="true" class="language-javascript">
					<xmp>Start-ADSyncSyncCycle -PolicyType Initial
</xmp>
				</code>
			</pre>
		</div>
						</div>
				</div>
				<div class="elementor-element elementor-element-7a64d3f elementor-widget elementor-widget-heading" data-id="7a64d3f" data-element_type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h2 class="elementor-heading-title elementor-size-default">Zobrazení stavu a nastavení plánovače</h2>				</div>
				</div>
				<div class="elementor-element elementor-element-1ddc14a elementor-widget elementor-widget-code-highlight" data-id="1ddc14a" data-element_type="widget" data-widget_type="code-highlight.default">
				<div class="elementor-widget-container">
							<div class="prismjs-default copy-to-clipboard ">
			<pre data-line="" class="highlight-height language-javascript line-numbers">
				<code readonly="true" class="language-javascript">
					<xmp>Get-ADSyncScheduler</xmp>
				</code>
			</pre>
		</div>
						</div>
				</div>
				<div class="elementor-element elementor-element-3cf71d5 elementor-widget elementor-widget-heading" data-id="3cf71d5" data-element_type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h2 class="elementor-heading-title elementor-size-default">Kontrola integrace Entra Connect Health Agent</h2>				</div>
				</div>
				<div class="elementor-element elementor-element-eb28a05 elementor-widget elementor-widget-code-highlight" data-id="eb28a05" data-element_type="widget" data-widget_type="code-highlight.default">
				<div class="elementor-widget-container">
							<div class="prismjs-default copy-to-clipboard ">
			<pre data-line="" class="highlight-height language-javascript line-numbers">
				<code readonly="true" class="language-javascript">
					<xmp>Test-AzureADConnectHealthConnectivity -Role Sync

Test-AzureADConnectHealthConnectivity -Role ADDS

Test-AzureADConnectHealthConnectivity -Role Sync -ShowResult</xmp>
				</code>
			</pre>
		</div>
						</div>
				</div>
				<div class="elementor-element elementor-element-380c111 elementor-widget elementor-widget-heading" data-id="380c111" data-element_type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h2 class="elementor-heading-title elementor-size-default">Ruční registrace Microsoft Entra Connect Health agent</h2>				</div>
				</div>
				<div class="elementor-element elementor-element-0fb94c0 elementor-alert-warning elementor-widget elementor-widget-alert" data-id="0fb94c0" data-element_type="widget" data-widget_type="alert.default">
				<div class="elementor-widget-container">
							<div class="elementor-alert" role="alert">

						<span class="elementor-alert-title">Pozor</span>
			
						<span class="elementor-alert-description">Tento příkaz použít pouze, pokud registrace agenta (při instalaci Microsoft Entra Connect) skončí chybou.</span>
			
						<button type="button" class="elementor-alert-dismiss" aria-label="Zavřít toto upozornění.">
									<span aria-hidden="true">&times;</span>
							</button>
			
		</div>
						</div>
				</div>
				<div class="elementor-element elementor-element-82356f4 elementor-widget elementor-widget-code-highlight" data-id="82356f4" data-element_type="widget" data-widget_type="code-highlight.default">
				<div class="elementor-widget-container">
							<div class="prismjs-default copy-to-clipboard ">
			<pre data-line="" class="highlight-height language-javascript line-numbers">
				<code readonly="true" class="language-javascript">
					<xmp>Register-AzureADConnectHealthSyncAgent -AttributeFiltering $true -StagingMode $false
</xmp>
				</code>
			</pre>
		</div>
						</div>
				</div>
				<div class="elementor-element elementor-element-b61a39e elementor-widget elementor-widget-text-editor" data-id="b61a39e" data-element_type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p>Jedná se o ruční registraci agenta Microsoft Entra Connect Health pro synchronizaci. Po úspěšné registraci agenta se spustí služby Microsoft Entra Connect Health.</p><p><strong>AttributeFiltering: $true</strong> (výchozí), pokud Microsoft Entra Connect <strong>nesynchronizuje výchozí sadu atributů</strong> a byl přizpůsoben tak, aby používal filtrovanou sadu atributů. V opačném případě použijte $false.</p><p><strong>StagingMode: $false</strong> (výchozí), pokud server Microsoft Entra Connect <strong>není</strong> v režimu staging. Pokud je server nakonfigurován tak, aby byl v režimu staging, použijte $true.</p><p>Dokumentace: <a href="https://learn.microsoft.com/en-us/entra/identity/hybrid/connect/how-to-connect-health-agent-install#manually-register-microsoft-entra-connect-health-for-sync" target="_blank" rel="noopener">https://learn.microsoft.com/en-us/entra/identity/hybrid/connect/how-to-connect-health-agent-install#manually-register-microsoft-entra-connect-health-for-sync</a></p>								</div>
				</div>
				<div class="elementor-element elementor-element-ea0f22a elementor-widget elementor-widget-video" data-id="ea0f22a" data-element_type="widget" data-settings="{&quot;youtube_url&quot;:&quot;https:\/\/youtu.be\/MrmG8gkpo18?si=Z0H9sb3VwV5Xm3Ym&quot;,&quot;start&quot;:153,&quot;video_type&quot;:&quot;youtube&quot;,&quot;controls&quot;:&quot;yes&quot;}" data-widget_type="video.default">
				<div class="elementor-widget-container">
							<div class="elementor-wrapper elementor-open-inline">
			<div class="elementor-video"></div>		</div>
						</div>
				</div>
				<div class="elementor-element elementor-element-e0c9759 elementor-widget elementor-widget-heading" data-id="e0c9759" data-element_type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h2 class="elementor-heading-title elementor-size-default">Zapnutí / vypnutí Staging mode</h2>				</div>
				</div>
				<div class="elementor-element elementor-element-193c58f elementor-widget elementor-widget-code-highlight" data-id="193c58f" data-element_type="widget" data-widget_type="code-highlight.default">
				<div class="elementor-widget-container">
							<div class="prismjs-default copy-to-clipboard ">
			<pre data-line="" class="highlight-height language-javascript line-numbers">
				<code readonly="true" class="language-javascript">
					<xmp># Načtení parametrů nastavení
$AADSyncGlobalSettings=Get-ADSyncGlobalSettings

# zobrazit parametry
$AADSyncGlobalSettings.parameters

# vypnout Staging mode
($AADSyncGlobalSettings.parameters | ?{$_.name -eq "Microsoft.Synchronize.StagingMode"}).value="False"

# zapnout Staging mode
($AADSyncGlobalSettings.parameters | ?{$_.name -eq "Microsoft.Synchronize.StagingMode"}).value="True"

# Uložit nastavení !!!
Set-ADSyncGlobalSettings $AADSyncGlobalSettings
</xmp>
				</code>
			</pre>
		</div>
						</div>
				</div>
				<div class="elementor-element elementor-element-7529e12 elementor-widget elementor-widget-heading" data-id="7529e12" data-element_type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h2 class="elementor-heading-title elementor-size-default">Změna plánu synchronizace</h2>				</div>
				</div>
				<div class="elementor-element elementor-element-126aae9 elementor-widget elementor-widget-text-editor" data-id="126aae9" data-element_type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p><strong>Výchozí nastavení synchronizace je 30 minut</strong>. Změny času synchronizace služby Entra Connect se provádějí pomocí příkazu <strong>Set-ADSyncScheduler</strong>.</p><p>Je však důležité si uvědomit, že pro plán synchronizace <strong>existují horní a dolní limity</strong>. Například plán synchronizace musí být spuštěn alespoň jednou za 7 dní. Kromě toho se synchronizační cyklus spouští pouze jednou za 30 minut. Nyní, s ohledem na tato omezení, použijme rutinu<strong> Set-ADSyncScheduler</strong> ke změně plánu na cyklus např. jednou za 2 hodiny:</p>								</div>
				</div>
				<div class="elementor-element elementor-element-4e4da13 elementor-widget elementor-widget-code-highlight" data-id="4e4da13" data-element_type="widget" data-widget_type="code-highlight.default">
				<div class="elementor-widget-container">
							<div class="prismjs-default copy-to-clipboard ">
			<pre data-line="" class="highlight-height language-javascript line-numbers">
				<code readonly="true" class="language-javascript">
					<xmp># Spusteni kazde 3 hodiny
Set-ADSyncScheduler -CustomizedSyncCycleInterval 03:00:00

# Spusteni 1x denne
Set-ADSyncScheduler -CustomizedSyncCycleInterval 1.0:0:0

#Syntaxe: Set-ADSyncScheduler -CustomizedSyncCycleInterval d.HH:mm:ss
#d - dny, HH - hodiny, mm - minuty, ss - sekundy
</xmp>
				</code>
			</pre>
		</div>
						</div>
				</div>
				<div class="elementor-element elementor-element-7c7dd44 elementor-widget elementor-widget-heading" data-id="7c7dd44" data-element_type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h2 class="elementor-heading-title elementor-size-default">Vypnutí a zapnutí synchronizace</h2>				</div>
				</div>
				<div class="elementor-element elementor-element-7e94f1c elementor-widget elementor-widget-code-highlight" data-id="7e94f1c" data-element_type="widget" data-widget_type="code-highlight.default">
				<div class="elementor-widget-container">
							<div class="prismjs-default copy-to-clipboard ">
			<pre data-line="" class="highlight-height language-javascript line-numbers">
				<code readonly="true" class="language-javascript">
					<xmp># Vypnuti synchronizace
Set-ADSyncScheduler -SyncCycleEnabled $false

# Zapnuti synchronizace
Set-ADSyncScheduler -SyncCycleEnabled $true</xmp>
				</code>
			</pre>
		</div>
						</div>
				</div>
				<div class="elementor-element elementor-element-401e29f elementor-widget elementor-widget-heading" data-id="401e29f" data-element_type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h2 class="elementor-heading-title elementor-size-default">Deletion trehsold exceeded</h2>				</div>
				</div>
				<div class="elementor-element elementor-element-8657af3 elementor-widget elementor-widget-text-editor" data-id="8657af3" data-element_type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p>Pokud při synchronizaci narazíte na problém, že se nemažou z Entra ID staré objekty, které se již nemjí synchronizovat, podívejte se do Synchronization Service Manager, zda-li náhodou neuvidíte ve sloupci Status informaci &#8222;<strong>stopped-deletion-treshold-exceeded</strong>&#8222;. Tato chyba značí, že se synchronizační proces szaží z Entra ID odebrat větší množství objektů, než je jeho limit. Toto lze vyřešit pomocí těchto příkazů:</p>								</div>
				</div>
				<div class="elementor-element elementor-element-7cbecea elementor-widget elementor-widget-image" data-id="7cbecea" data-element_type="widget" data-widget_type="image.default">
				<div class="elementor-widget-container">
																<a href="https://www.sraga.cz/wp-content/uploads/2024/02/entra-stopped-deletion-treshold-exceeded.png" data-elementor-open-lightbox="yes" data-elementor-lightbox-title="entra-stopped-deletion-treshold-exceeded" data-e-action-hash="#elementor-action%3Aaction%3Dlightbox%26settings%3DeyJpZCI6Njk4LCJ1cmwiOiJodHRwczpcL1wvd3d3LnNyYWdhLmN6XC93cC1jb250ZW50XC91cGxvYWRzXC8yMDI0XC8wMlwvZW50cmEtc3RvcHBlZC1kZWxldGlvbi10cmVzaG9sZC1leGNlZWRlZC5wbmcifQ%3D%3D">
							<img loading="lazy" decoding="async" width="768" height="345" src="https://www.sraga.cz/wp-content/uploads/2024/02/entra-stopped-deletion-treshold-exceeded-768x345.png" class="attachment-medium_large size-medium_large wp-image-698" alt="stopped-deletion-threshold-exceeded" srcset="https://www.sraga.cz/wp-content/uploads/2024/02/entra-stopped-deletion-treshold-exceeded-768x345.png 768w, https://www.sraga.cz/wp-content/uploads/2024/02/entra-stopped-deletion-treshold-exceeded-300x135.png 300w, https://www.sraga.cz/wp-content/uploads/2024/02/entra-stopped-deletion-treshold-exceeded.png 833w" sizes="(max-width: 768px) 100vw, 768px" />								</a>
															</div>
				</div>
				<div class="elementor-element elementor-element-ee3572b elementor-widget elementor-widget-code-highlight" data-id="ee3572b" data-element_type="widget" data-widget_type="code-highlight.default">
				<div class="elementor-widget-container">
							<div class="prismjs-default copy-to-clipboard ">
			<pre data-line="" class="highlight-height language-javascript line-numbers">
				<code readonly="true" class="language-javascript">
					<xmp># Zjisteni aktualniho limitu
Get-ADSyncExportDeletionThreshold


# Vypnuti limitu
Disable-ADSyncExportDeletionThreshold

# Opetovne zapnuti limitu
Enable-ADSyncExportDeletionThreshold -ThresholdCount 500
</xmp>
				</code>
			</pre>
		</div>
						</div>
				</div>
					</div>
				</div>
				</div>
		]]></content:encoded>
					
					<wfw:commentRss>https://www.sraga.cz/uzitecne-prikazy-pro-azure-ad-connect-entra-connect/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Jak zjistit aktuální verzi Microsoft Azure AD Connect  / Entra ID Connect</title>
		<link>https://www.sraga.cz/jak-zjistit-verzi-microsoft-azure-ad-connect-entra-id-connect/</link>
					<comments>https://www.sraga.cz/jak-zjistit-verzi-microsoft-azure-ad-connect-entra-id-connect/#respond</comments>
		
		<dc:creator><![CDATA[c]]></dc:creator>
		<pubDate>Wed, 07 Feb 2024 07:21:41 +0000</pubDate>
				<category><![CDATA[Azure AD / Entra ID]]></category>
		<category><![CDATA[AD Sync]]></category>
		<category><![CDATA[Azur AD Connect]]></category>
		<category><![CDATA[Entra Connect]]></category>
		<guid isPermaLink="false">https://www.sraga.cz/?p=60</guid>

					<description><![CDATA[Microsoft Entra Connect (dříve známý jako Azure AD Connect) je třeba pravidelně aktualizovat, protože společnost Microsoft pro něj vydává bezpečnostní opravy a vylepšení. V článku se dozvíte, jak zjistit verzi Azure AD Connect. Pozor! Microsoft upozorňuje, že synchronizace přestane fungovat 1. října 2023 pro všechny zákazníky, kteří stále používají Microsoft Entra Connect V1. Zákazníci používající ... <a title="Jak zjistit aktuální verzi Microsoft Azure AD Connect  / Entra ID Connect" class="read-more" href="https://www.sraga.cz/jak-zjistit-verzi-microsoft-azure-ad-connect-entra-id-connect/" aria-label="Číst více o Jak zjistit aktuální verzi Microsoft Azure AD Connect  / Entra ID Connect">Číst dál</a>]]></description>
										<content:encoded><![CDATA[		<div data-elementor-type="wp-post" data-elementor-id="60" class="elementor elementor-60" data-elementor-post-type="post">
				<div class="elementor-element elementor-element-a3ae106 e-flex e-con-boxed e-con e-parent" data-id="a3ae106" data-element_type="container">
					<div class="e-con-inner">
		<div class="elementor-element elementor-element-56ea8aa e-flex e-con-boxed e-con e-child" data-id="56ea8aa" data-element_type="container">
					<div class="e-con-inner">
				<div class="elementor-element elementor-element-5a43a18 elementor-widget elementor-widget-text-editor" data-id="5a43a18" data-element_type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p>Microsoft Entra Connect (dříve známý jako Azure AD Connect) je třeba pravidelně aktualizovat, protože společnost Microsoft pro něj vydává bezpečnostní opravy a vylepšení. V článku se dozvíte, jak zjistit verzi Azure AD Connect.</p>								</div>
				</div>
				<div class="elementor-element elementor-element-61109d4 elementor-alert-warning elementor-widget elementor-widget-alert" data-id="61109d4" data-element_type="widget" data-widget_type="alert.default">
				<div class="elementor-widget-container">
							<div class="elementor-alert" role="alert">

						<span class="elementor-alert-title">Pozor!</span>
			
						<span class="elementor-alert-description">Microsoft upozorňuje, že synchronizace přestane fungovat 1. října 2023 pro všechny zákazníky, kteří stále používají Microsoft Entra Connect V1.  Zákazníci používající cloudovou synchronizaci Microsoft Entra Connect nebo Microsoft Entra Connect V2 zůstanou plně funkční bez nutnosti jakékoli akce.</span>
			
			
		</div>
						</div>
				</div>
					</div>
				</div>
		<div class="elementor-element elementor-element-a962b77 e-flex e-con-boxed e-con e-child" data-id="a962b77" data-element_type="container">
					<div class="e-con-inner">
				<div class="elementor-element elementor-element-0a9e467 elementor-widget elementor-widget-heading" data-id="0a9e467" data-element_type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h2 class="elementor-heading-title elementor-size-default">Zjištění verze Microsoft Entra connect  přes Entra Admin centrum</h2>				</div>
				</div>
				<div class="elementor-element elementor-element-75f2d3c elementor-widget elementor-widget-text-editor" data-id="75f2d3c" data-element_type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<ol><li>Přihlaste se do <a href="https://entra.microsoft.com/" target="_blank" rel="noopener">Microsoft Entra Admin centra</a></li><li>Rozbalte nabídku <strong>Identity</strong></li><li>Dále rozbalte nabídku <strong>Hybrid management</strong></li><li>Klikněte na Microsoft <strong>Entra Connect</strong></li></ol>								</div>
				</div>
				<div class="elementor-element elementor-element-ef0aee6 elementor-widget elementor-widget-image" data-id="ef0aee6" data-element_type="widget" data-widget_type="image.default">
				<div class="elementor-widget-container">
																<a href="https://www.sraga.cz/wp-content/uploads/2024/02/Enta_version_1.png" data-elementor-open-lightbox="yes" data-elementor-lightbox-title="Enta_version_1" data-e-action-hash="#elementor-action%3Aaction%3Dlightbox%26settings%3DeyJpZCI6NzYsInVybCI6Imh0dHBzOlwvXC93d3cuc3JhZ2EuY3pcL3dwLWNvbnRlbnRcL3VwbG9hZHNcLzIwMjRcLzAyXC9FbnRhX3ZlcnNpb25fMS5wbmcifQ%3D%3D">
							<img loading="lazy" decoding="async" width="768" height="644" src="https://www.sraga.cz/wp-content/uploads/2024/02/Enta_version_1-768x644.png" class="attachment-medium_large size-medium_large wp-image-76" alt="Microsoft Entra Connect" srcset="https://www.sraga.cz/wp-content/uploads/2024/02/Enta_version_1-768x644.png 768w, https://www.sraga.cz/wp-content/uploads/2024/02/Enta_version_1-300x252.png 300w, https://www.sraga.cz/wp-content/uploads/2024/02/Enta_version_1-1024x859.png 1024w, https://www.sraga.cz/wp-content/uploads/2024/02/Enta_version_1.png 1229w" sizes="(max-width: 768px) 100vw, 768px" />								</a>
															</div>
				</div>
				<div class="elementor-element elementor-element-839901c elementor-widget elementor-widget-text-editor" data-id="839901c" data-element_type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p>5. V menu zvolte <strong>Connect Sync</strong><br />6. Scrolujte dolů na konec obrazovky a klikněte na <strong>Microsoft Entra Connect Health</strong></p>								</div>
				</div>
				<div class="elementor-element elementor-element-469df07 elementor-widget elementor-widget-image" data-id="469df07" data-element_type="widget" data-widget_type="image.default">
				<div class="elementor-widget-container">
																<a href="https://www.sraga.cz/wp-content/uploads/2024/02/Enta_version_2.png" data-elementor-open-lightbox="yes" data-elementor-lightbox-title="Enta_version_2" data-e-action-hash="#elementor-action%3Aaction%3Dlightbox%26settings%3DeyJpZCI6NzUsInVybCI6Imh0dHBzOlwvXC93d3cuc3JhZ2EuY3pcL3dwLWNvbnRlbnRcL3VwbG9hZHNcLzIwMjRcLzAyXC9FbnRhX3ZlcnNpb25fMi5wbmcifQ%3D%3D">
							<img loading="lazy" decoding="async" width="768" height="644" src="https://www.sraga.cz/wp-content/uploads/2024/02/Enta_version_2-768x644.png" class="attachment-medium_large size-medium_large wp-image-75" alt="Microsoft Entra Connect" srcset="https://www.sraga.cz/wp-content/uploads/2024/02/Enta_version_2-768x644.png 768w, https://www.sraga.cz/wp-content/uploads/2024/02/Enta_version_2-300x252.png 300w, https://www.sraga.cz/wp-content/uploads/2024/02/Enta_version_2-1024x858.png 1024w, https://www.sraga.cz/wp-content/uploads/2024/02/Enta_version_2.png 1231w" sizes="(max-width: 768px) 100vw, 768px" />								</a>
															</div>
				</div>
				<div class="elementor-element elementor-element-175fd5c elementor-widget elementor-widget-text-editor" data-id="175fd5c" data-element_type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p>7. Klikněte na <strong>Sync Services</strong><br />8. Vyberte <strong>Service Name</strong></p><p>Zkontrolujte Status, pokud používáte Health Agenta, měl by být Status Healthy.</p>								</div>
				</div>
				<div class="elementor-element elementor-element-0086fa9 elementor-widget elementor-widget-image" data-id="0086fa9" data-element_type="widget" data-widget_type="image.default">
				<div class="elementor-widget-container">
																<a href="https://www.sraga.cz/wp-content/uploads/2024/02/Enta_version_3.png" data-elementor-open-lightbox="yes" data-elementor-lightbox-title="Enta_version_3" data-e-action-hash="#elementor-action%3Aaction%3Dlightbox%26settings%3DeyJpZCI6NzQsInVybCI6Imh0dHBzOlwvXC93d3cuc3JhZ2EuY3pcL3dwLWNvbnRlbnRcL3VwbG9hZHNcLzIwMjRcLzAyXC9FbnRhX3ZlcnNpb25fMy5wbmcifQ%3D%3D">
							<img loading="lazy" decoding="async" width="768" height="644" src="https://www.sraga.cz/wp-content/uploads/2024/02/Enta_version_3-768x644.png" class="attachment-medium_large size-medium_large wp-image-74" alt="Microsoft Entra Connect" srcset="https://www.sraga.cz/wp-content/uploads/2024/02/Enta_version_3-768x644.png 768w, https://www.sraga.cz/wp-content/uploads/2024/02/Enta_version_3-300x252.png 300w, https://www.sraga.cz/wp-content/uploads/2024/02/Enta_version_3-1024x859.png 1024w, https://www.sraga.cz/wp-content/uploads/2024/02/Enta_version_3.png 1229w" sizes="(max-width: 768px) 100vw, 768px" />								</a>
															</div>
				</div>
				<div class="elementor-element elementor-element-ac1592f elementor-widget elementor-widget-text-editor" data-id="ac1592f" data-element_type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p>9. Zvolte <strong>Entra AD Connect Server</strong></p>								</div>
				</div>
				<div class="elementor-element elementor-element-e76c77a elementor-widget elementor-widget-image" data-id="e76c77a" data-element_type="widget" data-widget_type="image.default">
				<div class="elementor-widget-container">
															<img loading="lazy" decoding="async" width="900" height="755" src="https://www.sraga.cz/wp-content/uploads/2024/02/Enta_version_4-1024x859.png" class="attachment-large size-large wp-image-73" alt="Microsoft Entra Connect" srcset="https://www.sraga.cz/wp-content/uploads/2024/02/Enta_version_4-1024x859.png 1024w, https://www.sraga.cz/wp-content/uploads/2024/02/Enta_version_4-300x252.png 300w, https://www.sraga.cz/wp-content/uploads/2024/02/Enta_version_4-768x644.png 768w, https://www.sraga.cz/wp-content/uploads/2024/02/Enta_version_4.png 1229w" sizes="(max-width: 900px) 100vw, 900px" />															</div>
				</div>
				<div class="elementor-element elementor-element-5370d05 elementor-widget elementor-widget-text-editor" data-id="5370d05" data-element_type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p>10. Klikněte na <strong>Properties</strong></p>								</div>
				</div>
				<div class="elementor-element elementor-element-1ae3581 elementor-widget elementor-widget-image" data-id="1ae3581" data-element_type="widget" data-widget_type="image.default">
				<div class="elementor-widget-container">
																<a href="https://www.sraga.cz/wp-content/uploads/2024/02/Enta_version_5.png" data-elementor-open-lightbox="yes" data-elementor-lightbox-title="Enta_version_5" data-e-action-hash="#elementor-action%3Aaction%3Dlightbox%26settings%3DeyJpZCI6NzIsInVybCI6Imh0dHBzOlwvXC93d3cuc3JhZ2EuY3pcL3dwLWNvbnRlbnRcL3VwbG9hZHNcLzIwMjRcLzAyXC9FbnRhX3ZlcnNpb25fNS5wbmcifQ%3D%3D">
							<img loading="lazy" decoding="async" width="768" height="644" src="https://www.sraga.cz/wp-content/uploads/2024/02/Enta_version_5-768x644.png" class="attachment-medium_large size-medium_large wp-image-72" alt="Microsoft Entra Connect" srcset="https://www.sraga.cz/wp-content/uploads/2024/02/Enta_version_5-768x644.png 768w, https://www.sraga.cz/wp-content/uploads/2024/02/Enta_version_5-300x252.png 300w, https://www.sraga.cz/wp-content/uploads/2024/02/Enta_version_5-1024x859.png 1024w, https://www.sraga.cz/wp-content/uploads/2024/02/Enta_version_5.png 1229w" sizes="(max-width: 768px) 100vw, 768px" />								</a>
															</div>
				</div>
				<div class="elementor-element elementor-element-9938926 elementor-widget elementor-widget-text-editor" data-id="9938926" data-element_type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p>12. Klikněte na <strong>Synchronization</strong></p>								</div>
				</div>
				<div class="elementor-element elementor-element-a8359fe elementor-widget elementor-widget-image" data-id="a8359fe" data-element_type="widget" data-widget_type="image.default">
				<div class="elementor-widget-container">
															<img loading="lazy" decoding="async" width="900" height="754" src="https://www.sraga.cz/wp-content/uploads/2024/02/Enta_version_6-1024x858.png" class="attachment-large size-large wp-image-71" alt="Microsoft Entra Connect" srcset="https://www.sraga.cz/wp-content/uploads/2024/02/Enta_version_6-1024x858.png 1024w, https://www.sraga.cz/wp-content/uploads/2024/02/Enta_version_6-300x252.png 300w, https://www.sraga.cz/wp-content/uploads/2024/02/Enta_version_6-768x644.png 768w, https://www.sraga.cz/wp-content/uploads/2024/02/Enta_version_6.png 1231w" sizes="(max-width: 900px) 100vw, 900px" />															</div>
				</div>
				<div class="elementor-element elementor-element-2d92aa4 elementor-widget elementor-widget-text-editor" data-id="2d92aa4" data-element_type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p>13. Zkontrolujte parametr <strong>Version</strong>. V tomto případě se jedná o Entra Connect V2 verze 2.3.2.0</p>								</div>
				</div>
				<div class="elementor-element elementor-element-249c097 elementor-widget elementor-widget-image" data-id="249c097" data-element_type="widget" data-widget_type="image.default">
				<div class="elementor-widget-container">
																<a href="https://www.sraga.cz/wp-content/uploads/2024/02/Enta_version_7.png" data-elementor-open-lightbox="yes" data-elementor-lightbox-title="Enta_version_7" data-e-action-hash="#elementor-action%3Aaction%3Dlightbox%26settings%3DeyJpZCI6NzAsInVybCI6Imh0dHBzOlwvXC93d3cuc3JhZ2EuY3pcL3dwLWNvbnRlbnRcL3VwbG9hZHNcLzIwMjRcLzAyXC9FbnRhX3ZlcnNpb25fNy5wbmcifQ%3D%3D">
							<img loading="lazy" decoding="async" width="900" height="755" src="https://www.sraga.cz/wp-content/uploads/2024/02/Enta_version_7-1024x859.png" class="attachment-large size-large wp-image-70" alt="Microsoft Entra Connect" srcset="https://www.sraga.cz/wp-content/uploads/2024/02/Enta_version_7-1024x859.png 1024w, https://www.sraga.cz/wp-content/uploads/2024/02/Enta_version_7-300x252.png 300w, https://www.sraga.cz/wp-content/uploads/2024/02/Enta_version_7-768x644.png 768w, https://www.sraga.cz/wp-content/uploads/2024/02/Enta_version_7.png 1229w" sizes="(max-width: 900px) 100vw, 900px" />								</a>
															</div>
				</div>
				<div class="elementor-element elementor-element-d78e22c elementor-widget elementor-widget-heading" data-id="d78e22c" data-element_type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h2 class="elementor-heading-title elementor-size-default">Zjištění verze Microsoft Entra přes Synchronization Service Manager</h2>				</div>
				</div>
				<div class="elementor-element elementor-element-6ae682d elementor-widget elementor-widget-text-editor" data-id="6ae682d" data-element_type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<ol><li>Klikněte na <strong>Nabídku Start</strong></li><li>Použijte vyhledávání a zadejte <strong>Synchronization</strong> nebo najděte složku <strong>Azure AD Connect</strong> a rozbalte ji</li><li>Klikněte na <strong>Synchronization service</strong></li></ol>								</div>
				</div>
				<div class="elementor-element elementor-element-d415ccb elementor-widget elementor-widget-image" data-id="d415ccb" data-element_type="widget" data-widget_type="image.default">
				<div class="elementor-widget-container">
																<a href="https://www.sraga.cz/wp-content/uploads/2024/02/Entra_version_10.png" data-elementor-open-lightbox="yes" data-elementor-lightbox-title="Entra_version_10" data-e-action-hash="#elementor-action%3Aaction%3Dlightbox%26settings%3DeyJpZCI6OTcsInVybCI6Imh0dHBzOlwvXC93d3cuc3JhZ2EuY3pcL3dwLWNvbnRlbnRcL3VwbG9hZHNcLzIwMjRcLzAyXC9FbnRyYV92ZXJzaW9uXzEwLnBuZyJ9">
							<img loading="lazy" decoding="async" width="768" height="811" src="https://www.sraga.cz/wp-content/uploads/2024/02/Entra_version_10-768x811.png" class="attachment-medium_large size-medium_large wp-image-97" alt="Entra version 10" srcset="https://www.sraga.cz/wp-content/uploads/2024/02/Entra_version_10-768x811.png 768w, https://www.sraga.cz/wp-content/uploads/2024/02/Entra_version_10-284x300.png 284w, https://www.sraga.cz/wp-content/uploads/2024/02/Entra_version_10.png 779w" sizes="(max-width: 768px) 100vw, 768px">								</a>
															</div>
				</div>
				<div class="elementor-element elementor-element-346a2f9 elementor-widget elementor-widget-text-editor" data-id="346a2f9" data-element_type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p>4. V menu vyberte <strong>Help</strong> a <strong>About</strong></p>								</div>
				</div>
				<div class="elementor-element elementor-element-742c180 elementor-widget elementor-widget-image" data-id="742c180" data-element_type="widget" data-widget_type="image.default">
				<div class="elementor-widget-container">
																<a href="https://www.sraga.cz/wp-content/uploads/2024/02/Entra_version_11.png" data-elementor-open-lightbox="yes" data-elementor-lightbox-title="Entra_version_11" data-e-action-hash="#elementor-action%3Aaction%3Dlightbox%26settings%3DeyJpZCI6OTYsInVybCI6Imh0dHBzOlwvXC93d3cuc3JhZ2EuY3pcL3dwLWNvbnRlbnRcL3VwbG9hZHNcLzIwMjRcLzAyXC9FbnRyYV92ZXJzaW9uXzExLnBuZyJ9">
							<img loading="lazy" decoding="async" width="768" height="605" src="https://www.sraga.cz/wp-content/uploads/2024/02/Entra_version_11-768x605.png" class="attachment-medium_large size-medium_large wp-image-96" alt="Microsoft Entra Connect Version" srcset="https://www.sraga.cz/wp-content/uploads/2024/02/Entra_version_11-768x605.png 768w, https://www.sraga.cz/wp-content/uploads/2024/02/Entra_version_11-300x236.png 300w, https://www.sraga.cz/wp-content/uploads/2024/02/Entra_version_11.png 796w" sizes="(max-width: 768px) 100vw, 768px" />								</a>
															</div>
				</div>
				<div class="elementor-element elementor-element-a3ee644 elementor-widget elementor-widget-text-editor" data-id="a3ee644" data-element_type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p>5. Zobrazí se verze AD Connect</p>								</div>
				</div>
				<div class="elementor-element elementor-element-920a187 elementor-widget elementor-widget-image" data-id="920a187" data-element_type="widget" data-widget_type="image.default">
				<div class="elementor-widget-container">
																<a href="https://www.sraga.cz/wp-content/uploads/2024/02/Entra_version_12.png" data-elementor-open-lightbox="yes" data-elementor-lightbox-title="Entra_version_12" data-e-action-hash="#elementor-action%3Aaction%3Dlightbox%26settings%3DeyJpZCI6OTUsInVybCI6Imh0dHBzOlwvXC93d3cuc3JhZ2EuY3pcL3dwLWNvbnRlbnRcL3VwbG9hZHNcLzIwMjRcLzAyXC9FbnRyYV92ZXJzaW9uXzEyLnBuZyJ9">
							<img loading="lazy" decoding="async" width="768" height="605" src="https://www.sraga.cz/wp-content/uploads/2024/02/Entra_version_12-768x605.png" class="attachment-medium_large size-medium_large wp-image-95" alt="Microsoft Entra Connect Version" srcset="https://www.sraga.cz/wp-content/uploads/2024/02/Entra_version_12-768x605.png 768w, https://www.sraga.cz/wp-content/uploads/2024/02/Entra_version_12-300x236.png 300w, https://www.sraga.cz/wp-content/uploads/2024/02/Entra_version_12.png 796w" sizes="(max-width: 768px) 100vw, 768px" />								</a>
															</div>
				</div>
				<div class="elementor-element elementor-element-b42f4a0 elementor-widget elementor-widget-heading" data-id="b42f4a0" data-element_type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h2 class="elementor-heading-title elementor-size-default">Zjištění verze Microsoft Entra connect pomocí "Přidat /odebrat programy"</h2>				</div>
				</div>
				<div class="elementor-element elementor-element-3edfe04 elementor-widget elementor-widget-image" data-id="3edfe04" data-element_type="widget" data-widget_type="image.default">
				<div class="elementor-widget-container">
																<a href="https://www.sraga.cz/wp-content/uploads/2024/02/Entra_version_8.png" data-elementor-open-lightbox="yes" data-elementor-lightbox-title="Entra_version_8" data-e-action-hash="#elementor-action%3Aaction%3Dlightbox%26settings%3DeyJpZCI6ODgsInVybCI6Imh0dHBzOlwvXC93d3cuc3JhZ2EuY3pcL3dwLWNvbnRlbnRcL3VwbG9hZHNcLzIwMjRcLzAyXC9FbnRyYV92ZXJzaW9uXzgucG5nIn0%3D">
							<img loading="lazy" decoding="async" width="768" height="672" src="https://www.sraga.cz/wp-content/uploads/2024/02/Entra_version_8-768x672.png" class="attachment-medium_large size-medium_large wp-image-88" alt="Microsoft Entra Connect Version" srcset="https://www.sraga.cz/wp-content/uploads/2024/02/Entra_version_8-768x672.png 768w, https://www.sraga.cz/wp-content/uploads/2024/02/Entra_version_8-300x262.png 300w, https://www.sraga.cz/wp-content/uploads/2024/02/Entra_version_8.png 919w" sizes="(max-width: 768px) 100vw, 768px" />								</a>
															</div>
				</div>
				<div class="elementor-element elementor-element-e7f741c elementor-widget elementor-widget-text-editor" data-id="e7f741c" data-element_type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p>Otevřete <strong>Nastavení &#8211; Aplikace</strong></p><p><em>nebo</em></p><p>Ovládací panely &#8211; <strong>Programs and Features</strong></p>								</div>
				</div>
				<div class="elementor-element elementor-element-52b6874 elementor-widget elementor-widget-image" data-id="52b6874" data-element_type="widget" data-widget_type="image.default">
				<div class="elementor-widget-container">
																<a href="https://www.sraga.cz/wp-content/uploads/2024/02/Entra_version_9.png" data-elementor-open-lightbox="yes" data-elementor-lightbox-title="Entra_version_9" data-e-action-hash="#elementor-action%3Aaction%3Dlightbox%26settings%3DeyJpZCI6ODcsInVybCI6Imh0dHBzOlwvXC93d3cuc3JhZ2EuY3pcL3dwLWNvbnRlbnRcL3VwbG9hZHNcLzIwMjRcLzAyXC9FbnRyYV92ZXJzaW9uXzkucG5nIn0%3D">
							<img loading="lazy" decoding="async" width="768" height="358" src="https://www.sraga.cz/wp-content/uploads/2024/02/Entra_version_9-768x358.png" class="attachment-medium_large size-medium_large wp-image-87" alt="Microsoft Entra Connect Version" srcset="https://www.sraga.cz/wp-content/uploads/2024/02/Entra_version_9-768x358.png 768w, https://www.sraga.cz/wp-content/uploads/2024/02/Entra_version_9-300x140.png 300w, https://www.sraga.cz/wp-content/uploads/2024/02/Entra_version_9-1024x478.png 1024w, https://www.sraga.cz/wp-content/uploads/2024/02/Entra_version_9.png 1127w" sizes="(max-width: 768px) 100vw, 768px" />								</a>
															</div>
				</div>
				<div class="elementor-element elementor-element-a9cf43a elementor-widget elementor-widget-heading" data-id="a9cf43a" data-element_type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h2 class="elementor-heading-title elementor-size-default">Zjištění verze Microsoft Entra pomocí PowerShell</h2>				</div>
				</div>
				<div class="elementor-element elementor-element-2fe6dd4 elementor-widget elementor-widget-text-editor" data-id="2fe6dd4" data-element_type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<ol><li>Spusťte <strong>PowerShell</strong> s oprávněním <strong>Administrator</strong></li><li>Pokud nemáte, tak <strong>importujte modul ADSync</strong></li><li>Použijte příkaz <strong>Get-ADSyncGlobalSettings</strong></li></ol>								</div>
				</div>
				<div class="elementor-element elementor-element-bc58410 elementor-widget elementor-widget-code-highlight" data-id="bc58410" data-element_type="widget" data-widget_type="code-highlight.default">
				<div class="elementor-widget-container">
							<div class="prismjs-default copy-to-clipboard ">
			<pre data-line="" class="highlight-height language-javascript line-numbers">
				<code readonly="true" class="language-javascript">
					<xmp>Import-Module ADSync
(Get-ADSyncGlobalSettingsParameter | Where-Object { $_.Name -eq 'Microsoft.Synchronize.ServerConfigurationVersion'}).Value</xmp>
				</code>
			</pre>
		</div>
						</div>
				</div>
					</div>
				</div>
				<div class="elementor-element elementor-element-e31872e elementor-widget elementor-widget-heading" data-id="e31872e" data-element_type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h2 class="elementor-heading-title elementor-size-default">K dispozici je také video návod</h2>				</div>
				</div>
		<div class="elementor-element elementor-element-5e92f85 e-flex e-con-boxed e-con e-child" data-id="5e92f85" data-element_type="container">
					<div class="e-con-inner">
				<div class="elementor-element elementor-element-7c9e26c elementor-widget elementor-widget-video" data-id="7c9e26c" data-element_type="widget" data-settings="{&quot;youtube_url&quot;:&quot;https:\/\/youtu.be\/rmRlmoXRLz4&quot;,&quot;video_type&quot;:&quot;youtube&quot;,&quot;controls&quot;:&quot;yes&quot;}" data-widget_type="video.default">
				<div class="elementor-widget-container">
							<div class="elementor-wrapper elementor-open-inline">
			<div class="elementor-video"></div>		</div>
						</div>
				</div>
					</div>
				</div>
		<div class="elementor-element elementor-element-7ecce4d e-flex e-con-boxed e-con e-child" data-id="7ecce4d" data-element_type="container">
					<div class="e-con-inner">
				<div class="elementor-element elementor-element-4229490 elementor-widget elementor-widget-heading" data-id="4229490" data-element_type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h2 class="elementor-heading-title elementor-size-default">Užitečné odkazy</h2>				</div>
				</div>
					</div>
				</div>
				<div class="elementor-element elementor-element-df347b9 elementor-widget elementor-widget-text-editor" data-id="df347b9" data-element_type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<ul><li><a href="https://www.microsoft.com/en-us/download/details.aspx?id=47594" target="_blank" rel="noopener">Microsoft Entra Connect V2</a></li><li><a href="https://learn.microsoft.com/en-us/entra/identity/hybrid/connect/how-to-connect-health-agent-install" target="_blank" rel="noopener">Install the Microsoft Entra Connect Health agents</a></li></ul>								</div>
				</div>
					</div>
				</div>
				</div>
		]]></content:encoded>
					
					<wfw:commentRss>https://www.sraga.cz/jak-zjistit-verzi-microsoft-azure-ad-connect-entra-id-connect/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
