Skip to content
Summa Lai
Never Stop Learning, Building a Little Wiki…
Life is like riding a bicycle. To keep your balance, you must keep moving. But DON'T move too fast.
  • Home
  • Apple
  • Cloud
  • Linux
  • Microsoft
  • Networks
  • Solutions
  • TOOLS
  • Log In
  • About Me

How to Change the ADSync Service Account Password

Posted on August 6, 2024August 6, 2024 by Summa Lai

If you change the ADSync service account password, the Synchronization Service doesn’t start correctly until you abandon the encryption key and reinitialized the ADSync service account password.

Abandoning the ADSync service account encryption key

The following procedures only apply to Microsoft Entra Connect build 1.1.443.0 or older. This can’t be used for newer versions of Microsoft Entra Connect because abandoning the encryption key is handled by Microsoft Entra Connect itself when you change the AD sync service account password so the following steps are not needed in the newer versions.

Use the following procedures to abandon the encryption key.

What to do if you need to abandon the encryption key

If you need to abandon the encryption key, use the following procedures to accomplish that.

  1. Stop the Synchronization Service
  2. Abandon the existing encryption key
  3. Provide the password of the AD DS Connector account
  4. Reinitialize the password of the ADSync service account
  5. Start the Synchronization Service

Stop the Synchronization Service

First you can stop the service in the Windows Service Control Manager. Make sure that the service isn’t running when attempting to stop it. If it is, wait until it completes and then stop it.

  1. Go to Windows Service Control Manager (START → Services).
  2. Select Microsoft Entra ID Sync and click Stop.

Abandon the existing encryption key

Abandon the existing encryption key so that new encryption key can be created:

  1. Sign in to your Microsoft Entra Connect Server as administrator.
  2. Start a new PowerShell session.
  3. Navigate to folder: '$env:ProgramFiles\Microsoft Azure AD Sync\bin\'
  4. Run the command: ./miiskmu.exe /a
Screenshot that shows PowerShell after running the command.

Provide the password of the AD DS Connector account

As the existing passwords stored inside the database can no longer be decrypted, you need to provide the Synchronization Service with the password of the AD DS Connector account. The Synchronization Service encrypts the passwords using the new encryption key:

  1. Start the Synchronization Service Manager (START → Synchronization Service).
    Sync Service Manager
  2. Go to the Connectors tab.
  3. Select the AD Connector that corresponds to your on-premises AD. If you have more than one AD connector, repeat the following steps for each of them.
  4. Under Actions, select Properties.
  5. In the pop-up dialog, select Connect to Active Directory Forest:
  6. Enter the password of the AD DS account in the Password textbox. If you don’t know its password, you must set it to a known value before performing this step.
  7. Click OK to save the new password and close the pop-up dialog. Screenshot that shows the "Connect to Active Directory Forest" page in the "Properties" window.

Reinitialize the password of the Entra ID Connector account

You can’t directly provide the password of the Microsoft Entra service account to the Synchronization Service. Instead, you need to use the cmdlet Add-ADSyncAADServiceAccount to reinitialize the Microsoft Entra service account. The cmdlet resets the account password and makes it available to the Synchronization Service:

  1. Sign in to the Microsoft Entra Connect Sync server and open PowerShell.
  2. To provide the Microsoft Entra Global Administrator credentials, run $credential = Get-Credential.
  3. Run the cmdlet Add-ADSyncAADServiceAccount -AADCredential $credential.If the cmdlet is successful, the PowerShell command prompt appears.

The cmdlet resets the password for the service account and updates it both in Microsoft Entra ID and the sync engine.

Start the Synchronization Service

Now that the Synchronization Service has access to the encryption key and all the passwords it needs, you can restart the service in the Windows Service Control Manager:

  1. Go to Windows Service Control Manager (START → Services).
  2. Select Microsoft Entra ID Sync and click Restart.

Ref: Microsoft Entra Connect Sync: Changing the ADSync service account – Microsoft Entra ID | Microsoft Learn

Posted in Microsoft Family, Windows Servers Tagged Change the ADSync Service Account Password

Post navigation

← How to Mount an Azure File Share with Windows 10/11
How to Add Company Templates for All Users on Microsoft 365 →

Categories

  • About Me (1)
  • Apple (24)
    • Apple Devices (18)
    • iCloud (3)
    • Mac OS (7)
  • Certifications (21)
    • CCNP (21)
    • CompTIA A+ (2)
    • CompTIA Network+ (9)
  • Cloud (80)
    • AWS (2)
    • CloudFlare (2)
    • Google Cloud (19)
    • JumpCloud (1)
    • Microsoft 365 (49)
    • Oracle (1)
    • RADIUS (2)
  • Linux Family (57)
    • Apache (20)
    • CentOS (23)
    • PHP (3)
    • Putty / WinSCP (1)
    • Shopify (2)
    • WordPress (18)
  • Microsoft Family (537)
    • Autopilot / Intune (52)
    • Azure (94)
    • Compliance Portal (3)
    • Dymanic (2)
    • Exchange (13)
    • Hyper-V (1)
    • Microsoft Defender (6)
    • Microsoft Office (171)
    • Power BI (94)
    • PowerShell (15)
    • SQL (20)
    • Surface (3)
    • Teams / SharePoint (20)
    • Windows 7/8/10/11 (133)
    • Windows Servers (71)
  • Networks (122)
    • Adobe (1)
    • Darktrace (2)
    • Firewalls (21)
    • Google (12)
    • Hardware (21)
    • Meraki (1)
    • Mobile phones (5)
    • NordLayer (1)
    • Others (24)
    • Palo Alto (11)
    • Phones (1)
    • Router/Switch (26)
    • Ubiquiti (1)
    • Wi-Fi (9)
  • Oversea Living (26)
  • Solutions (51)
    • 1Password (2)
    • Adobe (2)
    • BI and Reporting (5)
    • BoardEffect (1)
    • eCommerce (8)
    • Forensics / Investigation (1)
    • Google Workspace (4)
    • IT Management (2)
    • KnowBe4 (1)
    • Password Management (5)
    • Project Management (2)
    • QuickBooks (1)
    • Sage (3)
  • Tools (15)
    • Atera (2)
    • Chocolatey (1)
    • Google (4)
    • PatchMyPC (3)
  • Travels (2)
  • Uncategorized (13)
  • VMware (2)

Recent Posts

  • How to View the Attribute Editor in Active Directory September 5, 2025
  • How to Unlock a User in BoardEffect September 4, 2025
  • How to Insert a Table of Contents with Office 365 June 19, 2025
  • Password Expiration Notification for Microsoft 365 Users May 1, 2025
  • How to Fix “Your organization does not allow external forwarding.” Microsoft 365 April 9, 2025
  • How to Check the Windows 11 Version and Build March 25, 2025
  • How to Remove Previously Granted Access to a User’s OneDrive February 13, 2025
  • How to Create a Milestone with Project for The Web February 4, 2025
  • How To Convert a .CRT Certificate into a .PEM or .PFX Format January 6, 2025
  • How to Deploy 1Password SCIM Bridge on Azure Container Apps January 2, 2025

Recent Comments

  • buy CBD on SUMMA LAI – NEVER STOP LEARNING

Archives

  • September 2025 (2)
  • June 2025 (1)
  • May 2025 (1)
  • April 2025 (1)
  • March 2025 (1)
  • February 2025 (2)
  • January 2025 (2)
  • December 2024 (2)
  • November 2024 (3)
  • October 2024 (4)
  • September 2024 (3)
  • August 2024 (7)
  • July 2024 (7)
  • June 2024 (4)
  • May 2024 (4)
  • April 2024 (1)
  • March 2024 (5)
  • February 2024 (7)
  • January 2024 (12)
  • December 2023 (7)
  • November 2023 (10)
  • October 2023 (8)
  • September 2023 (8)
  • August 2023 (6)
  • July 2023 (12)
  • June 2023 (15)
  • May 2023 (17)
  • April 2023 (18)
  • March 2023 (14)
  • February 2023 (17)
  • January 2023 (21)
  • December 2022 (17)
  • November 2022 (20)
  • October 2022 (18)
  • September 2022 (17)
  • August 2022 (17)
  • July 2022 (17)
  • June 2022 (18)
  • May 2022 (12)
  • March 2022 (11)
  • February 2022 (18)
  • January 2022 (22)
  • December 2021 (26)
  • November 2021 (22)
  • October 2021 (23)
  • September 2021 (24)
  • August 2021 (12)
  • July 2021 (14)
  • June 2021 (20)
  • May 2021 (23)
  • April 2021 (28)
  • March 2021 (24)
  • February 2021 (27)
  • January 2021 (28)
  • December 2020 (31)
  • November 2020 (13)
  • October 2020 (4)
  • September 2020 (3)
  • August 2020 (7)
  • July 2020 (23)
  • June 2020 (24)
  • May 2020 (21)
Copyright 2024, Privacy Policy
  • SUMMA LAI – NEVER STOP LEARNING