If you have your AD sync to Microsoft Azure and have installed the Active Directory connect, you may need to update, and here is how to do that
To see the status of sync, you can log in to the Microsoft admin portal at https://admin.microsoft.com
on the home page, you should see Sync Status, click on the Sync staus to get to the details page
data:image/s3,"s3://crabby-images/1b7ed/1b7ed87675dfe0701c2adea5f9e08cf78015ba88" alt=""
You should see something like this: Click on Microsoft Download Center or this link: https://www.microsoft.com/en-us/download/details.aspx?id=47594
data:image/s3,"s3://crabby-images/159c8/159c84723d11216672a2c605af3117694bd03755" alt=""
It will bring you to the Download page, read the requirements, and download to your software
data:image/s3,"s3://crabby-images/11961/11961f52b56df895b5d9b09af75713877cd8b633" alt=""
When you run the setup you may get an error message if you don’t have the TLS enabled
https://docs.microsoft.com/en-us/azure/active-directory/hybrid/reference-connect-tls-enforcement
data:image/s3,"s3://crabby-images/42721/427214731100b5a05ebf087519a32c1c36a363e9" alt=""
PowerShell command to enable TLS 1.2: got it from the link above, copy from Microsoft so you don’t have typo or if you know how to enable yourself do so
New-Item 'HKLM:SOFTWAREWOW6432NodeMicrosoft.NETFrameworkv4.0.30319' -Force | Out-Null
New-ItemProperty -path 'HKLM:SOFTWAREWOW6432NodeMicrosoft.NETFrameworkv4.0.30319' -name 'SystemDefaultTlsVersions' -value '1' -PropertyType 'DWord' -Force | Out-Null
New-ItemProperty -path 'HKLM:SOFTWAREWOW6432NodeMicrosoft.NETFrameworkv4.0.30319' -name 'SchUseStrongCrypto' -value '1' -PropertyType 'DWord' -Force | Out-Null
New-Item 'HKLM:SOFTWAREMicrosoft.NETFrameworkv4.0.30319' -Force | Out-Null
New-ItemProperty -path 'HKLM:SOFTWAREMicrosoft.NETFrameworkv4.0.30319' -name 'SystemDefaultTlsVersions' -value '1' -PropertyType 'DWord' -Force | Out-Null
New-ItemProperty -path 'HKLM:SOFTWAREMicrosoft.NETFrameworkv4.0.30319' -name 'SchUseStrongCrypto' -value '1' -PropertyType 'DWord' -Force | Out-Null
New-Item 'HKLM:SYSTEMCurrentControlSetControlSecurityProvidersSCHANNELProtocolsTLS 1.2Server' -Force | Out-Null
New-ItemProperty -path 'HKLM:SYSTEMCurrentControlSetControlSecurityProvidersSCHANNELProtocolsTLS 1.2Server' -name 'Enabled' -value '1' -PropertyType 'DWord' -Force | Out-Null
New-ItemProperty -path 'HKLM:SYSTEMCurrentControlSetControlSecurityProvidersSCHANNELProtocolsTLS 1.2Server' -name 'DisabledByDefault' -value 0 -PropertyType 'DWord' -Force | Out-Null
New-Item 'HKLM:SYSTEMCurrentControlSetControlSecurityProvidersSCHANNELProtocolsTLS 1.2Client' -Force | Out-Null
New-ItemProperty -path 'HKLM:SYSTEMCurrentControlSetControlSecurityProvidersSCHANNELProtocolsTLS 1.2Client' -name 'Enabled' -value '1' -PropertyType 'DWord' -Force | Out-Null
New-ItemProperty -path 'HKLM:SYSTEMCurrentControlSetControlSecurityProvidersSCHANNELProtocolsTLS 1.2Client' -name 'DisabledByDefault' -value 0 -PropertyType 'DWord' -Force | Out-Null
Write-Host 'TLS 1.2 has been enabled.'
Then re-run the AD Connect setup:
Note, if you have a big network, this may take some time, so do off-hours, because it will stop the sync of your AD until the upgrade is completed
data:image/s3,"s3://crabby-images/44d02/44d0275098490e38a388aaaa350ab981ebfab083" alt=""
You should see the upgrade process and synchronization
data:image/s3,"s3://crabby-images/0f2fa/0f2fa6c12928ad9f3433de031e4222a363dbd9de" alt=""
Then it will ask you for admin credentials:
data:image/s3,"s3://crabby-images/9e7c4/9e7c4a3c9b5e0a86bbc35e2e67af78893487813a" alt=""
If everything goes well you should see, Ready to configure, click Upgrade
data:image/s3,"s3://crabby-images/64524/64524662618a7515e016e3d577dd496d3e11487f" alt=""
Then, the configuration complete
data:image/s3,"s3://crabby-images/1788e/1788e6cdc25ac084678805c9fffa0a6c35b186f7" alt=""
now you can check the status on the admin page
data:image/s3,"s3://crabby-images/60ee7/60ee7d4f9fcbfe65a600130cf6e5c0230452093a" alt=""
That’s it, hope this helps someone