Uploaded image for project: 'Atlassian Guard'
  1. Atlassian Guard
  2. ACCESS-745

Provisioning: Azure AD - Sync. process is quarantined after a period of time

      Issue Summary

      After configuring provisioning as per the instructions here: Atlassian Cloud provisioning tutorial, the initial sync. works, but after a period of time the sync fails with this message on the Azure AD portal:

      Quarantined due to a high number of errors. Please view the audit logs below to assess the errors and remediate them. Sync interval reduced to once per 24 hours.​

      Environment

      • Azure Ad
      • Provisioning via SCIM

      Steps to Reproduce

      1. Configure provisioning with Azure AD as per the instructions here: Atlassian Cloud provisioning tutorial
      2. Select/check the "Clear current state and restart synchronization"
      3. Save the configuration
      4. The sync. process will start/complete
      5. Wait a while - testing has shown that sometime between 20mins and 2hrs the sync. will fail the message mentioned in the Issue Summary

      Expected Results

      • Sync. will continue to run

      Actual Results

      • This message is shown in the Provisioning configuration page on Azure AD:

        Quarantined due to a high number of errors. Please view the audit logs below to assess the errors and remediate them. Sync interval reduced to once per 24 hours.​

      • 401 responses from the Atlassian global proxy
      • In most cases, clicking "Test Connection" in Azure AD will return an error:

      Notes

      • You may need to switch between the two "Scope" options on the Azure AD configuration page i.e. toggle between "Sync all users and groups" and "Sync only assigned users and groups"
      • Checking "Clear current state and restart synchronization" may be necessary to reproduce the issue

      Workaround

      • Regenerate/rotate the API key(reference: User provisioning):
        1. Go to admin.atlassian.com and click your organization.
        2. Click Directory, then click User provisioning.
        3. Click the Directory tab, then click the Regenerate API key button.
        4. Click Regenerate key.
        5. Copy the organization ID and the API key to a safe place. Once you close the API key information screen, we won't show you this information again.
        6. Click Done.
      • Enter the new key into the "Secret Token" field on the Azure AD provisioning configuration page
      • Click "Test Connection" - the test should pass
      • Save the configuration
      • The sync. should restart

            [ACCESS-745] Provisioning: Azure AD - Sync. process is quarantined after a period of time

            Kat N added a comment -

            Hi everyone,
            Thank you for watching, following, and providing valuable feedback for our teams. Due to inactivity, we will be closing this bug as "Timed Out", but if this is still affecting your team, let us know on this ticket so we can potentially re-evaluate.

            Kat N added a comment - Hi everyone, Thank you for watching, following, and providing valuable feedback for our teams. Due to inactivity, we will be closing this bug as "Timed Out", but if this is still affecting your team, let us know on this ticket so we can potentially re-evaluate.

            Any update about this case?

            RAFAEL VALENTE GOMES MIRANDA added a comment - Any update about this case?

            Unfortunately, all the log says is:

            'Successful' 

             

            I can send the image from the error reproduction if you give me an email address or allow me to upload attachments to this ticket.

            Manuel Venegas added a comment - Unfortunately, all the log says is: 'Successful'     I can send the image from the error reproduction if you give me an email address or allow me to upload attachments to this ticket.

            Sai Majeti added a comment -

            Can you copy-paste any log section that contains the stacktrace or mentions about any Exception or Error ? 

            Sai Majeti added a comment - Can you copy-paste any log section that contains the stacktrace or mentions about any Exception  or  Error  ? 

            I'd like to attach them but I can't. Is there a way to get this info to you asap?

            Manuel Venegas added a comment - I'd like to attach them but I can't. Is there a way to get this info to you asap?

            f2210bf5ba12 does your azure logs mention any reason for these errors? 

            Sai Majeti added a comment - f2210bf5ba12  does your azure logs mention any reason for these errors? 

            Hi,

            Here's a screenshot of this error which we can still reproduce.

            Manuel Venegas added a comment - Hi, Here's a screenshot of this error which we can still reproduce.

            Sai Majeti added a comment -

            f2210bf5ba12, Microsoft replied back mentioning they fixed this issue and I was not able to reproduce this issue again on my testing env. We could close this issue no one else is experiencing this again. 

            Sai Majeti added a comment - f2210bf5ba12 , Microsoft replied back mentioning they fixed this issue and I was not able to reproduce this issue again on my testing env. We could close this issue no one else is experiencing this again. 

            Hi team,

            Are there any updates on the progress for this ticket?

            Manuel Venegas added a comment - Hi team, Are there any updates on the progress for this ticket?

            Sai Majeti added a comment -

            dnguyen4, I was able to reproduce this error yesterday but was successfully able to re sync multiple times today. 
            Can you try to reproduce this issue again on your end? 

            Sai Majeti added a comment - dnguyen4 , I was able to reproduce this error yesterday but was successfully able to re sync multiple times today.  Can you try to reproduce this issue again on your end? 

              yli2@atlassian.com Yang Li
              dnguyen4 Derrick Nguyen
              Affected customers:
              7 This affects my team
              Watchers:
              9 Start watching this issue

                Created:
                Updated:
                Resolved: