对 Azure AD Connect 中未同步的属性排除故障Troubleshoot an attribute not synchronizing in Azure AD Connect

在调查属性同步问题之前,先了解一下 Azure AD Connect 同步过程:Before investigating attribute syncing issues, let’s understand the Azure AD Connect syncing process:

Azure AD Connect 同步过程

术语Terminology

  • CS: 连接器空间,数据库中的一个表。CS: Connector Space, a table in database.
  • MV: Metaverse,数据库中的一个表。MV: Metaverse, a table in database.
  • AD: Active DirectoryAD: Active Directory
  • AAD: Azure Active DirectoryAAD: Azure Active Directory

同步步骤Synchronization Steps

  • 从 AD 导入:将 Active Directory 对象引入 AD CS。Import from AD: Active Directory objects are brought into AD CS.

  • 从 AAD 导入:将 Azure Active Directory 对象引入 AAD CS。Import from AAD: Azure Active Directory objects are brought into AAD CS.

  • 同步:入站同步规则和出站同步规则按优先数字从低到高的顺序运行。 Synchronization: Inbound Synchronization Rules and Outbound Synchronization Rules are run in the order of precedence number from lower to higher. 要查看同步规则,可以从桌面应用程序转到“同步规则编辑器” 。To view the Synchronization Rules, you can go to Synchronization Rules Editor from the desktop applications. 入站同步规则 将数据从 CS 引入 MV。The Inbound Synchronization Rules brings in data from CS to MV. 出站同步规则 将数据从 MV 移动到 CS。The Outbound Synchronization Rules moves data from MV to CS.

  • 导出到 AD:运行同步后,会将对象从 AD CS 导出到 Active Directory 。Export to AD: After running Synchronization, objects are exported from AD CS to Active Directory .

  • 导出到 AAD:运行同步后,会将对象从 AAD CS 导出到 Azure Active Directory 。Export to AAD: After running Synchronization, objects are exported from AAD CS to Azure Active Directory .

逐步调查Step by Step Investigation

  • 我们会从 Metaverse 开始搜索,并查看从源到目标的属性映射。We will start our search from the Metaverse and look at the attribute mapping from source to target.

  • 从桌面应用程序启动“Synchronization Service Manager” ,如下所示:Launch Synchronization Service Manager from the desktop applications, as shown below:

    启动 Synchronization Service Manager

  • 在“Synchronization Service Manager” 上,依次选择“Metaverse 搜索” 、“按对象类型限定范围” 和使用属性的对象,然后单击“搜索” 按钮。On the Synchronization Service Manager , select the Metaverse Search , select Scope by Object Type , select the object using an attribute, and click Search button.

    Metaverse 搜索

  • 双击在 Metaverse 搜索中找到的对象以查看所有属性。Double click the object found in the Metaverse search to view all its attributes. 可以单击“连接器” 选项卡以查看所有连接器空间 中的对应对象。You can click on the Connectors tab to look at corresponding object in all the Connector Spaces .

    Metaverse 对象连接器

  • 双击“Active Directory 连接器” 以查看连接器空间 属性。Double click on the Active Directory Connector to view the Connector Space attributes. 单击“预览” 按钮,在后续对话框中单击“生成预览” 按钮。Click on the Preview button, on the following dialog click on the Generate Preview button.

    此屏幕截图显示了“连接器空间对象属性”屏幕,其中突出显示了“预览”按钮。

  • 现在单击“导入属性流” ,这会显示从 Active Directory 连接器空间 到 Metaverse 的属性流。Now click on the Import Attribute Flow , this shows flow of attributes from Active Directory Connector Space to the Metaverse . “同步规则” 列显示影响该属性的同步规则 。Sync Rule column shows which Synchronization Rule contributed to that attribute. “数据源” 列显示来自连接器空间 的属性。Data Source column shows you the attributes from the Connector Space . “Metaverse 属性” 列显示 Metaverse 中的属性。Metaverse Attribute column shows you the attributes in the Metaverse . 可以此处查找未同步的属性。You can look for the attribute not syncing here. 如果在此处找不到属性,则此属性未映射,必须创建新的自定义同步规则 以映射属性。If you don't find the attribute here, then this is not mapped and you have to create new custom Synchronization Rule to map the attribute.

    连接器空间属性

  • 单击左窗格中的“导出属性流” 以查看使用出站同步规则 从 Metaverse 回到 Active Directory 连接器空间 的属性流。Click on the Export Attribute Flow in the left pane to view the attribute flow from Metaverse back to Active Directory Connector Space using Outbound Synchronization Rules .

    此屏幕截图显示了使用出站同步规则从 Metaverse 回到 Active Directory 连接器空间的属性流。

  • 同样,可以查看 Azure Active Directory 连接器空间 对象,并且可以生成预览 以查看从 Metaverse 到连接器空间 及相反方向的属性流,这样便可以调查属性为何未同步。Similarly, you can view the Azure Active Directory Connector Space object and can generate the Preview to view attribute flow from Metaverse to the Connector Space and vice versa, this way you can investigate why an attribute is not syncing.

后续步骤Next Steps