Microsoft Entra Connect uses an Active Directory Domain Services account to connect to and synchronize objects with an on-premises Active Directory environment.
When the password of this AD DS connector account is changed or expires, the new password must also be updated in Microsoft Entra Connect. Otherwise, synchronization operations may fail because the synchronization service is still using the old credentials. Microsoft documents this process as updating the AD DS account password in the Synchronization Service Manager.
This guide explains how to change the password safely and verify that synchronization is working again.
Important: This article applies to the password of the AD DS Connector account. It does not describe changing the password of the Microsoft Entra Connect Sync service account. That account uses encryption keys and requires a different procedure.
Environment Used in This Example
The following values are examples from a typical hybrid identity environment:
| Item | Example value |
|---|---|
| AD DS connector account | EntraSync_001 |
| Microsoft Entra Connect server | AADConnect01.example.net |
| Active Directory forest | example.net |
| Microsoft Entra Connect version | 2.5.79.0 |
| Required tool | Synchronization Service Manager |
Replace these values with the names used in your own environment.
For security reasons, never publish real service account passwords, internal server names, or sensitive tenant information in screenshots or public documentation.
What Happens When the Password Changes?
The AD DS connector account is used by Microsoft Entra Connect to communicate with the on-premises Active Directory forest.
If its password is changed in Active Directory but not updated in Microsoft Entra Connect, imports and exports can fail. Depending on the version and configuration, you may see errors such as:
- Invalid credentials.
no-start-credentials.- Failed import or export operations.
- Synchronization errors in the Synchronization Service Manager.
- Event ID 6000 in the Windows Application event log.
Microsoft recommends updating the connector configuration and restarting the Microsoft Entra ID Sync service so that the old password is removed from the service memory cache.
Step 1: Change the Password in Active Directory
First, change the password of the AD DS connector account in Active Directory.
In this example, the account is:
EntraSync001
Use your normal administrative process to set the new password.
After changing the password:
- Verify that the account is not disabled.
- Confirm that the account is not locked out.
- Check whether the password has expired.
- Store the new password in an approved password manager or password vault.
- Document the password change according to your organization’s security policy.
Avoid storing service account passwords in plain-text files, scripts, screenshots, tickets, or documentation repositories.
Security recommendation: If another service provider or support organization requires the password for documentation, use an approved secure transfer process. Never send credentials through an unprotected email or chat message.
Step 2: Open the Synchronization Service Manager
Sign in to the Microsoft Entra Connect server using an account with the permissions required to manage the synchronization service.
In this example, the server is:
AADConnect01
Open the Synchronization Service Manager:
- Open the Start menu.
- Search for Synchronization Service.
- Start the application with administrative privileges.
- Select the Connectors tab.
The Connectors tab displays the connection definitions used by Microsoft Entra Connect to communicate with Active Directory and Microsoft Entra ID.
Step 3: Update the AD DS Connector Password
Locate the connector that represents your on-premises Active Directory forest.
In this example, the connector is:
example.net
Then perform the following steps:
- Select the AD DS connector.
- Open Actions.
- Select Properties.
- Select Connect to Active Directory Forest.
- Enter the new password in the Password field.
- Verify that the displayed username is the correct AD DS connector account.
- Click OK to save the new credentials.
Microsoft’s documented procedure follows the same general workflow: select the relevant connector, open its properties, choose Connect to Active Directory Forest, enter the new password, and save the configuration.
You may receive a warning after clicking OK. Confirm the warning if you are certain that the password is correct and applies to the selected connector.
Step 4: Restart the Microsoft Entra ID Sync Service
After saving the new connector password, restart the synchronization service.
You can do this directly from the Windows Services console:
- Open
services.msc. - Locate Microsoft Entra ID Sync.
- Right-click the service.
- Select Restart.
Alternatively, use PowerShell:
Restart-Service -Name ADSyncCheck the service status afterward:
Get-Service -Name ADSyncThe expected status is:
Running
Restarting the service ensures that references to the old credentials are removed from the service memory cache.
Step 5: Start a Manual Synchronization
After restarting the service, start a manual synchronization cycle.
Open an elevated PowerShell session on the Microsoft Entra Connect server and run:
Start-ADSyncSyncCycle -PolicyType DeltaA delta synchronization processes recent changes only.
For a complete synchronization, use:
Start-ADSyncSyncCycle -PolicyType InitialUse an initial synchronization only when required by your operational procedure, because it processes a much larger set of objects and attributes.
To check the result, open the Synchronization Service Manager and review the Operations tab.
Verify that:
- The synchronization cycle starts successfully.
- The AD DS connector completes its import.
- The export operation completes without authentication errors.
- No
no-start-credentialserror is reported. - The latest operation shows a successful result.
Troubleshooting
Synchronization Still Fails
If synchronization continues to fail, verify the following:
- The password was entered correctly.
- The correct connector was selected.
- The connector uses the account whose password was changed.
- The account is not locked out or disabled.
- The account can authenticate against the Active Directory domain.
- DNS resolution is working correctly.
- The Microsoft Entra Connect server can communicate with the domain controllers.
- The Microsoft Entra ID Sync service is running.
- The server time is synchronized correctly.
- No firewall or network change is blocking domain controller communication.
You can also review the following locations:
- Synchronization Service Manager → Operations.
- Windows Event Viewer → Windows Logs → Application.
- Windows Event Viewer → Applications and Services Logs.
- Microsoft Entra Connect health monitoring, if configured.
Microsoft identifies invalid connector credentials and Event ID 6000 as possible indicators of an incorrect or outdated AD DS connector password.
The Synchronization Service Does Not Start
If the Synchronization Service itself does not start after changing a password, confirm which account was changed.
There are two different accounts that are often confused:
| Account type | Purpose | Password-change procedure |
|---|---|---|
| AD DS Connector account | Connects Microsoft Entra Connect to on-premises Active Directory | Update the password in the connector properties |
| Microsoft Entra Connect Sync service account | Runs the synchronization engine and protects stored credentials | Use Microsoft’s separate service-account recovery procedure |
Changing the Microsoft Entra Connect Sync service account password is different because encryption keys and DPAPI are involved. Microsoft states that the service may fail to start until the encryption key is abandoned and the service account is reinitialized.
Do not apply the procedure from this article to the Microsoft Entra Connect Sync service account.
Operational Checklist
Use the following checklist during a planned password change:
- Identify the correct AD DS connector account.
- Confirm the Microsoft Entra Connect server.
- Change the account password in Active Directory.
- Store the password securely.
- Open Synchronization Service Manager.
- Select the correct AD DS connector.
- Update the password under Connect to Active Directory Forest.
- Confirm the warning message.
- Restart the Microsoft Entra ID Sync service.
- Trigger a delta synchronization.
- Review the synchronization results.
- Check the Windows event logs if errors occur.
- Document the completed change without recording the password itself.
Conclusion
Changing the password of an AD DS connector account requires two coordinated steps: update the password in Active Directory and then update the same password in the Microsoft Entra Connect connector configuration.
After saving the new credentials, restart the Microsoft Entra ID Sync service and run a manual synchronization cycle. This confirms that Microsoft Entra Connect can authenticate successfully and continue synchronizing objects between the on-premises Active Directory and Microsoft Entra ID.
Always distinguish the AD DS Connector account from the Microsoft Entra Connect Sync service account. The latter uses a separate recovery process because its credentials are protected by encryption keys.