Checklist
Entra Connect sync errors: duplicates, InvalidSoftMatch and objects that never sync
Based on the article: Entra Connect sync errors: duplicates, InvalidSoftMatch and objects that never sync · 6 min read
Directory synchronization fails in two very different ways: an object is exported to Microsoft Entra ID and rejected with an error, or it never leaves the Entra Connect server at all. In this post I'll go through the export errors Microsoft documents, explain the hard-match and soft-match logic behind most of them, and show how to track down an object that simply never appears in the cloud.
Symptoms to confirm
You get the directory synchronization error email, the Microsoft 365 admin center flags a sync problem, or a user tells you their account or new email address isn't in Entra ID.
| Error | Meaning |
|---|---|
AttributeValueMustBeUnique | The object would receive a value of mail, proxyAddresses, signInName or userPrincipalName that another Entra object already holds. |
InvalidSoftMatch | No hard match was found, the soft match found an object, but that object already has a different immutableId, so it belongs to another on-premises object. |
ObjectTypeMismatch | The soft match found an object of a different type (for example a mail-enabled group with the same SMTP address as a new user). |
InvalidHardMatch | Entra ID blocked a hard match because the target cloud user is privileged (assigned or eligible for a privileged role) or already mapped to an on-premises object. Enforced automatically since July 1, 2026. |
IdentityDataValidationFailed / DataValidationFailed | Invalid data, typically unsupported characters or a bad format in the UPN. |
LargeObject / ExceededAllowedLength | The object exceeds the size limit, usually because of userCertificate, userSMIMECertificate, thumbnailPhoto or a very long proxyAddresses list. |
| Existing Admin Role Conflict | An on-premises user has the same UPN as a cloud user that holds an admin role; soft matching to admin accounts isn't allowed. |
Likely causes
- When Entra Connect adds a new object, Entra ID first tries a hard match on the
sourceAnchor, which is the Base64 form of the user'sms-DS-ConsistencyGuid(orobjectGUIDin older configurations) and is stored in the cloud asImmutableId. If nothing matches, it tries a soft match on theuserPrincipalNameor the primary SMTP address, meaning only theSMTP:entry inproxyAddresses. - Most duplicate errors are therefore one of three stories: two Active Directory objects share an address or UPN, an object was recreated (or moved between forests) so its
sourceAnchorchanged while the old cloud object still exists, or a cloud-created object collides with a newly synced one.
Checklist
- 1
Find the error details
The quickest view is the sync error report in Microsoft Entra Connect Health › Sync services.
- 2
Resolve duplicate values
For
AttributeValueMustBeUnique,InvalidSoftMatchandObjectTypeMismatch, decide which object should keep the value, remove it from the other one in its source directory, and let the next delta cycle export the change. Run IdFix against Active Directory to find every duplicate, blank or malformed value in one pass instead of chasing them one at a time. - 3
Make the right object match
When the new on-premises object should take over an existing cloud user (a recreated account, a forest move, or a reinstalled Entra Connect with a different anchor), force a hard match by writing the cloud
ImmutableIdinto the user'sms-DS-ConsistencyGuid:powershellConnect-MgGraph -Scopes "User.Read.All" $cloudUser = Get-MgUser -UserId "bob.taylor@contoso.com" -Property OnPremisesImmutableId $guid = [Guid][Convert]::FromBase64String($cloudUser.OnPremisesImmutableId) Set-ADUser -Identity bobt -Replace @{ 'mS-DS-ConsistencyGuid' = $guid.ToByteArray() } Start-ADSyncSyncCycle -PolicyType DeltaCheck the tenant's matching switches with the Microsoft Graph PowerShell SDK:
powershellConnect-MgGraph -Scopes "OnPremDirectorySynchronization.Read.All" Get-MgDirectoryOnPremiseSynchronization | Select-Object -ExpandProperty Features | Format-List - 4
Fix data validation and size errors
Correct UPNs with unsupported characters or formats (IdFix flags them), and verify the UPN suffix as a domain in the tenant, otherwise the user lands on the
onmicrosoft.comdomain. - 5
Find an object that never syncs
- On the Entra Connect server, start the wizard and go to Additional Tasks › Troubleshoot › Launch, then choose Troubleshoot Object Synchronization. Give it the object's distinguished name, the AD connector name and Hybrid Identity Administrator credentials. It checks UPN mismatch, domain and OU filtering, linked mailboxes and dynamic distribution groups, and writes an HTML report.
- Manually, open Synchronization Service Manager, select Connectors, the Active Directory connector and Search Connector Space. If the object is missing, it's outside domain or OU filtering: rerun the wizard and re-select the OU (a renamed OU drops out of scope silently).
- If the object is in the connector space but Metaverse Search doesn't find it, a scoping filter stopped it. In the Synchronization Rules Editor, compare the inbound rules' scoping filters with the object's attributes;
isCriticalSystemObjectand custom attribute filters are the usual culprits. - If it's in the metaverse but not in the Entra connector space, check the outbound rule scope and whether
cloudFilteredis True.
- 6
Run the right sync cycle
Delta syncs run every 30 minutes by default. Changing OU filtering needs a full import followed by a delta sync; changing attribute filtering needs a full synchronization. The simplest supported route is to put the server in staging mode and run:
powershellGet-ADSyncScheduler Start-ADSyncSyncCycle -PolicyType Initial # full import + full sync on all connectors Start-ADSyncSyncCycle -PolicyType Delta
Verify
- After the next export (and up to 30 minutes for Connect Health to refresh), the object no longer appears in the error report and the Operations tab shows
successfor the Entra connector. - In Entra ID › Users, the user shows On-premises sync enabled: Yes with the expected UPN and addresses, and the metaverse object lists both the Active Directory and Entra connectors on its Connectors tab.
- For a forced hard match, confirm the cloud user kept its licences, mailbox and group memberships.
Prevent it next time
- Clean Active Directory with IdFix before onboarding new domains, and keep
ms-DS-ConsistencyGuidas the source anchor so account recreations don't orphan cloud objects. - Don't create cloud-only users for people who exist in Active Directory; let synchronization create them.
- Install the Connect Health agent and watch the error report and alerts rather than waiting for the notification email.
- Consider Microsoft Entra Cloud Sync for new environments: lightweight provisioning agents, configuration stored in the cloud, multiple agents for high availability and support for disconnected forests. It's Microsoft's strategic direction for hybrid synchronization, but compare the feature list first, because not every Connect Sync capability is available yet.