We've detected an error while synchronizing to Enterprise Application Name" but there are no errors in the log.

David Pordomingo Moreno 0 Reputation points
2024-12-13T08:30:50.98+00:00

Hi.

In a Enterprise Application that we use for SAML authentication and the Provisioning is configured from time to time (almost every week) we receive the email alert that "We've detected an error while synchronizing to Enterprise Application Name**".** The email content is "While attempting to validate our authorization to access your application, we received this unexpected response: Message: An error occurred while sending the request. Please check the service. We've detected an error while synchronizing to Enterprise Application Name. You may want to visit the provisioning status page to examine and possibly mitigate the errors."

And when I check the Provisioning Status Page and the Provisioning Logs there are no errors.

Where I can find the reason of this email alert?

Thanks.

Azure App Service
Azure App Service
Azure App Service is a service used to create and deploy scalable, mission-critical web apps.
8,155 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
22,840 questions
0 comments No comments
{count} votes

2 answers

Sort by: Most helpful
  1. Navya 14,300 Reputation points Microsoft Vendor
    2024-12-16T22:23:05.54+00:00

    Hi @David Pordomingo Moreno

    Thank you for posting this in Microsoft Q&A.

    Based on the information you provided, it appears that you are receiving an email alert indicating an error occurred while synchronizing to an Enterprise Application that you use for SAML authentication and provisioning. However, when you check the Provisioning Status Page and the Provisioning Logs, there are no errors.

    You may receive this email if your Enterprise application provisioning is in quarantine status. The Microsoft Entra provisioning service monitors the health of your configuration and places unhealthy apps in a "quarantine" state.

    To check if your application is in quarantine, there are three ways:

    1.In the Microsoft Entra admin center, navigate to Identity > Applications > Enterprise applications > <application name> > Provisioning and review the progress bar for a quarantine message.

    2.In the Microsoft Entra admin center, navigate to Identity > Monitoring & health > Audit Logs > filter on Activity: Quarantine and review the quarantine history. The progress bar view as described above shows whether provisioning is currently in quarantine. The audit logs show the quarantine history for an application.

    3.Use the Microsoft Graph request Get synchronizationJob to programmatically get the status of the provisioning job

    GET https://graph.microsoft.com/beta/servicePrincipals/{id}/synchronization/jobs/{jobId}/
    

    There are multiple common reasons why your application may go into quarantine:

    1.Invalid credentials: When attempting to authorize access to the target application, we received a response from the target application that indicates the credentials provided are invalid.

    2.Duplicate roles: Roles imported from certain applications like Salesforce and Zendesk must be unique.

    3.SCIM Compliance issue: An HTTP/404 Not Found response was returned rather than the expected HTTP/200 OK response. In this case, the Microsoft Entra provisioning service has made a request to the target application and received an unexpected response

    For more information, please refer to this document: https://zcusa.951200.xyz/en-us/entra/identity/app-provisioning/application-provisioning-quarantine-status

    Hope this helps. Do let us know if you any further queries.

    Thanks,

    Navya.


    If this answers your query, do click Accept Answer and Yes for was this answer helpful. And, if you have any further query do let us know.

    1 person found this answer helpful.

  2. Deleted

    This answer has been deleted due to a violation of our Code of Conduct. The answer was manually reported or identified through automated detection before action was taken. Please refer to our Code of Conduct for more information.


    Comments have been turned off. Learn more

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.