Entra ID Connect sync Auto upgrade Not working as expected currently on N-1

AJAY PRAJAPATI 60 Reputation points
2026-06-23T13:53:09.2333333+00:00

Hi Experts,

We had a situation where we manually upgraded the Entra ID Connect Sync tool because it was on the Stage server. Since auto-upgrade only functions on the Primary Server, we switched the Stage Server to become the Primary Server after two days to enable auto-upgrading to the latest Entra ID Connect Sync Tool (2.6.3.0).

It has now been two months, and the system still hasn't upgraded to the latest version. Has anyone experienced this situation? If yes, how was it resolved?

Thank you

Microsoft Security | Microsoft Entra | Microsoft Entra ID

Answer accepted by question author
VEMULA SRISAI 14,065 Reputation points Microsoft External Staff Moderator
2026-06-23T14:40:27.15+00:00

Hello AJAY PRAJAPATI,

This is expected behavior and does not necessarily indicate an issue with your setup.

Auto-upgrade in Microsoft Entra Connect is not immediate and is rolled out in phases. Even if your server is now primary, it will only upgrade once it is eligible and targeted in the rollout. Additionally, not all versions are enabled for auto-upgrade, and some builds require a manual upgrade.

I recommend validating the auto-upgrade status using:

PowerShell

Get-ADSyncAutoUpgrade

Get-ADSyncAutoUpgrade -Detail

Show more lines

Ensure the state is Enabled (not Suspended) and confirm there are no eligibility constraints (custom configuration, connectivity to Entra Connect Health, etc.).

If everything looks healthy and you still need the latest version, the recommended approach is to proceed with a manual in-place upgrade, as auto-upgrade timing is not guaranteed.

Was this answer helpful?

1 person found this answer helpful.

1 additional answer

Sort by: Most helpful
  1. AI answer

    2026-06-23T13:53:38.0366667+00:00

    Automatic upgrade for Microsoft Entra Connect only runs when the installation is both eligible and not in a blocked/suspended state. In this scenario, after promoting the former staging server to primary, the installation is still not auto‑upgrading, which typically means one of the following:

    1. Auto‑upgrade is disabled or suspended
      Run on the current primary server:
         Get-ADSyncAutoUpgrade
         Get-ADSyncAutoUpgrade -Detail
      
      • If the state is Suspended, the detail string usually contains an UpgradeResult such as UpgradeNotSupportedNonLocalDbInstall or UpgradeAbortedSyncExeInUse that explains why auto‑upgrade is not running.
    2. The installation is not eligible for auto‑upgrade
      Auto‑upgrade will not proceed if any of the following are true:
      • UpgradeNotSupportedTLSVersionIncorrect – TLS < 1.2; update TLS as per the TLS enforcement guide.
      • UpgradeNotSupportedCustomizedSyncRules – custom sync rules (no longer blocking after version 2.2.1.0, but may still appear in history).
      • UpgradeNotSupportedInvalidPersistedState – installation is not Express settings or a DirSync upgrade.
      • UpgradeNotSupportedNonLocalDbInstall – using a full SQL Server instead of SQL Server Express LocalDB.
      • UpgradeNotSupportedLocalDbSizeExceeded – LocalDB size ≥ 8 GB.
      • UpgradeNotSupportedAADHealthUploadDisabled – Entra Connect Health uploads disabled from the portal.
      If Get-ADSyncAutoUpgrade -Detail shows any UpgradeNotSupported* result, the expectation is that the server must be upgraded manually.
    3. Temporary conditions aborting the upgrade
      If the result shows UpgradeAborted*, the upgrade was attempted but blocked by a temporary condition, for example:
      • UpgradeAbortedSyncExeInUse – Synchronization Service Manager UI open.
      • UpgradeAbortedServiceIsNotRunning / UpgradeAbortedServiceCanNotBeStarted / UpgradeAbortedServiceCanNotBeStopped – Entra ID Sync service issues.
      • UpgradeAbortedInsufficientDiskSpace – not enough disk space.
      • UpgradeAbortedInsufficientDatabasePermissions – built‑in Administrators group lacks database permissions (requires manual upgrade to fix).
      These are retried, but if the underlying condition persists, the version will not move to the latest build.
    4. Connectivity to Entra Connect Health / service endpoints
      Automatic upgrade uses Microsoft Entra Connect Health. Ensure:
      • Required URLs are allowed through proxy/firewall.
      • Health agents are configured to use the proxy if applicable.
      • Health connectivity tests to Microsoft Entra ID succeed.
    5. Check the event logs for upgrade attempts
      On the primary server:
      • Open Event Viewer → Application log.
      • Filter by Source = Microsoft Entra Connect Upgrade and Event IDs 300–399.
      • Review the result codes; they have prefixes such as Success, UpgradeAborted, or UpgradeNotSupported that show why the upgrade did or did not proceed.
    6. When to fall back to manual upgrade
      • If the result prefix is UpgradeNotSupported, the expectation is that the system must be upgraded manually and kept current that way.
      • If UpgradeAbortedInsufficientDatabasePermissions appears, the guidance is to manually upgrade to the latest version of Microsoft Entra Connect to correct the state.

    If, after checking Get-ADSyncAutoUpgrade, eligibility conditions, connectivity, and event logs, the result remains UpgradeNotSupported*, the practical resolution is to perform a manual upgrade to 2.6.3.0 and plan to keep this server updated manually unless the blocking condition can be removed.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.