SC‑300 Study Portal Dark

Unit 8: Implement Microsoft Entra Connect Health

1. Introduction: What Is Microsoft Entra Connect Health?

Microsoft Entra Connect Health is a cloud-based monitoring service designed to give administrators deep visibility into the health of their on-premises identity infrastructure, including:

It helps ensure reliable synchronization and authentication between on-prem AD and Microsoft Entra ID (Azure AD) by providing alerts, analytics, and performance insights.

2. Why Connect Health Is Important

Hybrid identity relies on multiple moving parts — directory synchronization, federation, and network connectivity. Without monitoring, failures can go unnoticed, leading to:

Connect Health centralizes visibility by continuously uploading telemetry from your on-prem identity servers to the Microsoft Entra admin center.

You can view it in the Microsoft Entra Connect Health portal, which displays:

3. Licensing Requirements

To use Connect Health, your organization must have at least:

Without it, you can’t register or configure the health agents or access the Connect Health portal.

4. Core Components of Connect Health

ComponentDescription
Health AgentsInstalled on-prem on AD FS, AD DS, or Entra Connect servers. Collect telemetry and send it securely to the cloud.
Connect Health ServiceCloud-based service hosted in Microsoft Entra ID. Processes data from agents and presents insights in the portal.
Connect Health PortalAccessible via the Microsoft Entra admin center. Provides dashboards, alerts, and performance data for each service.

5. Supported Monitored Services

ServiceWhat It MonitorsKey Benefits
Microsoft Entra Connect (Sync)Sync cycles, errors, latency, scheduler stateDetect sync failures early
AD FSToken issuance, authentication failures, certificate expiryDetect sign-in outages or load issues
Active Directory DSReplication, domain controller performance, replication latencyIdentify domain health issues affecting hybrid identity

6. Connect Health Architecture Overview

Flow Summary:

7. Installing and Configuring Microsoft Entra Connect Health Agents

Prerequisites

Before installing, ensure:

Firewall Requirements

PortPurpose
TCP 443HTTPS communication between the agent and the Connect Health service
TCP 5671Used by older agents (no longer required in latest version)

Agent Installation Locations

Agent TypeInstall On
AD FS AgentEach AD FS server in the farm (not the sync server).
AD DS AgentAt least one domain controller per domain.
Sync AgentAutomatically installed with Microsoft Entra Connect (latest versions).

8. Installing the Connect Health Agent for AD FS

Tip: Don’t install the AD FS agent on the same server as your Entra Connect sync service. Keep roles separated.

9. Installing the Connect Health Agent for Sync

If you use the latest version of Microsoft Entra Connect, the Sync Health Agent is automatically installed and configured during setup.

To verify:

If they are stopped, start them manually and ensure the service account has Internet access.

10. Verifying Installation

After the agents are configured:

11. What You Can Monitor

For AD FS

For Sync

For AD DS

12. Alerts and Health Indicators

Connect Health automatically generates alerts when it detects abnormalities. Examples include:

Alert ExamplePossible CauseRecommended Action
Sync cycle has not run in 24 hoursScheduler disabled or network issueRe-enable scheduler and test connectivity
AD FS token signing certificate will expire soonCertificate near expirationRenew certificate and update federation trust
High AD FS authentication failure rateIncorrect passwords or external attackInvestigate AD FS logs for failed IPs
Replication latency above thresholdSlow domain replicationCheck AD replication topology

Each alert includes a description, cause, and fix recommendation in the portal.

13. Real-World Example

Scenario: A large retail company notices users can’t sign in to Microsoft 365. Their hybrid environment uses AD FS.

Using Connect Health:

Result: Outage resolved quickly thanks to proactive monitoring.

14. Best Practices

15. Exam Tips

16. Summary

Microsoft Entra Connect Health provides a unified monitoring solution that ensures your hybrid identity infrastructure remains healthy and reliable. By deploying lightweight agents across your AD DS, AD FS, and Entra Connect servers, you can:

This service is essential for maintaining continuous hybrid identity synchronization and secure, uninterrupted access to Microsoft 365 and other cloud applications.