Monday, November 9, 2015

Home / AADConnect – An error occurred executing Create AD Trust task

AADConnect – An error occurred executing Create AD Trust task

Azure custom domain name verification process is little different if you are enabling SSO using ADFS (Federated domain).  If you select “I plan to configure the domain for a single sing-on with my local Active Directory” option, you will not get a TXT or MX record from this window for the domain verification. 

image

The TXT and MX records will be provided during the AADConnect configuration as shown in the following screenshot:
image

However, sometime you will get the AzureDomainNotVerifiedException error message during the AADConnect domain verification process.  The error messages and details are provided  below:

Create AAD Trust
Add error occurred executing CreAAD Trust task:  Exception of type ‘Microsoft.Online.Deployment.Types.AzureDomainNotVerifiedException’ was thrown.

clip_image001

Resolution / Workaround
1. Delete the custom domain from Azure. 
2.  Add a new custom domain and DO NOT select “I plan to configure the domain for a single sing-on with my local Active Directory” option.
3. Get the TXT record and verify the domain. 

4.  Perform AADConnect configuration. During this configuration, domain will be converted from Managed to Federated.
SS

Santhosh Sivarajan

Microsoft MVP · Identity & Cybersecurity Architect

Santhosh has 30+ years of hands-on enterprise experience in Identity and Access Management, Microsoft Entra ID, Active Directory, Microsoft 365 and Zero Trust architecture. He is the author of two books on Windows Server and security, and leads consulting, assessments and training at SAG Business Group.

4 comments:

I have learned a lot of useful information from your blog.GoMovies

Registering a domain is easy but its verification is way too difficult as it consists of so many technicalities. As I and my friends started an online MBA Essay writers website we faced numerous issues with domain verification and it cost us a lot. I wish we had found this post before so that it would have provided us with a little bit of ease.

I have two domains that are almost two years old, and now I want to use them but don't know how can I use Dissertation Writing Services for this. Can you please write something valuable on this for me?

DATAFOREST provided me with exceptional custom data-driven solutions tailored to my business needs. Their expertise in data engineering allowed them to effectively leverage my data, resulting in valuable insights and improved decision-making. I highly recommend their custom solutions.

Post a Comment

Popular Posts
Workstation Trust Relationship Issue Issue: You receive the following error message, when you try to login to the domain.  The security database on the server does not have ... ADMT Service Account - Permission and Configuration The ADMT service account needs to have proper permission in source and target domains.  You don’t need to use 2 separate accounts.  You can ... My First Peek into Microsoft Exchange 2010 By Santhosh Sivarajan Before I really dive into Exchange 2010, I thought I would install and play with it first. I took some screen shots and notes during the ins... ObjectSID and Active Directory What is an objectSID in Active Directory? When a new object is created in Active Directory, Domain Controller assigns a unique value used ... AD Group Report - List Group Members in Active Directory–PowerShell Script Updated Script - http://portal.sivarajan.com/2011/10/search-ad-collect-local-admin-group.html Script #1 This script... Add Users to a Group–PowerShell Script Purpose – Add users to a group from an input file – PowerShell V2 Script.  Input file – Input file (Users.csv) contains samAccountName in... User Account Migration and Merging – Part I (ADMT) Part I - User Account Migration and Merging Using ADMT Part II - User Account Migration and Merging Using QMM pre-creating user account ... User Account Migration and Merging – Part II (Quest Migration Manager) Part I - User Account Migration and Merging Using ADMT Part II - User Account Migration and Merging Using QMM Pre-creating user account in... Delete Stale or Inactive Computer Accounts from Active Directory Here is an easy way to identify and delete inactive or stale computers in an Active Directory environment.  Using the dsquery command you c... Converting PowerShell (PS1) to EXE / Standalone Application As we know, there many applications available to convert a PowerShell file to a standalone executable file.  Based on my experience, PowerSh...