AttributeValueMustBeUnique means Microsoft Entra Connect tried to write a proxyAddresses, userPrincipalName, mail or signInName value that another object in Microsoft Entra ID already holds. To fix it, identify the duplicated value from the error, find every object in Active Directory and in the cloud that holds it, decide which one should keep it, remove it from the other in the directory that owns that object, and let the next sync cycle export the change. The conflict never resolves itself: even when duplicate attribute resiliency quarantines the value and lets the object sync, one of the two objects is missing data until you fix the source.
Who this is for and what you will have
This guide is for administrators running Microsoft Entra Connect Sync in a hybrid Active Directory and Microsoft 365 environment, often in the middle of a mailbox migration or right after a reorganization that reused email addresses. By the end you will have:
- The exact conflicting value and both objects involved.
- PowerShell queries that search Active Directory, Exchange Online and Microsoft Entra ID for a given address.
- A corrected source object and a clean export on the next sync cycle.
- A short list of habits that stop the error coming back.
Duplicate addresses are especially common after a tenant consolidation or a cross-tenant move. If that is your situation, the cross-tenant migration architecture guide covers how to plan address ownership before cutover.
How the error appears
You will usually meet the error in one of four places:
- Email: the Identity Synchronization Error Report sent to the tenant's technical notification contact.
- Synchronization Service Manager: on the Entra Connect server, the Operations tab shows an export run on the Entra connector (named in the format
contoso.onmicrosoft.com) with acompleted-*-errorsstatus. Select the run and look under Synchronization Errors. - Application event log: event ID 6941 from source
ADSync. - Admin portals: Microsoft Entra Connect Health and the Microsoft 365 admin center.
The event log text is the most useful because it names the attribute and the value:
Event ID: 6941
Log Name: Application
Source: ADSync
Level: Error
Details:
ECMA2 MA export run caused an error.
Error Name: AttributeValueMustBeUnique
Error Detail: Unable to update this object because the following attributes associated
with this object have values that may already be associated with another object in your
local directory services: [UserPrincipalName john@contoso.com;]. Correct or remove the
duplicate values in your local directory. Please refer to
https://support.microsoft.com/kb/2647098 for more information on identifying objects
with duplicate attribute values.For a proxy address conflict, the bracketed part reads [ProxyAddresses SMTP:john@contoso.com;] instead.
Related errors with the same root cause
| Error | What happened | Typical trigger |
|---|---|---|
AttributeValueMustBeUnique | An update or new object uses a unique value that another Entra object already has | An address added to a synced user that another synced user already holds |
InvalidSoftMatch | No hard match on sourceAnchor, but a soft match on proxyAddresses or UPN found an object with a different immutableId | Two on-premises objects share an address; an object was deleted and recreated; the sourceAnchor attribute changed |
ObjectTypeMismatch | The soft match found an object of a different type with the same value | A new on-premises user has the address of a cloud mail-enabled group |
All three are fixed the same way: remove the duplicate from the object that shouldn't have it. Microsoft lists mail, proxyAddresses, signInName and userPrincipalName as attributes that must be unique for AttributeValueMustBeUnique.
How duplicate attribute resiliency changes what you see
Duplicate attribute resiliency is on by default for tenants and can't be turned off. Instead of failing the whole export, Entra ID quarantines the conflicting UPN or SMTP proxy address:
- A conflicting proxy address is simply left off the object, and the object is created or updated without it.
- A conflicting UPN is replaced with a placeholder in the format
<OriginalPrefix>+<4DigitNumber>@<InitialTenantDomain>.onmicrosoft.com, because every user needs a UPN. - The quarantined value is stored in the object's provisioning errors, and the error report email mentions it once, at the time of quarantine.
- A background task runs every hour, finds conflicts that have been resolved, and puts the quarantined value back.
This is why a user can appear with an odd onmicrosoft.com UPN, or a mailbox is missing one alias, with no recurring error in the sync client. The data still needs fixing. Microsoft also documents cases where resiliency doesn't apply and a normal export error is retried every cycle, for example a new user whose address conflicts with an existing group.
Prerequisites
- Hybrid Identity Administrator (or Global Administrator) to view sync errors in the Microsoft 365 admin center.
- The Active Directory PowerShell module on a domain-joined machine, with rights to modify the affected objects.
- Exchange Online PowerShell for cloud recipients.
- Microsoft Graph PowerShell or Microsoft Entra PowerShell for directory queries.
- Access to the Entra Connect server to run a sync cycle.
Step 1: Get the list of conflicts
Microsoft Entra Connect Health
If the Connect Health agent is installed on the sync server, open Connect Health, select Sync services, then the service, and open the synchronization errors. The report groups errors into categories, including Duplicate Attribute and Data Mismatch, shows a side-by-side comparison of the objects in conflict, highlights the conflicting attribute, and lets you export a CSV. It is updated every 30 minutes from the latest export run.
Microsoft 365 admin center
On the Home page, find the User management card and select Sync errors under Microsoft Entra Connect. Only user objects appear here, not conflicts between groups and contacts.
Microsoft Entra PowerShell
Get-EntraDirectoryObjectOnPremisesProvisioningError returns sync errors for users, groups and organizational contacts, including the property and value in conflict:
Connect-Entra -Scopes 'User.Read.All', 'Directory.Read.All', 'Group.Read.All', 'Contacts.Read'
# Every quarantined or conflicting value
Get-EntraDirectoryObjectOnPremisesProvisioningError | Format-Table -AutoSize
# Only proxy address conflicts
Get-EntraDirectoryObjectOnPremisesProvisioningError |
Where-Object PropertyCausingError -eq 'ProxyAddresses' |
Format-Table Id, DisplayName, Value, OccurredDateTime -AutoSizeThe output includes PropertyCausingError (ProxyAddresses or UserPrincipalName), Category (for example PropertyConflict) and Value, such as SMTP:john@contoso.com. Write down each value; the next step finds who else has it.
Step 2: Find every object that holds the value
A duplicate can live in on-premises Active Directory, in the cloud, or both. Check all three places before you change anything.
Active Directory
Search the whole forest through a global catalog so you don't miss objects in other domains. With the search base set to an empty string on the global catalog port, all partitions are searched:
$address = 'john@contoso.com'
Get-ADObject -Server 'dc01.contoso.com:3268' -SearchBase '' `
-LDAPFilter "(|(proxyAddresses=*:$address)(mail=$address)(userPrincipalName=$address))" `
-Properties proxyAddresses, mail, userPrincipalName, objectClass |
Select-Object Name, ObjectClass, DistinguishedName, userPrincipalName, mail,
@{n='proxyAddresses';e={$_.proxyAddresses -join '; '}}The *: prefix in the filter matches the address whatever the address type prefix is. Contacts and groups are included because Get-ADObject isn't limited to users.
Exchange Online
Get-Recipient returns every mail-enabled object type: mailboxes, mail users, contacts and distribution groups. Microsoft 365 Groups need -RecipientTypeDetails GroupMailbox. With an exact address you don't need the smtp: prefix:
Connect-ExchangeOnline -UserPrincipalName admin@contoso.com
Get-Recipient -Filter "EmailAddresses -eq 'john@contoso.com'" |
Format-Table Name, RecipientTypeDetails, PrimarySmtpAddress, IsDirSynced -AutoSize
Get-Recipient -RecipientTypeDetails GroupMailbox -Filter "EmailAddresses -eq 'john@contoso.com'"IsDirSynced tells you whether the cloud object is synced from Active Directory or was created in the cloud, which decides where you fix it.
Microsoft Entra ID
Microsoft Graph supports endsWith on proxyAddresses as an advanced query. Include the colon in the suffix so the filter matches the address with either the SMTP: or smtp: prefix, but not a longer address such as bigjohn@contoso.com:
Connect-MgGraph -Scopes 'User.Read.All', 'Group.Read.All'
Get-MgUser -Filter "proxyAddresses/any(p:endsWith(p, ':john@contoso.com'))" `
-ConsistencyLevel eventual -CountVariable userCount `
-Property Id, DisplayName, UserPrincipalName, OnPremisesSyncEnabled, ProxyAddresses |
Select-Object DisplayName, UserPrincipalName, OnPremisesSyncEnabled
Get-MgGroup -Filter "proxyAddresses/any(p:endsWith(p, ':john@contoso.com'))" `
-ConsistencyLevel eventual -CountVariable groupCount `
-Property Id, DisplayName, OnPremisesSyncEnabled, ProxyAddresses |
Select-Object DisplayName, OnPremisesSyncEnabledOnPremisesSyncEnabled is True for objects synced from Active Directory and empty for cloud-only objects.
Step 3: Decide which object keeps the value
Use this table to choose where to make the change:
| Situation | Where to fix |
|---|---|
| Two on-premises objects share the address | Active Directory: remove it from the object that shouldn't have it |
| On-premises object conflicts with a cloud-only group, mailbox or contact | Exchange Online or the Microsoft 365 admin center: remove it from the cloud object, or rename the on-premises address |
| Old object was deleted and recreated on-premises | Decide which cloud object should survive; the troubleshooting section covers matching |
| Object moved between forests, or Entra Connect was reinstalled with a different sourceAnchor | Not a duplicate in the data; the sourceAnchor changed, so the soft match fails with InvalidSoftMatch |
Microsoft's guidance is to make the change in the directory where the object is sourced. In some cases you might need to delete one of the objects in conflict.
Step 4: Remove the duplicate
On-premises object
Remove the exact value returned in step 2 from the object that shouldn't have it:
Set-ADUser -Identity 'CN=John Taylor,OU=Users,DC=contoso,DC=com' `
-Remove @{proxyAddresses = 'smtp:john@contoso.com'}For a contact or group, use Set-ADObject with the same -Remove hashtable. If an on-premises Exchange server manages that recipient, consider making the change with the Exchange management tools so its view of the recipient stays consistent.
If the conflict is in userPrincipalName, change the UPN on the object that shouldn't have it. If you need to change UPN suffixes or prepare a non-routable domain, plan it as a separate change rather than as part of an error fix.
Cloud-only object
Remove the alias from the cloud mailbox, group or contact in the Exchange admin center or the Microsoft 365 admin center. Confirm with Get-Recipient that the address no longer appears on it.
Step 5: Sync and verify
On the Entra Connect server, start a delta cycle instead of waiting for the 30-minute schedule:
Import-Module ADSync
Get-ADSyncScheduler | Select-Object SyncCycleEnabled, NextSyncCycleStartTimeInUTC
Start-ADSyncSyncCycle -PolicyType DeltaThen verify:
- The export run on the Entra connector in Synchronization Service Manager shows
success, or no longer lists the object under Synchronization Errors. Get-EntraDirectoryObjectOnPremisesProvisioningErrorno longer returns the value. If it was quarantined, allow up to an hour for the background task to restore it to the right object.Get-Recipient -Filter "EmailAddresses -eq 'john@contoso.com'"returns exactly one object, the intended one.- Connect Health clears the error after its next 30-minute refresh.
Troubleshooting
The error names a value that doesn't exist on-premises. The other holder is a cloud-only object. Search with Get-Recipient and the Graph queries in step 2 and look for objects where IsDirSynced is False or OnPremisesSyncEnabled is empty.
InvalidSoftMatch after a user was deleted and recreated in Active Directory. The new object has a different sourceAnchor, so it can't match the existing cloud user, whose immutableId still points at the old object. Decide which cloud object you want to keep, and follow Microsoft's hard match and soft match guidance for that case rather than deleting cloud users blindly.
InvalidSoftMatch for every object after reinstalling Entra Connect. Microsoft lists this pattern when a different attribute was chosen as the sourceAnchor during reinstallation, so all previously synced objects stop matching. Check which attribute the original installation used before changing any objects.
ObjectTypeMismatch. A user or contact and a group share an address. Remove it from whichever object type shouldn't have it, often a cloud group created for a shared address.
InvalidHardMatch with "The cloud user with privileged roles is not allowed to be taken over." Since July 1, 2026, Entra ID blocks hard matches onto cloud users that hold or are eligible for privileged roles. Temporarily remove the role or eligibility, let the match complete, then restore it.
Existing Admin Role Conflict. Entra Connect won't soft match an on-premises user onto a cloud user with an admin role. Microsoft's fix is to remove the cloud account from all admin roles, hard delete the quarantined object in the cloud, let the next sync cycle soft match the on-premises user to the cloud account, and then restore the role memberships.
The export run stops with stopped-error-limit. There are more than 5,000 errors. Fix the bulk cause first, often a scripted address change or a filtering change, before working through individual objects.
Prevent it from coming back
- Treat Active Directory as the only place to create addresses for synced objects, and check the address with the queries in step 2 before you assign it.
- Before creating a cloud group or shared mailbox, search on-premises for the address you plan to use.
- Don't reuse a departed user's address on a new object until the old object is gone from both directories.
- Don't change the sourceAnchor attribute or delete and recreate users to "reset" them.
- Install the Connect Health agent so conflicts appear in a report with both objects side by side.
Checklist
- Conflicting values listed from Connect Health, the admin center or
Get-EntraDirectoryObjectOnPremisesProvisioningError. - Each value searched in Active Directory, Exchange Online and Entra ID.
- Owner decided for every value; change made in the source directory.
- Delta sync run and export confirmed clean.
- Quarantined values confirmed restored within the hour.
References
- Microsoft Entra Connect: Troubleshoot errors during synchronization
- Identity synchronization and duplicate attribute resiliency
- Troubleshoot directory synchronization errors with event 6941
- Using Microsoft Entra Connect Health with sync
- View directory synchronization errors in Microsoft 365
- Get-EntraDirectoryObjectOnPremisesProvisioningError
- Microsoft Entra Connect Sync: Scheduler
- Synchronization Service Manager Operations tab
- Advanced query capabilities on Microsoft Entra ID objects
- Get-Recipient
- Filterable properties for the Filter parameter
- Get-ADObject
- Set-ADUser