Security & identity

Fix Entra Connect AttributeValueMustBeUnique and duplicate proxy addresses

Find which object already holds the duplicated proxyAddresses or userPrincipalName value, remove it from the right side, and confirm the next Entra Connect sync exports cleanly.

12 min read
On this page

AttributeValueMustBeUnique means Microsoft Entra Connect tried to write a proxyAddresses, userPrincipalName, mail or signInName value that another object in Microsoft Entra ID already holds. To fix it, identify the duplicated value from the error, find every object in Active Directory and in the cloud that holds it, decide which one should keep it, remove it from the other in the directory that owns that object, and let the next sync cycle export the change. The conflict never resolves itself: even when duplicate attribute resiliency quarantines the value and lets the object sync, one of the two objects is missing data until you fix the source.

Who this is for and what you will have

This guide is for administrators running Microsoft Entra Connect Sync in a hybrid Active Directory and Microsoft 365 environment, often in the middle of a mailbox migration or right after a reorganization that reused email addresses. By the end you will have:

  • The exact conflicting value and both objects involved.
  • PowerShell queries that search Active Directory, Exchange Online and Microsoft Entra ID for a given address.
  • A corrected source object and a clean export on the next sync cycle.
  • A short list of habits that stop the error coming back.

Duplicate addresses are especially common after a tenant consolidation or a cross-tenant move. If that is your situation, the cross-tenant migration architecture guide covers how to plan address ownership before cutover.

How the error appears

You will usually meet the error in one of four places:

  • Email: the Identity Synchronization Error Report sent to the tenant's technical notification contact.
  • Synchronization Service Manager: on the Entra Connect server, the Operations tab shows an export run on the Entra connector (named in the format contoso.onmicrosoft.com) with a completed-*-errors status. Select the run and look under Synchronization Errors.
  • Application event log: event ID 6941 from source ADSync.
  • Admin portals: Microsoft Entra Connect Health and the Microsoft 365 admin center.

The event log text is the most useful because it names the attribute and the value:

Event ID: 6941
Log Name: Application
Source: ADSync
Level: Error
Details:
ECMA2 MA export run caused an error.
 
Error Name: AttributeValueMustBeUnique
Error Detail: Unable to update this object because the following attributes associated
with this object have values that may already be associated with another object in your
local directory services: [UserPrincipalName john@contoso.com;]. Correct or remove the
duplicate values in your local directory. Please refer to
https://support.microsoft.com/kb/2647098 for more information on identifying objects
with duplicate attribute values.

For a proxy address conflict, the bracketed part reads [ProxyAddresses SMTP:john@contoso.com;] instead.

ErrorWhat happenedTypical trigger
AttributeValueMustBeUniqueAn update or new object uses a unique value that another Entra object already hasAn address added to a synced user that another synced user already holds
InvalidSoftMatchNo hard match on sourceAnchor, but a soft match on proxyAddresses or UPN found an object with a different immutableIdTwo on-premises objects share an address; an object was deleted and recreated; the sourceAnchor attribute changed
ObjectTypeMismatchThe soft match found an object of a different type with the same valueA new on-premises user has the address of a cloud mail-enabled group

All three are fixed the same way: remove the duplicate from the object that shouldn't have it. Microsoft lists mail, proxyAddresses, signInName and userPrincipalName as attributes that must be unique for AttributeValueMustBeUnique.

How duplicate attribute resiliency changes what you see

Duplicate attribute resiliency is on by default for tenants and can't be turned off. Instead of failing the whole export, Entra ID quarantines the conflicting UPN or SMTP proxy address:

  • A conflicting proxy address is simply left off the object, and the object is created or updated without it.
  • A conflicting UPN is replaced with a placeholder in the format <OriginalPrefix>+<4DigitNumber>@<InitialTenantDomain>.onmicrosoft.com, because every user needs a UPN.
  • The quarantined value is stored in the object's provisioning errors, and the error report email mentions it once, at the time of quarantine.
  • A background task runs every hour, finds conflicts that have been resolved, and puts the quarantined value back.

This is why a user can appear with an odd onmicrosoft.com UPN, or a mailbox is missing one alias, with no recurring error in the sync client. The data still needs fixing. Microsoft also documents cases where resiliency doesn't apply and a normal export error is retried every cycle, for example a new user whose address conflicts with an existing group.

Prerequisites

  • Hybrid Identity Administrator (or Global Administrator) to view sync errors in the Microsoft 365 admin center.
  • The Active Directory PowerShell module on a domain-joined machine, with rights to modify the affected objects.
  • Exchange Online PowerShell for cloud recipients.
  • Microsoft Graph PowerShell or Microsoft Entra PowerShell for directory queries.
  • Access to the Entra Connect server to run a sync cycle.

Step 1: Get the list of conflicts

Microsoft Entra Connect Health

If the Connect Health agent is installed on the sync server, open Connect Health, select Sync services, then the service, and open the synchronization errors. The report groups errors into categories, including Duplicate Attribute and Data Mismatch, shows a side-by-side comparison of the objects in conflict, highlights the conflicting attribute, and lets you export a CSV. It is updated every 30 minutes from the latest export run.

Microsoft 365 admin center

On the Home page, find the User management card and select Sync errors under Microsoft Entra Connect. Only user objects appear here, not conflicts between groups and contacts.

Microsoft Entra PowerShell

Get-EntraDirectoryObjectOnPremisesProvisioningError returns sync errors for users, groups and organizational contacts, including the property and value in conflict:

Connect-Entra -Scopes 'User.Read.All', 'Directory.Read.All', 'Group.Read.All', 'Contacts.Read'
 
# Every quarantined or conflicting value
Get-EntraDirectoryObjectOnPremisesProvisioningError | Format-Table -AutoSize
 
# Only proxy address conflicts
Get-EntraDirectoryObjectOnPremisesProvisioningError |
    Where-Object PropertyCausingError -eq 'ProxyAddresses' |
    Format-Table Id, DisplayName, Value, OccurredDateTime -AutoSize

The output includes PropertyCausingError (ProxyAddresses or UserPrincipalName), Category (for example PropertyConflict) and Value, such as SMTP:john@contoso.com. Write down each value; the next step finds who else has it.

Step 2: Find every object that holds the value

A duplicate can live in on-premises Active Directory, in the cloud, or both. Check all three places before you change anything.

Active Directory

Search the whole forest through a global catalog so you don't miss objects in other domains. With the search base set to an empty string on the global catalog port, all partitions are searched:

$address = 'john@contoso.com'
 
Get-ADObject -Server 'dc01.contoso.com:3268' -SearchBase '' `
    -LDAPFilter "(|(proxyAddresses=*:$address)(mail=$address)(userPrincipalName=$address))" `
    -Properties proxyAddresses, mail, userPrincipalName, objectClass |
    Select-Object Name, ObjectClass, DistinguishedName, userPrincipalName, mail,
        @{n='proxyAddresses';e={$_.proxyAddresses -join '; '}}

The *: prefix in the filter matches the address whatever the address type prefix is. Contacts and groups are included because Get-ADObject isn't limited to users.

Exchange Online

Get-Recipient returns every mail-enabled object type: mailboxes, mail users, contacts and distribution groups. Microsoft 365 Groups need -RecipientTypeDetails GroupMailbox. With an exact address you don't need the smtp: prefix:

Connect-ExchangeOnline -UserPrincipalName admin@contoso.com
 
Get-Recipient -Filter "EmailAddresses -eq 'john@contoso.com'" |
    Format-Table Name, RecipientTypeDetails, PrimarySmtpAddress, IsDirSynced -AutoSize
 
Get-Recipient -RecipientTypeDetails GroupMailbox -Filter "EmailAddresses -eq 'john@contoso.com'"

IsDirSynced tells you whether the cloud object is synced from Active Directory or was created in the cloud, which decides where you fix it.

Microsoft Entra ID

Microsoft Graph supports endsWith on proxyAddresses as an advanced query. Include the colon in the suffix so the filter matches the address with either the SMTP: or smtp: prefix, but not a longer address such as bigjohn@contoso.com:

Connect-MgGraph -Scopes 'User.Read.All', 'Group.Read.All'
 
Get-MgUser -Filter "proxyAddresses/any(p:endsWith(p, ':john@contoso.com'))" `
    -ConsistencyLevel eventual -CountVariable userCount `
    -Property Id, DisplayName, UserPrincipalName, OnPremisesSyncEnabled, ProxyAddresses |
    Select-Object DisplayName, UserPrincipalName, OnPremisesSyncEnabled
 
Get-MgGroup -Filter "proxyAddresses/any(p:endsWith(p, ':john@contoso.com'))" `
    -ConsistencyLevel eventual -CountVariable groupCount `
    -Property Id, DisplayName, OnPremisesSyncEnabled, ProxyAddresses |
    Select-Object DisplayName, OnPremisesSyncEnabled

OnPremisesSyncEnabled is True for objects synced from Active Directory and empty for cloud-only objects.

Step 3: Decide which object keeps the value

Use this table to choose where to make the change:

SituationWhere to fix
Two on-premises objects share the addressActive Directory: remove it from the object that shouldn't have it
On-premises object conflicts with a cloud-only group, mailbox or contactExchange Online or the Microsoft 365 admin center: remove it from the cloud object, or rename the on-premises address
Old object was deleted and recreated on-premisesDecide which cloud object should survive; the troubleshooting section covers matching
Object moved between forests, or Entra Connect was reinstalled with a different sourceAnchorNot a duplicate in the data; the sourceAnchor changed, so the soft match fails with InvalidSoftMatch

Microsoft's guidance is to make the change in the directory where the object is sourced. In some cases you might need to delete one of the objects in conflict.

Step 4: Remove the duplicate

On-premises object

Remove the exact value returned in step 2 from the object that shouldn't have it:

Set-ADUser -Identity 'CN=John Taylor,OU=Users,DC=contoso,DC=com' `
    -Remove @{proxyAddresses = 'smtp:john@contoso.com'}

For a contact or group, use Set-ADObject with the same -Remove hashtable. If an on-premises Exchange server manages that recipient, consider making the change with the Exchange management tools so its view of the recipient stays consistent.

If the conflict is in userPrincipalName, change the UPN on the object that shouldn't have it. If you need to change UPN suffixes or prepare a non-routable domain, plan it as a separate change rather than as part of an error fix.

Cloud-only object

Remove the alias from the cloud mailbox, group or contact in the Exchange admin center or the Microsoft 365 admin center. Confirm with Get-Recipient that the address no longer appears on it.

Step 5: Sync and verify

On the Entra Connect server, start a delta cycle instead of waiting for the 30-minute schedule:

Import-Module ADSync
Get-ADSyncScheduler | Select-Object SyncCycleEnabled, NextSyncCycleStartTimeInUTC
Start-ADSyncSyncCycle -PolicyType Delta

Then verify:

  • The export run on the Entra connector in Synchronization Service Manager shows success, or no longer lists the object under Synchronization Errors.
  • Get-EntraDirectoryObjectOnPremisesProvisioningError no longer returns the value. If it was quarantined, allow up to an hour for the background task to restore it to the right object.
  • Get-Recipient -Filter "EmailAddresses -eq 'john@contoso.com'" returns exactly one object, the intended one.
  • Connect Health clears the error after its next 30-minute refresh.

Troubleshooting

The error names a value that doesn't exist on-premises. The other holder is a cloud-only object. Search with Get-Recipient and the Graph queries in step 2 and look for objects where IsDirSynced is False or OnPremisesSyncEnabled is empty.

InvalidSoftMatch after a user was deleted and recreated in Active Directory. The new object has a different sourceAnchor, so it can't match the existing cloud user, whose immutableId still points at the old object. Decide which cloud object you want to keep, and follow Microsoft's hard match and soft match guidance for that case rather than deleting cloud users blindly.

InvalidSoftMatch for every object after reinstalling Entra Connect. Microsoft lists this pattern when a different attribute was chosen as the sourceAnchor during reinstallation, so all previously synced objects stop matching. Check which attribute the original installation used before changing any objects.

ObjectTypeMismatch. A user or contact and a group share an address. Remove it from whichever object type shouldn't have it, often a cloud group created for a shared address.

InvalidHardMatch with "The cloud user with privileged roles is not allowed to be taken over." Since July 1, 2026, Entra ID blocks hard matches onto cloud users that hold or are eligible for privileged roles. Temporarily remove the role or eligibility, let the match complete, then restore it.

Existing Admin Role Conflict. Entra Connect won't soft match an on-premises user onto a cloud user with an admin role. Microsoft's fix is to remove the cloud account from all admin roles, hard delete the quarantined object in the cloud, let the next sync cycle soft match the on-premises user to the cloud account, and then restore the role memberships.

The export run stops with stopped-error-limit. There are more than 5,000 errors. Fix the bulk cause first, often a scripted address change or a filtering change, before working through individual objects.

Prevent it from coming back

  • Treat Active Directory as the only place to create addresses for synced objects, and check the address with the queries in step 2 before you assign it.
  • Before creating a cloud group or shared mailbox, search on-premises for the address you plan to use.
  • Don't reuse a departed user's address on a new object until the old object is gone from both directories.
  • Don't change the sourceAnchor attribute or delete and recreate users to "reset" them.
  • Install the Connect Health agent so conflicts appear in a report with both objects side by side.

Checklist

  • Conflicting values listed from Connect Health, the admin center or Get-EntraDirectoryObjectOnPremisesProvisioningError.
  • Each value searched in Active Directory, Exchange Online and Entra ID.
  • Owner decided for every value; change made in the source directory.
  • Delta sync run and export confirmed clean.
  • Quarantined values confirmed restored within the hour.

References

Questions people ask

What does AttributeValueMustBeUnique mean in Entra Connect?

Entra Connect tried to add or update an object with a mail, proxyAddresses, signInName or userPrincipalName value that another object in Microsoft Entra ID already has. The schema requires those values to be unique, so the export fails until one of the two objects stops using the value.

Will the error go away on its own?

No. Duplicate attribute resiliency may quarantine the conflicting value so the object can still sync, but the duplicate data still has to be fixed. Once you remove the value from the wrong object, a background task that runs every hour adds the quarantined value back to the right one.

Why does a user suddenly have a UPN ending in onmicrosoft.com?

That is duplicate attribute resiliency at work. When a UPN conflict happens, Entra ID assigns a placeholder in the format OriginalPrefix plus a four-digit number at the initial onmicrosoft.com domain, so the object can still be created. Fix the conflict and the real UPN is applied.

Where do I see directory sync errors in the Microsoft 365 admin center?

On the Home page, the User management card has a Sync errors link under Microsoft Entra Connect that opens the Directory sync errors page. That page only shows user objects, so use Connect Health or PowerShell to see conflicts involving groups and contacts.

Entra ConnectActive DirectoryExchange OnlinePowerShellMicrosoft Entra ID
  1. Block legacy authentication in Microsoft 365 without breaking printers

    Find every device and app that still signs in with legacy authentication, move printers and scanners to a supported sending method, then block legacy auth with Conditional Access.

  2. Compromised Microsoft 365 account runbook: contain, investigate, recover

    A step-by-step runbook for a confirmed Microsoft 365 account takeover: disable and revoke, remove attacker persistence, scope the breach with audit logs and restore the user safely.

  3. Entra Cloud Sync vs Connect Sync - choose an engine and migrate safely

    Compare Microsoft Entra Cloud Sync and Entra Connect Sync feature by feature, check migration readiness, and move with the guided tool or a phased OU pilot.