A cloud-based identity and access management service for securing user authentication and resource access
The error indicates that a previous operation to enable directory synchronization (DirSync) is still in a pending state, so a disable request is blocked until that operation completes.
Behavior from the cmdlet documentation:
-
Set-EntraDirSyncEnabledturns directory synchronization on or off for the tenant. - Deactivating DirSync may take up to 72 hours, depending on the number of objects in the subscription.
- Once a DirSync state change is in progress, it cannot be canceled and must complete before any further action (including re-enabling or disabling DirSync) can be taken.
In this situation:
- Wait for the current DirSync state change (the pending enable) to fully complete. This can take significant time depending on tenant size.
- After the enable operation has finished and the tenant is in a stable state, run the disable command again:
Connect-Entra -Scopes 'OnPremDirectorySynchronization.ReadWrite.All', 'Organization.ReadWrite.All' $tenantID = (Get-EntraContext).TenantId Set-EntraDirSyncEnabled -EnableDirsync $false -TenantId $tenantID -Force
If BlockCloudObjectTakeoverThroughHardMatch is enabled and DirSync is later re-enabled, on-premises to cloud object takeover/updates for Microsoft Entra ID–mastered objects will be blocked until that setting is set to false.
References: