An Azure offering that provides a suite of purpose-built technologies for protected health information in the cloud.
The alert indicates that Microsoft Entra Connect Health hasn't received complete data from one or more on-premises Health agents in the last two hours. This is typically caused by connectivity or agent/service issues.
To troubleshoot and resolve it, follow these steps:
- Verify the alert details
- In the Azure portal, go to Microsoft Entra Connect Health.
- Open the relevant service (Sync, AD DS, or AD FS) and select Alerts.
- Open the Health service data isn't up to date alert and then select the Server Name.
- Review Alert Details and Data Type Details to see which data types are missing and from which agent/service.
- Check agent versions and services
- Ensure the latest Microsoft Entra Connect Health agents are installed on the affected servers (Sync, AD DS, AD FS as applicable).
- On each affected server, open Services and confirm all relevant Microsoft Entra Connect Health services are Running (for example, for AD FS there should be two Health services; for Sync/AD DS see the table in the documentation).
- Validate prerequisites and connectivity
- Confirm all requirements for Microsoft Entra Connect Health are met (firewall, TLS, permissions, etc.).
- If an HTTP proxy is used, ensure it is configured for the Health agents as documented.
- Run the connectivity test on the affected server:
or useTest-MicrosoftEntraConnectHealthConnectivity -Role ADFS-Role Syncor-Role ADDSdepending on the service. If this fails, fix the reported connectivity issues (network, firewall, proxy, TLS inspection).
- Check for registration and endpoint issues
- If the agent cannot register or communicate:
- Ensure outbound communication to required endpoints and ports is allowed.
- Verify there is no TLS inspection replacing certificates on outbound traffic.
- Ensure the account registering the agent has appropriate permissions (for example, Global Administrator or delegated via Azure RBAC).
- If the agent cannot register or communicate:
- Consider data retention behavior
- If a server has an active Health service data is not up to date error for more than 30 consecutive days, it will be disabled and no longer shown in the Connect Health portal.
- To re-enable such a server, uninstall and then reinstall the Health agent on that server.
- Understand alert behavior
- Warning: Health Service received only partial data types in the last two hours (no email notification).
- Error: Health Service received no data types in the last two hours (email notification is sent).
- Alerts resolve automatically when agents successfully send complete data again, or are suppressed if the error condition is not seen for 72 hours.
If these steps are followed and connectivity plus agent health are restored, the alert should clear automatically once fresh data is uploaded.
References:
- Health service data isn't up to date alert
- Troubleshoot data freshness alerts in Microsoft Entra Connect Health
- User privacy and Microsoft Entra Connect Health
- Microsoft Entra Connect Health frequently asked questions
- Install the Microsoft Entra Connect Health agents
- Microsoft Entra Connect Health Alert Catalog