Microsoft 365 Tenant Errors Reference
Use this reference to identify the error states that can appear for your Microsoft 365 Tenants, understand what causes each one, and apply the correct resolution.
Notes:
- “Shared” in the Category column means the error can apply to either a CSP / Child Tenant or a Single Tenant.
- If your user account lacks the required Syncro permissions (such as "Tenant List View" or "Add Microsoft 365 Tenant"), you will receive a 403 error when attempting to interact with a tenant. This is a platform-level permission issue, not a tenant-specific error. To resolve it, adjust your Syncro user permissions to include the required access.
| Category | Error Type | Error | Status Indicator | Description | Resolution |
|---|---|---|---|---|---|
| CSP / Child Tenant | Microsoft 365 Connection | Missing Admin Relationship | Red | No active CSP Admin relationship exists between your Syncro account and the tenant. | Re-establish the CSP relationship via the Microsoft Partner Center. |
| CSP / Child Tenant | Microsoft 365 Connection | Missing Roles | Red | The CSP account lacks the required GDAP roles or is not a Global Admin. | Assign required GDAP roles (or Global Admin) in the Microsoft Partner Center / Admin Portal. |
| CSP / Child Tenant | Microsoft 365 Connection | Missing Security Group | Red | The specific security group required for management is missing, lacks proper roles, or the service account is not a member. | Verify/configure the security group in the Microsoft 365 Admin Center and ensure the service account is a member. |
| CSP / Child Tenant | Microsoft 365 Connection | Consent Pending | Yellow | Awaiting Microsoft to process the request (specific to the CSP handshake). | Awaiting Microsoft; no action required. Monitor the status for transition to active. |
| CSP / Child Tenant | Microsoft 365 Connection | Consent Failure | Red | The CSP Auth is active, but Microsoft returned a consent-related error. | Re-initiate the connection flow in Syncro or re-approve consent in the Microsoft Admin Portal. |
| CSP / Child Tenant | Microsoft 365 Connection | Unknown | A general, catch-all error state for CSP/consent or Microsoft API failures. | Retry the connection; check Microsoft Service Health to ensure no API disruptions are affecting the tenant. | |
| Single Tenant | Microsoft 365 Connection | Consent Failed | Red | The specific onboarding process failed; requires re-authorization of that individual Microsoft account. | Open the context menu and select "Reauthorize Microsoft 365." |
| Shared | Microsoft 365 Connection | Auth Errors | Red | Top-level "health" indicators. They surface for any tenant (CSP or individual) where there is an active authentication failure. | Open the context menu and select "Reauthorize Microsoft 365." |
| Shared | Microsoft 365 Connection | Sync Status (Auth Error) | Red | Indicates a general failure while making requests for the tenant. | Open the context menu and select "Reauthorize Microsoft 365." |
| Single Tenant | Backup Status | Backup Failure | Red | (Often) caused by missing Admin consent or specific app permissions for that individual tenant. | Open the context menu and select "Reauthorize Backup." |
| Single Tenant | Backup Status | No Data Backed Up | Red | Onboarding for this specific tenant was interrupted or incomplete. | Open the context menu and either select "Enable Backup" or, if the connection failed, "Reauthorize Backup." |
| Single Tenant | Authentication Error | Cloud Backup Could Not Be Enabled | Occurs if you attempt to enable backup for a tenant already being backed up elsewhere (there can only be one Microsoft Tenant associated with a Syncro Tenant). | Open the context menu for the other tenant and select "Disable Backup." When that association is cleared, you can "Enable Backup" on the new tenant. | |
| Shared | -- | A Sync Error Has Occurred | -- | A temporary disruption between the Backup Portal and the server (usually transient). | Transient. Wait for sync; if persistent, open the context menu and select "Reauthorize Microsoft 365." |