TFS service account requires read permission in user domains

When TFS is deployed in an active directory domain environment, it makes use of windows accounts stored in domain. TFS uses the service account, usually TfsService, to read SID, email, display name and other account information from AD where TFS users belong to. As you can see here, the service account requires read permission in all TFS user domains.

Account synchronization condition
The synchronization happens

  1. When TFS starts up
  2. When an account is added to a TFS group via Team Explorer
  3. When TFS task scheduler fires a synchronization every one hour

Multiple domain consideration
In organizations that TFS users may come from multiple domains, we can use a service account from a domain that is trusted by all other domains. When using Visual Studio to add users to TFS, we can log on the domain that is trusted by other domains so that we can list all domain accounts.

How to deal with TF200035?
Many customers reported TF200035: One or more errors occurred when Team Foundation Server attempted to synchronize with the following Active Directory identity error. It means TFS can't read account information from active directory for some TFS users. Please check if the account specified in this error message actually exists in the domain. We can also use "TfsSecurity /server:TfsServer /imx domain\account" to simulate TFS synchronizing an account or group. If TFS can retrieve account information for an existing TFS user, it will display something like the following:


More resources to read
Trusts and Forests Considerations for Team Foundation Server.

6 comments:

Anonymous January 15, 2010 at 4:37 AM

Pretty nice place you've got here. Thank you for it. I like such themes and everything that is connected to them. I would like to read a bit more soon.

Unknown June 29, 2012 at 5:28 AM

Hey Bill, thanks a lot for sharing this nice enlightening post. You have actually decoded the in and out of TFS.

Personal Injury Lawyer Temecula

fdhty April 23, 2013 at 6:44 PM

I have a simple philosophy: Fill what's empty. Empty what's full. Scratch where it itches RS GP, Don't go around saying the world owes you a living. The world owes you nothing. It was here first RuneScape Gold, Being happy doesn't mean that everything is perfect. It means that rs gold you've decided to look beyond the imperfections.

Many people in this life deny their freedom. They sit back in their misery and blame it on their parents, or their childhood, their health, or their financial problems Buy Xbox Live Points, they never once stand up and take responsibility for their own lives and their own happiness Ultimate Game Card, of all the wonderful gifts that we've been given, one of the greatest is freedom Cheap Minecraft Gift Code.

NIta September 27, 2019 at 10:55 PM

Untuk bertukar Informasi mengenai Game Online, silahkan kunjungi Blog kami yang ada dibawah ini:

OSG777
SCR888 Indonesia
Login Sbobet
Joker123
918Kiss

jonet October 20, 2019 at 5:19 AM

I truly appreciate this article post. idnlive Really looking forward to read more. Fantastic.

Ayu Ratna Sari October 24, 2019 at 2:32 AM

SBOBET adalah situs taruhan secara daring. Sbobet beroperasi di Asia yang dilisensikan oleh First Cagayan Leisure & Resort Corporation, Manila-Filipina dan di Eropa dilisensikan oleh Pemerintah Isle of Man untuk beroperasi sebagai juru taruhan olahraga sedunia. SBOBET menawarkan taruhan olahraga dalam beberapa bahasa. Sbobet biasanya disebut sebagai Situs Bandar Judi Bola Terpercaya yang sudah dikenal di Indonesi sejak tahun 2014.