Technical Tip: Attempting to sync a large Azure AD directory may timeout when photo sync is enabled
| Description | This article describes that attempting to sync a large Azure AD directory with photo sync enabled may timeout after 10 minutes and throw an error. |
| Scope | FortiDLP. |
| Solution | Impact: Users who are attempting to sync a large Azure AD environment with photo sync enabled may experience a 502 error after attempting to sync the directory. Users may find that only a portion of their Azure AD users have been imported into the tenant.
The following error may occur after selecting the Sync button on the Azure AD Admin page: An unknown error occurred (502).
Root Cause: Attempting to sync many users with photo sync enabled may reach a 10-minute timeout, causing the sync to be stopped before all users are processed. This issue should only affect deployments with more than 9000 Azure AD users where at least 1000 of them have configured profile pictures.
Workaround: Customers can manually sync a large Azure AD directory with photo sync disabled. This can be achieved using the API Explorer.
The Request body will automatically default to disabling photo sync.
![]() |




