Synchronize AlwaysOn Replicas Configuration and Server Level Objects (Logins, Permissions, Jobs….)



AlwaysOnSynchronizer is a free .NET console application that is designed to be run by an SQL Server Agent job and address the issue of synchronizing “server level objects” from the primary replica to the secondary replica(s).

Here is a direct download link to AlwaysOnSynchronizer from the sqlserverutilities site.

The utility comes in to address the need where environments that have implemented AlwaysOn Availability Groups need to synchronize “server level objects” that are beyond the scope of the Availability Databases that actually synchronize the databases only but do not synchronize objects outside the scope of the database. This leaves objects that are crucial for the ongoing operation such as logins and jobs not synchronized/ updated on the secondary replica(s) and in the event of a failover things stop working and effect the business operation.

I actually coded this tool for a customer that had faced the situation described above and due to lack of a login and a login having it’s password out of date on the secondary replica, applications stopped working following a failover, resulting in an unplanned downtime.

The utility currently synchronizes Logins, Permissions, Linked Servers, Jobs and the Server Wide Configuration (sp_configure) but the existing infrastructure allows me to easily add any additional object that may be needed so if you need to add any object not yet included let me know and I will do that.

Here is the Microsoft documentation showing all objects that should be taken into consideration, and as you can see there is still some way to go. I did not want to invest my time supporting all these objects simply because my current implementation does not require it but as I mentioned I will add support for any object that you will need that is not yet supported.



AlwaysOnSynchronizer maintains a copy of the tables being synchronized at the master database. For example the table dbo.server_principals_snapshot is a copy of the sys.server_principals DMV. Based on the snapshot tables the utility figures out the diff. This is done by comparing the current state against the snapshot table. The detected differences are scripted and saved to script files, a script file per object type. The saved script files are then read from disk and get executed at each secondary replica.


Setup and configuration

Having downloaded the AlwaysOnSynchronizer_Setup.rar file from the link at the top of this post just extract the rar file and locate it at your preferred location.

There is a single configuration file to configure called Servers.config located under the Configuration folder.

Edit the WindowsCluster xml node and type in your WSFC name (the windows cluster name). AlwaysOnSynchronizer uses the query in the bellow snippet to retrieve the replicas belonging to the cluster along with their role.

In the ExecutionOptions xml node edit the attribute PathToLocateSQLScriptFiles and type in the location where you want the generated synchronization script files to be saved. This can be a local path or a UNC path just make sure the account running the utility has read/write access to that location.

The Boolean attribute ExecuteScriptFiles allows you to control if the generated synchronization script files that have been saved will be executed on the secondary replica(s) or not.

Having done that you are all set and ready to go. All other attributes belonging to the ScriptFilesOptions xml node just allow you to control what objects you want to synchronize. Typically you will stay with the defaults but the flexibility exists.

Servers.config configuration file





Query used to get all replicas along with their roles

FROM sys.availability_groups_cluster AS ag
INNER JOIN sys.dm_hadr_availability_replica_cluster_states AS cs ON cs.group_id = ag.group_id
INNER JOIN sys.dm_hadr_availability_replica_states AS rs ON rs.replica_id = cs.replica_id;



I use SQL Server Agent job to run the AlwaysOnSynchronizer executable wrapped up in T-SQL code that uses xp_cmdshell and capture the exit code in order to raise an error if the returned exit code is not 0 and fail the job step
The available exit codes are:
0 – Success
1 – Failure
2 – The number of servers found in the Windows Cluster is smaller than 2 which is unexpected and there is nothing to sync.


-- Turn on xp_cmdshell if needed
DECLARE @is_config_changed bit = 0;
IF EXISTS(SELECT * FROM sys.configurations where name = 'xp_cmdshell' AND value_in_use = 0)
IF EXISTS (SELECT * FROM sys.configurations WHERE name = 'show advanced options' AND value_in_use = 0)
EXEC sys.sp_configure 'show advanced options', 1; RECONFIGURE WITH OVERRIDE;

EXEC sys.sp_configure 'xp_cmdshell', 1; RECONFIGURE WITH OVERRIDE;
SELECT @is_config_changed =1;

DECLARE @rc int;
EXEC @rc = xp_cmdshell 'D:\Team\C#\AlwaysOnSyncronizer\bin\Debug\AlwaysOnSyncronizer.exe', no_output;

IF @rc <> 0
RAISERROR (N'AlwaysOnSyncronizer terminated with a return status of: %d. For additional information check the AlwaysOnSyncronizer.log file.', 16, 1, @rc);

-- Revert back if changed the config
IF @is_config_changed = 1
EXEC sys.sp_configure 'xp_cmdshell', 0; RECONFIGURE WITH OVERRIDE;


You can also check out this related post which is an add on to SSMS for manual synchronization

20170203 – Update: Check out the latest release here

20180112 – Update: Important – Check out this post of AlwaysOnSynchronizer version 1.7.0 that shows a major change in the configuration file Servers.config


Add comment
facebook linkedin twitter email

Leave a Reply

Your email address will not be published.

You may use these HTML tags and attributes: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <s> <strike> <strong>



  1. stilgaw20/06/2016 ב 14:46

    Hi Yaniv,
    This tool looks clever and useful.
    It inspires me somehow to write similar one, personalized for my needs 🙂
    If it is not a problem, could you write what was the reason of introducing snapshotting and T-SQL scripts?
    I am thinking about scripting the objects for each execution of the “AlwaysOnSynchronizer” using SQL Server Management Objects.
    For example for jobs:
    1) scripting objects on primary,
    2) scripting objects on secondary
    3) comparison,
    4) introduce the differences on secondary nodes
    Was the performance the reason?
    But on the other hand I was also thinking that introducing the T-SQL scripts for each object type and placing them in the subfolder could be used for generic behaviour.
    Each new script could correspond to new type that we want to sync.

    Thank you in advance.

    1. Yanco
      Yanco13/08/2016 ב 16:57

      Sorry, I just noticed your comment now. Please let me know if it is still relevant before I reply

  2. Yossi21/09/2016 ב 2:32

    Hi Yaniv,
    This is a great tool, thank you very much for sharing it.
    Is there a way to control the generate script to do execute if not exists (instead of the current version which checking if exists and then drop and create the object)
    It will be nice to have Operators object sync as well ?

    1. Yaniv
      Yaniv16/10/2016 ב 10:50

      I plan to take the time and add your 2 requests for an upcoming release.


      1. Dan15/11/2016 ב 12:57

        version 1.5.0 has a problem:
        a job shedule that was updated at the primary replica would remain unchanged at the secondary replica(s)

        1. Yaniv
          Yaniv26/01/2017 ב 16:39

          Thanks Dan, this is true. I have verified this.
          When you remove a schedule the column date_modified at sysjobs is modified but when you add a new schedule or modify an existing schedule this is not reflected at sysjobs and the date_modified column remains unchanged.
          AlwaysOnSyncronizer is built with a concept of maintaining snapshot tables that keep a copy of the data in the online tables and detects a diff based on a comparison done between the snapshot tables against the online tables. Given that the modification in sysschedules is not reflected in sysjobs this is the reason for this bug.
          You can see the procedures used by the program to get the diffs and to populate the snapshot tables at the working dir or at the master database

    2. Yaniv
      Yaniv26/01/2017 ב 16:29

      Hi Yossi,
      Operators were added in the latest release 1.6 per your request. See this latest post bellow.

      Regarding the IF EXISTS…. as far as I recall it is only used for the login script. Is that what you were referring to?


      1. Amit Arora30/01/2017 ב 2:10

        Hi Yaniv

        Where does the log file get generated? As I am getting the failure code 1 and I want to know why.



        1. Yanco
          Yanco03/02/2017 ב 10:41

          If the defaults were not changed then at the working dir.
          The program uses the log4net logger that have it’s config file (log4net.config) that by default maintains a log file at the folder were the executable runs.

      2. Yossi08/04/2017 ב 20:53

        Thank you Yaniv!.
        Yes, the IF EXISTS was related to Logins.

  3. YvesA08/03/2017 ב 12:57

    Hello Yaniv,
    The Server.config file included in the ZIP is different as the one specified in your blog.
    Instead the …, there’s a … .

    Can you clarify this point please ?


    1. Yanco
      Yanco09/03/2017 ב 8:32

      Yes, you are correct. The blog shows the config file of the very first version and it has slightly changed since. However, the keys at the config file are self-descriptive. Is there any specific key you are not sure about?

      1. YvesA10/03/2017 ב 11:36

        Hi Yaniv,
        Seems that the answer I posted yesterday was lost somewhere 🙂

        Thanks for your answer!

        It works much better with the correct parameters in the Servers.config file!

        Thanks a lot

  4. Julian05/05/2017 ב 18:47


    Is the code open source? or any plans for it?

    Thanks in advance!

    1. Yaniv
      Yaniv05/05/2017 ב 22:18

      At the moment it is not open source but I may do so in the future.

  5. Yanco
    Yanco08/10/2017 ב 8:45

    Sorry for my late response.
    This is the bit of code belonging to the stored procedure get_jobs_to_delete that gets the jobs that were deleted by comparing the snapshot table against sysjobs table.

    — Jobs that were deleted
    FROM master.dbo.jobs_snapshot s
    LEFT JOIN msdb.dbo.sysjobs j ON s.job_id = j.job_id

    Trying to understand the issue you experience we can start by a simple simulation using SSMS.

    The following code
    1. Creates a job
    2. Executes the procedure that looks for jobs that were deleted
    3. Executes the procedure that refreshes (delete and insert) the snapshot table that is used as a reference for the future comparison.

    USE [msdb];
    IF EXISTS (SELECT * FROM sysjobs WHERE name = ‘__test’)
    EXEC msdb.dbo.sp_delete_job @job_name = N’__test’, @delete_unused_schedule=1;

    EXEC msdb.dbo.sp_add_job @job_name=N’__test’,
    @description=N’No description available.’,
    @category_name=N'[Uncategorized (Local)]’,

    use master;
    exec get_jobs_to_delete
    exec dbo.insert_jobs_snapshot

    1. Jason04/01/2018 ב 6:52

      Fantastic script – it has a lot of promise in our environments to overcome some of the shortfalls with AlwaysOn AG’s.

      Query however – I’ve been trying to use a regex to exclude particular agent tasks – mainly beginning with a particular string, without success.

      How could you use a wildcard or pattern match under the ‘ScriptJobsToExclude’ config file tag?


      1. Yaniv
        Yaniv13/01/2018 ב 1:21

        Hi Jason, thanks for your comment.
        I have implemented your request at version 1.7.2
        See this post release here:


  6. BT20/01/2018 ב 18:54

    Hi Yaniv,
    Thanks for the Synch tool!! We’re running a simple setup w/ AlwaysOn (SQL 2016 Ent) with ServerNode1 and ServerNode2. Our Availability Replicas are listed in SSMS as ServerNode1 and ServerNode2.

    In your tools v1.7.2 the Servers.Config file sample, under ServerSettings, you lists PrimaryRelica YANIV and SecondaryReplica YANIV. Why is YANIV listed twice, duplicate here? Shouldn’t these be your NODE1 Replica name and your Node 2 Replica name .. representing the 2 SQL Server names?

    1. Yanco
      Yanco08/02/2018 ב 21:30

      Hi, YANIV appears twice (once for the PrimaryRelica and once for SecondaryRelica ) and I agree it is somewhat confusing but this is so simply because I was testing on a single machine (my laptop). Hope this clarifies it.