Anyone experienced intermittent authentication failures when Azure AD App Proxy is used with hybrid users?

Hey community!!!

We use Azure AD Connect to sync users into Microsoft Entra ID and set up a hybrid identity.

We also use Azure AD Application Proxy to publish some internal apps to the outside world.

For the last few days, random users (not specific groups) have been getting:

We can’t sign you in right now. Please try again later.

Sometimes refreshing the page works, and sometimes it doesn’t.

What I’ve checked so far:

  • Azure AD Connect sync is healthy

  • No changes to Conditional Access recently

  • The App Proxy connector looks good

  • No changes to DNS on-prem

Has anyone else had problems with App Proxy that cause it to fail to authenticate sometimes?

Should I check the Connector logs next? Networking latency? Setting up the connector group?

Any guidance or similar experiences would help.

Thanks in advance!