Co-management azure ad roles

William Hanna 1 Reputation point
2020-10-01T10:48:25.323+00:00

Hello,

We would like to enable co-management and dont want to give service account full global admin.
Do someone know which roles the azure ad account need to integrate co-management?

Is it one time job or will it act as a service account?

Microsoft Intune
Microsoft Intune
A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.
4,332 questions
Microsoft Configuration Manager
0 comments No comments
{count} votes

2 answers

Sort by: Most helpful
  1. Jason Sandys 31,151 Reputation points Microsoft Employee
    2020-10-01T14:37:18.497+00:00

    There are no service accounts in ConfigMgr. Also, no global admin permissions are given or delegated during co-management configuration.

    A global admin account is required during co-management setup to create an Azure AD app registration. There is no other way to create this registration. This is a one time activity that only occurs during setup usin the credentials supplied during the wizard.

    0 comments No comments

  2. Crystal-MSFT 42,961 Reputation points Microsoft Vendor
    2020-10-02T01:50:19.06+00:00

    @William Hanna For co-management, please ensure the Prerequisites in the following are met:
    https://learn.microsoft.com/en-us/mem/configmgr/comanage/overview#prerequisites

    For the role and permission, we can refer to the following table:
    29726-image.png

    Hope it can help.


    If the response is helpful, please click "Accept Answer" and upvote it.
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.