Co-management azure ad roles

William Hanna 1 Reputation point
2020-10-01T10:48:25.323+00:00

Hello,

We would like to enable co-management and dont want to give service account full global admin.
Do someone know which roles the azure ad account need to integrate co-management?

Is it one time job or will it act as a service account?

Microsoft Intune
Microsoft Intune
A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.
5,176 questions
Microsoft Configuration Manager
0 comments No comments
{count} votes

2 answers

Sort by: Most helpful
  1. Jason Sandys 31,306 Reputation points Microsoft Employee
    2020-10-01T14:37:18.497+00:00

    There are no service accounts in ConfigMgr. Also, no global admin permissions are given or delegated during co-management configuration.

    A global admin account is required during co-management setup to create an Azure AD app registration. There is no other way to create this registration. This is a one time activity that only occurs during setup usin the credentials supplied during the wizard.

    0 comments No comments

  2. Crystal-MSFT 49,271 Reputation points Microsoft Vendor
    2020-10-02T01:50:19.06+00:00

    @William Hanna For co-management, please ensure the Prerequisites in the following are met:
    https://learn.microsoft.com/en-us/mem/configmgr/comanage/overview#prerequisites

    For the role and permission, we can refer to the following table:
    29726-image.png

    Hope it can help.


    If the response is helpful, please click "Accept Answer" and upvote it.
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.