Share via

Access level clarification needed

Anonymous
2023-05-24T18:17:50.6833333+00:00

This article says "Create a dedicated service account. Create a dedicated user/service account in the Active Directory forest that is located in the identity provider organization."
But gives no information about what rights this service account needs. Is it a Domain User account, a Domain Admin or does it need to be a member of any particular security group?

Windows for business | Windows Client for IT Pros | Directory services | Active Directory
Windows for business | Windows Server | User experience | Other
0 comments No comments

Answer accepted by question author

Anonymous
2023-05-24T23:56:59.3766667+00:00

Any standard domain account can be used as a service account for AD FS. Group Managed Service accounts are also supported. The permissions required at runtime will be added automatically when you configure AD FS.

https://learn.microsoft.com/en-us/windows-server/identity/ad-fs/overview/ad-fs-requirements#BKMK_4

--please don't forget to upvote and Accept as answer if the reply is helpful--

Was this answer helpful?

1 person found this answer helpful.

1 additional answer

Sort by: Most helpful
  1. Deleted

    This answer has been deleted due to a violation of our Code of Conduct. The answer was manually reported or identified through automated detection before action was taken. Please refer to our Code of Conduct for more information.


    Comments have been turned off. Learn more

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.