Co-management azure ad roles

William Hanna 1 Reputation point


We would like to enable co-management and dont want to give service account full global admin.
Do someone know which roles the azure ad account need to integrate co-management?

Is it one time job or will it act as a service account?

Microsoft Intune
Microsoft Intune
A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.
4,080 questions
Microsoft Configuration Manager
0 comments No comments
{count} votes

2 answers

Sort by: Most helpful
  1. Jason Sandys 31,121 Reputation points Microsoft Employee

    There are no service accounts in ConfigMgr. Also, no global admin permissions are given or delegated during co-management configuration.

    A global admin account is required during co-management setup to create an Azure AD app registration. There is no other way to create this registration. This is a one time activity that only occurs during setup usin the credentials supplied during the wizard.

    0 comments No comments

  2. Crystal-MSFT 40,706 Reputation points Microsoft Vendor

    @William Hanna For co-management, please ensure the Prerequisites in the following are met:

    For the role and permission, we can refer to the following table:

    Hope it can help.

    If the response is helpful, please click "Accept Answer" and upvote it.
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.