Assign Hybrid Identity Administrator Pre AD Connect

Justin Lee 221 Reputation points
2023-01-29T14:28:17.4733333+00:00

How do I assign a user a Hybrid Identity Admin in Azure to setup AAD connect when we don’t have users yet because we haven’t connected to AD DS

Microsoft Security | Microsoft Entra | Microsoft Entra ID
Microsoft Security | Intune | Other
{count} votes

Accepted answer
  1. Thameur-BOURBITA 36,266 Reputation points Moderator
    2023-01-29T19:33:56.9433333+00:00

    Hi,

    If I pretty understand your question, you want create a admin account to manage and configure Azure AD connect.

    To setup AAD connect you have to use a admin account in same domain of AAD connect.

    A admin cloud-only can't setup azure AD connect.

    This admin account should be not synched in azure. It's not recommended to synchronize on-premise admin account.

    Please don't forget to mark helpful answer as accepted


1 additional answer

Sort by: Most helpful
  1. Andy David - MVP 157.8K Reputation points
    2023-01-29T14:52:30.68+00:00

    HI, the AADConnect setup requires a Global Admin to initially set things up:

    https://learn.microsoft.com/en-us/azure/active-directory/hybrid/reference-connect-accounts-permissions#accounts-used-for-azure-ad-connect

    User's image

    The hybrid Identity Role role is a standard one in Azure. You can certainly add any account you want to this role to manage options in Azure.

    https://learn.microsoft.com/en-us/azure/active-directory/roles/permissions-reference#hybrid-identity-administrator

    To assign:

    https://learn.microsoft.com/en-us/azure/active-directory/roles/manage-roles-portal#assign-a-role

    User's image


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.