Assign Hybrid Identity Administrator Pre AD Connect

Justin Lee 221 Reputation points
2023-01-29T14:28:17.4733333+00:00

How do I assign a user a Hybrid Identity Admin in Azure to setup AAD connect when we don’t have users yet because we haven’t connected to AD DS

Microsoft Intune
Microsoft Intune
A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.
4,321 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
19,451 questions
{count} votes

Accepted answer
  1. Thameur-BOURBITA 32,501 Reputation points
    2023-01-29T19:33:56.9433333+00:00

    Hi,

    If I pretty understand your question, you want create a admin account to manage and configure Azure AD connect.

    To setup AAD connect you have to use a admin account in same domain of AAD connect.

    A admin cloud-only can't setup azure AD connect.

    This admin account should be not synched in azure. It's not recommended to synchronize on-premise admin account.

    Please don't forget to mark helpful answer as accepted


1 additional answer

Sort by: Most helpful
  1. Andy David - MVP 141.5K Reputation points MVP
    2023-01-29T14:52:30.68+00:00

    HI, the AADConnect setup requires a Global Admin to initially set things up:

    https://learn.microsoft.com/en-us/azure/active-directory/hybrid/reference-connect-accounts-permissions#accounts-used-for-azure-ad-connect

    User's image

    The hybrid Identity Role role is a standard one in Azure. You can certainly add any account you want to this role to manage options in Azure.

    https://learn.microsoft.com/en-us/azure/active-directory/roles/permissions-reference#hybrid-identity-administrator

    To assign:

    https://learn.microsoft.com/en-us/azure/active-directory/roles/manage-roles-portal#assign-a-role

    User's image