Global Admin requirement for using Hybrid Configuration Wizard to create a full classic hybrid deployment?

EnterpriseArchitect 5,761 Reputation points
2023-08-16T06:55:11.9866667+00:00

Based on this article: https://learn.microsoft.com/en-us/exchange/hybrid-deployment/deploy-hybrid#use-the-exchange-admin-center-and-hybrid-configuration-wizard-to-create-a-full-classic-hybrid-deployment

Does the service account used by Hybrid Configuration Wizard to create a full classic hybrid deployment can be my own admin account with MFA/2FA enforced?

Or is this must be a separate OnPremise AD account with the Global Administrator role with no MFA/2FA enforced?

Microsoft Exchange Online
Exchange Server Management
Exchange Server Management
Exchange Server: A family of Microsoft client/server messaging and collaboration software.Management: The act or process of organizing, handling, directing or controlling something.
7,854 questions
Microsoft Exchange Hybrid Management
Microsoft Exchange Hybrid Management
Microsoft Exchange: Microsoft messaging and collaboration software.Hybrid Management: Organizing, handling, directing or controlling hybrid deployments.
2,271 questions
Microsoft Entra
Microsoft Entra
A group of Microsoft multicloud identity and access solutions.
2,550 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
24,187 questions
{count} votes

Accepted answer
  1. Vasil Michev 116.8K Reputation points MVP
    2023-08-16T07:01:15.8333333+00:00

    The HCW supports using accounts protected by MFA, yes. And all your Global admins should be protected by MFA!

    1 person found this answer helpful.

1 additional answer

Sort by: Most helpful
  1. Yuki Sun-MSFT 41,336 Reputation points Microsoft External Staff
    2023-08-17T02:42:43.2533333+00:00

    Hi @EnterpriseArchitect ,

    Not quite clear about the exact role group membership of your current admin account, but as aforementioned, basically, there are 2 types of Admin accounts needed to run HCW:

    • On-premises Exchange Account This account needs to be member of Organization Management.
    • Microsoft 365 Exchange Online Account. This needs to be a Global Admin (Exchange Admin included)

    You can use the existent admin accounts that meet the requirements, regardless of whether they are with or without MFA.

    Here's one more blog with some screenshots for your reference:
    (The UI might have changed a bit but the basic concepts still apply)

    Modern HCW (Hybrid Agent): troubleshooting like a pro
    User's image


    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.