The HCW supports using accounts protected by MFA, yes. And all your Global admins should be protected by MFA!
Global Admin requirement for using Hybrid Configuration Wizard to create a full classic hybrid deployment?

Based on this article: https://learn.microsoft.com/en-us/exchange/hybrid-deployment/deploy-hybrid#use-the-exchange-admin-center-and-hybrid-configuration-wizard-to-create-a-full-classic-hybrid-deployment
Does the service account used by Hybrid Configuration Wizard to create a full classic hybrid deployment can be my own admin account with MFA/2FA enforced?
Or is this must be a separate OnPremise AD account with the Global Administrator role with no MFA/2FA enforced?
1 additional answer
Sort by: Most helpful
-
Yuki Sun-MSFT 41,336 Reputation points Microsoft External Staff
2023-08-17T02:42:43.2533333+00:00 Hi @EnterpriseArchitect ,
Not quite clear about the exact role group membership of your current admin account, but as aforementioned, basically, there are 2 types of Admin accounts needed to run HCW:
- On-premises Exchange Account This account needs to be member of Organization Management.
- Microsoft 365 Exchange Online Account. This needs to be a Global Admin (Exchange Admin included)
You can use the existent admin accounts that meet the requirements, regardless of whether they are with or without MFA.
Here's one more blog with some screenshots for your reference:
(The UI might have changed a bit but the basic concepts still apply)Modern HCW (Hybrid Agent): troubleshooting like a pro
If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".
Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.