Azure AD Connect Permissions

Pedro Osório 0 Reputation points
2023-12-07T15:05:02.3433333+00:00

Hello Team,

Could you please confirm, if the Azure AD Connect Service Account created on AD On-premise need to be Domain Admin to be used for the sync between AD On-prem and Entra ID (Azure AD)?

Or just needed during the installation? After that, can be removed from Domain Admin group? If so, what permissions need to be added to this service account?

Thank you very much.

Microsoft Security | Microsoft Entra | Microsoft Entra ID
{count} votes

2 answers

Sort by: Most helpful
  1. Andreas Baumgarten 123.6K Reputation points MVP Volunteer Moderator
    2023-12-07T15:13:14.8066667+00:00

    Hi @Pedro Osório ,

    the accounts and permissions used by Azure Entra Connect are listed here:

    Accounts used for Microsoft Entra Connect

    There is a difference for installation and sync tasks of Azure Entra Connect.

    AD DS Connector account: Used to read and write information to Windows Server AD by using Active Directory Domain Services (AD DS)

    AD DS Enterprise Administrator account: Optionally used to create the required AD DS Connector account

    For the sync task of Azure Entra Connect you need the permission to read and write in your on-premises AD. That doesn't mean an on-premises Domain Admin is required.


    (If the reply was helpful please don't forget to upvote and/or accept as answer, thank you)

    Regards

    Andreas Baumgarten

    0 comments No comments

  2. Thameur-BOURBITA 36,261 Reputation points Moderator
    2023-12-08T23:16:43.5133333+00:00

    Hi @Pedro Osório

    You don't to need to use a domain admin account when you install Entra connect service.

    You can prepare create the service account and use a Powershell command as described in the article below:

    Microsoft Entra Connect: Configure AD DS Connector Account Permissions


    Please don't forget to accept helpful answer


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.