Can a group managed service account be cloud sync'ed?

Gordon Johnson 20 Reputation points
2024-06-03T20:34:17.7766667+00:00

Can a group managed service account be Azure cloud synchronized?

Active Directory
Active Directory
A set of directory-based technologies included in Windows Server.
6,061 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
20,104 questions
{count} votes

Accepted answer
  1. Yanhong Liu 3,740 Reputation points Microsoft Vendor
    2024-06-04T02:02:54.8533333+00:00

    Hello

    Thank you for posting in Q&A forum.

    gMSA is mainly used in local environments and integrated with Active Directory. It cannot be used directly with Azure AD.

    The synchronization between local Active Directory and Azure AD requires the use of the Azure AD Connect tool. Azure AD Connect does not involve the synchronization of gMSA. The features and management of gMSA are still limited to the scope of local AD and cannot be directly extended to Azure AD.

    In the Azure cloud environment, it is recommended to use Azure Managed Identities (AMI) when handling authentication and access control of services and applications.

    I hope the information above is helpful.

    Best Regards,

    Yanhong Liu

    ============================================

    If the Answer is helpful, please click "Accept Answer" and upvote it.

    1 person found this answer helpful.
    0 comments No comments

1 additional answer

Sort by: Most helpful
  1. Andy David - MVP 143.6K Reputation points MVP
    2024-06-03T21:03:11.67+00:00

    No those are not sycned.

    The easiest way to confirm is to run the following on-prem:

    get-adserviceaccount

    then look to see if those are sycned to Entra and you wont see them.

    0 comments No comments