Service Account for Federation Connection in Microsoft Authentication

Jason Rodriguez 0 Reputation points
2025-04-08T20:25:27.4766667+00:00

An application needs to log in via https://login.microsoftonline.com/ to retrieve information for synchronization (users/groups). However, the user used to initialize the synchronization isn't allowed to sync as a user for federated authentication. What is the appropriate user or service account that would be able to log in via https://login.microsoftonline.com/ and be assigned the appropriate access for user syncing?

Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
24,273 questions
{count} votes

1 answer

Sort by: Most helpful
  1. Harshitha Eligeti 2,680 Reputation points Microsoft External Staff
    2025-04-10T14:37:36.19+00:00

    Hello @Jason Rodriguez
    I understand that your application needs to log in via https://login.microsoftonline.com/ to retrieve information for synchronization (users/groups). Since the user used to initialize the synchronization is not permitted to sync as a user for federated authentication. Now, you need to know the appropriate user or service account that can log in via https://login.microsoftonline.com/ and be granted the necessary access for user synchronization.
    As you mentioned federated authentication, could you clarify where you are expecting this to be implemented? Additionally, since you indicated that you are unable to sync a user with federated authentication, could you specify which synchronization process you are referring to?

    If you have any further questions, feel free to reach out. We are happy to assist you further.

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.