how to sync on-prem gMSA with Azure Active Directory?

A Lee 21 Reputation points
2021-07-21T12:45:16.477+00:00

Is this even possible today?

Microsoft Security | Microsoft Entra | Other
0 comments No comments
{count} votes

Answer accepted by question author
  1. Vipul Sparsh 16,331 Reputation points Microsoft Employee Moderator
    2021-07-22T05:13:16.89+00:00

    @A Lee Thanks for reaching out.

    On prem GMSA are not synced to azure AD as of today. Many of the azure services utilize AAD managed identity for Authentication and since we don't sync it, the GMSA never really gets any AAD specific Identity to use for Azure services.

    If you have Azure AD Domain Services, you can create a GMSA there if it fits your need.
    https://learn.microsoft.com/en-us/azure/active-directory-domain-services/create-gmsa

    ---------------------------------------------------------------------------------------------------------

    Please remember to "Accept Answer" if any answer/reply helped, so that others in the community facing similar issues can easily find the solution.

    0 comments No comments

1 additional answer

Sort by: Most helpful
  1. A Lee 21 Reputation points
    2021-07-23T03:25:45.583+00:00

    Yes. I also receive confirmation from Microsoft about it.

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.