how to sync on-prem gMSA with Azure Active Directory?

A Lee 21 Reputation points
2021-07-21T12:45:16.477+00:00

Is this even possible today?

Microsoft Entra
0 comments No comments
{count} votes

Accepted answer
  1. VipulSparsh-MSFT 16,271 Reputation points Microsoft Employee
    2021-07-22T05:13:16.89+00:00

    @A Lee Thanks for reaching out.

    On prem GMSA are not synced to azure AD as of today. Many of the azure services utilize AAD managed identity for Authentication and since we don't sync it, the GMSA never really gets any AAD specific Identity to use for Azure services.

    If you have Azure AD Domain Services, you can create a GMSA there if it fits your need.
    https://learn.microsoft.com/en-us/azure/active-directory-domain-services/create-gmsa

    ---------------------------------------------------------------------------------------------------------

    Please remember to "Accept Answer" if any answer/reply helped, so that others in the community facing similar issues can easily find the solution.

    0 comments No comments

1 additional answer

Sort by: Most helpful
  1. A Lee 21 Reputation points
    2021-07-23T03:25:45.583+00:00

    Yes. I also receive confirmation from Microsoft about it.

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.