Procedure to replace the Service Account with gMSA for Entra ID Connect

EnterpriseArchitect 6,301 Reputation points
2025-12-10T10:39:33.1233333+00:00

People,

I have identified that there are two Entra ID Connect in my Forest that are syncing AD Users to the cloud.

Both of them are using a traditional user account, which I wanted to decommission.

Starting from the passive server, what are the steps I must take to replace the existing AD Service Account that is DOMAIN\Enterprise.Admins with a more secure alternative, like gMSA for Entra ID Connect ?

Followed by failvoer and then replacing the other server,

https://learn.microsoft.com/en-us/entra/identity/hybrid/connect/how-to-connect-sync-change-serviceacct-pass

https://learn.microsoft.com/en-us/entra/identity/hybrid/connect/concept-adsync-service-account#virtual-service-account

Any help would be greatly appreciated.

Microsoft Security | Microsoft Entra | Microsoft Entra ID
{count} votes

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.