You're Enterprise Administrator must grant the required permissions to your synchronization account

ComputerHabit 781 Reputation points
2022-09-01T17:17:00.503+00:00

I have an AD Connect setup with two forests. Each forest has it's own MSOL_ service account. When adding a new subdomain I am getting a message about ensuring the MSOL_ service account has the correct permissions. It is asking this of the MSOL_ account in the separate Forest.

I feel like this error is probably a non issue but wanted to reach out if others had experienced this.

Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
19,422 questions
0 comments No comments
{count} votes

6 answers

Sort by: Most helpful
  1. ComputerHabit 781 Reputation points
    2022-09-06T16:58:09.437+00:00

    Did not work for me in production. Bummer.

    0 comments No comments