AD Connect (dirsync) setting AD permissions


on "install required components" page in custom setting setup wizard can give service account:

1) account used start sync service locally on server?
2) account not used in sync tool connect to ad and in connector configuration connect ad?

on "connect directories" page in custom setting setup wizard need enter credentials:

1) account used in sync tool connect to ad , in connector configuration connect ad? 
2) account enter can domain user right
3) blog (https://azure.microsoft.com/nl-nl/documentation/articles/active-directory-aadconnect-account-summary/) spreaks setting additional permissions on account if use specific scenario such password sync , hybrid environment. blog post describes permissions needed not how set these. there guide how set these permissions, there script how set permissions?

hi,

1 , 2) provide 2 sets of credentials, first has account ad administrative permissions, second should enterprise admin:

the configuration wizard uses enterprise administrator credentials create directory synchronization service account, msol_ad_sync. configuration wizard creates service account domain account directory replication permissions on local active directory, randomly generated complex password never expires.

furter reading on this:

active directory credentials

getting started windows azure active directory – setting windows azure ad tenant

3)

here's example on how set such permissions: how grant "replicating directory changes" permission microsoft metadirectory services adma service account


post provided no warranties or guarantees, , confers no rights.
~~~
questo post non fornisce garanzie e non conferisce diritti



Windows Server  >  Directory Services



Comments

Popular posts from this blog

WIMMount (HSM) causing cluster storage to go redirected (2012r2 DC)

Failed to delete the test record dcdiag-test-record in zone test.com

Azure MFA with Azure AD and RDS