码迷,mamicode.com
首页 > 其他好文 > 详细

AZ-303 - AAD

时间:2021-05-24 04:09:23      阅读:0      评论:0      收藏:0      [点我收藏+]

标签:http   reference   configure   global   director   orm   hang   lob   ted   

Accounts used for Azure AD Connect

技术图片

Azure AD Connect uses 3 accounts in order to synchronize information from on-premises or Windows Server Active Directory to Azure Active Directory. These accounts are:

  • AD DS Connector account: used to read/write information to Windows Server Active Directory

  • ADSync service account: used to run the synchronization service and access the SQL database

  • Azure AD Connector account: used to write information to Azure AD

 

AD DS Enterprise Admin credentials

The AD DS Enterprise Admin account is used to configure your on-premises Active Directory. These credentials are only used during the installation and are not used after the installation has completed. The Enterprise Admin, not the Domain Admin should make sure the permissions in Active Directory can be set in all domains.

If you are upgrading from DirSync, the AD DS Enterprise Admins credentials are used to reset the password for the account used by DirSync. You also need Azure AD Global Administrator credentials.

Azure AD Global Admin credentials

These credentials are only used during the installation and are not used after the installation has completed. It is used to create the Azure AD Connector account used for synchronizing changes to Azure AD. The account also enables sync as a feature in Azure AD.

 

AZ-303 - AAD

标签:http   reference   configure   global   director   orm   hang   lob   ted   

原文地址:https://www.cnblogs.com/chun2021/p/14750288.html

(0)
(0)
   
举报
评论 一句话评论(0
登录后才能评论!
© 2014 mamicode.com 版权所有  联系我们:gaon5@hotmail.com
迷上了代码!