You will use the Express Settings option in Azure AD Connect to synchronize a contoso.com Active Directory forest to Azure AD. Following least privilege, which two roles/groups are required to perform this configuration?
Choose an answer
Tap an option to check your answer.
Correct answer: the Global administrator role in Azure AD, the Enterprise Admins group in Active Directory.
Why this is the answer
To configure Azure AD Connect using Express Settings, the account used in the on-premises Active Directory must be a member of the Enterprise Admins group. This group has the necessary permissions to create and modify objects across the entire forest, which Azure AD Connect requires for synchronization. The account used in Azure AD must have the Global administrator role. This role provides the highest level of administrative privileges in Azure AD, enabling it to create and manage directory objects, synchronize with on-premises directories, and configure other critical services. The Domain Admins group is insufficient as it only has administrative rights within a specific domain, not the entire forest. The Security administrator and User administrator roles in Azure AD lack the broad permissions required to configure Azure AD Connect and establish directory synchronization.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed