question

WilliamHanna-6349 avatar image
0 Votes"
WilliamHanna-6349 asked saldana-msft edited

Co-management azure ad roles

Hello,

We would like to enable co-management and dont want to give service account full global admin.
Do someone know which roles the azure ad account need to integrate co-management?

Is it one time job or will it act as a service account?

mem-cm-generalmem-intune-generalmem-cm-co-management
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

Jason-MSFT avatar image
0 Votes"
Jason-MSFT answered

There are no service accounts in ConfigMgr. Also, no global admin permissions are given or delegated during co-management configuration.

A global admin account is required during co-management setup to create an Azure AD app registration. There is no other way to create this registration. This is a one time activity that only occurs during setup usin the credentials supplied during the wizard.

5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

Crystal-MSFT avatar image
0 Votes"
Crystal-MSFT answered Crystal-MSFT commented

@WilliamHanna-6349 For co-management, please ensure the Prerequisites in the following are met:
https://docs.microsoft.com/en-us/mem/configmgr/comanage/overview#prerequisites

For the role and permission, we can refer to the following table:
29726-image.png

Hope it can help.


If the response is helpful, please click "Accept Answer" and upvote it.
Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.



image.png (40.3 KiB)
· 1
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

@WilliamHanna-6349, Hope everything is going well. I am writing to see if there's anything else we can help. If yes, feel free to let us know.

0 Votes 0 ·