question

ALAJ-6858 avatar image
0 Votes"
ALAJ-6858 asked ALAJ-6858 answered

how to sync on-prem gMSA with Azure Active Directory?

Is this even possible today?

azure-ad-domain-services
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

vipulsparsh-MSFT avatar image
0 Votes"
vipulsparsh-MSFT answered

@ALAJ-6858 Thanks for reaching out.

On prem GMSA are not synced to azure AD as of today. Many of the azure services utilize AAD managed identity for Authentication and since we don't sync it, the GMSA never really gets any AAD specific Identity to use for Azure services.

If you have Azure AD Domain Services, you can create a GMSA there if it fits your need.
https://docs.microsoft.com/en-us/azure/active-directory-domain-services/create-gmsa





Please remember to "Accept Answer" if any answer/reply helped, so that others in the community facing similar issues can easily find the solution.

5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

ALAJ-6858 avatar image
0 Votes"
ALAJ-6858 answered

Yes. I also receive confirmation from Microsoft about it.

5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.