Skip to content

Commit 918c405

Browse files
authored
Adding more information about the service account
Current documentation does not reflect which permission the service account must have on-premises to function as expected.
1 parent ef13ca5 commit 918c405

1 file changed

Lines changed: 3 additions & 0 deletions

File tree

memdocs/autopilot/windows-autopilot-hybrid.md

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -117,6 +117,9 @@ The Intune Connector for Active Directory must be installed on a computer that's
117117

118118
> [!NOTE]
119119
> If your organization has multiple domains and you install multiple Intune Connectors, you must use a service account that's able to create computer objects in all domains, even if you plan to implement hybrid Azure AD join only for a specific domain. If these are untrusted domains, you must uninstall the connectors from domains in which you don't want to use Windows Autopilot. Otherwise, with multiple connectors across multiple domains, all connectors must be able to create computer objects in all domains.
120+
> The connector service account must have the following permissions:
121+
> - [**Logon as Service**](/system-center/scsm/enable-service-log-on-sm?view=sc-sm-2019&preserve-view=true)
122+
> - Must be part of the **Domain user** group and a member of the local **Administrators** group on the Windows server that hosts the connector.
120123
121124
The Intune Connector requires the [same endpoints as Intune](../intune/fundamentals/intune-endpoints.md).
122125

0 commit comments

Comments
 (0)