Jump to content

Recommended Posts

Posted (edited)
If you hybrid join all your clients and servers I think you can use AzureAD joined as a control as well as MFA which gets round the need for P1 issue. I can see that most orgs will need P2 at some point. You may need to push an extension to Chrome. Edited by free780
Posted
This made me think about the account used for Azure AD Connect. How does this effect the account used to Sync. Or is that account excluded?

 

Found following article but it is a bit vague.

 

https://techcommunity.microsoft.com/t5/azure-active-directory-identity/azure-ad-connect-sync-account-mfa-support/m-p/689153

We have MFA enabled on the sync account and it only asks for MFA when making changes. Not when running a sync etc. The same as Outlook desktop or mobile apps don't re-ask unless you change security settings or device your using.
  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...