Skip to main content

Permissions for Active Directory Sync

The following permissions are required for the credential used by Threat Manager for Active Directory Sync. See the Entra ID Sync Page topic for additional information about syncing the configured Active Directory domain(s) in Threat Manager.

Object TypeFunctionAccess Requirements
GroupRetrieve all deleted groupsRead Access to group objects under the Deleted Objects Container
GroupRetrieve all groupsRead Access to all group objects in the domain
UserRetrieve all deleted usersRead Access to user objects under the Deleted Objects Container
UserRetrieve all usersRead all user objects from the domain
ComputerRetrieve all deleted computer objectsRead all computer objects under the Deleted Objects Container
ComputerRetrieve all computer objectsRead all computer objects in the domain
GroupUsed specifically for groups that have large memberships which get automatically truncated by the queryRead Access to memberof for all group objects in the domain
GMSARetrieve all Group Managed Service AccountsRead access to all msDS-groupmanagedserviceaccount objects in the domain
SecretRetrieve all DPAPI master backup keys (Secret objects)Read access to all secret objects in Active Directory