Highly privileged accounts shall be cloud-only
Last updated
Last updated
Assign users that need to perform highly privileged tasks to cloud-only Azure AD accounts to minimize the collateral damage of an on-premises identity compromise.
Users that need to be assigned to highly privileged Azure AD roles SHALL be provisioned cloud-only accounts that are separate from the on-premises directory or other federated identity providers.
• All Microsoft Licensing Models support this configuration.
Follow to review the administrative roles like Global Administrator
Ensure that these accounts are cloud only
There is no real end user impact here as you are establishing cloud only administrative accounts.
• None Currently
Getting Sync Status: