Why is Doman Admin Required for Legacy Password Sync?
The requirement from the product documentation is the following.
The requirement is due to the password sync having to communicate with LSASS, and access to ADMIN$ and to accomplish this the account must be either a Domain Admin or an admin such as a service account and belongs to the built-in admin role.
There are two other new password sync options available either Modern Password Sync or Password Propagation Service.
To learn more about these options and the requirements for each see the links below.
© 2025 Quest Software Inc. ALL RIGHTS RESERVED. Nutzungsbedingungen Datenschutz Cookie Preference Center