Hybrid Identity Administrator is the newest addition to the list of permissions for the Cloud Discoveries. The Entra ID discovery collects attributes related to Hybrid AD Connect. Enterprise Reporter collects and reports on attributes for a tenant including "On-Premises Last Password Sync Date Time" and "On-Premises Password Hash Sync Enabled"
Microsoft recently changed what permissions are required to collect these attributes, this is the reason behind this requirement.
Azure Active Directory/ Entra ID discovery now require the following roles:
Global Reader
Report Reader
Hybrid Identity Administrator
© 2025 Quest Software Inc. ALL RIGHTS RESERVED. Terms of Use Privacy Cookie Preference Center