Enterprise Reporter now requires the Hybrid Identity Administrator role, in addition to Global Reader and Report Reader, for Entra ID (Azure AD) discovery. This change affects the collection of Hybrid AD Connect attributes such as On-Premises Last Password Sync Date Time and On-Premises Password Hash Sync Enabled.
The requirement is due to recent updates in Microsoft’s permissions model, which now restrict access to certain Hybrid AD Connect attributes to users with the Hybrid Identity Administrator role. Question here is, Whether the role is only needed during initial setup or must remain assigned for ongoing discovery and reporting, and how this aligns with least-privilege security practices.
This requirement is due to a change in Microsoft’s permissions model. The Hybrid Identity Administrator role is needed during tenant application creation and admin consent to allow Enterprise Reporter to access Hybrid AD Connect attributes.
After setup, the role can be removed. However, if Hybrid attributes remain selected for discovery, 403 permission errors may occur for those attributes. The discovery process will skip the restricted data and continue running successfully.