When applying the concept of least permissions to On Demand Migration (ODM), full functionality of the tool will require two Entra ID accounts in the target tenant. The first account, is the "consent granting admin account" will need to grant consent to the ODM Service Principals (Enterprise Applications) for the workloads to be migrated. This "consent granting admin account" is the only account required for the source tenant.
The second account is required for ODM to automatically pre-provision OneDrives in the target tenant, as part of the initial OneDrive migration.
1.) Dedicated ODM Consent Account
A dedicated consent account will be required to "grant consent" to the ODM workloads, which are represented by Enterprise Applications in Azure Active Directory.
2.) Optional ODM OneDrive pre-provision service account
A dedicated ODM OneDrive admin service account (Azure AD user account) will be required for processes that, due to API limitations, must be performed outside of the consents granted by the GA account above. Here are examples of tasks where this ODM admin service account is required:
OneDrive migrations
Note: It is possible to pre-provision OneDrive accounts in the target outside of ODM using this Microsoft article. However, guest user migrations and process resource features will not be available unless this optional service account is provided.
ODM OneDrive Admin Service Account Requirements:
OneDrive Service Account can be managed in ODM by going to ODM Accounts | Dashboard | Configure Connections | Target