Skip to main content

Permissions for Active Directory Sync

The following permissions are required for the credential used by Threat Manager for Active Directory Sync. See the Entra ID Sync Page topic for additional information about syncing the configured Active Directory domain(s) in Threat Manager.

Object TypeFunctionAccess Requirements
GroupRetrieve all deleted groupsRead Access to group objects under the Deleted Objects Container
GroupRetrieve all groupsRead Access to all group objects in the domain
UserRetrieve all deleted usersRead Access to user objects under the Deleted Objects Container
UserRetrieve all usersRead all user objects from the domain
ComputerRetrieve all deleted computer objectsRead all computer objects under the Deleted Objects Container
ComputerRetrieve all computer objectsRead all computer objects in the domain
GroupUsed specifically for groups that have large memberships which get automatically truncated by the queryRead Access to memberof for all group objects in the domain
GMSARetrieve all Group Managed Service AccountsRead access to all msDS-groupmanagedserviceaccount objects in the domain
SecretRetrieve all DPAPI master backup keys (Secret objects)Read access to all secret objects in Active Directory

Application Permissions for Entra ID Sync

The following permissions are required for the credential used by Threat Manager for Microsoft Entra ID Sync. See the Active Directory Sync Page topic for additional information about syncing the configured Microsoft Entra ID tenant(s) in Threat Manager.

Object TypeFunctionAccess Requirements
Administrative UnitRetrieve all administrative unitsAdministrativeUnit.Read.All
ApplicationRetrieve all applicationsApplication.Read.All
DeviceRetrieve all devicesDevice.Read.All
GroupRetrieve all groupsGroup.Read.All
Group MemberRetrieve all group membersGroupMember.Read.All
Identity Risky Service PrincipalRetrieve all risky service principalsIdentityRiskyServicePrincipal.Read.All
Identity Risky UserRetrieve all risky usersIdentityRiskyUser.Read.All
OrganizationRetrieve organization informationOrganization.Read.All
Role Assignment ScheduleRead and write role assignment schedules in the directoryRoleAssignmentSchedule.ReadWrite.Directory
Role Eligibility ScheduleRead and write role eligibility schedules in the directoryRoleEligibilitySchedule.ReadWrite.Directory
Role ManagementRetrieve all role management dataRoleManagement.Read.All
UserRetrieve all usersUser.Read.All

Overview

To sync Active Directory domain(s) and Microsoft Entra ID tenant(s) in Threat Manager you must use service accounts with the required permissions. See the following topics for details on these permission.