Skip to content

Prerequisites

Michael Mardahl edited this page Aug 19, 2026 · 1 revision

Prerequisites

PowerShell modules

The tool installs these to the current user on first connection:

  • ExchangeOnlineManagement, for mailboxes and the organization setting
  • Microsoft.Graph.Authentication, for groups and contacts

The RSAT ActiveDirectory module is needed only for the group forward audit (V key). That audit walks on-premises AD membership, so it works only on Windows with RSAT present.

Roles

  • Mailboxes and organization: Exchange Administrator (Global Admin also works)
  • Groups and contacts: Hybrid Identity Administrator

If you use PIM, activate the role before you connect. If you activate after connecting, press W to disconnect and sign in again.

Graph scopes

The tool requests: Group.Read.All, GroupMember.Read.All, User.Read.All, Group-OnPremisesSyncBehavior.ReadWrite.All, OrgContact.Read.All, Contacts-OnPremisesSyncBehavior.ReadWrite.All.

The two OnPremisesSyncBehavior scopes need admin consent in the tenant. See Configure Group SOA for consent steps.

Sync client versions

Microsoft gates these features on specific sync client versions. Older versions either fail or keep pushing old values after the SOA change.

Feature Minimum version
Mailbox Exchange-attribute SOA Entra Connect Sync 2.5.190.0 or higher
Group and contact object SOA Entra Connect Sync 2.5.76.0 or higher, or Cloud Sync 1.1.1370.0 or higher
Exchange attribute writeback to AD Cloud Sync provisioning agent 1.1.1107.0 or higher

Check Connect Sync in Programs and Features, or with:

(Get-ADSyncGlobalSettings).Parameters['Microsoft.Synchronize.ServerConfigurationVersion']

Check the Cloud Sync agent by right-clicking AADConnectProvisioningAgent.exe in C:\Program Files\Microsoft Azure AD Connect Provisioning Agent and reading the Details tab.

Clone this wiki locally