Repository navigation
Prerequisites
The tool installs these to the current user on first connection:
- ExchangeOnlineManagement, for mailboxes and the organization setting
- Microsoft.Graph.Authentication, for groups and contacts
The RSAT ActiveDirectory module is needed only for the group forward audit (V key). That audit walks on-premises AD membership, so it works only on Windows with RSAT present.
- Mailboxes and organization: Exchange Administrator (Global Admin also works)
- Groups and contacts: Hybrid Identity Administrator
If you use PIM, activate the role before you connect. If you activate after connecting, press W to disconnect and sign in again.
The tool requests: Group.Read.All, GroupMember.Read.All, User.Read.All, Group-OnPremisesSyncBehavior.ReadWrite.All, OrgContact.Read.All, Contacts-OnPremisesSyncBehavior.ReadWrite.All.
The two OnPremisesSyncBehavior scopes need admin consent in the tenant. See Configure Group SOA for consent steps.
Microsoft gates these features on specific sync client versions. Older versions either fail or keep pushing old values after the SOA change.
| Feature | Minimum version |
|---|---|
| Mailbox Exchange-attribute SOA | Entra Connect Sync 2.5.190.0 or higher |
| Group and contact object SOA | Entra Connect Sync 2.5.76.0 or higher, or Cloud Sync 1.1.1370.0 or higher |
| Exchange attribute writeback to AD | Cloud Sync provisioning agent 1.1.1107.0 or higher |
Check Connect Sync in Programs and Features, or with:
(Get-ADSyncGlobalSettings).Parameters['Microsoft.Synchronize.ServerConfigurationVersion']Check the Cloud Sync agent by right-clicking AADConnectProvisioningAgent.exe in C:\Program Files\Microsoft Azure AD Connect Provisioning Agent and reading the Details tab.