Skip to content

Add hybrid identity administrator as a possible role for config change#1876

Open
AugustDailey wants to merge 1 commit intoMicrosoftDocs:mainfrom
AugustDailey:fix/role-for-fed-config
Open

Add hybrid identity administrator as a possible role for config change#1876
AugustDailey wants to merge 1 commit intoMicrosoftDocs:mainfrom
AugustDailey:fix/role-for-fed-config

Conversation

@AugustDailey
Copy link
Copy Markdown
Contributor

Adding Hybrid Identity Administrator as a valid role that can achieve the same prerequisite as Global Admin.

Entra Role - Hybrid Identity Administrator

@prmerger-automator
Copy link
Copy Markdown
Contributor

@AugustDailey : Thanks for your contribution! The author(s) and reviewer(s) have been notified to review your proposed change.

@AugustDailey AugustDailey force-pushed the fix/role-for-fed-config branch from 2bc3d61 to 8ffc5e4 Compare February 2, 2026 15:46
@AugustDailey
Copy link
Copy Markdown
Contributor Author

Force push was to fix a spelling error in the commit message.

@AugustDailey AugustDailey changed the title Add hybrid identity adminsitrator as a possible role for config change Add hybrid identity administrator as a possible role for config change Feb 2, 2026
@learn-build-service-prod
Copy link
Copy Markdown
Contributor

Learn Build status updates of commit 2bc3d61:

✅ Validation status: passed

File Status Preview URL Details
docs/identity/hybrid/connect/migrate-from-federation-to-cloud-authentication.md ✅Succeeded

For more details, please refer to the build report.

@learn-build-service-prod
Copy link
Copy Markdown
Contributor

Learn Build status updates of commit 8ffc5e4:

✅ Validation status: passed

File Status Preview URL Details
docs/identity/hybrid/connect/migrate-from-federation-to-cloud-authentication.md ✅Succeeded

For more details, please refer to the build report.

Copy link
Copy Markdown
Contributor

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR updates the migration guidance to recognize the Hybrid Identity Administrator role as an alternative to Global Administrator for specific sign-in/configuration steps during federation-to-cloud-auth conversion.

Changes:

  • Updates the Microsoft Entra Connect wizard step to allow using a Global Administrator or Hybrid Identity Administrator account.
  • Updates the Microsoft Graph PowerShell sign-in step to allow using a Global Administrator or Hybrid Identity Administrator account.

![View Additional tasks](media/deploy-cloud-user-authentication/additional-tasks.png)

3. On the **Connect to Microsoft Entra ID** page, enter your Global Administrator account credentials.
3. On the **Connect to Microsoft Entra ID** page, enter your Global Administrator or Hybrid Identity Administrator account credentials.
Copy link

Copilot AI Feb 2, 2026

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This wording is a bit ambiguous (it can read like you have two different accounts). Consider rephrasing to something like “enter credentials for an account that’s assigned the Global Administrator or Hybrid Identity Administrator role” for clarity. Also, later in this article the authentication agent installation step still says a Global Administrator account is required (around line 296), so please confirm whether Hybrid Identity Administrator should be accepted there too and keep the role requirements consistent to avoid confusing readers.

Suggested change
3. On the **Connect to Microsoft Entra ID** page, enter your Global Administrator or Hybrid Identity Administrator account credentials.
3. On the **Connect to Microsoft Entra ID** page, enter credentials for an account that's assigned the Global Administrator or Hybrid Identity Administrator role.

Copilot uses AI. Check for mistakes.
**Complete the conversion by using the Microsoft Graph PowerShell SDK:**

1. In PowerShell, sign in to Microsoft Entra ID by using a Global Administrator account.
1. In PowerShell, sign in to Microsoft Entra ID by using a Global Administrator or Hybrid Identity Administrator account.
Copy link

Copilot AI Feb 2, 2026

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Consider rephrasing to “sign in … using an account assigned the Global Administrator or Hybrid Identity Administrator role” to avoid implying these are separate dedicated accounts. As with the earlier wizard step, please also ensure the role requirement is consistent with the rest of the article (there’s at least one other step that still states Global Administrator is required).

Suggested change
1. In PowerShell, sign in to Microsoft Entra ID by using a Global Administrator or Hybrid Identity Administrator account.
1. In PowerShell, sign in to Microsoft Entra ID by using an account assigned the Global Administrator or Hybrid Identity Administrator role.

Copilot uses AI. Check for mistakes.
@ttorble
Copy link
Copy Markdown
Contributor

ttorble commented Feb 2, 2026

@Gargi-Sinha

Can you review the proposed changes?

IMPORTANT: When the changes are ready for publication, adding a #sign-off comment is the best way to signal that the PR is ready for the review team to merge.

#label:"aq-pr-triaged"
@MicrosoftDocs/public-repo-pr-review-team

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants