Forum Discussion
StuartK73
Jan 18, 2026Iron Contributor
Hybrid Identity Admin Questions
Hi All I hope you are well. Anyway, we are migrating our Entra Connect Sync server to it's own dedicated server. With regards to the Hybrid Identity admin role, do we: Include MFA on...
Kidd_Ip
Jan 19, 2026MVP
Microsoft strongly advises enabling Multi-Factor Authentication (MFA) for all privileged accounts, including the Hybrid Identity Administrator role. Within Privileged Identity Management (PIM), the recommended approach is to configure the role as Eligible rather than Permanent. This ensures that administrative access is granted only when required, thereby reducing standing privileges and enhancing overall security posture.
Microsoft Entra built-in roles - Microsoft Entra ID | Microsoft Learn