Forum Discussion
Error running on-premises Intune Connector for Active Directory (ODJ Connector).
Don't use any domain admin account. Satisfy the above 5 condition, this WebView2 Runtime should be installed before running the installer. The user who is installing the Intune connector for active directory should have the necessary permission on the OU. Once the installation is complete it will create MSA which will the same right on that OU once we add the distinguished name of the OU in the config file.
For uninstall delete the Managed service account which is created and uninstall using the ODJConnectorBootstrapper.
Firewall rules should be configure for outbound connectivity to the cloud.
login.microsoftonline.com
graph.windows.net
*.officeconfig.msocdn.com
config.office.com
enterpriseregistration.windows.net
certauth.enterpriseregistration.windows.net
*.notify.windows.com
*.wns.windows.com
sinwns1011421.wns.windows.com
sin.notify.windows.com
*.windowsupdate.com
*.dl.delivery.mp.microsoft.com
*.prod.do.dsp.mp.microsoft.com
*.delivery.mp.microsoft.com
*.update.microsoft.com
tsfe.trafficshaping.dsp.mp.microsoft.com
adl.windows.com
time.windows.com
clientconfig.passport.net
windowsphone.com
s-microsoft.com
c.s-microsoft.com
ekop.intel.com
ekcert.spserv.microsoft.com
ftpm.amd.com
lgmsapeweu.blob.core.windows.net
lgmsapewus2.blob.core.windows.net
lgmsapesea.blob.core.windows.net
lgmsapeaus.blob.core.windows.net
lgmsapeind.blob.core.windows.net
*.manage.microsoft.com
manage.microsoft.com
*.delivery.mp.microsoft.com
*.update.microsoft.com
*.windowsupdate.com
adl.windows.com
tsfe.trafficshaping.dsp.mp.microsoft.com
time.windows.com
*.s-microsoft.com
clientconfig.passport.net
windowsphone.com
approdimedatahotfix.azureedge.net
approdimedatapri.azureedge.net
approdimedatasec.azureedge.net
euprodimedatahotfix.azureedge.net
euprodimedatapri.azureedge.net
euprodimedatasec.azureedge.net
naprodimedatahotfix.azureedge.net
naprodimedatapri.azureedge.net
naprodimedatasec.azureedge.net
swda01-mscdn.azureedge.net
swda02-mscdn.azureedge.net
swdb01-mscdn.azureedge.net
swdb02-mscdn.azureedge.net
swdc01-mscdn.azureedge.net
swdc02-mscdn.azureedge.net
swdd01-mscdn.azureedge.net
swdd02-mscdn.azureedge.net
swdin01-mscdn.azureedge.net
swdin02-mscdn.azureedge.net
*.notify.windows.com
*.wns.windows.com
*.do.dsp.mp.microsoft.com
ekcert.spserv.microsoft.com
ekop.intel.com
ftpm.amd.com
*.itunes.apple.com
*.mzstatic.com
*.phobos.apple.com
5-courier.push.apple.com
ax.itunes.apple.com.edgesuite.net
itunes.apple.com
ocsp.apple.com
phobos.apple.com
phobos.itunes-apple.com.akadns.net
intunecdnpeasd.azureedge.net
*.monitor.azure.com
*.support.services.microsoft.com
*.trouter.communication.microsoft.com
*.trouter.skype.com
*.trouter.teams.microsoft.com
api.flightproxy.skype.com
ecs.communication.microsoft.com
edge.microsoft.com
edge.skype.com
remoteassistanceprodacs.communication.azure.com
remoteassistanceprodacseu.communication.azure.com
remotehelp.microsoft.com
wcpstatic.microsoft.com
lgmsapeweu.blob.core.windows.net
intunemaape1.eus.attest.azure.net
intunemaape10.weu.attest.azure.net
intunemaape11.weu.attest.azure.net
intunemaape12.weu.attest.azure.net
intunemaape13.jpe.attest.azure.net
intunemaape17.jpe.attest.azure.net
intunemaape18.jpe.attest.azure.net
intunemaape19.jpe.attest.azure.net
intunemaape2.eus2.attest.azure.net
intunemaape3.cus.attest.azure.net
intunemaape4.wus.attest.azure.net
intunemaape5.scus.attest.azure.net
intunemaape7.neu.attest.azure.net
intunemaape8.neu.attest.azure.net
intunemaape9.neu.attest.azure.net
*.webpubsub.azure.com
*.gov.teams.microsoft.us
remoteassistanceweb.usgov.communication.azure.us
config.edge.skype.com
contentauthassetscdn-prod.azureedge.net
contentauthassetscdn-prodeur.azureedge.net
contentauthrafcontentcdn-prod.azureedge.net
contentauthrafcontentcdn-prodeur.azureedge.net
fd.api.orgmsg.microsoft.com
ris.prod.api.personalization.ideas.microsoft.com