All Conditional Access policies are configured to exclude directory synchronization accounts or do not scope them
Waarom dit van Belang is
Serviceaccounts, zoals de Microsoft Entra Connect Sync Account, zijn essentieel voor directorysynchronisatie, maar mogen nooit worden onderworpen aan voorwaardelijketoegangsbeleid dat gebruikersinteractie vereist, zoals multi-factorauthenticatie. Als deze accounts worden geblokkeerd door regels voor voorwaardelijke toegang, kan de synchronisatie mislukken, wat leidt tot identiteitsinconsistenties en mogelijke uitval in uw tenant.
Wat Aether365 Controleert
Deze controle verifieert dat al het voorwaardelijketoegangsbeleid expliciet directorysynchronisatie-serviceaccounts uitsluit of deze helemaal niet omvat. Het verschijnt in het Aether365-dashboard onder de categorie microsoft-365 als controle AE.1020.