Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Sophos Active Directory Sync - What rights are needed?

Hello.

 

I've been getting errors from Sophos AD Sync lately, I suspect it is because I removed the service account from the Domain Admins group.  The help file - https://docs.sophos.com/central/Customer/help/en-us/central/Customer/tasks/ActiveDirectorySyncSetup.html - says "On the AD Configuration page, specify your Active Directory LDAP server and credentials for a user account that has read access to the entire Active Directory forest with which you want to synchronize. To stay secure, use an account with the least rights that will give this access."  But it does not say what rights are actually needed?

 

We have only a single domain in our enterprise.  I do not want to leave this account as a member of Domain / Enterprise Admins. 

 

What rights are sufficient for this account?

 

Thanks.



This thread was automatically locked due to age.
Parents Reply Children