This guide details the Active Directory (AD DS) setup required for a hybrid identity environment. Its primary purpose is to walk through the identity lifecycle management process and demonstrate how on-premises infrastructure powers the overarching orchestration workflow.
Specifically, the child post covers how to:
1. Integrate Microsoft Entra Connect (formerly AD Connect) directory synchronization into the provisioning pipeline.
2. Configure and grant least-privilege permissions for dedicated service accounts.
3. Provision on-premises user mailboxes and attributes using Exchange Admin Center (EAC).
4. Review the commands to manage local Active Directory group memberships via custom runbook script.
