This guide provides a detailed breakdown of the CiraSync Service Account Requirements for On-Premises Environments:
On-Premises Environment
Use Case: For reading an on-prem AD and syncing directly to Exchange on-prem mailboxes we will need following
In this scenario the following service account setup is required:
Service Account Requirements
To read an on-prem AD and sync directly to Exchange on-prem mailboxes, we will need the following:
- An on-prem service account
- Must have access to the on-prem AD (this account will be used to run Itrezzo services and read the on-prem AD).
- Must be a member of the Local Administrators group on the server where the software will be installed.
- Must have « Log on as a service » rights on the server where the software will be installed.
- Must be mail-enabled – this account will store the majority of the Itrezzo UCM software configuration, including licenses.
- Must be able to receive mail from the internet (required for licensing).
- Must have the Application Impersonation role (App Impersonation is still supported in on-prem environments). This role allows the account to open targeted user mailboxes and write the necessary synchronization data (contacts, calendars, etc.).
- All retention policies and archiving must be disabled on this mailbox.