Adding important note to solve #3493

This commit is contained in:
Jose Ortega
2019-05-20 23:42:46 -05:00
parent 30ab9bb02e
commit 22de41ba08

View File

@ -23,11 +23,14 @@ ms.date: 08/19/2018
- Key trust
## Directory Synchronization
In hybrid deployments, users register the public portion of their Windows Hello for Business credential with Azure. Azure AD Connect synchronizes the Windows Hello for Business public key to Active Directory.
### Group Memberships for the Azure AD Connect Service Account
>[!IMPORTANT]
> If you already have a Windows Server 2016 domain controller in your domain, you can skip Configure Permissions for Key Synchronization. For more please check [Configure Hybrid Windows Hello for Business: Directory Synchronization](https://docs.microsoft.com/windows/security/identity-protection/hello-for-business/hello-hybrid-cert-whfb-settings-dir-sync)
The KeyAdmins global group provides the Azure AD Connect service with the permissions needed to read and write the public key to Active Directory.
@ -47,9 +50,7 @@ Sign-in a domain controller or management workstation with _Domain Admin_ equiva
>[!div class="step-by-step"]
[< Configure Active Directory](hello-hybrid-key-whfb-settings-ad.md)
[Configure PKI >](hello-hybrid-key-whfb-settings-pki.md)
<br><br>
[Configure PKI >](hello-hybrid-key-whfb-settings-pki.md)
<hr>