A Home Realm Discovery (HRD) policy allows a specific application to use the Password Hash Sync stored in Entra ID to determine the validity of a provided password. This HRD policy is applied to an individual app registration and is not a global setting.
Applying the HRD policy to Jamf Connect ensures that end users are directed to the correct IdP for authentication.
A user with Entra ID Global Administrator rights
Microsoft PowerShell. See PowerShell Documentation (Microsoft) for more information.
The Microsoft Graph PowerShell Module. See Microsoft Graph PowerShell (Microsoft) for installation instructions.
To validate the HRD policy, navigate to Jamf Connect Configuration, and then run the ROPG test again. For more information, see Testing Password Hash Sync with Jamf Connect Configuration.
If you continue to see failures after adding a HRD policy, see the Selective password hash synchronization configuration for Microsoft Entra Connect documentation from Microsoft. Determine if an administrator set a policy to restrict Password Hash Sync on your domain and discuss with your domain administrator the use of Jamf Connect and how policies can be created to turn on Password Hash Sync for user accounts while leaving service accounts out of Entra ID.