Forum Discussion
Azure AD connect in more than one DC
I have an on permise DC where Azure AD connect is already configured and installed and I have a replica of my DC on AWS. Everything from my DC1 replicates to DC2 at AWS except the Azure AD connect not configured on AWS. The question is . Is is possible to install another Azure AD connect on DC2 at AWS while I already have one in DC1?
you can install Azure AD connect on another machine, but it must be in Staging mode. Azure AD connected cannot be running on 2 servers at the same time. There is not a great high availability story at this time. Any configuration changes you make on the operating instance need to be manually made on the staging instance. see https://docs.microsoft.com/en-us/azure/active-directory/connect/active-directory-aadconnectsync-operations for more details.
On a related note, the recommended best practice is to not put AAD connect on the DC. If you have an issue with AAD connect, you don't want it to affect the DC.
- Dean_GrossSilver Contributor
you can install Azure AD connect on another machine, but it must be in Staging mode. Azure AD connected cannot be running on 2 servers at the same time. There is not a great high availability story at this time. Any configuration changes you make on the operating instance need to be manually made on the staging instance. see https://docs.microsoft.com/en-us/azure/active-directory/connect/active-directory-aadconnectsync-operations for more details.
On a related note, the recommended best practice is to not put AAD connect on the DC. If you have an issue with AAD connect, you don't want it to affect the DC.
- DeletedThanks Dean,
This was a quick and helpful response- Dean_GrossSilver Contributor
You are welcome. edX has a good online class about this at https://courses.edx.org/courses/course-v1:Microsoft+CLD212.1x+3T2017/courseware/1d115a213d454e8387d74d3b7d345f25/d2639e4049d94ac9aace0fd16ddef434/?activate_block_id=block-v1%3AMicrosoft%2BCLD212.1x%2B3T2017%2Btype%40sequential%2Bblock%40d2639e4049d94ac9aace0fd16ddef434
- Joshua VillagomezCopper Contributor
Hello Emal,
Assuming you are interested in exporting to the same AAD directory, you can only have one AAD Connect server exporting to the same tenant. As was mentioned, you can have a server in "Staging Mode", but that's more like a fall-back solution should your primary AAD Connect server be down. However, even if it were down, you will not lose authentication. Only new, modified, or removed objects will not synchronize. Many customers swap between a primary and Staged AAD Connect servers when performing upgrades. But if you decide to have a secondary AAD Connect server for fallback solutions, you need to make sure every thing is like-for-like, especially the binaries. Hope this helps.
- DeletedThanks Josh,
Yes I will stand it up as staging AAD. Just have quick question Does it Matter to have the primary AAD connect on AWS replica of my DC or its good practice to have the AAD Connect primary one on premise ?- Josh VillagomezMicrosoft
Hello Emal
AAD Connect can be installed on premises or on a virtual network. The key thing is a good VPN solution if you decide for AWS. Technically speaking, if it's on AWS, then it's considered on premises if it's on the same on premises network. It would be best to have the DC on AWS as well to insure performance with low latencies. This being said, most AAD Connect services I've supported have been installed on-premises. -Josh