Forum Discussion
Arya1028
Mar 24, 2020Copper Contributor
Azure AD Hybrid Setup
Hi Everyone, I have multi forest environment that I would like to sync to Azure AD with AD connect, is it possible to achieve below: 1. Sync two domains to one Tenant. 2. SSO for the two dom...
- Mar 24, 2020Hi Arya,
1. Yes, you can sync directories. It should be under Add Directory in Ad Connect. You need to have s2s vpn between the domains.
Check Multiple forests single AD tenant.
https://docs.microsoft.com/en-us/azure/active-directory/hybrid/plan-connect-topologies
2. I recommend using Seamless SSO, easy to setup with AD-Connect.
https://docs.microsoft.com/bs-latn-ba/azure/active-directory/hybrid/tshoot-connect-sso
3. You can use GPO to enroll devices to MDM, you have some prerequisites like Intune license, Windows build version and Intune Cname setup etc.
https://docs.microsoft.com/en-us/windows/client-management/mdm/enroll-a-windows-10-device-automatically-using-group-policy#configure-the-auto-enrollment-group-policy-for-a-single-pc
Hope this helps!
Moe
Moe_Kinani
Mar 24, 2020Bronze Contributor
Hi Arya,
1. Yes, you can sync directories. It should be under Add Directory in Ad Connect. You need to have s2s vpn between the domains.
Check Multiple forests single AD tenant.
https://docs.microsoft.com/en-us/azure/active-directory/hybrid/plan-connect-topologies
2. I recommend using Seamless SSO, easy to setup with AD-Connect.
https://docs.microsoft.com/bs-latn-ba/azure/active-directory/hybrid/tshoot-connect-sso
3. You can use GPO to enroll devices to MDM, you have some prerequisites like Intune license, Windows build version and Intune Cname setup etc.
https://docs.microsoft.com/en-us/windows/client-management/mdm/enroll-a-windows-10-device-automatically-using-group-policy#configure-the-auto-enrollment-group-policy-for-a-single-pc
Hope this helps!
Moe
1. Yes, you can sync directories. It should be under Add Directory in Ad Connect. You need to have s2s vpn between the domains.
Check Multiple forests single AD tenant.
https://docs.microsoft.com/en-us/azure/active-directory/hybrid/plan-connect-topologies
2. I recommend using Seamless SSO, easy to setup with AD-Connect.
https://docs.microsoft.com/bs-latn-ba/azure/active-directory/hybrid/tshoot-connect-sso
3. You can use GPO to enroll devices to MDM, you have some prerequisites like Intune license, Windows build version and Intune Cname setup etc.
https://docs.microsoft.com/en-us/windows/client-management/mdm/enroll-a-windows-10-device-automatically-using-group-policy#configure-the-auto-enrollment-group-policy-for-a-single-pc
Hope this helps!
Moe