Forum Discussion

ompakim's avatar
ompakim
Copper Contributor
Oct 13, 2022
Solved

Allow multiple Azure tenants to sign into my on-prem RDS environment

Hello,   I currently have an on-prem AD and RDS environment with multiple session host. Each session host is dedicated to a specific customer.   The customers are currently signing into their ...
  • LainRobertson's avatar
    Oct 13, 2022

    ompakim 

     

    It's possible but probably not practical.

     

    This model (below) carries a lot of implications that most external organisations won't agree to, not the least of which is how to negate the implied transitive trusts that would then exist between clients (which can be achieved, it's just complex.)

     

     

    You'd also have to reinvent your RDS deployment entirely.

     

    So, as I say, doable but practical? Unless you've got some folks internally that live and breathe this stuff, I'd say no, it's not practical.

     

    Note: As an aside, you can have a model of a single on-premise AD synchronising to multiple tenants, however, I'd expect these external tenants to be doing their own synchronising via AAD Connect which is all but guaranteed to rule this approach out.

     

    Even if they weren't using AAD Connect (for example if they're cloud-native), it would still be unlikely that anyone would agree to the required changes to make this work.

     

     

    Cheers,

    Lain

Resources