Forum Discussion
Help! AWS Microsoft Directory Services, Azure Active Directory, AAD Connect Hybrid Join and Intune..
Seems like you've inherited two half completed projects!
It certainly feels that way! In their defense, a lot of these decisions were made on the fly to get things up and running. I don't think there was any thought about what the ramifications would be going down the managed AD route.
We don't have a lot of devices as we're currently just shy of about 100 users. Some of these users have two devices (a laptop or Surface and a phone). We have maybe 140 devices currently registered into Azure AD. Quite honestly, it wouldn't be a huge deal especially given the benefits that come with having device hybrid azure AD joined. One of the biggest being the automatic enrollment of our endpoints which is an incredibly cumbersome and manual process.
symm_adrian, Did you get any definitive answer from AWS, we are in the same scenario as you, we have AWS directory services and we need to enable Hybrid join.
- symm_adrianJan 25, 2021Brass Contributor
Hey luissoto, I'm not sure what you're trying to accomplish but we managed to set up Hybrid AAD but with everything I read after this post, you should really try to just go straight to Azure AD joining. All of the group policy concerns I had can supposedly be configured via Azure AD configurations so I don't think there's an issue doing everything in Azure/Azure AD.
There are some challenges in trying to use AWS' Microsoft Managed AD as your administrative rights are restricted and they don't give access to the main Admin account to keep management of the service to a minimum. That was basically the reply I got from AWS.
- luissotoJan 25, 2021Copper ContributorThank you for your reply.
We are trying to setup Co-management and autopilot for our company, but I also encounter the same issue as you when trying to configure Azure Hybrid join with AWS managed AD, we need "Enterprise admin" permissions but i was hoping that someone have found a workaround to this issue.
I am guessing I will need to stick to just having a CMG (Cloud Management Gateway ).- symm_adrianJan 25, 2021Brass Contributor
luissoto Ah, yeah. Unfortunately, AWS will not provide credentials for the EA account as it is a managed service. There were some other walls we ran up against like enabling logging for auditing that they wouldn't enable either. Pros and cons to a managed AD solution, as it were.
I'm not familiar with CMG but we did get Autopilot working in our environment. Its been a bit of a challenge, though as they don't support Autopilot configurations over VPN and with all of the work from home going on, we don't have people in office provisioning those machines.
Good luck!