Forum Discussion
symm_adrian
Aug 01, 2019Brass Contributor
Help! AWS Microsoft Directory Services, Azure Active Directory, AAD Connect Hybrid Join and Intune..
Bare with me as I'm new to Azure, AWS and O365 services. We work with an MSP that set up our infrastructure and from everything I can tell, we have what would be considered Hybrid. Unfortunately, du...
luissoto
Jan 25, 2021Copper Contributor
symm_adrian, Did you get any definitive answer from AWS, we are in the same scenario as you, we have AWS directory services and we need to enable Hybrid join.
symm_adrian
Jan 25, 2021Brass Contributor
Hey luissoto, I'm not sure what you're trying to accomplish but we managed to set up Hybrid AAD but with everything I read after this post, you should really try to just go straight to Azure AD joining. All of the group policy concerns I had can supposedly be configured via Azure AD configurations so I don't think there's an issue doing everything in Azure/Azure AD.
There are some challenges in trying to use AWS' Microsoft Managed AD as your administrative rights are restricted and they don't give access to the main Admin account to keep management of the service to a minimum. That was basically the reply I got from AWS.
- luissotoJan 25, 2021Copper ContributorThank you for your reply.
We are trying to setup Co-management and autopilot for our company, but I also encounter the same issue as you when trying to configure Azure Hybrid join with AWS managed AD, we need "Enterprise admin" permissions but i was hoping that someone have found a workaround to this issue.
I am guessing I will need to stick to just having a CMG (Cloud Management Gateway ).- symm_adrianJan 25, 2021Brass Contributor
luissoto Ah, yeah. Unfortunately, AWS will not provide credentials for the EA account as it is a managed service. There were some other walls we ran up against like enabling logging for auditing that they wouldn't enable either. Pros and cons to a managed AD solution, as it were.
I'm not familiar with CMG but we did get Autopilot working in our environment. Its been a bit of a challenge, though as they don't support Autopilot configurations over VPN and with all of the work from home going on, we don't have people in office provisioning those machines.
Good luck!
- luissotoJan 25, 2021Copper ContributorJust out of curiosity, can you point me to the documentation that you used to setup autopilot in your environment.
thank you for your help