SOLVED
Home

Azure AD connect in more than one DC

%3CLINGO-SUB%20id%3D%22lingo-sub-98367%22%20slang%3D%22en-US%22%3EAzure%20AD%20connect%20in%20more%20than%20one%20DC%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-98367%22%20slang%3D%22en-US%22%3E%3CP%3EI%20have%20an%20on%20permise%20DC%20where%20Azure%20AD%20connect%20is%20already%20configured%20and%20installed%20and%20I%20have%20a%20replica%20of%20my%20DC%20on%20AWS.%20Everything%20from%20my%20DC1%20replicates%20to%20DC2%20at%20AWS%20except%20the%20Azure%20AD%20connect%20not%20configured%20on%20AWS.%20The%20question%20is%20.%20Is%20is%20possible%20to%20install%20another%20Azure%20AD%20connect%20on%20DC2%20at%20AWS%20while%20I%20already%20have%20one%20in%20DC1%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-98367%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EAzure%20AD%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EOffice%20365%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-195980%22%20slang%3D%22en-US%22%3ERe%3A%20Azure%20AD%20connect%20in%20more%20than%20one%20DC%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-195980%22%20slang%3D%22en-US%22%3EHi%20Josh%2C%3CBR%20%2F%3EThanks!%20that%20worked%20for%20me%20for%20having%20AD%20on%20AWS.%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-101344%22%20slang%3D%22en-US%22%3ERe%3A%20Azure%20AD%20connect%20in%20more%20than%20one%20DC%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-101344%22%20slang%3D%22en-US%22%3E%3CP%3EHello%20Emal%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EAAD%20Connect%20can%20be%20installed%20on%20premises%20or%20on%20a%20virtual%20network.%20The%20key%20thing%20is%20a%20good%20VPN%20solution%20if%20you%20decide%20for%20AWS.%20Technically%20speaking%2C%20if%20it's%20on%20AWS%2C%20then%20it's%20considered%20on%20premises%20if%20it's%20on%20the%20same%20on%20premises%20network.%20It%20would%20be%20best%20to%20have%20the%20DC%20on%20AWS%20as%20well%20to%20insure%20performance%20with%20low%20latencies.%20This%20being%20said%2C%20most%20AAD%20Connect%20services%20I've%20supported%20have%20been%20installed%20on-premises.%20-Josh%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-100840%22%20slang%3D%22en-US%22%3ERe%3A%20Azure%20AD%20connect%20in%20more%20than%20one%20DC%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-100840%22%20slang%3D%22en-US%22%3EThanks%20Josh%2C%3CBR%20%2F%3EYes%20I%20will%20stand%20it%20up%20as%20staging%20AAD.%20Just%20have%20quick%20question%20Does%20it%20Matter%20to%20have%20the%20primary%20AAD%20connect%20on%20AWS%20replica%20of%20my%20DC%20or%20its%20good%20practice%20to%20have%20the%20AAD%20Connect%20primary%20one%20on%20premise%20%3F%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-100385%22%20slang%3D%22en-US%22%3ERe%3A%20Azure%20AD%20connect%20in%20more%20than%20one%20DC%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-100385%22%20slang%3D%22en-US%22%3E%3CP%3EHello%20Emal%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAssuming%20you%20are%20interested%20in%20exporting%20to%20the%20same%20AAD%20directory%2C%20you%20can%20only%20have%20one%20AAD%20Connect%20server%20exporting%20to%20the%20same%20tenant.%20As%20was%20mentioned%2C%20you%20can%20have%20a%20server%20in%20%22Staging%20Mode%22%2C%20but%20that's%20more%20like%20a%20fall-back%20solution%20should%20your%20primary%20AAD%20Connect%20server%20be%20down.%20However%2C%20even%20if%20it%20were%20down%2C%20you%20will%20not%20lose%20authentication.%20Only%20new%2C%20modified%2C%20or%20removed%20objects%20will%20not%20synchronize.%20Many%20customers%20swap%20between%20a%20primary%20and%20Staged%20AAD%20Connect%20servers%20when%20performing%20upgrades.%20But%20if%20you%20decide%20to%20have%20a%20secondary%20AAD%20Connect%20server%20for%20fallback%20solutions%2C%20you%20need%20to%20make%20sure%20every%20thing%20is%20like-for-like%2C%20especially%20the%20binaries.%20Hope%20this%20helps.%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-98419%22%20slang%3D%22en-US%22%3ERe%3A%20Azure%20AD%20connect%20in%20more%20than%20one%20DC%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-98419%22%20slang%3D%22en-US%22%3E%3CP%3EYou%20are%20welcome.%20edX%20has%20a%20good%20online%20class%20about%20this%20at%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fcourses.edx.org%2Fcourses%2Fcourse-v1%3AMicrosoft%2BCLD212.1x%2B3T2017%2Fcourseware%2F1d115a213d454e8387d74d3b7d345f25%2Fd2639e4049d94ac9aace0fd16ddef434%2F%3Factivate_block_id%3Dblock-v1%253AMicrosoft%252BCLD212.1x%252B3T2017%252Btype%2540sequential%252Bblock%2540d2639e4049d94ac9aace0fd16ddef434%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fcourses.edx.org%2Fcourses%2Fcourse-v1%3AMicrosoft%2BCLD212.1x%2B3T2017%2Fcourseware%2F1d115a213d454e8387d74d3b7d345f25%2Fd2639e4049d94ac9aace0fd16ddef434%2F%3Factivate_block_id%3Dblock-v1%253AMicrosoft%252BCLD212.1x%252B3T2017%252Btype%2540sequential%252Bblock%2540d2639e4049d94ac9aace0fd16ddef434%3C%2FA%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-98415%22%20slang%3D%22en-US%22%3ERe%3A%20Azure%20AD%20connect%20in%20more%20than%20one%20DC%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-98415%22%20slang%3D%22en-US%22%3EThanks%20Dean%2C%3CBR%20%2F%3EThis%20was%20a%20quick%20and%20helpful%20response%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-98399%22%20slang%3D%22en-US%22%3ERe%3A%20Azure%20AD%20connect%20in%20more%20than%20one%20DC%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-98399%22%20slang%3D%22en-US%22%3E%3CP%3Eyou%20can%20install%20Azure%20AD%20connect%20on%20another%20machine%2C%20but%20it%20must%20be%20in%20Staging%20mode.%20Azure%20AD%20connected%20cannot%20be%20running%20on%202%20servers%20at%20the%20same%20time.%20There%20is%20not%20a%20great%20high%20availability%20story%20at%20this%20time.%20Any%20configuration%20changes%20you%20make%20on%20the%20operating%20instance%20need%20to%20be%20manually%20made%20on%20the%20staging%20instance.%20see%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Factive-directory%2Fconnect%2Factive-directory-aadconnectsync-operations%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Factive-directory%2Fconnect%2Factive-directory-aadconnectsync-operations%3C%2FA%3E%20for%20more%20details.%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EOn%20a%20related%20note%2C%20the%20recommended%20best%20practice%20is%20to%20not%20put%20AAD%20connect%20on%20the%20DC.%20If%20you%20have%20an%20issue%20with%20AAD%20connect%2C%20you%20don't%20want%20it%20to%20affect%20the%20DC.%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E
Deleted
Not applicable

I have an on permise DC where Azure AD connect is already configured and installed and I have a replica of my DC on AWS. Everything from my DC1 replicates to DC2 at AWS except the Azure AD connect not configured on AWS. The question is . Is is possible to install another Azure AD connect on DC2 at AWS while I already have one in DC1?

7 Replies
Solution

you can install Azure AD connect on another machine, but it must be in Staging mode. Azure AD connected cannot be running on 2 servers at the same time. There is not a great high availability story at this time. Any configuration changes you make on the operating instance need to be manually made on the staging instance. see https://docs.microsoft.com/en-us/azure/active-directory/connect/active-directory-aadconnectsync-oper... for more details. 

 

On a related note, the recommended best practice is to not put AAD connect on the DC. If you have an issue with AAD connect, you don't want it to affect the DC. 

Thanks Dean,
This was a quick and helpful response

Hello Emal,

 

Assuming you are interested in exporting to the same AAD directory, you can only have one AAD Connect server exporting to the same tenant. As was mentioned, you can have a server in "Staging Mode", but that's more like a fall-back solution should your primary AAD Connect server be down. However, even if it were down, you will not lose authentication. Only new, modified, or removed objects will not synchronize. Many customers swap between a primary and Staged AAD Connect servers when performing upgrades. But if you decide to have a secondary AAD Connect server for fallback solutions, you need to make sure every thing is like-for-like, especially the binaries. Hope this helps. 

Thanks Josh,
Yes I will stand it up as staging AAD. Just have quick question Does it Matter to have the primary AAD connect on AWS replica of my DC or its good practice to have the AAD Connect primary one on premise ?

Hello Emal

 

AAD Connect can be installed on premises or on a virtual network. The key thing is a good VPN solution if you decide for AWS. Technically speaking, if it's on AWS, then it's considered on premises if it's on the same on premises network. It would be best to have the DC on AWS as well to insure performance with low latencies. This being said, most AAD Connect services I've supported have been installed on-premises. -Josh

Hi Josh,
Thanks! that worked for me for having AD on AWS.
Related Conversations
Tabs and Dark Mode
cjc2112 in Discussions on
46 Replies
Extentions Synchronization
Deleted in Discussions on
3 Replies
Stable version of Edge insider browser
HotCakeX in Discussions on
35 Replies
flashing a white screen while open new tab
Deleted in Discussions on
14 Replies
How to Prevent Teams from Auto-Launch
chenrylee in Microsoft Teams on
29 Replies
Security Community Webinars
Valon_Kolica in Security, Privacy & Compliance on
13 Replies