Home

Keep Azure Active Directory features when connecting AD via AD Connect

%3CLINGO-SUB%20id%3D%22lingo-sub-814574%22%20slang%3D%22en-US%22%3EKeep%20Azure%20Active%20Directory%20features%20when%20connecting%20AD%20via%20AD%20Connect%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-814574%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20All%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EOur%20situation%20is%20the%20following%3A%20We%20have%20our%20users%20in%20Azure%20Active%20Directory.%20We%20have%20a%20Azure%20AD%20Premium%20subscription%20and%20are%20using%20all%20the%20cool%20stuff%20like%20MFA%20to%20secure%20everything%20%26amp%3B%20dynamic%20groups%20to%20get%20users%20to%20the%20right%20resources%20in%20an%20automated%20way.%20We%20also%20have%20a%20few%20legacy%20line%20of%20business%20apps%20that%20run%20in%20an%20on%20premises%20domain.%20I%20would%20like%20to%20make%20a%20secure%2C%20MFA%20protected%20connection%20to%20our%20local%20domain%20to%20give%20our%20users%20single%20sign%20on%20into%20the%20local%20domain.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ENow%20I%20thought%20that%20this%20exercise%20would%20always%20start%20with%20setting%20up%20a%20sync%20between%20Azure%20Active%20Directory%20and%20the%20local%20AD%20via%20AD%20Connect.%20Two%20problems%3A%3C%2FP%3E%3CP%3E1.%20AD%20Connect%20does%20not%20seem%20to%20work%20on%20Server%202019%3F%20It%20has%20to%20do%20with%20a%20SQL%202012%20instance%20for%20the%20tool%3F%20Is%20that%20correct%3F%20I%20can%20hardly%20believe%20that%3F%3C%2FP%3E%3CP%3E2.%20After%20we%20ran%20AD%20Connect%20on%20Server%202016%2C%20the%20users%20'source'%20in%20AAD%20changed%20to%20the%20Windows%20Server%20AD%2C%20clearing%20all%20info%20in%20AAD%20(and%20thus%20dynamically%20removing%20everybody%20from%20all%20groups).%20Furthermore%20I%20can't%20edit%20those%20properties%20any%20longer%20in%20AAD.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-center%22%20style%3D%22width%3A%20999px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F127770i3531C6EE4152059B%2Fimage-size%2Flarge%3Fv%3D1.0%26amp%3Bpx%3D999%22%20alt%3D%22Screenshot.png%22%20title%3D%22Screenshot.png%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EQuestion%201%3A%20Is%20there%20another%20way%20to%20achieve%20what%20I%20would%20like%20to%20do%3F%20Another%20solutions%20I%20looked%20into%20is%20Parallels%20RAS%20but%20I%20don't%20know%20if%20you%20still%20need%20an%20AD%20Connect%20with%20that%20solution.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EQuestion%202%3A%20If%20I%20really%20need%20AD%20Connect%2C%20is%20there%20a%20way%20to%20keep%20the%20'authority'%20in%20the%20hybrid%20scenario%20in%20Azure%20Active%20directory%3F%20So%20I%20can%20create%20users%20in%20M365%2C%20use%20all%20cool%20features%20of%20AAD%20etc%20etc%3F%20I%20know%20that%20Windows%20Virtual%20Desktop%20is%20on%20it's%20way%20but%20you%20still%20need%20an%20AD%20connect%20between%20your%20domain%20were%20the%20hostpools%20are%20and%20your%20AAD%20in%20that%20scenario.%3C%2FP%3E%3CP%3ERemark%3A%20I'm%20the%20cloud%20guy%20and%20I%20know%20nothing%20about%20on%20premises%20server%20configuration%20so%20some%20of%20my%20questions%20are%20'basic'.%20As%20a%20newbee%20I'm%20truly%20amazed%20that%20a%20'common'%20scenario%20like%20that%20is%20still%20so%20difficult%20anno%202019.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThank%20you.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-814574%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EAccess%20Management%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EAzure%20AD%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EIdentity%20Management%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-814931%22%20slang%3D%22en-US%22%3ERe%3A%20Keep%20Azure%20Active%20Directory%20features%20when%20connecting%20AD%20via%20AD%20Connect%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-814931%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F176421%22%20target%3D%22_blank%22%3E%40Emanuel%20van%20der%20Aalst%3C%2FA%3E%26nbsp%3B%20Hybrid%20Azure%20AD%20join%20may%20be.%20Refer%20documentation%20for%20all%20features%20that%20you%20need%20and%20if%20are%20in%20supported%20architecture%20compared%20to%20yours%20-%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Factive-directory%2Fdevices%2Fhybrid-azuread-join-federated-domains%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Factive-directory%2Fdevices%2Fhybrid-azuread-join-federated-domains%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Factive-directory%2Fdevices%2Fhybrid-azuread-join-plan%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Factive-directory%2Fdevices%2Fhybrid-azuread-join-plan%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Factive-directory%2Fdevices%2Fhybrid-azuread-join-manual%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Factive-directory%2Fdevices%2Fhybrid-azuread-join-manual%3C%2FA%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ECheers%20!!%3C%2FP%3E%3CP%3EAnkit%20Shukla%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-815002%22%20slang%3D%22en-US%22%3ERe%3A%20Keep%20Azure%20Active%20Directory%20features%20when%20connecting%20AD%20via%20AD%20Connect%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-815002%22%20slang%3D%22en-US%22%3EThank%20you.%20My%20first%20impression%20was%20that%20hybrid%20Azure%20AD%20join%20was%20all%20about%20devices%20and%20that%20it%20therefore%20was%20not%20solving%20my%20'user%20identity'%20related%20issues.%20But%20now%20that%20I%20have%20thought%20about%20it%2C%20If%20you%20can%20'only'%20do%20a%20device%20sync%20and%20leave%20the%20users%20untouched%20(and%20therefore%20managed%20in%20AAD)%20it%20could%20totally%20work.%20I'm%20going%20to%20read%20into%20it%20and%20try%20it%20out.%20Thank%20you.%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-822801%22%20slang%3D%22en-US%22%3ERe%3A%20Keep%20Azure%20Active%20Directory%20features%20when%20connecting%20AD%20via%20AD%20Connect%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-822801%22%20slang%3D%22en-US%22%3E%3CP%3ESettings%20Azure%20Hybrid%20Join%20up%20it%20appaers%20so%20that%20devices%20are%20only%20synced%20from%20AD%20tot%20Azure%20AD.%20Or%20is%20it%20possible%20to%20have%20it%20the%20other%20way%20around%20also.%20So%20if%20I%20join%20a%20device%20in%20Azure%20AD%20via%20Autopilot%20for%20example%20and%20have%20that%20device%20synced%20to%20local%20AD.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20immediately%20tried%20the%20device%20writeback%20option%20in%20AD%20Connect%20and%20that%20synchronises%20devices%20from%20Azure%20AD%20to%20AD%20but%20they%20and%20up%20in%20a%20container%20in%20AD%20and%20then%20what%3F%20As%20far%20as%20we%20can%20see%2C%20you%20can't%20get%20SSO%20from%20that%20scenario%20nor%20can%20you%20do%20anything%20with%20thos%20devices...%3C%2FP%3E%3C%2FLINGO-BODY%3E
Highlighted
Emanuel van der Aalst
Occasional Contributor

Hi All

 

Our situation is the following: We have our users in Azure Active Directory. We have a Azure AD Premium subscription and are using all the cool stuff like MFA to secure everything & dynamic groups to get users to the right resources in an automated way. We also have a few legacy line of business apps that run in an on premises domain. I would like to make a secure, MFA protected connection to our local domain to give our users single sign on into the local domain.

 

Now I thought that this exercise would always start with setting up a sync between Azure Active Directory and the local AD via AD Connect. Two problems:

1. AD Connect does not seem to work on Server 2019? It has to do with a SQL 2012 instance for the tool? Is that correct? I can hardly believe that?

2. After we ran AD Connect on Server 2016, the users 'source' in AAD changed to the Windows Server AD, clearing all info in AAD (and thus dynamically removing everybody from all groups). Furthermore I can't edit those properties any longer in AAD.

 

Screenshot.png

 

Question 1: Is there another way to achieve what I would like to do? Another solutions I looked into is Parallels RAS but I don't know if you still need an AD Connect with that solution.

 

Question 2: If I really need AD Connect, is there a way to keep the 'authority' in the hybrid scenario in Azure Active directory? So I can create users in M365, use all cool features of AAD etc etc? I know that Windows Virtual Desktop is on it's way but you still need an AD connect between your domain were the hostpools are and your AAD in that scenario.

Remark: I'm the cloud guy and I know nothing about on premises server configuration so some of my questions are 'basic'. As a newbee I'm truly amazed that a 'common' scenario like that is still so difficult anno 2019.

 

Thank you.

 

 

 

3 Replies
Thank you. My first impression was that hybrid Azure AD join was all about devices and that it therefore was not solving my 'user identity' related issues. But now that I have thought about it, If you can 'only' do a device sync and leave the users untouched (and therefore managed in AAD) it could totally work. I'm going to read into it and try it out. Thank you.

Settings Azure Hybrid Join up it appaers so that devices are only synced from AD tot Azure AD. Or is it possible to have it the other way around also. So if I join a device in Azure AD via Autopilot for example and have that device synced to local AD.

 

I immediately tried the device writeback option in AD Connect and that synchronises devices from Azure AD to AD but they and up in a container in AD and then what? As far as we can see, you can't get SSO from that scenario nor can you do anything with thos devices...

Related Conversations
Tabs and Dark Mode
cjc2112 in Discussions on
48 Replies
Extentions Synchronization
Deleted in Discussions on
3 Replies
Stable version of Edge insider browser
HotCakeX in Discussions on
35 Replies
How to Prevent Teams from Auto-Launch
chenrylee in Microsoft Teams on
30 Replies
flashing a white screen while open new tab
Deleted in Discussions on
14 Replies
Security Community Webinars
Valon_Kolica in Security, Privacy & Compliance on
13 Replies