Home

Moving from Hybrid to Cloud Only Tenant

%3CLINGO-SUB%20id%3D%22lingo-sub-393029%22%20slang%3D%22en-US%22%3EMoving%20from%20Hybrid%20to%20Cloud%20Only%20Tenant%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-393029%22%20slang%3D%22en-US%22%3E%3CP%3EThis%20is%20different%20question%20than%20was%20asked%20%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2FAzure-Active-Directory%2FConverting-Azure-AD-accounts-to-cloud-only%2Fm-p%2F391896%23M2721%22%20target%3D%22_blank%22%20rel%3D%22noopener%22%3Ehere%3C%2FA%3E.%20As%20it%20pertains%20to%20what%20happens%20after%20that%20everything%20is%20in%20cloud.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20am%20looking%20at%20moving%20the%20tenant%20I%20manage%20from%20hybrid%20to%20full%20cloud.%20I%20have%20read%20all%20of%20the%20documentation%20about%20removing%20the%20last%20Exchange%20server%20and%20stopping%20the%20sync%20process.%20Then%20waiting%20x%20hours%20for%20O365%20to%20convert%20the%20accounts%20to%20cloud%20only.%20At%20that%20point%20we%20would%20manage%20users%20and%20email%20in%20from%20the%20Admin%20Center(s)%20with%20the%20source%20of%20authority%20moving%20to%20Azure%20AD%20and%20Exchange%20Online.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThis%20is%20where%20I%20have%20an%20issue%20or%20don't%20have%20a%20complete%20picture.%20Now%20that%20all%20of%20my%20info%20is%20in%20the%20cloud%2C%20the%20connection%20between%20AD%20and%20Azure%20AD%20is%20broken%20and%20all%20of%20us%20admins%20are%20managing%20from%20the%20cloud...how%20do%20we%20keep%20our%20on-premise%20domain%20controllers%20up%20to%20date.%20We%20would%20still%20have%20a%20need%20to%20use%20on-premise%20AD%20for%20authentication%20of%20computers%2C%20certain%20applications%20and%20probably%20some%20other%20things%20I%20haven't%20considered.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIs%20there%20any%20documentation%5Cblog%20sites%20on%20this%20scenario%20and%20the%20paths%20that%20could%20be%20taken%3F%20I%20have%20been%20thinking%20we%20would%20have%20to%20do%20some%20type%20of%20ADFS%20setup%20or%20would%20it%20be%20an%20Azure%20join%20but%20I%20am%20not%20sure.%20I%20am%20pretty%20sure%20someone%20has%20asked%20the%20question%20before%20I%20have%20just%20not%20been%20able%20to%20come%20across%20it.%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-393029%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EAzure%20AD%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EOffice%20365%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-393154%22%20slang%3D%22en-US%22%3ERe%3A%20Moving%20from%20Hybrid%20to%20Cloud%20Only%20Tenant%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-393154%22%20slang%3D%22en-US%22%3E%3CP%3EOffice%20365%2FAzure%20AD%20has%20nothing%20to%20do%20with%20your%20on-premises%20infrastructure%20in%20such%20scenario.%20You%20keep%20on%20managing%20your%20DCs%2C%20members%20servers%2C%20On-Prem%20users%20and%20applications%20like%20you%20would%20without%20any%20cloud%20services%20in%20the%20picture.%20Which%20brings%20up%20one%20of%20the%20major%20issues%20with%20such%20%22disconnected%22%20approach%20-%20any%20changes%20you%20made%20to%20users%20or%20passwords%20on-premises%20will%20not%20be%20synced%20anymore%2C%20and%20(at%20least%20some)%20users%20will%20have%20to%20work%20with%20two%20different%20sets%20of%20credentials.%3C%2FP%3E%3C%2FLINGO-BODY%3E
Deleted
Not applicable

This is different question than was asked here. As it pertains to what happens after that everything is in cloud.

 

I am looking at moving the tenant I manage from hybrid to full cloud. I have read all of the documentation about removing the last Exchange server and stopping the sync process. Then waiting x hours for O365 to convert the accounts to cloud only. At that point we would manage users and email in from the Admin Center(s) with the source of authority moving to Azure AD and Exchange Online.

 

This is where I have an issue or don't have a complete picture. Now that all of my info is in the cloud, the connection between AD and Azure AD is broken and all of us admins are managing from the cloud...how do we keep our on-premise domain controllers up to date. We would still have a need to use on-premise AD for authentication of computers, certain applications and probably some other things I haven't considered.

 

Is there any documentation\blog sites on this scenario and the paths that could be taken? I have been thinking we would have to do some type of ADFS setup or would it be an Azure join but I am not sure. I am pretty sure someone has asked the question before I have just not been able to come across it. 

 

1 Reply

Office 365/Azure AD has nothing to do with your on-premises infrastructure in such scenario. You keep on managing your DCs, members servers, On-Prem users and applications like you would without any cloud services in the picture. Which brings up one of the major issues with such "disconnected" approach - any changes you made to users or passwords on-premises will not be synced anymore, and (at least some) users will have to work with two different sets of credentials.

Related Conversations
Tabs and Dark Mode
cjc2112 in Discussions on
35 Replies
Extentions Synchronization
Deleted in Discussions on
3 Replies
Security Community Webinars
Valon_Kolica in Security, Privacy & Compliance on
9 Replies
flashing a white screen while open new tab
Deleted in Discussions on
14 Replies