Home

Multi forest planning - joining parent company tenant

%3CLINGO-SUB%20id%3D%22lingo-sub-904820%22%20slang%3D%22en-US%22%3EMulti%20forest%20planning%20-%20joining%20parent%20company%20tenant%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-904820%22%20slang%3D%22en-US%22%3E%3CP%3EHey%20guys%2C%3CBR%20%2F%3E%3CBR%20%2F%3Ewe%20have%20a%20customer%20who%20is%20just%20challenged%20to%20migrate%20to%20Exchange%20Online.%20In%20first%20line%20they%20were%20interested%20to%20move%20to%20their%20own%20dedicated%20tenant%2C%20but%20their%20parent%20company%20advised%20to%20join%20their%20global%20tenant.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ESo%20we%20have%20Company%20A%20and%20SubCompany%20B.%20We%20already%20told%20SubCompany%20B%20that%20there%20is%20only%20one%20AAD%20Connect%20server%20allowed.%20It%20is%20for%20sure%20that%20Company%20A%20already%20utilizes%20this%20service.%20Therefore%20it%20is%20only%20needed%20that%20the%20AAD%20Connect%20server%20needs%20to%20fetch%20the%20Active%20Directory%20form%20SubCompany%20B.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EBTW%3A%20I%20already%20read%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fde-de%2Fazure%2Factive-directory%2Fhybrid%2Fplan-connect-topologies%22%20target%3D%22_self%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%22%3EPlan%20connect%20topologies%3C%2FA%3E%3CBR%20%2F%3E%3CBR%20%2F%3ESo%20there%20are%20scenarios%20where%20there%20will%20be%20an%20AD%20trust%20and%20some%20without.%20Does%20it%20matter%20if%20the%20AAD%20Connect%20server%20is%20located%20in%20the%20internal%20or%20the%20DMZ%20network%3F%3C%2FP%3E%3CP%3EI%20already%20learned%2C%20if%20you%20are%20not%20using%20the%20trust%2C%20the%20only%20choice%20for%20authentication%20is%20ADFS.%20But%20what%20possibilities%20do%20we%20have%2C%20if%20we%20create%20a%20trust%3F%3C%2FP%3E%3CP%3EWe%20don't%20know%2C%20yet%20if%20Company%20A%20uses%20passthrough%20authentication%20for%20example.%20If%20this%20would%20be%20the%20case%2C%20would%20SubCompany%20B%20be%20forced%20to%20use%20this%20authentication%20as%20well%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAre%20there%20limitations%20for%20the%20new%20company%20joining%20an%20established%20multi%20forest%20single%20tenant%20scenario%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ERecommendation%20from%20Company%20A%20is%20to%20migrate%20the%20whole%20accounts%20to%20their%20infrastructure.%20For%20them%20it%20sounds%20easy%2C%20because%20the%20have%20migrated%20some%20smaller%20companies.%20It%20looks%20like%20they%20are%20not%20considerating%20that%20there%20will%20be%20a%20huge%20amount%20of%20data%20to%20move.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWhat%20are%20the%20disadvantages%20for%20SubCompany%20B%20for%20migrating%20to%20Company%20A%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E-%20No%20dedicated%20GPO's%3C%2FP%3E%3CP%3E-%20No%20Control%20regarding%20the%20own%20user%20accounts%3C%2FP%3E%3CP%3E-%20complicated%20if%20some%20services%20will%20stay%20in%20SubCompany%20B%20forest%3C%2FP%3E%3CP%3E-%20what%20do%20you%20think%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThanks%20for%20your%20help.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EKind%20regards%2C%3C%2FP%3E%3CP%3EChristian%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-904820%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EAzure%20AD%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3ECloud%20Essentials%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EIdentity%20Management%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EOffice%20365%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E
woelki
Contributor

Hey guys,

we have a customer who is just challenged to migrate to Exchange Online. In first line they were interested to move to their own dedicated tenant, but their parent company advised to join their global tenant.

 

So we have Company A and SubCompany B. We already told SubCompany B that there is only one AAD Connect server allowed. It is for sure that Company A already utilizes this service. Therefore it is only needed that the AAD Connect server needs to fetch the Active Directory form SubCompany B.

 

BTW: I already read Plan connect topologies

So there are scenarios where there will be an AD trust and some without. Does it matter if the AAD Connect server is located in the internal or the DMZ network?

I already learned, if you are not using the trust, the only choice for authentication is ADFS. But what possibilities do we have, if we create a trust?

We don't know, yet if Company A uses passthrough authentication for example. If this would be the case, would SubCompany B be forced to use this authentication as well?

 

Are there limitations for the new company joining an established multi forest single tenant scenario?

 

Recommendation from Company A is to migrate the whole accounts to their infrastructure. For them it sounds easy, because the have migrated some smaller companies. It looks like they are not considerating that there will be a huge amount of data to move.

 

What are the disadvantages for SubCompany B for migrating to Company A?

 

- No dedicated GPO's

- No Control regarding the own user accounts

- complicated if some services will stay in SubCompany B forest

- what do you think?

 

Thanks for your help.

 

Kind regards,

Christian

Related Conversations
Tabs and Dark Mode
cjc2112 in Discussions on
35 Replies
Extentions Synchronization
Deleted in Discussions on
3 Replies
Stable version of Edge insider browser
HotCakeX in Discussions on
35 Replies
flashing a white screen while open new tab
Deleted in Discussions on
14 Replies
How to Prevent Teams from Auto-Launch
chenrylee in Microsoft Teams on
29 Replies
Security Community Webinars
Valon_Kolica in Security, Privacy & Compliance on
9 Replies