Home

Using the ActiveDirectory module against on-prem ad when connected to azure ad

%3CLINGO-SUB%20id%3D%22lingo-sub-89747%22%20slang%3D%22en-US%22%3EUsing%20the%20ActiveDirectory%20module%20against%20on-prem%20ad%20when%20connected%20to%20azure%20ad%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-89747%22%20slang%3D%22en-US%22%3E%3CP%3EGreetings%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20recently%20disconnected%20my%20on-prem%20AD%20machine%20and%20joined%20my%20machine%20to%20azure%20ad.%20%26nbsp%3BI'm%20doing%20this%20to%20test%20some%20of%20the%20azure%20ad%20features%20and%20viability%20for%20some%20of%20our%20use%20cases%20to%20use%20azure%20ad%20instead..%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWith%20my%20azure%20ad%20joined%20machine%20i%20can%20%5C%5C%20unc%20to%20on-prem%20resources%2C%20start%20and%20use%20ADUC%2C%20rdp%20to%20on-prem%20servers%20etc%2C%20essential%20i%20can%20do%20everything%20i%20used%20to%20be%20able%20to%20do%20when%20my%20machine%20was%20joined%20to%20on-prem%20AD%2C%20the%20only%20thing%20i%20cannot%20do%20is%20use%20the%20ActiveDriectory%20module%20in%20powershell.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20can%20use%20powershell%20remoting%2C%20eg%2C%20invoke-command%20against%20my%20on-prem%20AD%2C%20i%20can%20enter-pssession%20to%20AD%2C%20but%20i%20cannot%20do%20stuff%20like%20get-adcomputer%2C%20or%20get-aduser%20from%20my%20local%20powershell%20session%20any%20more..%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3Ethe%20error%20i%20receive%20is%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CPRE%3EPS%20C%3A%5CUsers%5CAndrew%26gt%3B%20Get-ADComputer%20abcd123%0AGet-ADComputer%20%3A%20Unable%20to%20find%20a%20default%20server%20with%20Active%20Directory%20Web%20Services%20running.%3C%2FPRE%3E%3CP%3EI%20have%20my%20on-prem%20ca%20root%20certificate%20installed%20in%20my%20local%20machine%20personal%20store.%20I%20have%20also%20tried%20the%20above%20command%20using%20the%20various%26nbsp%3B%3CSTRONG%3E-AuthType%3C%2FSTRONG%3Eand%20%3CSTRONG%3E-Credential%26nbsp%3B%3C%2FSTRONG%3Eswitches%2Fparameters%2C%20but%20i%20get%20the%20same%20web%20services%20error.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAny%20clues%20why%20i%20cannot%20use%20the%20ActiveDirectory%20powershell%20module%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-89747%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EAzure%20AD%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-90172%22%20slang%3D%22en-US%22%3ERe%3A%20Using%20the%20ActiveDirectory%20module%20against%20on-prem%20ad%20when%20connected%20to%20azure%20ad%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-90172%22%20slang%3D%22en-US%22%3E%3CP%3EAzure%20AD%20is%20not%20a%20%22traditional%22%20AD%2C%20and%20definitely%20not%20a%20replacement%20for%20on-prem%20AD.%20It's%20a%20poor%20choice%20of%20terminology%20basically%2C%20combined%20with%20some%20marketing%20crap.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EBut%20to%20answer%20the%20question%2C%20yes%2C%20you%20can%20%22connect%22%20domain-joined%20machines%20to%20Azure%20AD.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-89863%22%20slang%3D%22en-US%22%3ERe%3A%20Using%20the%20ActiveDirectory%20module%20against%20on-prem%20ad%20when%20connected%20to%20azure%20ad%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-89863%22%20slang%3D%22en-US%22%3E%3CP%3EOh%20wow%20i%20didnt%20know%20that%2C%20so%20i%20can%20be%20joined%20to%20two%20directories%20at%20the%20same%20time%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-89807%22%20slang%3D%22en-US%22%3ERe%3A%20Using%20the%20ActiveDirectory%20module%20against%20on-prem%20ad%20when%20connected%20to%20azure%20ad%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-89807%22%20slang%3D%22en-US%22%3E%3CP%3EWell%2C%20at%20the%20very%20least%20you%20will%20have%20to%20use%20the%20Credentials%20parameter%20when%20running%20AD%20PowerShell%20cmdlets%20on%20a%20non-domain%20PC.%20Or%20you%20can%20just%20open%20implicit%20remoting%20session%20via%20Enter-PSSession.%20Probably%20the%20network%20rules%20need%20to%20be%20adjusted%2C%20as%20well%20as%20WinRM%20config.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EYou%20dont%20have%20to%20leave%20the%20domain%20in%20order%20to%20join%20the%20computer%20to%20Azure%20AD%20btw.%3C%2FP%3E%3C%2FLINGO-BODY%3E
Frequent Contributor

Greetings,

 

I recently disconnected my on-prem AD machine and joined my machine to azure ad.  I'm doing this to test some of the azure ad features and viability for some of our use cases to use azure ad instead..

 

With my azure ad joined machine i can \\ unc to on-prem resources, start and use ADUC, rdp to on-prem servers etc, essential i can do everything i used to be able to do when my machine was joined to on-prem AD, the only thing i cannot do is use the ActiveDriectory module in powershell.

 

I can use powershell remoting, eg, invoke-command against my on-prem AD, i can enter-pssession to AD, but i cannot do stuff like get-adcomputer, or get-aduser from my local powershell session any more..

 

the error i receive is 

 

PS C:\Users\Andrew> Get-ADComputer abcd123
Get-ADComputer : Unable to find a default server with Active Directory Web Services running.

I have my on-prem ca root certificate installed in my local machine personal store. I have also tried the above command using the various -AuthType and -Credential switches/parameters, but i get the same web services error.

 

Any clues why i cannot use the ActiveDirectory powershell module?

3 Replies

Well, at the very least you will have to use the Credentials parameter when running AD PowerShell cmdlets on a non-domain PC. Or you can just open implicit remoting session via Enter-PSSession. Probably the network rules need to be adjusted, as well as WinRM config.

 

You dont have to leave the domain in order to join the computer to Azure AD btw.

Oh wow i didnt know that, so i can be joined to two directories at the same time?

Azure AD is not a "traditional" AD, and definitely not a replacement for on-prem AD. It's a poor choice of terminology basically, combined with some marketing crap.

 

But to answer the question, yes, you can "connect" domain-joined machines to Azure AD.

Related Conversations
Extentions Synchronization
Deleted in Discussions on
3 Replies
Tabs and Dark Mode
cjc2112 in Discussions on
36 Replies
flashing a white screen while open new tab
Deleted in Discussions on
14 Replies
Stable version of Edge insider browser
HotCakeX in Discussions on
35 Replies
Security Community Webinars
Valon_Kolica in Security, Privacy & Compliance on
9 Replies