Azure AD - ADFS accounts without synchronization

%3CLINGO-SUB%20id%3D%22lingo-sub-2021206%22%20slang%3D%22en-US%22%3EAzure%20AD%20-%20ADFS%20accounts%20without%20synchronization%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2021206%22%20slang%3D%22en-US%22%3E%3CP%3EHello%20guys%2C%3C%2FP%3E%3CP%3ECouple%20of%20simple%20(I%20hope)%20questions%3A%3C%2FP%3E%3CP%3E-%20is%20it%20possible%20to%20authenticate%20users%20through%20on-premise%20ADFS%20server%20in%20Azure%20without%20actually%20importing%20users%20to%20the%20Azure%20AD%3F%20Or%20the%20user%20always%20has%20to%20be%20imported%20because%20only%20then%20he%20gets%20Azure%20Id%20and%20can%20use%20Azure%20resources%3F%26nbsp%3B%3C%2FP%3E%3CP%3E-%20is%20there%20any%20option%20except%20Azure%20AD%20Connect%20to%20establish%20connection%20between%20ADFS%20server%20and%20Azure%20AD%20(so%20ADFS%20users%20can%20be%20authenticated)%3F%20The%20thing%20is%20that%20I%20don't%20have%20access%20to%20physical%20ADFS%20server%2C%20so%20I%20cannot%20install%20Azure%20AD%20Connect%20there.%3C%2FP%3E%3CP%3ERegards%20and%20thanks!%3C%2FP%3E%3CP%3ETomasz%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-2021206%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EAzure%20AD%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EIdentity%20Management%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2021222%22%20slang%3D%22en-US%22%3ERe%3A%20Azure%20AD%20-%20ADFS%20accounts%20without%20synchronization%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2021222%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F913827%22%20target%3D%22_blank%22%3E%40zielonywojo%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EHi%2C%20you%20will%20need%20Azure%20AD%20Connect%20in%20order%20for%20this%20to%20work%20and%20have%20the%20users%20visible%20in%20Azure%20AD.%26nbsp%3B%20Check%20out%20-%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Factive-directory%2Fhybrid%2Fhow-to-connect-fed-whatis%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Factive-directory%2Fhybrid%2Fhow-to-connect-fed-whatis%3C%2FA%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EThe%20AADC%20server%20does%20not%20have%20to%20be%20on%20the%20same%20server%20as%20AD%20FS%20though.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2021346%22%20slang%3D%22en-US%22%3ERe%3A%20Azure%20AD%20-%20ADFS%20accounts%20without%20synchronization%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2021346%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F616707%22%20target%3D%22_blank%22%3E%40PeterRising%3C%2FA%3E%26nbsp%3Bso%20if%20I%20got%20that%20right%20-%20I%20may%20install%20and%20run%20Azure%20AD%20Connect%20on%20different%20machine%20and%20use%20it%20only%20for%20account%20synchronization%2C%20correct%3F%20This%20sounds%20promising.%26nbsp%3B%3C%2FP%3E%3CP%3EAbout%20user%20synchronization%20-%20I%20was%20kind%20of%20hoping%20it%20won't%20be%20needed%20to%20import%20all%20these%20users%20(it's%20around%205k%20in%20this%20particular%20case)%20to%20AAD%2C%20I'm%20worried%20a%20bit%20about%20that%20(it%20could%20be%20a%20nightmare%20in%20terms%20of%20management).%3C%2FP%3E%3CP%3EThanks%20for%20quick%20answer!%3C%2FP%3E%3CP%3ERegards%3C%2FP%3E%3CP%3ETomasz%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E
New Contributor

Hello guys,

Couple of simple (I hope) questions:

- is it possible to authenticate users through on-premise ADFS server in Azure without actually importing users to the Azure AD? Or the user always has to be imported because only then he gets Azure Id and can use Azure resources? 

- is there any option except Azure AD Connect to establish connection between ADFS server and Azure AD (so ADFS users can be authenticated)? The thing is that I don't have access to physical ADFS server, so I cannot install Azure AD Connect there.

Regards and thanks!

Tomasz

5 Replies

@zielonywojo 

 

Hi, you will need Azure AD Connect in order for this to work and have the users visible in Azure AD.  Check out - https://docs.microsoft.com/en-us/azure/active-directory/hybrid/how-to-connect-fed-whatis

 

The AADC server does not have to be on the same server as AD FS though.

@PeterRising so if I got that right - I may install and run Azure AD Connect on different machine and use it only for account synchronization, correct? This sounds promising. 

About user synchronization - I was kind of hoping it won't be needed to import all these users (it's around 5k in this particular case) to AAD, I'm worried a bit about that (it could be a nightmare in terms of management).

Thanks for quick answer!

Regards

Tomasz

 

@zielonywojo 

 

Yep, that's right.  AADC can be run on a different machine.  You'd need to run a custom installation and choose the option of Federation with AD FS as shown below.

 

Screenshot 2020-12-29 at 21.03.06.png

 

Question though - do you really need AD FS for O365?  Could you not go for Password Hash Sync or Pass through authentication instead?

@PeterRising 

The scenario here is that we have many users being in multiple external on-premises ADs. These on-premises ADs are gathered together in one master AD FS server and this is actually the only option from my point of view. The goal is to make it possible for these users to login to our App Service web app which we host in Azure. The requirement is to have SSO for these users, so they can reuse their domain accounts.

Regards

Tomasz

@zielonywojo 

 

I see, so no small task moving away from AD FS then.  I get it.