Integrating On-Premise AD with Cloud AD tenants

%3CLINGO-SUB%20id%3D%22lingo-sub-390725%22%20slang%3D%22en-US%22%3EIntegrating%20On-Premise%20AD%20with%20Cloud%20AD%20tenants%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-390725%22%20slang%3D%22en-US%22%3E%3CP%3EHello%20folks%2C%3C%2FP%3E%3CP%3EAny%20one%20here%20has%20knowledge%20on%20Hybrid%20AD%20setup%20using%20On-Prem%20AD%20in%20combination%20with%20Cloud%20AD%20providers%3F%3C%2FP%3E%3CP%3E%3CBR%20%2F%3ENeed%20help%20understanding%20a%20scenario%2C%20if%20it%20is%20possible%20or%20not.%20Thanks!%20%3A%20)%3C%2FP%3E%3CP%3E-%20Situation%3A%20Already%20running%20on-prem%20AD%20integrated%20with%20Azure%20AD.%3CBR%20%2F%3E-%20Problem%3A%20Want%20to%20integrate%20another%20cloud%20AD%20to%20the%20setup%20above.%20In%20this%20new%20cloud%20AD%2C%20a%20sub%20setup%20of%20groups%2Froles%2Fpolicies%20will%20be%20defined%2C%20but%20all%20user%20identifiers%2C%20objects%20etc%20still%20live%20in%20on-prem%20AD.%3CBR%20%2F%3E-%20Possible%20Solutions%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAny%20inputs%20appreciated%20%3A%20)%3CBR%20%2F%3EThanks!%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-390740%22%20slang%3D%22en-US%22%3ERe%3A%20Integrating%20On-Premise%20AD%20with%20Cloud%20AD%20tenants%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-390740%22%20slang%3D%22en-US%22%3EAlright..%3CBR%20%2F%3E%3CBR%20%2F%3EThanks%20for%20your%20help!%20%3A)%3C%2Fimg%3E%3CBR%20%2F%3E%3CBR%20%2F%3E%2F%2FRaywon%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-390739%22%20slang%3D%22en-US%22%3ERe%3A%20Integrating%20On-Premise%20AD%20with%20Cloud%20AD%20tenants%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-390739%22%20slang%3D%22en-US%22%3ENot%20that%20I%20know%20of!%20The%20different%20supported%20scenarios%20are%20what%20you%20get%20basically!%3CBR%20%2F%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-390736%22%20slang%3D%22en-US%22%3ERe%3A%20Integrating%20On-Premise%20AD%20with%20Cloud%20AD%20tenants%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-390736%22%20slang%3D%22en-US%22%3EThank%20you%20for%20your%20inputs%20%3A)%3C%2Fimg%3E%3CBR%20%2F%3E%3CBR%20%2F%3EDo%20you%20know%20if%20there%20is%20any%20alternate%20solutions%20to%20the%20situation%3F%3CBR%20%2F%3E%3CBR%20%2F%3EWe%20have%20several%20organizational%20units%20and%20want%20to%20control%20access%20to%20applications%20for%20users%20part%20of%20our%20unit%20only%2C%20and%20other%20units%20control%20their%20sub%20set%20of%20users%20etc.%20Also%20we%20do%20have%20some%20central%20applications%20as%20well%20which%20are%20common%20for%20all%20users.%3CBR%20%2F%3E%3CBR%20%2F%3EAppreciate%20your%20help.%20Thanks!%20%3A)%3C%2Fimg%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-390726%22%20slang%3D%22en-US%22%3ERe%3A%20Integrating%20On-Premise%20AD%20with%20Cloud%20AD%20tenants%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-390726%22%20slang%3D%22en-US%22%3EYou%20can%20never%20have%20the%20same%20objects%20syncing%20with%20more%20than%20one%20AAD!%3CBR%20%2F%3EAlso%20you%20will%20always%20need%20one%20AD%20Connect%20per%20AAD!%3CBR%20%2F%3E%3CBR%20%2F%3EI%E2%80%99ll%20suggest%20taking%20a%20look%20at%20the%20supported%20scenarios%20listed%20here%3A%3CBR%20%2F%3E%3CBR%20%2F%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Factive-directory%2Fhybrid%2Fplan-connect-topologies%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Factive-directory%2Fhybrid%2Fplan-connect-topologies%3C%2FA%3E%3CBR%20%2F%3E%3CBR%20%2F%3EIn%20your%20case%20the%20Following%20scenario%20from%20the%20link%20is%20of%20interest%3A%3CBR%20%2F%3E%3CBR%20%2F%3E%E2%80%9CEach%20object%20only%20once%20in%20an%20Azure%20AD%20tenant%E2%80%9D%3CBR%20%2F%3E%3CBR%20%2F%3EAdam%3C%2FLINGO-BODY%3E
New Contributor

Hello folks,

Any one here has knowledge on Hybrid AD setup using On-Prem AD in combination with Cloud AD providers?


Need help understanding a scenario, if it is possible or not. Thanks! : )

- Situation: Already running on-prem AD integrated with Azure AD.
- Problem: Want to integrate another cloud AD to the setup above. In this new cloud AD, a sub setup of groups/roles/policies will be defined, but all user identifiers, objects etc still live in on-prem AD.
- Possible Solutions?

 

Any inputs appreciated : )
Thanks!

4 Replies
You can never have the same objects syncing with more than one AAD!
Also you will always need one AD Connect per AAD!

I’ll suggest taking a look at the supported scenarios listed here:

https://docs.microsoft.com/en-us/azure/active-directory/hybrid/plan-connect-topologies

In your case the Following scenario from the link is of interest:

“Each object only once in an Azure AD tenant”

Adam
Thank you for your inputs :)

Do you know if there is any alternate solutions to the situation?

We have several organizational units and want to control access to applications for users part of our unit only, and other units control their sub set of users etc. Also we do have some central applications as well which are common for all users.

Appreciate your help. Thanks! :)
Not that I know of! The different supported scenarios are what you get basically!
Alright..

Thanks for your help! :)

//Raywon