SOLVED

Leaving On-prem Active Directory

%3CLINGO-SUB%20id%3D%22lingo-sub-1117953%22%20slang%3D%22en-US%22%3ELeaving%20On-prem%20Active%20Directory%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1117953%22%20slang%3D%22en-US%22%3EI%E2%80%99ve%20drunk%20the%20cool-aid%20and%20keen%20to%20fully%20embrace%20Azure%2C%20though%20I%E2%80%99m%20wondering%20is%20it%20possible%20to%20completely%20abandon%20the%20traditional%20On-prem%20or%20IaaS%20Active%20Directory%20instanced%20and%20purely%20use%20Azure%20AD%20%26amp%3B%20Azure%20Active%20Directory%20Services(Azure%20PaaS).%3CBR%20%2F%3E%3CBR%20%2F%3EIs%20there%20a%20useful%20blog%20on%20how%20to%20go%20down%20this%20path%20%3F%3CBR%20%2F%3E%3CBR%20%2F%3EI%20have%20two%20forests%20and%208%20domains%20with%207%20of%20them%20in%20one%20of%20the%20forests.%3CBR%20%2F%3EI%E2%80%99m%20wondering%20if%20it%20makes%20more%20sense%20to%20flatten%20those%20domains%20down%20to%20a%20single%20domain%20and%20Sync%20the%20new%20clean%20domain%20into%20Azure%2C%20or%20could%20I%20(should%20I)%20just%20sync%20all%208%20domains%20into%20a%20single%20Azure%20directory%3F%3CBR%20%2F%3E%3CBR%20%2F%3EI%E2%80%99d%20be%20happy%20to%20see%20any%20blogs%20as%20what%20I%E2%80%99m%20stuck%20on%20is%20that%20I%20could%20easily%20enough%20break%20this%20out%20into%20multiple%20steps%20such%20as%20Consolidate%20and%20then%20migrate%20but%20looking%20for%20ideas%20for%20a%20better%20approach%20to%20take.%3CBR%20%2F%3E%3CBR%20%2F%3EIdeal%20endpoint%20-%20Purely%20using%20Azure%20AD%20and%20Azure%20Directory%20services%20and%20no%20longer%20reliant%20of%20an%20IaaS%20Active%20Directory%20Instance.%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-1117953%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EAccess%20Management%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EActive%20Directory%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EAzure%20AD%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1118647%22%20slang%3D%22en-US%22%3ERe%3A%20Leaving%20On-prem%20Active%20Directory%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1118647%22%20slang%3D%22en-US%22%3EHi%20Yuukan%2C%3CBR%20%2F%3E%3CBR%20%2F%3EI%20have%20done%20similar%20migration%20with%20two%20forests.%20You%20have%20three%20options%20here%3A%3CBR%20%2F%3E%3CBR%20%2F%3E1.%20Using%20AD%20migration%20tool%20to%20migrate%20all%20domains%20into%20one%2C%20and%20then%20migrate%20to%20AAD%20domain%20services%20with%20clean%20Domain%20and%20sync%20to%20cloud.%20I%20can%20send%20you%20blogs%20on%20how%20to%20do%20it.%3CBR%20%2F%3E%3CBR%20%2F%3E2.%20Move%20all%20forests%20and%20domains%20AAD%20Domain%20services%2C%20then%20sync%20all%20domains%20to%20the%20cloud.%20You%20pay%20a%20lot%20more%20with%20this%20method.%3CBR%20%2F%3E%3CBR%20%2F%3E3.%20Use%20only%20AAD%20without%20traditional%20AD%20but%20you%20have%20to%20migrate%20group%20policies%20to%20Intune.%20You%20can%20use%20Securitly%20Baseline%2C%20Administrative%20Template%20and%20OMI%20profiles.%3CBR%20%2F%3E%3CBR%20%2F%3EI%20would%20definitely%20go%20with%20take%20number%201%20because%20cleaner%20and%20cheaper%20because%20you%E2%80%99re%20using%20only%20one%20domain.%20I%20don%E2%80%99t%20have%20blog%20with%20summarize%20all%20the%20steps%20but%20happy%20to%20answer%20any%20questions.%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1119803%22%20slang%3D%22en-US%22%3ERe%3A%20Leaving%20On-prem%20Active%20Directory%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1119803%22%20slang%3D%22en-US%22%3ESo%20Option%201%20is%20the%20approach%20I'm%20planning%20to%20do%20at%20the%20moment%20and%20would%20be%20happy%20to%20see%20this%20one.%20I'd%20be%20happy%20to%20look%20at%20some%20of%20those%20blogs%20you%20suggested.%3CBR%20%2F%3E%3CBR%20%2F%3EI%20was%20a%20bit%20thrown%20by%20some%20colleagues%20saying%20that%20the%20intermediate%20domain%20domain%20would%20be%20a%20waste%20of%20time%20and%20effort%20if%20we%20are%20anyway%20going%20to%20sync%20up%20into%20AAD%20DS.%3CBR%20%2F%3EIn%20my%20head%20it%20is%20an%20extra%20step%2C%20but%20you%20are%20setting%20yourself%20a%20fall%20back%20safety%20net%20should%20the%20initial%20migration%20run%20into%20any%20troubles.%3CBR%20%2F%3E%3CBR%20%2F%3EHave%20you%20ever%20had%20to%20do%20this%20with%20a%20client%20that%20already%20has%20a%20somewhat%20partial%20footprint%20in%20Azure%20%26amp%3B%20O365%20%3F%3CBR%20%2F%3E%3CBR%20%2F%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1121539%22%20slang%3D%22en-US%22%3ERe%3A%20Leaving%20On-prem%20Active%20Directory%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1121539%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F492419%22%20target%3D%22_blank%22%3E%40Yuukan%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20used%20the%20articles%20below%20to%20migrate%20the%20domains%2C%20hope%20it%20helps%20as%20well.%3C%2FP%3E%3CDIV%3E%3CA%20href%3D%22https%3A%2F%2Fwww.petenetlive.com%2FKB%2FArticle%2F0001305%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fwww.petenetlive.com%2FKB%2FArticle%2F0001305%3C%2FA%3E%3C%2FDIV%3E%3CDIV%3E%3CA%20href%3D%22https%3A%2F%2Fwww.petenetlive.com%2FKB%2FArticle%2F0001306%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fwww.petenetlive.com%2FKB%2FArticle%2F0001306%3C%2FA%3E%3C%2FDIV%3E%3CDIV%3E%3CA%20href%3D%22https%3A%2F%2Fwww.petenetlive.com%2FKB%2FArticle%2F0001307%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fwww.petenetlive.com%2FKB%2FArticle%2F0001307%3C%2FA%3E%3C%2FDIV%3E%3CDIV%3E%3CA%20href%3D%22https%3A%2F%2Fwww.petenetlive.com%2FKB%2FArticle%2F0001308%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fwww.petenetlive.com%2FKB%2FArticle%2F0001308%3C%2FA%3E%3C%2FDIV%3E%3CDIV%3E%26nbsp%3B%3C%2FDIV%3E%3CDIV%3EThe%20client%20was%20already%20using%20O365%20and%20Azure%20in%20Hybrid%20Environment%2C%20multiple%20domains%20were%20syncing%20with%20ADConnect%20to%20one%20MSFT%20Tenant.%26nbsp%3B%3C%2FDIV%3E%3CDIV%3E%26nbsp%3B%3C%2FDIV%3E%3CDIV%3ELet%20me%20know%20if%20you%20have%20any%20questions..%20Good%20Luck!%3C%2FDIV%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1120805%22%20slang%3D%22en-US%22%3ERe%3A%20Leaving%20On-prem%20Active%20Directory%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1120805%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F492419%22%20target%3D%22_blank%22%3E%40Yuukan%3C%2FA%3E%26nbsp%3Bwhat%20services%20are%20currently%20using%20Active%20Directory%3F%20Azure%20AD%20has%20a%20new%20provisioning%20service%20that%20allows%20you%20to%20take%20several%20domains%20in%20to%20one%20AAD%20tenant.%20Are%20you%20using%20Dot1x%20network%20security%20either%20wired%20or%20wireless%3F%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWhat%20services%20are%20using%20your%20AD%20environment%3F%20VPN%3F%20File%20Shares%3F%20Does%20everything%20you%20use%20work%20with%20AAD%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E
Highlighted
Occasional Contributor
I’ve drunk the cool-aid and keen to fully embrace Azure, though I’m wondering is it possible to completely abandon the traditional On-prem or IaaS Active Directory instanced and purely use Azure AD & Azure Active Directory Services(Azure PaaS).

Is there a useful blog on how to go down this path ?

I have two forests and 8 domains with 7 of them in one of the forests.
I’m wondering if it makes more sense to flatten those domains down to a single domain and Sync the new clean domain into Azure, or could I (should I) just sync all 8 domains into a single Azure directory?

I’d be happy to see any blogs as what I’m stuck on is that I could easily enough break this out into multiple steps such as Consolidate and then migrate but looking for ideas for a better approach to take.

Ideal endpoint - Purely using Azure AD and Azure Directory services and no longer reliant of an IaaS Active Directory Instance.
5 Replies
Hi Yuukan,

I have done similar migration with two forests. You have three options here:

1. Using AD migration tool to migrate all domains into one, and then migrate to AAD domain services with clean Domain and sync to cloud. I can send you blogs on how to do it.

2. Move all forests and domains AAD Domain services, then sync all domains to the cloud. You pay a lot more with this method.

3. Use only AAD without traditional AD but you have to migrate group policies to Intune. You can use Securitly Baseline, Administrative Template and OMI profiles.

I would definitely go with take number 1 because cleaner and cheaper because you’re using only one domain. I don’t have blog with summarize all the steps but happy to answer any questions.
Highlighted
So Option 1 is the approach I'm planning to do at the moment and would be happy to see this one. I'd be happy to look at some of those blogs you suggested.

I was a bit thrown by some colleagues saying that the intermediate domain domain would be a waste of time and effort if we are anyway going to sync up into AAD DS.
In my head it is an extra step, but you are setting yourself a fall back safety net should the initial migration run into any troubles.

Have you ever had to do this with a client that already has a somewhat partial footprint in Azure & O365 ?

Highlighted

@Yuukan what services are currently using Active Directory? Azure AD has a new provisioning service that allows you to take several domains in to one AAD tenant. Are you using Dot1x network security either wired or wireless? 

 

What services are using your AD environment? VPN? File Shares? Does everything you use work with AAD?

Highlighted
Best Response confirmed by Yuukan (Occasional Contributor)
Solution

@Yuukan 

 

I used the articles below to migrate the domains, hope it helps as well.

 
The client was already using O365 and Azure in Hybrid Environment, multiple domains were syncing with ADConnect to one MSFT Tenant. 
 
Let me know if you have any questions.. Good Luck!

 

Highlighted

@Moe_Kinani 
That sounds like a similar setup to the environment I'm  working on at the moment.