SOLVED

Single Forest AD Sync to Multiple Azure AD

%3CLINGO-SUB%20id%3D%22lingo-sub-12588%22%20slang%3D%22en-US%22%3ESingle%20Forest%20AD%20Sync%20to%20Multiple%20Azure%20AD%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-12588%22%20slang%3D%22en-US%22%3E%3CP%3EDoes%20anyone%20have%20any%20information%20on%20approved%20architecture%20for%20the%20following%3A%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ESingle%20AD%20Forest%20to%20two%20disperate%20Azure%20AD%20Connect%20instances.%20%26nbsp%3BEach%20synced%20to%20different%20OUs.%20%26nbsp%3BUnderlying%20issue%20is%20multiple%20tenants%2C%20one%20AD.%20%26nbsp%3BUltimately%20would%20like%20to%20be%20able%20to%20sync%20single%20AD%20forest%20to%20both%20tenants%2C%20different%20OUs.%20%26nbsp%3BAny%20direction%20is%20appreciated.%20%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-394087%22%20slang%3D%22en-US%22%3ERe%3A%20Single%20Forest%20AD%20Sync%20to%20Multiple%20Azure%20AD%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-394087%22%20slang%3D%22en-US%22%3EYeah%2C%20not%20possible%3CBR%20%2F%3E%3CBR%20%2F%3EPlease%20see%20this%20link%20for%20supported%20scenarios%3A%3CBR%20%2F%3E%3CBR%20%2F%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Factive-directory%2Fhybrid%2Fplan-connect-topologies%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Factive-directory%2Fhybrid%2Fplan-connect-topologies%3C%2FA%3E%3CBR%20%2F%3E%3CBR%20%2F%3EAdam%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-394082%22%20slang%3D%22en-US%22%3ERe%3A%20Single%20Forest%20AD%20Sync%20to%20Multiple%20Azure%20AD%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-394082%22%20slang%3D%22en-US%22%3E%3CP%3E%26nbsp%3BHi%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F11171%22%20target%3D%22_blank%22%3E%40Max%20Fritz%3C%2FA%3E%2C%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EYou%20can%20only%20have%20one%20Hybrid%20per%20Tenant%20and%20you%20can%20only%20configure%20one%20Hybrid%2C%20so%20that%20scenario%20is%20not%20possible.%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-393831%22%20slang%3D%22en-US%22%3ERe%3A%20Single%20Forest%20AD%20Sync%20to%20Multiple%20Azure%20AD%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-393831%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20Max%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3Ehow%20to%20configure%20Hybrid%20setup%20with%20single%20Exchange%20Organization%20to%20Multiple%20Office%20365%20Tenants.%20is%20it%20possible%3F%3F%20please%20share%20if%20you%20have%20some%20Documents.%3C%2FP%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F11171%22%20target%3D%22_blank%22%3E%40Max%20Fritz%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-78770%22%20slang%3D%22en-US%22%3ERe%3A%20Single%20Forest%20AD%20Sync%20to%20Multiple%20Azure%20AD%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-78770%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20Jo%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EHere%20is%20the%20official%20article%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fsupport.office.com%2Fen-us%2Farticle%2FHow-to-migrate-mailboxes-from-one-Office-365-tenant-to-another-65af7d77-3e79-44d4-9173-04fd991358b7%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fsupport.office.com%2Fen-us%2Farticle%2FHow-to-migrate-mailboxes-from-one-Office-365-tenant-to-another-65af7d77-3e79-44d4-9173-04fd991358b7%3C%2FA%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EBut%20to%20migrate%20other%20workloads%20is%20better%20to%20use%20third%20party%20tools.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-78765%22%20slang%3D%22en-US%22%3ERe%3A%20Single%20Forest%20AD%20Sync%20to%20Multiple%20Azure%20AD%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-78765%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20Max%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWe%20want%20to%20migrate%20our%20office%20365%20tenant%20to%20another%20tenant%20because%20of%20a%20name%20change.%3C%2FP%3E%3CP%3EHowever%2C%20we%20want%20to%20keep%20our%20on%20premise%20AD.%3C%2FP%3E%3CP%3EThis%20means%20both%20users%20will%20have%20to%20exist%20in%20both%20tenants.%3C%2FP%3E%3CP%3EThat's%20why%20I'm%20very%20interested%20in%20your%20guidelines%20and%20starting%20points.%3C%2FP%3E%3CP%3EIs%20it%20possible%20to%20sent%20me%20some%20more%20information%20about%20this%3F%3C%2FP%3E%3CP%3EThx%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-13357%22%20slang%3D%22en-US%22%3ERe%3A%20Single%20Forest%20AD%20Sync%20to%20Multiple%20Azure%20AD%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-13357%22%20slang%3D%22en-US%22%3E%3CP%3EYes%2C%20I've%20done%20this%20a%20few%20times.%20So%20long%20as%20the%20two%20Azure%20AD%20Connect%20instances%20are%20each%20on%20different%20servers%2C%20you%20will%20be%20fine.%20Will%20any%20users%20need%20to%20exist%20in%20both%20tenants%3F%20That's%20where%20things%20can%20get%20sticky.%3C%2FP%3E%3CP%3E%26nbsp%3BLet%20me%20know%20and%20I%20can%20send%20you%20some%20guidelines%20and%20starting%20points%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-12649%22%20slang%3D%22en-US%22%3ERe%3A%20Single%20Forest%20AD%20Sync%20to%20Multiple%20Azure%20AD%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-12649%22%20slang%3D%22en-US%22%3EI%20would%20recommend%20asking%20this%20in%20Azure%20AD%20space%20at%20%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2FAzure-Active-Directory%2Fbd-p%2FAzure-Active-Directory%22%20target%3D%22_blank%22%3Ehttps%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2FAzure-Active-Directory%2Fbd-p%2FAzure-Active-Directory%3C%2FA%3E.%20I%20think%20that%20this%20space%20is%20for%20people%20to%20talk%20about%20the%20overall%20MS%20Tech%20Community.%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2583962%22%20slang%3D%22en-US%22%3ERe%3A%20Single%20Forest%20AD%20Sync%20to%20Multiple%20Azure%20AD%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2583962%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F11171%22%20target%3D%22_blank%22%3E%40Max%20Fritz%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EPlease%20can%20you%20help%20me%20for%20the%20scenario%20where%20a%20specific%20OU%20from%20AD%20will%20be%20synced%20to%202%20Azure%20AD%20tenants.%20First%20tenant%20will%20have%20o365%20Exchange%2C%20Sharepoint%2C%20the%202nd%20tenant%20will%20have%20o365%20Power%20BI.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EUsers%20access%20to%20o365%20from%201st%20Tenant%20and%20Power%20BI%20from%202nd%20Tenant%20both%20with%20MFA.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3Ethanks%3CBR%20%2F%3ESai%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E
Deleted
Not applicable

Does anyone have any information on approved architecture for the following:

 

Single AD Forest to two disperate Azure AD Connect instances.  Each synced to different OUs.  Underlying issue is multiple tenants, one AD.  Ultimately would like to be able to sync single AD forest to both tenants, different OUs.  Any direction is appreciated.  

8 Replies
I would recommend asking this in Azure AD space at https://techcommunity.microsoft.com/t5/Azure-Active-Directory/bd-p/Azure-Active-Directory. I think that this space is for people to talk about the overall MS Tech Community.
best response confirmed by Anna Chu (Microsoft)
Solution

Yes, I've done this a few times. So long as the two Azure AD Connect instances are each on different servers, you will be fine. Will any users need to exist in both tenants? That's where things can get sticky.

 Let me know and I can send you some guidelines and starting points

Hi Max,

 

We want to migrate our office 365 tenant to another tenant because of a name change.

However, we want to keep our on premise AD.

This means both users will have to exist in both tenants.

That's why I'm very interested in your guidelines and starting points.

Is it possible to sent me some more information about this?

Thx

Hi Jo,

 

Here is the official article https://support.office.com/en-us/article/How-to-migrate-mailboxes-from-one-Office-365-tenant-to-anot...

 

But to migrate other workloads is better to use third party tools.

Hi Max,

 

how to configure Hybrid setup with single Exchange Organization to Multiple Office 365 Tenants. is it possible?? please share if you have some Documents.

@Max Fritz 

 Hi @Max Fritz,

 

You can only have one Hybrid per Tenant and you can only configure one Hybrid, so that scenario is not possible. 

Yeah, not possible

Please see this link for supported scenarios:

https://docs.microsoft.com/en-us/azure/active-directory/hybrid/plan-connect-topologies

Adam

@Max Fritz 

 

Please can you help me for the scenario where a specific OU from AD will be synced to 2 Azure AD tenants. First tenant will have o365 Exchange, Sharepoint, the 2nd tenant will have o365 Power BI.

 

Users access to o365 from 1st Tenant and Power BI from 2nd Tenant both with MFA.

 

thanks
Sai