Sync Computers to Azure

%3CLINGO-SUB%20id%3D%22lingo-sub-1224430%22%20slang%3D%22en-US%22%3ERe%3A%20Sync%20Computers%20to%20Azure%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1224430%22%20slang%3D%22en-US%22%3EHi%20Christian%2C%3CBR%20%2F%3E%3CBR%20%2F%3EYou%20can%20sync%20computer%20to%20Azure%20AD%20by%20using%20ADConnect%20and%20update%20the%20config%20under%20Device%20options%20%E2%80%98Hybrid%20AD%20join%E2%80%99.%20Then%20place%20their%20computer%20in%20Syncing%20OU.%3CBR%20%2F%3E%3CBR%20%2F%3EHope%20this%20helps!%3CBR%20%2F%3EMoe%3CBR%20%2F%3E%3CBR%20%2F%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Factive-directory%2Fdevices%2Fhybrid-azuread-join-managed-domains%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Factive-directory%2Fdevices%2Fhybrid-azuread-join-managed-domains%3C%2FA%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1224742%22%20slang%3D%22en-US%22%3ERe%3A%20Sync%20Computers%20to%20Azure%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1224742%22%20slang%3D%22en-US%22%3ESyncing%20computers%20(Hybrid%20Joining)%20goes%20in%20conjunction%20with%20AAD%20Connect.%3CBR%20%2F%3E%3CBR%20%2F%3EAs%20there%20can%20only%20be%20one%20AAD%20Connect%2C%20this%20is%20not%20possible.%3CBR%20%2F%3ECheck%20this%20out%3A%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Factive-directory%2Fhybrid%2Fplan-connect-topologies%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Factive-directory%2Fhybrid%2Fplan-connect-topologies%3C%2FA%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1224732%22%20slang%3D%22en-US%22%3ERe%3A%20Sync%20Computers%20to%20Azure%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1224732%22%20slang%3D%22en-US%22%3E%3CP%3EI%20am%20aware%20of%20the%20ability%20to%20sync%20what%20I%20am%20trying%20to%20get%20clarity%20on%20is%20can%20I%20sync%20computers%20on%20a%20different%20domain.%26nbsp%3B%20in%20my%20OP%20i%20mentioned%20that%20I%20am%20trying%20to%20sync%20domain%20computers%20from%20another%20domain%20to%20my%20AAD%20tenant.%26nbsp%3B%20This%20other%20Domain%20is%20internal%20to%20me%20what%20would%20be%20the%20process%20to%20get%20them%20in%20AAD.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWould%20creating%20a%20trust%20between%20our%20domain%20allow%20me%20to%20see%20the%20computer%20objects%20and%20then%20sync%20them.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1224852%22%20slang%3D%22en-US%22%3ERe%3A%20Sync%20Computers%20to%20Azure%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1224852%22%20slang%3D%22en-US%22%3EHi%20Christian%2C%3CBR%20%2F%3E%3CBR%20%2F%3EYou%20should%20be%20able%20to%20sync%20two%20domains%20to%20one%20tenant%2C%20this%20how%20my%20test%20environment%20setup%3A%3CBR%20%2F%3E%3CBR%20%2F%3EAbc.local%20%2B%20jwz.local%20%E2%80%94%26amp%3Bgt%3B%20trust%20relation%20between%20two%20domains.%3CBR%20%2F%3E%3CBR%20%2F%3ESync%20hybrid%20joined%20to%20one%20tenant%20using%20one%20ADconnect.%20It%20should%20be%20under%20Customize%20Synchronization%20Options-%26gt%3BConnect%20Directories-%26gt%3BAdd%20Directory.%3CBR%20%2F%3E%3CBR%20%2F%3ELet%20me%20know%20if%20you%20have%20any%20questions%20and%20sorry%20about%20confusion%20earlier.%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1224884%22%20slang%3D%22en-US%22%3ERe%3A%20Sync%20Computers%20to%20Azure%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1224884%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F503735%22%20target%3D%22_blank%22%3E%40Moe_Kinani%3C%2FA%3E%26nbsp%3BThat%20sheds%20light%20on%20this%20now!!%26nbsp%3B%20Now%20with%20a%20trust%20in%20place%20do%20the%20computer%20objects%20in%20Domain%201%20show%20up%20in%20Domain%202%20(this%20domain%20is%20sync%3Bd%20to%20Azure)%20%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1224895%22%20slang%3D%22en-US%22%3ERe%3A%20Sync%20Computers%20to%20Azure%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1224895%22%20slang%3D%22en-US%22%3ENo%2C%20they%20will%20be%20synced%20to%20Azure%20AD%20only.%3CBR%20%2F%3E%3CBR%20%2F%3EYou%20can%20migrate%20them%20from%20domain1%20to%20domain%202%20using%20ADMT.%20I%20used%20articles%20below%20to%20do%20the%20job!%3CBR%20%2F%3E%3CBR%20%2F%3E%3CA%20href%3D%22https%3A%2F%2Fwww.petenetlive.com%2FKB%2FArticle%2F0001305%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fwww.petenetlive.com%2FKB%2FArticle%2F0001305%3C%2FA%3E%3CBR%20%2F%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1221006%22%20slang%3D%22en-US%22%3ESync%20Computers%20to%20Azure%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1221006%22%20slang%3D%22en-US%22%3E%3CP%3EI%20have%20a%20dept%20in%20house%20that%20is%20on%20a%20separate%20network%20with%20their%20own%20domain%2FDCs.%3C%2FP%3E%3CP%3EWe%20need%20to%20have%20somewhat%20of%20an%20ethical%20wall%20between%20us%20but%20they%20still%20need%20access%20to%20certain%20items%20that%20are%20being%20are%20being%20blocked%20by%20conditional%20access.%26nbsp%3B%20Items%20like%20SPO%2FTEAMs%20etc.%26nbsp%3B%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIm%20think%20of%20how%20can%20I%20sync%20the%20computer%20accounts%20to%20our%20Azure%20tenant%20but%20what%20the%20best%20way%20to%20get%20their%20computers%20in%20our%20Azure%20Tenant%20as%20Hybrid%20Joined%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-1221006%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EAzure%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E
Highlighted
Frequent Contributor

I have a dept in house that is on a separate network with their own domain/DCs.

We need to have somewhat of an ethical wall between us but they still need access to certain items that are being are being blocked by conditional access.  Items like SPO/TEAMs etc.  

 

Im think of how can I sync the computer accounts to our Azure tenant but what the best way to get their computers in our Azure Tenant as Hybrid Joined?

 

 

 

6 Replies
Highlighted
Hi Christian,

You can sync computer to Azure AD by using ADConnect and update the config under Device options ‘Hybrid AD join’. Then place their computer in Syncing OU.

Hope this helps!
Moe

https://docs.microsoft.com/en-us/azure/active-directory/devices/hybrid-azuread-join-managed-domains
Highlighted

I am aware of the ability to sync what I am trying to get clarity on is can I sync computers on a different domain.  in my OP i mentioned that I am trying to sync domain computers from another domain to my AAD tenant.  This other Domain is internal to me what would be the process to get them in AAD.

 

Would creating a trust between our domain allow me to see the computer objects and then sync them.

Highlighted
Syncing computers (Hybrid Joining) goes in conjunction with AAD Connect.

As there can only be one AAD Connect, this is not possible.
Check this out: https://docs.microsoft.com/en-us/azure/active-directory/hybrid/plan-connect-topologies
Highlighted
Hi Christian,

You should be able to sync two domains to one tenant, this how my test environment setup:

Abc.local + jwz.local —> trust relation between two domains.

Sync hybrid joined to one tenant using one ADconnect. It should be under Customize Synchronization Options->Connect Directories->Add Directory.

Let me know if you have any questions and sorry about confusion earlier.
Highlighted

@Moe_Kinani That sheds light on this now!!  Now with a trust in place do the computer objects in Domain 1 show up in Domain 2 (this domain is sync;d to Azure) ?

Highlighted
No, they will be synced to Azure AD only.

You can migrate them from domain1 to domain 2 using ADMT. I used articles below to do the job!

https://www.petenetlive.com/KB/Article/0001305