Home

Multiple Instances of Azure AD connect on a single network.

%3CLINGO-SUB%20id%3D%22lingo-sub-1027497%22%20slang%3D%22en-US%22%3EMultiple%20Instances%20of%20Azure%20AD%20connect%20on%20a%20single%20network.%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1027497%22%20slang%3D%22en-US%22%3E%3CP%3EI%20have%20a%20hosted%20exchange%20that%20is%20moving%20us%20to%20office%20365%2C%20and%20they%20have%20AD%20connect%20on%20one%20of%20my%20servers.%20I%20want%20to%20use%20Azure%20MFA%20and%20need%20to%20also%20have%20AD%20connect.%20There%20will%20be%20multiple%20users%20on%20both%20instances.%20Is%20this%20possible%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-1027497%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EAzure%20AD%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1028749%22%20slang%3D%22en-US%22%3ERe%3A%20Multiple%20Instances%20of%20Azure%20AD%20connect%20on%20a%20single%20network.%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1028749%22%20slang%3D%22en-US%22%3E%3CP%3EHello%20%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F466217%22%20target%3D%22_blank%22%3E%40SHD_IT%3C%2FA%3E%26nbsp%3B%3CBR%20%2F%3EYes%20It's%20possible%20to%20use%20Azure%20MFA%20in%20a%20hybrid%20environment.%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EJust%20note%20that%20out%20of%20the%20box%2C%20Azure%20MFA%20will%20only%20affect%20Azure%2FO365%20related%20services%20and%20not%20your%20local%20Exchange%20.%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EKind%20RegardsOliwer%20Sj%C3%B6berg%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1029943%22%20slang%3D%22en-US%22%3ERe%3A%20Multiple%20Instances%20of%20Azure%20AD%20connect%20on%20a%20single%20network.%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1029943%22%20slang%3D%22en-US%22%3E%3CP%3EHi%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F466217%22%20target%3D%22_blank%22%3E%40SHD_IT%3C%2FA%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ESo%20to%20get%20the%20image%20right%2C%20you%20have%20Hosted%20Exchange%20Environment%2C%20that%20is%20probably%20configured%20like%20that%20each%20Customer%20has%20it's%20own%20OU%20(Organizational%20Unite)%20for%20their%20AD%20Objects%20right%20%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIf%20we%20take%20that%20in%20perspective%2C%20then%20you%20need%20to%20have%20separate%20AD%20Connect%20Server%20for%20each%20Customer%20(Organizational%20Unit)%20and%20use%20extreme%20OU%20Filtering%2C%20as%20you%20will%20be%20syncing%20the%20User%20Objects%20from%20your%20Shared%20AD%20to%20multiple%20tenants%2C%20which%20is%20not%20recommended%20by%20Microsoft%20unless%20in%20extremely%20complicated%20scenarios%20as%20this%20might%20get%20really%20hard%20to%20manage%20in%20the%20long%20run%20and%20there%20is%20a%20tiny%20window%20for%20mistakes%20when%20it%20comes%20to%20Object%20Sync%20scenario%2C%20when%20for%20example%20someone%20from%20your%20help%20desk%20%2F%20support%20or%20something%20configures%20a%20wrong%20user%2C%20or%20object%2C%20then%20it%20gets%20synced%20to%20a%20wrong%20Tenant%2C%20we%20are%20all%20humans%20so%20we%20sometimes%20tend%20to%20make%20mistake%20like%20this%20%3B)%3C%2Fimg%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EBut%20if%20this%20is%20more%20like%20Hosted%20Exchange%20for%20your%20company%2C%20that%20is%20used%20to%20divide%20departments%20down%2C%20then%20I%20would%20recommend%20migrating%20the%20whole%20Exchange%20to%20one%20Office%20365%20tenant%20and%20then%20use%20good%20access%20control%20between%20departments%20if%20they%20shouldn't%20be%20able%20to%20see%20each%20other%2C%20that%20will%20be%20much%20more%20easier%20management%2C%20also%20when%20it%20comes%20to%20Azure%20AD%20Connect%20%2F%20Hybrid%20Azure%20AD%20Join%20and%20other%20features%20it's%20better%20to%20have%20one%20Office%20365%20tenant%20as%20you%20will%20loose%20those%20features%20when%20syncing%20%22One%20AD%22%20to%20multiple%20tenants.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EHope%20this%20helps%2C%20please%20feel%20free%20to%20clarify%20if%20I'm%20not%20painting%20your%20picture%20right%2C%20let's%20find%20a%20solution%20to%20your%20question.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EKind%20Regards%3C%2FP%3E%3CP%3EHaflidi%20Fridthjofsson.%3C%2FP%3E%3C%2FLINGO-BODY%3E
Highlighted
Occasional Visitor

I have a hosted exchange that is moving us to office 365, and they have AD connect on one of my servers. I want to use Azure MFA and need to also have AD connect. There will be multiple users on both instances. Is this possible?

2 Replies

Hello @SHD_IT 
Yes It's possible to use Azure MFA in a hybrid environment. 

 

Just note that out of the box, Azure MFA will only affect Azure/O365 related services and not your local Exchange . 

 

Kind Regards
Oliwer Sjöberg

Highlighted

Hi @SHD_IT

 

So to get the image right, you have Hosted Exchange Environment, that is probably configured like that each Customer has it's own OU (Organizational Unite) for their AD Objects right ?

 

If we take that in perspective, then you need to have separate AD Connect Server for each Customer (Organizational Unit) and use extreme OU Filtering, as you will be syncing the User Objects from your Shared AD to multiple tenants, which is not recommended by Microsoft unless in extremely complicated scenarios as this might get really hard to manage in the long run and there is a tiny window for mistakes when it comes to Object Sync scenario, when for example someone from your help desk / support or something configures a wrong user, or object, then it gets synced to a wrong Tenant, we are all humans so we sometimes tend to make mistake like this ;)

 

But if this is more like Hosted Exchange for your company, that is used to divide departments down, then I would recommend migrating the whole Exchange to one Office 365 tenant and then use good access control between departments if they shouldn't be able to see each other, that will be much more easier management, also when it comes to Azure AD Connect / Hybrid Azure AD Join and other features it's better to have one Office 365 tenant as you will loose those features when syncing "One AD" to multiple tenants.

 

Hope this helps, please feel free to clarify if I'm not painting your picture right, let's find a solution to your question.

 

Kind Regards

Haflidi Fridthjofsson.

Related Conversations
Global Azure Virtual 2020
Gregor Suttie in Azure on
0 Replies
Azure key vault export keys
AzureRanger in Azure on
0 Replies
WVD Publish individual apps to sessions
Chris-424 in Windows Virtual Desktop on
0 Replies
PDF generation in Azure App Service
Ryan Stone in Azure on
0 Replies