Implementing AD into existing Cloud Azure AD

Copper Contributor

Hi,

 

we currently have Azure AD setup in our company and have our devices joined via AzureAD. Even though that works quite well, it doesn't offer the full capabilities as a normal AD would (GPO, Kerberos aso.). Therefore we would now like to implement a hybrid solution. I have heart of Azure AD connect sync but for my understanding that is meant to be used when syncing on prem to azure and not the other way around. Has anyone experience with such a scenario? Any input is appreciated.

 

Thanks

2 Replies

Hi,@User9081238989012380  

Kerberos is supported now for Azure AD Check this tutorial for more info Kerberos-based single sign-on (SSO) in Azure Active Directory with Application Proxy - Microsoft Ent...
If you enable Azure Active Directory Domain Services (Azure AD DS) you can also work with GPOs.
Create and manage group policy in Azure AD Domain Services | Microsoft Learn
Check this documentation for more information. Azure AD Domain Services documentation | Microsoft Learn

Azure Active Directory Domain Services (AADDS) will do the one-way sync from Azure AD to AADDS, that is however not technically considered a hybrid identity. It will give you GPOs and Kerberos authentication though.

Have a look at this if you want to look at doing traditional AD - https://learn.microsoft.com/en-us/azure/active-directory/hybrid/how-to-connect-install-existing-tena...