Can we use Azure Active Directory to remove local Domain Controller?

%3CLINGO-SUB%20id%3D%22lingo-sub-710892%22%20slang%3D%22en-US%22%3ECan%20we%20use%20Azure%20Active%20Directory%20to%20remove%20local%20Domain%20Controller%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-710892%22%20slang%3D%22en-US%22%3E%3CP%3EDear%20all%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20have%20done%20some%20research%20and%20I%20cannot%20get%20a%20straight%20answer%20so%20far.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20am%20aware%20of%20Azure%20active%20directory%20domain%20services%20.%20But%20I%20wonder%20if%20it%20or%20anything%20Microsoft%20Azure%20has%20can%20delete%20or%20remove%20a%20local%20Domain%20Controller%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EBy%20local%20I%20presume%20it%20means%20on-premise%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EPlease%20advise.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThank%20you%20very%20much.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-710892%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EAzure%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-710971%22%20slang%3D%22en-US%22%3ERe%3A%20Can%20we%20use%20Azure%20Active%20Directory%20to%20remove%20local%20Domain%20Controller%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-710971%22%20slang%3D%22en-US%22%3E%3CP%3EAzure%20Active%20Directory%20can%20be%20used%20to%20replace%20your%20on%20premises%20domain%20controllers.%20If%20you%20are%20simply%20looking%20to%20use%20it%20as%20an%20identity%20provider%20you%20can%20use%20the%20basic%20tier.%20If%20you%20are%20looking%20for%20a%20MDM%20or%20MAM%20solution%20you%20need%20to%20purchase%20some%20additional%20licencing%20to%20use%20Intune.%20To%20unlock%20some%20of%20the%20other%20features%20you%20may%20also%20need%20to%20purchase%20Azure%20AD%20Premium%20tier%201%20or%202.%20Azure%20active%20directory%20domain%20services%20currently%20has%20a%20limitation%20of%20bringing%20your%20current%20domain%20into%20that%20service.%20You%20have%20to%20provision%20a%20new%20domain%20meaning%20a%20migration.%20The%20last%20option%20you%20could%20look%20at%20is%20putting%20a%20domain%20controller%20in%20Azure%20and%20setup%20a%20VPN.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ELet%20me%20know%20if%20you%20have%20additional%20questions%20and%20I%20would%20be%20happy%20to%20guide%20you%20to%20the%20right%20place.%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F363823%22%20target%3D%22_blank%22%3E%40gough2%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-711013%22%20slang%3D%22en-US%22%3ERe%3A%20Can%20we%20use%20Azure%20Active%20Directory%20to%20remove%20local%20Domain%20Controller%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-711013%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F183000%22%20target%3D%22_blank%22%3E%40Bryan%20Haslip%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EHi%20Bryan%2C%3C%2FP%3E%3CP%3EThank%20you%20very%20much%20for%20your%20quick%20response.%3C%2FP%3E%3CP%3EI%20wonder%20with%20a%20hyrbrid%20structure%20in%20place%2C%20(i.e.%20part%20Azure%20and%20part%20on-premise%20Active%20Directory)%20%2C%20if%20there%20is%20a%20way%20for%20Azure%20Active%20Directory%20to%20delete%20a%20local%20(on-premise)%20Domain%20Controller%3F%3C%2FP%3E%3CP%3EPlease%20advise.%3C%2FP%3E%3CP%3EThank%20you%20very%20much.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-711711%22%20slang%3D%22en-US%22%3ERe%3A%20Can%20we%20use%20Azure%20Active%20Directory%20to%20remove%20local%20Domain%20Controller%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-711711%22%20slang%3D%22en-US%22%3E%3CP%3EAzure%20active%20directory%20is%20not%20a%20direct%20replacement%20for%20you%20on%20premieres%20AD.%20If%20you%20have%20no%20need%20for%20some%20of%20the%20traditional%20features%20such%20as%20GPO's%2C%20Azure%20AD%20may%20be%20a%20good%20fit%20for%20a%20replacement.%20It%20really%20depends%20on%20what%20the%20important%20features%20you%20want%20to%20retain.%20Could%20you%20possibly%20list%20out%20the%20functionality%20you%20are%20looking%20for%3F%20Then%20I%20can%20help%20list%20out%20what%20might%20be%20the%20best%20course%20of%20action.%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F363823%22%20target%3D%22_blank%22%3E%40gough2%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-770175%22%20slang%3D%22en-US%22%3ERe%3A%20Can%20we%20use%20Azure%20Active%20Directory%20to%20remove%20local%20Domain%20Controller%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-770175%22%20slang%3D%22en-US%22%3E%3CP%3EConsidering%20the%20following%20scenario%3A%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E-%20(1)%20Site%20in%20one%20country%20with%20Local%20Domain%20Controller%20and%20several%20remote%20workers%20in%20another%20country%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWhat%20is%20the%20best%20Deployment%20(HA)%20option%20using%20Azure%3A%3C%2FP%3E%3CP%3E-%20We%20have%20an%20active%20VM%20in%20Azure%20with%20an%20AD%20connected%20and%20synchronized%20with%20the%20Local%20Domain%20Controller%20through%20a%20VPN%20Site-Site%20connection%3F%3CBR%20%2F%3E-%20We%20have%20an%20active%20VM%20in%20Azure%20with%20an%20AD%20and%20connected%20to%20the%20local%20Site%20through%20a%20Site-Site%20VPN%20and%20eliminate%20the%20Local%20Domain%20Controller%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIn%20any%20of%20the%20options%3A%3C%2FP%3E%3CP%3E-%20How%20it%20would%20be%20the%20handling%20of%20remote%20users%3C%2FP%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F183000%22%20target%3D%22_blank%22%3E%40Bryan%20Haslip%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E
Highlighted
New Contributor

Dear all,

 

I have done some research and I cannot get a straight answer so far.

 

I am aware of Azure active directory domain services . But I wonder if it or anything Microsoft Azure has can delete or remove a local Domain Controller?

 

By local I presume it means on-premise?

 

Please advise.

 

Thank you very much.

 

4 Replies
Highlighted

Azure Active Directory can be used to replace your on premises domain controllers. If you are simply looking to use it as an identity provider you can use the basic tier. If you are looking for a MDM or MAM solution you need to purchase some additional licencing to use Intune. To unlock some of the other features you may also need to purchase Azure AD Premium tier 1 or 2. Azure active directory domain services currently has a limitation of bringing your current domain into that service. You have to provision a new domain meaning a migration. The last option you could look at is putting a domain controller in Azure and setup a VPN.

 

Let me know if you have additional questions and I would be happy to guide you to the right place. 

 @gough2 

Highlighted

@Bryan Haslip 

 

Hi Bryan,

Thank you very much for your quick response.

I wonder with a hyrbrid structure in place, (i.e. part Azure and part on-premise Active Directory) , if there is a way for Azure Active Directory to delete a local (on-premise) Domain Controller?

Please advise.

Thank you very much.

Highlighted

Azure active directory is not a direct replacement for you on premieres AD. If you have no need for some of the traditional features such as GPO's, Azure AD may be a good fit for a replacement. It really depends on what the important features you want to retain. Could you possibly list out the functionality you are looking for? Then I can help list out what might be the best course of action. @gough2 

Highlighted

Considering the following scenario:

 

- (1) Site in one country with Local Domain Controller and several remote workers in another country

 

What is the best Deployment (HA) option using Azure:

- We have an active VM in Azure with an AD connected and synchronized with the Local Domain Controller through a VPN Site-Site connection?
- We have an active VM in Azure with an AD and connected to the local Site through a Site-Site VPN and eliminate the Local Domain Controller?

 

In any of the options:

- How it would be the handling of remote users

@Bryan Haslip