Can you Migrate from Microsoft Cloud Identity to ADFS

%3CLINGO-SUB%20id%3D%22lingo-sub-266405%22%20slang%3D%22en-US%22%3ECan%20you%20Migrate%20from%20Microsoft%20Cloud%20Identity%20to%20ADFS%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-266405%22%20slang%3D%22en-US%22%3E%3CP%3EHello%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIf%20you%20start%20a%20new%20full-cloud%20O365%20tenant%20with%20Azure%20AD%20and%20Azure%20ADDS%20using%20just%20the%20Cloud%20Identity%20authentication%20model%2C%20can%20you%20later%20upgrade%20to%20using%20ADFS%20for%20authentication%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Foffice365%2Fenterprise%2Fplan-for-directory-synchronization%23office-365-identity-models%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Foffice365%2Fenterprise%2Fplan-for-directory-synchronization%23office-365-identity-models%3C%2FA%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThank%20you%20in%20advance!%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EPhillip%20Toynton%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-266405%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EAzure%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-267257%22%20slang%3D%22en-US%22%3ERe%3A%20Can%20you%20Migrate%20from%20Microsoft%20Cloud%20Identity%20to%20ADFS%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-267257%22%20slang%3D%22en-US%22%3ESorry%2C%20I%20might%20have%20misspoken.%20I%20never%20had%20to%20do%20this%20and%20last%20time%20I%20checked%2C%20most%20people%20said%20that%20it%20was%20impossible%20to%20break%20the%20AD%20Sync%20without%20deleting%20users%20but%20according%20to%20this%20article%20you%20can%20stop%20the%20AD%20Connect%20synchronization%20and%20then%20you%20would%20be%20able%20to%20manage%20users%20in%20Azure%20AD%20alone.%3CBR%20%2F%3E%3CBR%20%2F%3E%3CA%20href%3D%22https%3A%2F%2Fsupport.microsoft.com%2Fen-us%2Fhelp%2F2619062%2Fyou-can-t-manage-or-remove-objects-that-were-synchronized-through-the%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fsupport.microsoft.com%2Fen-us%2Fhelp%2F2619062%2Fyou-can-t-manage-or-remove-objects-that-were-synchronized-through-the%3C%2FA%3E%3CBR%20%2F%3E%3CBR%20%2F%3EFair%20warning%3B%20I%20have%20never%20tried%20this%20method%20before%20so%20I'm%20not%20100%25%20sure%20about%20the%20outcome.%20According%20to%20how%20I%20read%20that%20article%20you%20should%20be%20able%20to%20connect%20to%20Azure%20AD%20and%20say%20that%20it%20shouldn't%20use%20sync%20from%20on-prem%20and%20thus%20be%20able%20to%20edit%20users%20previously%20synchronized.%3CBR%20%2F%3E%3CBR%20%2F%3EThank%20you%20for%20the%20question%2C%20I'm%20here%20to%20learn%20new%20things%20as%20well%20as%20help%20and%20this%20definitely%20helped%20me.%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-266877%22%20slang%3D%22en-US%22%3ERe%3A%20Can%20you%20Migrate%20from%20Microsoft%20Cloud%20Identity%20to%20ADFS%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-266877%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20Robert%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAgain%20-%20thank%20you%20so%20much%20for%20responding.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%22%3CSPAN%3EAny%20users%20created%20on-prem%20will%20be%20deleted%20in%20Azure%20AD%20if%20you%20stop%20the%20sync%20from%20AD.%22%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%3EBut%20what%20if%20I%20first%20import%20them%20into%20a%20O365%20environment%3F%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%3EWe're%20looking%20to%20create%20a%20new%20PDC%20in%20Azure%20(with%20another%20for%20fault%20tolerance).%26nbsp%3B%20My%20understanding%20is%20that%20if%20we%20don't%20need%20SSO%2C%20we%20don't%20have%20to%20setup%20the%26nbsp%3BAD%20sync%20%2F%20AD%20Connect%20or%20the%20ADFS%20farm.%26nbsp%3B%20We%20can%20just%20use%20Cloud%20Identity%20to%20manage%20our%20users.%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%3EIs%20this%20not%20true%3F%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%3EThank%20you%2C%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%3EPhil%3C%2FSPAN%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-266579%22%20slang%3D%22en-US%22%3ERe%3A%20Can%20you%20Migrate%20from%20Microsoft%20Cloud%20Identity%20to%20ADFS%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-266579%22%20slang%3D%22en-US%22%3EAny%20users%20created%20on-prem%20will%20be%20deleted%20in%20Azure%20AD%20if%20you%20stop%20the%20sync%20from%20AD.%3CBR%20%2F%3E%3CBR%20%2F%3EYou%20can%20set%20up%20your%20servers%20in%20Azure%2C%20but%20before%20removing%20anything%20on-prem%20you%20need%20to%20migrate%20the%20PDC%20to%20a%20DC%20in%20Azure%20and%20set%20up%20a%20new%20AAD%20Connect%20there.%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-266540%22%20slang%3D%22en-US%22%3ERe%3A%20Can%20you%20Migrate%20from%20Microsoft%20Cloud%20Identity%20to%20ADFS%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-266540%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20Robert%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThank%20you%20for%20the%20reply.%26nbsp%3B%20We're%20actually%20planning%20on%20moving%20away%20from%20a%20hybrid%20environment%20and%26nbsp%3Bwe're%20actively%20working%20on%26nbsp%3B%3CSTRONG%3Enot%3C%2FSTRONG%3E%20having%20any%20on-prem%20AD%20servers%20in-house.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWe've%20been%20in%20a%20hybrid%20environment%20for%20over%204%20years%20and%20our%20business%20model%20has%20never%20needed%20and%2For%20wanted%20to%20use%20the%20SSO%20capabilities%20with%20ADFS%20authentication%20model.%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWhat%20I%20want%20to%20know%20is%20IF%20we%20go%20to%20full%20O365%20cloud%20and%20use%20Azure%20to%20ONLY%20host%20a%20newly%20created%20DC%20(and%20a%20fault%20tolerance%20DC)%2C%20and%20use%20Cloud%20Identity%20for%20authentication%2C%20can%20we%20later%20(6%20months%3F%20a%20year%3F%205%20years%3F)%20add%20ADFS%2C%20AD%20Sync%20and%20AD%20Connect%3F%26nbsp%3B%20There%20is%20a%20strong%20desire%20to%20simplify%20our%20infrastructure.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EPhil%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-266479%22%20slang%3D%22en-US%22%3ERe%3A%20Can%20you%20Migrate%20from%20Microsoft%20Cloud%20Identity%20to%20ADFS%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-266479%22%20slang%3D%22en-US%22%3E%3CP%3EIf%20you%20have%20on-prem%20Active%20Directory%2C%20it%20would%20be%20easier%20for%20you%20to%20set%20up%20Azure%20AD%20Connect%20and%20sync%20the%20users%20that%20way.%20If%20you%20don't%20set%20up%20AD%20FS%2C%20you%20would%20log%20in%20the%20same%20way%20as%20if%20the%20users%20were%20created%20directly%20in%20the%20cloud.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThen%20you%20could%20later%20set%20up%20AD%20FS%20and%20reap%20all%20the%20benefits%20from%20that.%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIt's%20completely%20feasible%20to%20create%20the%20users%20directly%20in%20Office%20365%2C%20then%20synchronize%20the%20users%20and%20set%20up%20AD%20FS%20but%20it's%20much%20easier%20to%20just%20start%20off%20with%20Azure%20AD%20Connect%20in%20the%20first%20place.%3C%2FP%3E%3C%2FLINGO-BODY%3E
New Contributor

Hello,

 

If you start a new full-cloud O365 tenant with Azure AD and Azure ADDS using just the Cloud Identity authentication model, can you later upgrade to using ADFS for authentication?

 

https://docs.microsoft.com/en-us/office365/enterprise/plan-for-directory-synchronization#office-365-...

 

Thank you in advance!

 

Phillip Toynton

 

 

5 Replies

If you have on-prem Active Directory, it would be easier for you to set up Azure AD Connect and sync the users that way. If you don't set up AD FS, you would log in the same way as if the users were created directly in the cloud.

 

Then you could later set up AD FS and reap all the benefits from that. 

 

It's completely feasible to create the users directly in Office 365, then synchronize the users and set up AD FS but it's much easier to just start off with Azure AD Connect in the first place.

Hi Robert,

 

Thank you for the reply.  We're actually planning on moving away from a hybrid environment and we're actively working on not having any on-prem AD servers in-house.

 

We've been in a hybrid environment for over 4 years and our business model has never needed and/or wanted to use the SSO capabilities with ADFS authentication model. 

 

What I want to know is IF we go to full O365 cloud and use Azure to ONLY host a newly created DC (and a fault tolerance DC), and use Cloud Identity for authentication, can we later (6 months? a year? 5 years?) add ADFS, AD Sync and AD Connect?  There is a strong desire to simplify our infrastructure.

 

Phil

Any users created on-prem will be deleted in Azure AD if you stop the sync from AD.

You can set up your servers in Azure, but before removing anything on-prem you need to migrate the PDC to a DC in Azure and set up a new AAD Connect there.

Hi Robert,

 

Again - thank you so much for responding.

 

"Any users created on-prem will be deleted in Azure AD if you stop the sync from AD."

 

But what if I first import them into a O365 environment?

 

We're looking to create a new PDC in Azure (with another for fault tolerance).  My understanding is that if we don't need SSO, we don't have to setup the AD sync / AD Connect or the ADFS farm.  We can just use Cloud Identity to manage our users.

 

Is this not true?

 

Thank you,

 

Phil

Sorry, I might have misspoken. I never had to do this and last time I checked, most people said that it was impossible to break the AD Sync without deleting users but according to this article you can stop the AD Connect synchronization and then you would be able to manage users in Azure AD alone.

https://support.microsoft.com/en-us/help/2619062/you-can-t-manage-or-remove-objects-that-were-synchr...

Fair warning; I have never tried this method before so I'm not 100% sure about the outcome. According to how I read that article you should be able to connect to Azure AD and say that it shouldn't use sync from on-prem and thus be able to edit users previously synchronized.

Thank you for the question, I'm here to learn new things as well as help and this definitely helped me.