Microsoft Azure AD Connect and on prem Exchange

%3CLINGO-SUB%20id%3D%22lingo-sub-2484211%22%20slang%3D%22de-DE%22%3EMicrosoft%20Azure%20AD%20Connect%20and%20on%20prem%20Exchange%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2484211%22%20slang%3D%22de-DE%22%3E%3CP%3EHi.%20At%20the%20moment%20we%20are%20using%20Azure%20AD%20Connect%20to%20sync%20our%20local%20AD%20users%20to%20the%20cloud.%3C%2FP%3E%3CP%3EWe%20also%20have%20an%20Exchange%20Server%202016%20Hybrid%20on%20prem%20Server.%20Additionally%20we%20use%20ADFS%20Servers%20for%20SSO.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAt%20the%20moment%20we%20are%20trying%20to%20figure%20out%2C%20if%20we%20still%20need%20this%20stuff%20on%20prem%3F%20Or%20if%20there%20is%20a%20better%20solution%20as%20Azure%20AD%20Connect%20%2F%20ADFS%20%3F%20Are%20there%20any%20alternatives%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIs%20ist%20still%20neccessary%20to%20use%20an%20on%20Prem%20Exchange%20%2F%20Azure%20AD%20Connect%3F%20Or%20is%20it%20just%20for%20some%20attributes%3F%20And%20if%20yes%20which%20attributes%20are%20these%3F%20Which%20ways%20are%20supported%20by%20Microsoft%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThank%20you%20for%20your%20help%20%3A)%3C%2Fimg%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E
New Contributor

Hi. At the moment we are using Azure AD Connect to sync our local AD users to the cloud.

We also have an Exchange Server 2016 Hybrid on prem Server. Additionally we use ADFS Servers for SSO.

 

At the moment we are trying to figure out, if we still need this stuff on prem? Or if there is a better solution as Azure AD Connect / ADFS ? Are there any alternatives?

 

Is ist still neccessary to use an on Prem Exchange / Azure AD Connect? Or is it just for some attributes? And if yes which attributes are these? Which ways are supported by Microsoft?

 

Thank you for your help :)

1 Reply
This is a big question, it depends.
M365 etc can all be Cloud-based.
You don't need ADFS if you migrate apps to Azure AD SSO - https://docs.microsoft.com/en-us/azure/active-directory/manage-apps/add-application-portal-setup-sso
If you have your users in Azure, you can look at Azure Directory Domain Services - https://azure.microsoft.com/en-us/services/active-directory-ds/
You can remove your Domain Controllers and go completely Cloud-based using Azure AD as the identities.. as long as your servers and applications all support it.

Its something you will need to work through, develop a plan for and test.