Setup ADConnect for private domain

%3CLINGO-SUB%20id%3D%22lingo-sub-1547430%22%20slang%3D%22en-US%22%3ESetup%20ADConnect%20for%20private%20domain%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1547430%22%20slang%3D%22en-US%22%3E%3CP%3EHello!%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIn%20our%20organization%20we%20are%20using%20private%20domain%20name%20(.local)%2C%20how%20I%20can%20setup%20this%20domain%20for%20ADConnect%3F%20I'll%20try%20to%20create%20Private%20DNS%20domain%20zone.%20But%20in%20additional%20domain%20names%20can't%20verify%20this%20domain%20name.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1547576%22%20slang%3D%22en-US%22%3ERe%3A%20Setup%20ADConnect%20for%20private%20domain%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1547576%22%20slang%3D%22en-US%22%3E%3CP%3EIf%20you%20have%20your%20own%20domain%2C%20you%20should%20first%20add%20it%20to%20the%20Azure%20Portal.%20Then%20you%20should%20adjust%20the%20local%20AD%2C%20namely%20the%20UPN%20of%20the%20users.%20If%20you%20do%20not%20have%20your%20own%20domain%2C%20you%20can%20easily%20install%20and%20set%20up%20Azure%20AD%20Connect.%20The%20accounts%20in%20Azure%20AD%20are%20then%20extended%20with%20the%20standard%20DNS%20suffix.%20For%20example%20firstname.lastname%40company.%3CSTRONG%3Eonmicrosoft.com%20%3C%2FSTRONG%3EThe%20last%20part%20from%20the%20UPN%20%22onmicrosoft.com%22%20are%20the%20standard%20DNS%20Suffix%20from%20Microsoft.%20Regards%20Tom%20Wechsler%3C%2FP%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F740846%22%20target%3D%22_blank%22%3E%40AlexeyUstalov%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1547636%22%20slang%3D%22en-US%22%3ERe%3A%20Setup%20ADConnect%20for%20private%20domain%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1547636%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F593067%22%20target%3D%22_blank%22%3E%40TomWechsler%3C%2FA%3E%26nbsp%3Bthank%20for%20answer.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EHow%20I%20can%20add%20my%20domain%20if%20his%20internal%20name%20(.local)%20and%20I%20can't%20verify%20them%3F%20I'll%20add%20our%20public%20domain%20name%2C%20but%20we%20are%20not%20using%20him.%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1547652%22%20slang%3D%22en-US%22%3ERe%3A%20Setup%20ADConnect%20for%20private%20domain%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1547652%22%20slang%3D%22en-US%22%3E%3CP%3EYou%20cannot%20add%2Fverify%20the%20local%20domain%20in%20the%20Azure%20Portal.%20You%20can%20set%20up%20Azure%20AD%20Connect%20without%20a%20verified%20domain.%20As%20mentioned%2C%20the%20accounts%20are%20then%20extended%20with%20the%20default%20DNS%20suffix%20from%20Microsoft.%3C%2FP%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F740846%22%20target%3D%22_blank%22%3E%40AlexeyUstalov%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1547667%22%20slang%3D%22en-US%22%3ERe%3A%20Setup%20ADConnect%20for%20private%20domain%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1547667%22%20slang%3D%22en-US%22%3EThank!%20One%20more%20question.%20I'll%20setup%20ADConnect%20and%20my%20first%20sync%20create%20all%20domain%20users%20on%20Azure%20Portal%2C%20after%20I'll%20set%20OU%20for%20sync%20and%20tried%20full%20sync%20but%20users%20still%20presents%20on%20Azure%20Portal%2C%20it's%20normal%20(timeout%20for%20removing)%3F%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1547782%22%20slang%3D%22en-US%22%3ERe%3A%20Setup%20ADConnect%20for%20private%20domain%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1547782%22%20slang%3D%22en-US%22%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIt%20was%20threshold%20limit%20%3A)%3C%2Fimg%3E%20thanks%20for%20answering%2C%20going%20to%20testing%20%3A)%3C%2Fimg%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E
Highlighted
New Contributor

Hello!

 

In our organization we are using private domain name (.local), how I can setup this domain for ADConnect? I'll try to create Private DNS domain zone. But in additional domain names can't verify this domain name.

6 Replies
Highlighted

If you have your own domain, you should first add it to the Azure Portal. Then you should adjust the local AD, namely the UPN of the users. If you do not have your own domain, you can easily install and set up Azure AD Connect. The accounts in Azure AD are then extended with the standard DNS suffix. For example firstname.lastname@company.onmicrosoft.com The last part from the UPN "onmicrosoft.com" are the standard DNS Suffix from Microsoft. Regards Tom Wechsler

@AlexeyUstalov 

Highlighted

@TomWechsler thank for answer.

 

How I can add my domain if his internal name (.local) and I can't verify them? I'll add our public domain name, but we are not using him. 

Highlighted

You cannot add/verify the local domain in the Azure Portal. You can set up Azure AD Connect without a verified domain. As mentioned, the accounts are then extended with the default DNS suffix from Microsoft.

@AlexeyUstalov 

Highlighted
Thank! One more question. I'll setup ADConnect and my first sync create all domain users on Azure Portal, after I'll set OU for sync and tried full sync but users still presents on Azure Portal, it's normal (timeout for removing)?
Highlighted

 

It was threshold limit :) thanks for answering, going to testing :)

 

Highlighted

It's a pleasure. Regards Tom Wechsler

@AlexeyUstalov