SOLVED
Home

Mix Password Sync and ADFS - multiple Forests

%3CLINGO-SUB%20id%3D%22lingo-sub-126212%22%20slang%3D%22en-US%22%3EMix%20Password%20Sync%20and%20ADFS%20-%20multiple%20Forests%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-126212%22%20slang%3D%22en-US%22%3E%3CP%3EHi%2C%3C%2FP%3E%3CP%3Ewe%20have%20an%20Office%20365%20tenant%20configured%20with%26nbsp%3BPassword%20Sync%20and%20Single%20Sign%20On%20enabled%2C%20which%20works%20fine.%3C%2FP%3E%3CP%3ENow%20we%20want%20to%20integrate%20a%20child%20company%20with%20a%20new%20forest%20which%20should%20work%20with%20AD%20Connect.%20The%20child%20company%20is%20already%20having%20an%20Office%20365%20with%20ADFS%20enabled.%3C%2FP%3E%3CP%3ESo%20now%20my%20question%20is%2C%20when%20I%20add%20the%20new%20forest%20to%20our%20AD%20Connect%20server%2C%20could%20I%20configure%20the%20different%20domain%20to%20work%20with%20existing%20ADFS%20infrastructure%20and%20leave%20our%20domain%20on%20Password%20sync%20configured%3F%3C%2FP%3E%3CP%3EThanks%2C%3C%2FP%3E%3CP%3EMichael%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-126212%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EAD%20Connect%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3Eadfs%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EAuthentication%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EIdentity%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EOffice%20365%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-126506%22%20slang%3D%22en-US%22%3ERe%3A%20Mix%20Password%20Sync%20and%20ADFS%20-%20multiple%20Forests%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-126506%22%20slang%3D%22en-US%22%3E%3CP%3EThanks%20Joe%2C%20that%20was%20the%20response%20I%20was%20looking%20for.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EMichael%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-126469%22%20slang%3D%22en-US%22%3ERe%3A%20Mix%20Password%20Sync%20and%20ADFS%20-%20multiple%20Forests%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-126469%22%20slang%3D%22en-US%22%3E%3CBLOCKQUOTE%3E%3CHR%20%2F%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F93886%22%20target%3D%22_blank%22%3E%40Michael%20Obernberger%3C%2FA%3E%20wrote%3A%3CBR%20%2F%3E%3CP%3E%22The%20child%20company%20is%20already%20having%20an%20Office%20365%20with%20ADFS%20enabled%22%3C%2FP%3E%3CP%3E%22So%20now%20my%20question%20is%2C%20when%20I%20add%20the%20new%20forest%20to%20our%20AD%20Connect%20server...%22%3C%2FP%3E%3CHR%20%2F%3E%3C%2FBLOCKQUOTE%3E%3CP%3EStop%20right%20there%20%3D)%3C%2Fimg%3E%26nbsp%3B%20If%20the%20new%20company%20you%20acquired%20or%20have%20already%20has%20their%20own%20separate%20AD%20Tenant%2C%20you%20cannot%20add%20their%20forest%20into%20your%20Azure%20AD%20Connect.%20That%20is%20an%20unsupported%20Azure%20AD%20Connect%20topology.%20See%20this%20article%20for%20more%20information%3A%3C%2FP%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Factive-directory%2Fconnect%2Factive-directory-aadconnect-topologies%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Factive-directory%2Fconnect%2Factive-directory-aadconnect-topologies%3C%2FA%3E%3C%2FP%3E%3CP%3EHowever%2C%20once%20you%20remove%20all%20their%20user%20objects%20from%20their%20O365%20tenant%2C%20and%20you%20remove%20their%20domain%20name%20from%20their%20tenant%20and%20move%20it%20to%20your%20tenant%2C%20THEN%2C%20and%20only%20then%2C%20can%20you%20accomplish%20what%20you%20were%20hoping%20for%20..%20YES%2C%20you%20can%20federate%20their%20domain%20name%20with%20their%20existing%20ADFS%20forest%2C%20pointing%20all%20that%20to%20your%20tenant.%3C%2FP%3E%3CP%3EIf%20you%20have%20not%20done%20this%20before%2C%20you%20should%20work%20with%20a%20Microsoft%20Partner%20to%20help%20you.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E
Highlighted
Michael Obernberger
Occasional Contributor

Hi,

we have an Office 365 tenant configured with Password Sync and Single Sign On enabled, which works fine.

Now we want to integrate a child company with a new forest which should work with AD Connect. The child company is already having an Office 365 with ADFS enabled.

So now my question is, when I add the new forest to our AD Connect server, could I configure the different domain to work with existing ADFS infrastructure and leave our domain on Password sync configured?

Thanks,

Michael

2 Replies
Highlighted
Solution

@Michael Obernberger wrote:

"The child company is already having an Office 365 with ADFS enabled"

"So now my question is, when I add the new forest to our AD Connect server..."


Stop right there =)  If the new company you acquired or have already has their own separate AD Tenant, you cannot add their forest into your Azure AD Connect. That is an unsupported Azure AD Connect topology. See this article for more information:

https://docs.microsoft.com/en-us/azure/active-directory/connect/active-directory-aadconnect-topologi...

However, once you remove all their user objects from their O365 tenant, and you remove their domain name from their tenant and move it to your tenant, THEN, and only then, can you accomplish what you were hoping for .. YES, you can federate their domain name with their existing ADFS forest, pointing all that to your tenant.

If you have not done this before, you should work with a Microsoft Partner to help you.

 

Highlighted

Thanks Joe, that was the response I was looking for.

 

Michael

Related Conversations