PTA single tenant two forest

%3CLINGO-SUB%20id%3D%22lingo-sub-1798790%22%20slang%3D%22en-US%22%3EPTA%20single%20tenant%20two%20forest%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1798790%22%20slang%3D%22en-US%22%3E%3CP%3EHi%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20have%20question%2C%20i%20have%20two%20forest%20contoso.com%20and%20fabrikam.com.%20I%20plan%20install%20Azure%20AD%20Connect%20on%20contoso.com%20and%20sync%20contoso%20and%20fabrikam%20user%20to%20cloud%20with%20single%20tenant.%20My%20question%20is%3C%2FP%3E%3COL%3E%3CLI%3ECan%20I%20use%20PTA%20and%20place%20PTA%20in%20two%20forest%20%3F%20if%20user%20login%20to%26nbsp%3B%40contoso.com%2C%20login%20will%20be%20handle%20by%20contoso%20PTA%20server%20and%20same%20with%20fabrikam.%20If%26nbsp%3Buser%20login%20to%26nbsp%3B%40fabrikam.com%2C%20login%20will%20be%20handle%20by%20fabrikam%20PTA%20server%3C%2FLI%3E%3CLI%3EIs%20there%20any%20related%20document%20that%20support%20my%20scenario%20%3F%3C%2FLI%3E%3C%2FOL%3E%3CP%3EThanks%3C%2FP%3E%3CP%3EIchwan%20Z%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-1798790%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EIdentity%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EOffice%20365%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3ESecurity%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2029918%22%20slang%3D%22en-US%22%3ERe%3A%20PTA%20single%20tenant%20two%20forest%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2029918%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20Ichwan%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EPer%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Factive-directory%2Fhybrid%2Fhow-to-connect-pta%3A%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Factive-directory%2Fhybrid%2Fhow-to-connect-pta%3A%3C%2FA%3E%3C%2FP%3E%3CUL%20class%3D%22lia-list-style-type-circle%22%3E%3CLI%3EMulti-forest%20environments%20are%20supported%20if%20there%20are%20forest%20trusts%20between%20your%20AD%20forests%20and%20if%20name%20suffix%20routing%20is%20correctly%20configured.%3C%2FLI%3E%3C%2FUL%3E%3CP%3EAlso%20per%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fbs-latn-ba%2FAzure%2Factive-directory%2Fhybrid%2Fplan-connect-topologies%23multiple-forests-single-azure-ad-tenant%3A%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fbs-latn-ba%2FAzure%2Factive-directory%2Fhybrid%2Fplan-connect-topologies%23multiple-forests-single-azure-ad-tenant%3A%3C%2FA%3E%3C%2FP%3E%3CUL%20class%3D%22lia-list-style-type-circle%22%3E%3CLI%3E%3CSPAN%3EWhen%20you%20have%20multiple%20forests%2C%20all%20forests%20must%20be%20reachable%20by%20a%20single%20Azure%20AD%20Connect%20sync%20server%3C%2FSPAN%3E%3C%2FLI%3E%3C%2FUL%3E%3C%2FLINGO-BODY%3E
Occasional Contributor

Hi,

 

I have question, i have two forest contoso.com and fabrikam.com. I plan install Azure AD Connect on contoso.com and sync contoso and fabrikam user to cloud with single tenant. My question is

  1. Can I use PTA and place PTA in two forest ? if user login to @contoso.com, login will be handle by contoso PTA server and same with fabrikam. If user login to @fabrikam.com, login will be handle by fabrikam PTA server
  2. Is there any related document that support my scenario ?

Thanks

Ichwan Z

1 Reply

Hi Ichwan,

 

Per https://docs.microsoft.com/en-us/azure/active-directory/hybrid/how-to-connect-pta:

  • Multi-forest environments are supported if there are forest trusts between your AD forests and if name suffix routing is correctly configured.

Also per https://docs.microsoft.com/bs-latn-ba/Azure/active-directory/hybrid/plan-connect-topologies#multiple...

  • When you have multiple forests, all forests must be reachable by a single Azure AD Connect sync server