%3CLINGO-SUB%20id%3D%22lingo-sub-1286005%22%20slang%3D%22en-US%22%3EIntroduction%20to%20Building%20a%20Replica%20Domain%20Controller%20ARM%20Template%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1286005%22%20slang%3D%22en-US%22%3E%3CP%3EThe%20idea%20behind%20this%20blog%20series%20came%20after%20something%20I%20noticed%20Microsoft%20does%20not%20have%20from%20an%20artifact%20perspective.%20Microsoft%20talks%20a%20lot%20about%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fdevops%2Flearn%2Fwhat-is-infrastructure-as-code%3FWT.mc_id%3DITOPSTALK-blog-shkuehn%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noopener%20noreferrer%20noopener%20noreferrer%22%3Einfrastructure%20as%20code%3C%2FA%3E%20by%20using%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fazure-resource-manager%2Ftemplates%2Foverview%3FWT.mc_id%3DITOPSTALK-blog-shkuehn%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noopener%20noreferrer%20noopener%20noreferrer%22%3EARM%20Templates%3C%2FA%3E.%20ARM%20Templates%20make%20cloud%20deployments%20declarative%2C%20idempotent%2C%20and%20add%20increased%20agility%20related%20to%20the%20speed%20of%20provisioning%20resources%20in%20Azure.%20Declarative%20deployments%20scale%20significantly%20better%2C%20versus%20leaning%20on%20manual%20configurations%20or%20running%20a%20series%20of%20scripts.%20Microsoft%20maintains%20an%20%3CA%20href%3D%22https%3A%2F%2Fgithub.com%2FAzure%2Fazure-quickstart-templates%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noopener%20noreferrer%20noopener%20noreferrer%22%3EAzure%20Quickstarts%20Repo%3C%2FA%3E%20on%20GitHub%20that%20provides%20a%20lot%20of%20starter%20ARM%20Template%20code%20to%20familiarize%20yourself%20with%20how%20these%20configuration%20files%20are%20structured.%20Additionally%2C%20Microsoft%20authored%20%3CA%20href%3D%22http%3A%2F%2Fdownload.microsoft.com%2Fdownload%2F8%2FE%2F1%2F8E1DBEFA-CECE-4DC9-A813-93520A5D7CFE%2FWorld%2520Class%2520ARM%2520Templates%2520-%2520Considerations%2520and%2520Proven%2520Practices.pdf%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noopener%20noreferrer%20noopener%20noreferrer%22%3EWorld%20Class%20ARM%20Templates%3C%2FA%3E%2C%20provides%20a%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fazure-resource-manager%2Ftemplates%2Ftemplate-best-practices%3FWT.mc_id%3DITOPSTALK-blog-shkuehn%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ebest%20practices%3C%2FA%3E%20guide%2C%20plus%20an%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Ftemplates%3FWT.mc_id%3DITOPSTALK-blog-shkuehn%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noopener%20noreferrer%20noopener%20noreferrer%22%3EARM%20Template%20reference%3C%2FA%3E.%20Within%20the%20Quickstarts%20Repo%2C%20there%20are%20a%20few%20templates%20that%20surround%20Active%20Directory%20Domain%20Services%20(ADDS)%2C%20however%20they%20focus%20on%20building%20brand%20new%20forests%20and%20domains%20vs.%20customers%20attempting%20to%20extend%20their%20existing%20ADDS%20environment%20into%20Azure.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EBefore%20we%20get%20too%20ahead%20of%20ourselves%2C%20let%20us%20take%20a%20quick%20step%20back%20and%20set%20the%20stage.%20As%20cloud%20adoption%20grows%2C%20many%20enterprises%20are%20faced%20with%20embarking%20upon%20a%20digital%20transformation%20journey%20that%20may%20feel%20a%20bit%20uncomfortable%20and%20overwhelming%20as%20many%20decisions%20need%20to%20be%20made.%20Microsoft%20now%20provides%20a%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fcloud-adoption-framework%3FWT.mc_id%3DITOPSTALK-blog-shkuehn%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noopener%20noreferrer%20noopener%20noreferrer%22%3ECloud%20Adoption%20Framework%3C%2FA%3E%20that%20equips%20customers%20with%20a%20set%20of%20tools%2C%20guidance%2C%20and%20best%20practices%20that%20will%20prove%20helpful%20in%20ensuring%20continued%20success%20as%20more%20workloads%20adopt%20a%20cloud%20first%20mindset.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3ESome%20of%20the%20first%20design%20considerations%20that%20need%20to%20be%20solved%20for%20surround%20hybrid%20connectivity%20and%20identity.%20For%20hybrid%20network%20connectivity%2C%20customers%20can%20either%20choose%20to%20deploy%20a%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fvpn-gateway%3FWT.mc_id%3DITOPSTALK-blog-shkuehn%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noopener%20noreferrer%20noopener%20noreferrer%22%3ESite-to-Site%20VPN%3C%2FA%3E%20or%20procure%20and%20set%20up%20an%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fexpressroute%3FWT.mc_id%3DITOPSTALK-blog-shkuehn%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noopener%20noreferrer%20noopener%20noreferrer%22%3EExpressRoute%3C%2FA%3E%20connection.%20For%20purposes%20of%20this%20blog%20series%2C%20I%20will%20encourage%20readers%20to%20explore%20the%20topic%20of%20hybrid%20network%20connectivity%20separately%2C%20as%20the%20rest%20of%20these%20posts%20will%20surround%20extending%20ADDS%20into%20Azure.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EHistorically%2C%20companies%20have%20spent%20a%20great%20deal%20of%20time%20and%20effort%2C%20both%20in%20building%20and%20maintaining%20traditional%20ADDS%20environments%20on-premises.%20With%20customers%20I%20have%20worked%20with%20previously%2C%20the%20topic%20of%20identity%20tends%20to%20become%20a%20trickier%20conversation%20when%20first%20brought%20up.%20There%20are%20several%20design%20considerations%20companies%20made%20many%20years%20ago%20using%20various%20iterations%20of%20Microsoft%20best%20practices%20regarding%20topics%20like%20the%20domain%20to%20forest%20ratio%2C%20resource%20forests%2C%20which%20forests%20trusted%20one%20another%2C%20the%20type%20of%20trusts%20for%20best%20security%2C%20etc.%2C%20etc.%20Extending%20the%20domain%20space%20into%20Azure%20usually%20is%20not%20an%20easy%20conversation%20for%20companies%20that%20may%20have%20multiple%20forests%2C%20multiple%20one-way%20trusts%2C%20and%20identities%20split%20in%20between%20a%20few%20different%20domains%2C%20which%20tends%20to%20happen%20during%20something%20like%20merger%20and%20acquisition%20activities.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EDetermined%20to%20build%20something%20that%20someone%20could%20plug%20and%20play%20into%20their%20environment%20quickly%20vs.%20manually%20configuring%20domain%20controllers%20in%20Azure%20using%20the%20Azure%20Resource%20Manager%20(ARM)%20portal%2C%20I%20set%20off%20to%20create%20an%20ARM%20Template%20that%20deploys%20the%20following%20architecture%3A%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CUL%3E%0A%3CLI%3E(2)%20Windows%20Server%202019%20Datacenter%20VMs%20in%20an%20Availability%20Set%20(note%2C%20the%20OS%20version%20can%20be%20adjusted%20to%20meet%20your%20organization's%20needs)%3CUL%3E%0A%3CLI%3EThe%20OS%20and%20ephemeral%20disks%20get%20installed%20by%20default%3C%2FLI%3E%0A%3C%2FUL%3E%0A%3C%2FLI%3E%0A%3CLI%3EA%20non-cached%20data%20disk%20is%20added%20for%20SYSVOL%3C%2FLI%3E%0A%3C%2FUL%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EWe%20will%20be%20unpacking%20the%20replica%20domain%20controller%20build%20in%20this%20series%20over%20the%20next%20handful%20of%20weeks.%20Due%20to%20the%20deployment%20complexity%2C%20breaking%20this%20up%20into%20manageable%20chunks%20seemed%20like%20the%20most%20viable%20option%20for%20full%20understanding.%20So%2C%20tune%20in%20next%20time%20as%20I%20identify%20all%20pre-requisites%20that%20need%20to%20be%20met%20prior%20to%20deployment.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-TEASER%20id%3D%22lingo-teaser-1286005%22%20slang%3D%22en-US%22%3E%3CP%3EMost%20enterprises%20extend%20Active%20Directory%20Domain%20Services%20into%20Azure%20vs.%20building%20a%20brand%20new%20forest%20and%20domain(s).%20Microsoft%20provides%20a%20lot%20of%20guidance%20on%20design%20considerations%20to%20achieve%20this%20end%20result%20architecturally%2C%20however%20there%20does%20not%20seem%20to%20be%20an%20ARM%20Template%20that%20deploys%20replica%20domain%20controllers%20in%20any%20of%20the%20Microsoft%20or%20community%20lead%20GitHub%20repositories.%20This%20blog%20series%20will%20walk%20through%20standing%20up%202%20replica%20domain%20controllers%20in%20Azure%20using%20an%20ARM%20Template.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20image-alt%3D%22azure-resource-manager-export-deploy-template-portal-Shannon-Kuehn.png%22%20style%3D%22width%3A%20367px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F182518iF07838B6B306082E%2Fimage-size%2Flarge%3Fv%3D1.0%26amp%3Bpx%3D999%22%20title%3D%22azure-resource-manager-export-deploy-template-portal-Shannon-Kuehn.png%22%20alt%3D%22azure-resource-manager-export-deploy-template-portal-Shannon-Kuehn%22%20%2F%3E%3CSPAN%20class%3D%22lia-inline-image-caption%22%20onclick%3D%22event.preventDefault()%3B%22%3Eazure-resource-manager-export-deploy-template-portal-Shannon-Kuehn%3C%2FSPAN%3E%3C%2FSPAN%3E%3C%2FP%3E%3C%2FLINGO-TEASER%3E%3CLINGO-LABS%20id%3D%22lingo-labs-1286005%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EAzure%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EShannon%20Kuehn%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EWindows%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EWindows%20Server%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E
Microsoft

The idea behind this blog series came after something I noticed Microsoft does not have from an artifact perspective. Microsoft talks a lot about infrastructure as code by using ARM Templates. ARM Templates make cloud deployments declarative, idempotent, and add increased agility related to the speed of provisioning resources in Azure. Declarative deployments scale significantly better, versus leaning on manual configurations or running a series of scripts. Microsoft maintains an Azure Quickstarts Repo on GitHub that provides a lot of starter ARM Template code to familiarize yourself with how these configuration files are structured. Additionally, Microsoft authored World Class ARM Templates, provides a best practices guide, plus an ARM Template reference. Within the Quickstarts Repo, there are a few templates that surround Active Directory Domain Services (ADDS), however they focus on building brand new forests and domains vs. customers attempting to extend their existing ADDS environment into Azure.

 

Before we get too ahead of ourselves, let us take a quick step back and set the stage. As cloud adoption grows, many enterprises are faced with embarking upon a digital transformation journey that may feel a bit uncomfortable and overwhelming as many decisions need to be made. Microsoft now provides a Cloud Adoption Framework that equips customers with a set of tools, guidance, and best practices that will prove helpful in ensuring continued success as more workloads adopt a cloud first mindset.

 

Some of the first design considerations that need to be solved for surround hybrid connectivity and identity. For hybrid network connectivity, customers can either choose to deploy a Site-to-Site VPN or procure and set up an ExpressRoute connection. For purposes of this blog series, I will encourage readers to explore the topic of hybrid network connectivity separately, as the rest of these posts will surround extending ADDS into Azure.

 

Historically, companies have spent a great deal of time and effort, both in building and maintaining traditional ADDS environments on-premises. With customers I have worked with previously, the topic of identity tends to become a trickier conversation when first brought up. There are several design considerations companies made many years ago using various iterations of Microsoft best practices regarding topics like the domain to forest ratio, resource forests, which forests trusted one another, the type of trusts for best security, etc., etc. Extending the domain space into Azure usually is not an easy conversation for companies that may have multiple forests, multiple one-way trusts, and identities split in between a few different domains, which tends to happen during something like merger and acquisition activities.

 

Determined to build something that someone could plug and play into their environment quickly vs. manually configuring domain controllers in Azure using the Azure Resource Manager (ARM) portal, I set off to create an ARM Template that deploys the following architecture:

 

  • (2) Windows Server 2019 Datacenter VMs in an Availability Set (note, the OS version can be adjusted to meet your organization's needs)
    • The OS and ephemeral disks get installed by default
  • A non-cached data disk is added for SYSVOL

 

We will be unpacking the replica domain controller build in this series over the next handful of weeks. Due to the deployment complexity, breaking this up into manageable chunks seemed like the most viable option for full understanding. So, tune in next time as I identify all pre-requisites that need to be met prior to deployment.