Forum Discussion

DerrickFl's avatar
DerrickFl
Copper Contributor
Aug 01, 2017

Azure Active Directory Domain Services On -premises workstation Join

Hello, Just a quick one, I know this might not be something new but was wondering if anyone can help.   Scenario:   Company A is a start up company who wants a cloud only infrastructure with Offi...
  • Josh Villagomez's avatar
    Aug 02, 2017

    Hello Gian,

     

    Microsoft is trying to help customers simplify their cloud networks by building more services in the cloud. Before AAD DS, many customers used to build AD DS VMs on Azure in order to provide LDAP/Kerberos, etc., authentication for specific requirements. So, MS has simplified this by implementing AAD DS, meaning you get two IP DNS sources that are, in effect, AD DS VMs unmanaged by you. This is desgined devices that are on your Azure virtual network. This being said, for on-premises devices to authenticate to AAD DS, you must have a point-to-point VPN tunnel and point the local devices to your AAD DS DNS ips. But you should have a reliable network connection. As for AAD Connect (formerly DirSync), thats required for local AD DS synchronization to your AAD. Given that you prefer not having any local server resources, this would not apply in your case. Hope this helps.

Resources