SRV record conflict between on-prem SfB server and Teams

%3CLINGO-SUB%20id%3D%22lingo-sub-1641222%22%20slang%3D%22en-US%22%3ESRV%20record%20conflict%20between%20on-prem%20SfB%20server%20and%20Teams%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1641222%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20Community%2C%3C%2FP%3E%3CP%3EOne%20of%20our%20customer%20currently%20has%20Teams%20tenant%20and%20the%20required%20DNS%20records%20in%20Public%20DNS.%20But%20there%20are%20some%20higher%20officials%20accounts%20requires%20on-prem%20SfB%20server%20for%20security%20reasons.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ECustomer%20would%20like%20to%20enable%20SRV%20records%20in%20on-prem%20for%20automatic%20sign%20in%2C%20external%20sign%20in%20etc.%20They%20don't%20want%20to%20create%20hybrid%20deployment.%3C%2FP%3E%3CP%3EThe%20reason%20is%20we%20need%20create%20the%20SRV%20record%2C%20_sipfederationtls_tcp.contoso.com%20pointing%20to%20on-prem%20Access%20edge%20for%20external%20signin.%3C%2FP%3E%3CP%3ESimilarly%20we%20need%20to%20create%20the%20SRV%20record%20for%20online%20Teams%20signin%20pointing%20to%20sipfed.lync.online.com%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EQuestions%3A%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E1.Is%20there%20any%20conflict%20on%20SRV%20records%20required%20for%20on-prem%20external%2C%20automatic%20sign%20in%20and%20Teams%20users%20sign%20in%20%3F%20(Because%20we%20don't%20have%20hybrid%20deployment%20but%20the%20domain%20is%20same%20for%20on-prem%20and%20online%2C%20but%20there%20is%20no%20hybrid%2C%20split%20domain%2C%26nbsp%3B%20for%20example%20Contoso.com)%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E2.%20Will%20public%20DNS%20accept%20two%20similar%20entries%20(_sipfederationtls)%20one%20for%20on-prem%20and%20another%20one%20for%20Teams%20tenant%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAny%20guidance%20would%20be%20of%20help.%20Many%20thanks!%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-1641222%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3ESRV%20record%20conflict%20between%20on-prem%20SfB%20server%20and%20Teams%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1641626%22%20slang%3D%22en-US%22%3ERe%3A%20SRV%20record%20conflict%20between%20on-prem%20SfB%20server%20and%20Teams%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1641626%22%20slang%3D%22en-US%22%3E%3CP%3EHi%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F301435%22%20target%3D%22_blank%22%3E%40Newlife%3C%2FA%3E%26nbsp%3B%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ENot%20a%20direct%20answer%20to%20your%20specific%20query%20but%20I%20am%20concerned%20by%20the%20reason%20of%20using%20SfB%20on%20prem%20over%20Teams.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20would%20argue%20that%20Microsoft%20would%20be%20able%20to%20secure%20any%20infrastructure%20better%20than%20any%20single%20business%20but%20that%20is%20subjective%20I%20suppose.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EBack%20to%20the%20DNS%20point%2C%20I%20can%20only%20recommend%20that%20you%20follow%20official%20Microsoft%20guidance.%20As%20to%20be%20honest%20if%20you%20are%20wanting%20to%20make%20use%20of%20On%20Prem%20and%20Cloud%20technologies%20that%20is%20100%25%20the%20reason%20for%20Hybrid%20deployment%20options%20and%20to%20do%20otherwise%2C%20working%20or%20not%2C%20is%20going%20to%20probably%20be%20unsupported%20and%20a%20big%20business%20risk%20because%20of%20it.%3CBR%20%2F%3E%3CBR%20%2F%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fskypeforbusiness%2Fplan-your-deployment%2Fnetwork-requirements%2Fdns%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fskypeforbusiness%2Fplan-your-deployment%2Fnetwork-requirements%2Fdns%3C%2FA%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThanks%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EHenry%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E
Highlighted
Frequent Contributor

Hi Community,

One of our customer currently has Teams tenant and the required DNS records in Public DNS. But there are some higher officials accounts requires on-prem SfB server for security reasons.

 

Customer would like to enable SRV records in on-prem for automatic sign in, external sign in etc. They don't want to create hybrid deployment.

The reason is we need create the SRV record, _sipfederationtls_tcp.contoso.com pointing to on-prem Access edge for external signin.

Similarly we need to create the SRV record for online Teams signin pointing to sipfed.lync.online.com

 

Questions:

 

1.Is there any conflict on SRV records required for on-prem external, automatic sign in and Teams users sign in ? (Because we don't have hybrid deployment but the domain is same for on-prem and online, but there is no hybrid, split domain,  for example Contoso.com)

 

2. Will public DNS accept two similar entries (_sipfederationtls) one for on-prem and another one for Teams tenant?

 

Any guidance would be of help. Many thanks!

 

1 Reply
Highlighted

Hi @Newlife ,

 

Not a direct answer to your specific query but I am concerned by the reason of using SfB on prem over Teams.

 

I would argue that Microsoft would be able to secure any infrastructure better than any single business but that is subjective I suppose.

 

Back to the DNS point, I can only recommend that you follow official Microsoft guidance. As to be honest if you are wanting to make use of On Prem and Cloud technologies that is 100% the reason for Hybrid deployment options and to do otherwise, working or not, is going to probably be unsupported and a big business risk because of it.

https://docs.microsoft.com/en-us/skypeforbusiness/plan-your-deployment/network-requirements/dns

 

Thanks

 

Henry