AD Connect Enterprise Sync, Multiple Forests, Single Azure Tenant.

%3CLINGO-SUB%20id%3D%22lingo-sub-860212%22%20slang%3D%22en-US%22%3EAD%20Connect%20Enterprise%20Sync%2C%20Multiple%20Forests%2C%20Single%20Azure%20Tenant.%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-860212%22%20slang%3D%22en-US%22%3E%3CP%3EHey%20Guys%2C%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EQuick%20question%20here.%20If%20we%20have%20the%20following%3A%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E1)%20Multiple%20AD%20Forests%2C%20Multiple%20Domains%20(in%20each%20forest)%26nbsp%3B%3C%2FP%3E%3CP%3E2)%20Single%20Azure%20Tenant%2C%20want%20to%20sync%20objects%20from%20each%20of%20forest%3C%2FP%3E%3CP%3E3)%20Single%20Instance%20of%20AD%20Connect%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThis%20portion%20of%20this%20document%3A%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Factive-directory%2Fhybrid%2Fplan-connect-topologies%23multiple-forests-full-mesh-with-optional-galsync%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Factive-directory%2Fhybrid%2Fplan-connect-topologies%23multiple-forests-full-mesh-with-optional-galsync%3C%2FA%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%3EWhen%20you%20have%20%3CSTRONG%3Emultiple%20forests%3C%2FSTRONG%3E%2C%20all%20forests%20must%20be%20reachable%20by%20a%20single%20Azure%20AD%20Connect%20sync%20server.%20%3CSTRONG%3EThe%20server%20must%20be%20joined%20to%20a%20domain%3C%2FSTRONG%3E.%20If%20necessary%20to%20reach%20all%20forests%2C%20you%20can%20place%20the%20server%20in%20a%20perimeter%20network%20(also%20known%20as%20DMZ%2C%20demilitarized%20zone%2C%20and%20screened%20subnet).%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%3EI%20really%20want%26nbsp%3Bto%20make%20sure%20i%20understand%20that%2C%20am%20I%20supposed%20to%20join%20the%20the%20AD%20Connect%20Server%20to%20a%20single%20forest%2Fdomain%20and%20then%20add%20the%20other%20forests%20when%20i%20am%20doing%20my%20custom%20configuration%3F%20if%20so%20which%20forest%3F%26nbsp%3B%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%3EI%20was%20always%20under%20the%20impression%26nbsp%3Bthat%20when%20connecting%20to%20multiple%20AD%20forests%2C%20you%20should%20NOT%20join%20the%20AD%20Connect%20server%20to%20ANY%20domain%20and%20just%20add%20the%20other%20forests%2C%20domains%20as%20needed%2C%20using%20their%20respective%20credentials.%26nbsp%3B%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%3EThanks%2C%26nbsp%3B%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%3ERobert%26nbsp%3B%3C%2FSPAN%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-860212%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EExchange%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EHybrid%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EOffice%20365%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-985101%22%20slang%3D%22en-US%22%3ERe%3A%20AD%20Connect%20Enterprise%20Sync%2C%20Multiple%20Forests%2C%20Single%20Azure%20Tenant.%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-985101%22%20slang%3D%22en-US%22%3Etry%20that%20%3CA%20href%3D%22https%3A%2F%2Fwww.day-one.us%2F%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fwww.day-one.us%2F%3C%2FA%3E%3CBR%20%2F%3E%3C%2FLINGO-BODY%3E
Highlighted
Frequent Contributor

Hey Guys, 

 

Quick question here. If we have the following: 

 

1) Multiple AD Forests, Multiple Domains (in each forest) 

2) Single Azure Tenant, want to sync objects from each of forest

3) Single Instance of AD Connect

 

This portion of this document: https://docs.microsoft.com/en-us/azure/active-directory/hybrid/plan-connect-topologies#multiple-fore...

 

When you have multiple forests, all forests must be reachable by a single Azure AD Connect sync server. The server must be joined to a domain. If necessary to reach all forests, you can place the server in a perimeter network (also known as DMZ, demilitarized zone, and screened subnet).

 

I really want to make sure i understand that, am I supposed to join the the AD Connect Server to a single forest/domain and then add the other forests when i am doing my custom configuration? if so which forest? 

 

I was always under the impression that when connecting to multiple AD forests, you should NOT join the AD Connect server to ANY domain and just add the other forests, domains as needed, using their respective credentials. 

 

Thanks, 

 

Robert 

0 Replies