Starting a new On Premise organization to connect Office 365 - Recommendations

%3CLINGO-SUB%20id%3D%22lingo-sub-638059%22%20slang%3D%22en-US%22%3EStarting%20a%20new%20On%20Premise%20organization%20to%20connect%20Office%20365%20-%20Recommendations%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-638059%22%20slang%3D%22en-US%22%3E%3CP%3EHi!%3C%2FP%3E%3CP%3EWe%20have%20a%20Active%20Directory%20forest%20and%20we%20are%20using%20Office%20365%20but%20our%20domain%20is%20not%20connected%2Fsynced.%20But%20now%20we%20need%20to%20move%20some%20of%20our%20users%20to%20a%20all%20new%20domain.%20So%2C%20as%20we%20are%20going%20to%20install%20a%20new%20forest%2C%20new%20DNS%20name...%20and%20then%20sync%20this%20forest%20to%20Office%20365%2C%20it's%20a%20great%20moment%20to%20do%20it%20in%20the%20best%20possible%20way.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EOur%20most%20important%20question%20is%3A%20split-dns%20or%20not%3F%20%3A)%3C%2Fimg%3E%3C%2FP%3E%3CP%3EWe%20read%20Microsoft%20recommendation%20about%20not%20to%20use%20split-dns%20and%20for%20internal%20network%20use%20a%20subdomain%20of%20the%20public%20domain%20(%3CA%20href%3D%22https%3A%2F%2Fsocial.technet.microsoft.com%2Fwiki%2Fcontents%2Farticles%2F34981.active-directory-best-practices-for-internal-domain-and-network-names.aspx%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fsocial.technet.microsoft.com%2Fwiki%2Fcontents%2Farticles%2F34981.active-directory-best-practices-for-internal-domain-and-network-names.aspx%3C%2FA%3E)%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWhat%20do%20you%20recommend%20to%20do%3F%20Is%20there%20an%20official%20recommendation%20about%20that%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThanks!%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-638059%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EOffice%20365%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EOn-Premises%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-638534%22%20slang%3D%22en-US%22%3ERe%3A%20Starting%20a%20new%20On%20Premise%20organization%20to%20connect%20Office%20365%20-%20Recommendations%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-638534%22%20slang%3D%22en-US%22%3E%3CP%3EHaving%20no%20knowledge%20of%20your%20organization's%20structure%20and%20infrastructure%2C%20all%20we%20can%20do%20is%20repeat%20the%20general%20recommendations.%20Write%20down%20your%20specific%20requirements%20and%20concerns%2C%20then%20do%20some%20research%2C%20or%20hire%20a%20consultant%20to%20go%20over%20it%20with%20you.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EHow%20does%20this%20relate%20to%20O365%20btw%3F%20%3A)%3C%2Fimg%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-651327%22%20slang%3D%22en-US%22%3ERe%3A%20Starting%20a%20new%20On%20Premise%20organization%20to%20connect%20Office%20365%20-%20Recommendations%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-651327%22%20slang%3D%22en-US%22%3E%3CP%3EHi!%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ENow%20we%20are%20using%20a%20domain1.com%20for%20our%20enterprise.%20We%20are%20going%20to%20move%20some%20users%20and%20servers%20to%20a%20new%20domain%20(our%20enterprise%20is%20going%20to%20be%20separated%20in%20two).%20We%20use%20Office%20365%2C%20but%20we%20have%20not%20sync%20with%20our%20internal%20Active%20Directory.%20In%20our%20desktops%20use%20internal%20AD%20account%20to%20login.%20And%20we%20put%20credentials%20when%20outlook%20connects%20to%20Office365.%20Same%20for%20Onedrive%20and%20another%20products.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ESo%20we%20will%20install%20a%20domain2.com%2C%20new%20Active%20Directory%20forest%2C%20create%20forest%20trust%20between%20domain1.com%20and%20domain2.com%2C%20migrate%20users...%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAs%20we%20can%20do%20it%20all%20from%20the%20beginning%2C%20we%20want%20to%20ask%20if%20it's%20better%20to%20use%20DNS%20split%20or%20use%20domain2.com%20to%20external%20connections%20and%20some%20like%20domain2.int%20for%20internal%20users.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThanks!%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-651557%22%20slang%3D%22en-US%22%3ERe%3A%20Starting%20a%20new%20On%20Premise%20organization%20to%20connect%20Office%20365%20-%20Recommendations%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-651557%22%20slang%3D%22en-US%22%3E%3CP%3EI'm%20thinking%20more%20about%20this%20problem.%20I%20was%20forgetting%20a%20topic.%3CBR%20%2F%3EWe%20have%20a%20domain%20domain1.com%20now%20but%20for%20email%20and%20for%20Office365%20we%20have%20registered%20a%20domain%20newcompany.com%3CBR%20%2F%3ESo%20on%20the%20one%20hand%20we%20have%20a%20domain1.com%20in%20the%20internal%20Active%20Directory%20that%20is%20used%20to%20log%20on%20to%20the%20computers.%3CBR%20%2F%3EThe%20new%20domain%20would%20be%20called%20newcompany.com%2C%20with%20the%20Split%20DNS%20doubt.%3CBR%20%2F%3EBut%20now%20we%20are%20in%20doubt%3A%20in%20Office%20365%20we%20have%20created%20users%2C%20with%20the%20domain%20newcompany.com%3CBR%20%2F%3EWould%20it%20be%20a%20possibility%20to%20install%20domain%20controllers%20on%20premises%20that%20synchronize%20and%20those%20Office%20365%20users%3F%3CBR%20%2F%3EThank%20you!%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-652395%22%20slang%3D%22en-US%22%3ERe%3A%20Starting%20a%20new%20On%20Premise%20organization%20to%20connect%20Office%20365%20-%20Recommendations%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-652395%22%20slang%3D%22en-US%22%3E%3CP%3EReading%20more%20about%20the%20internal%20DNS%20name%20to%20use%2C%20now%20we've%20registered%20newcompany.com%20at%20Office365.%3C%2FP%3E%3CP%3EIf%20the%20recomendation%20is%20to%20put%20a%20subdomain%20as%20the%20internal%20forest%2C%20we%20can%20use%20internal.newdomain.com.%20We%20can%20deploy%20a%20new%20forest%20called%20internal.newdomain.com.%3C%2FP%3E%3CP%3EIs%20it%20a%20problem%20to%20sync%20with%20Office365%20or%20it's%20better%20to%20use%20newdomain.com%20in%20the%20new%20forest%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThanks!!%3C%2FP%3E%3C%2FLINGO-BODY%3E
Highlighted
Occasional Contributor

Hi!

We have a Active Directory forest and we are using Office 365 but our domain is not connected/synced. But now we need to move some of our users to a all new domain. So, as we are going to install a new forest, new DNS name... and then sync this forest to Office 365, it's a great moment to do it in the best possible way.

 

Our most important question is: split-dns or not? :)

We read Microsoft recommendation about not to use split-dns and for internal network use a subdomain of the public domain (https://social.technet.microsoft.com/wiki/contents/articles/34981.active-directory-best-practices-fo...)

 

What do you recommend to do? Is there an official recommendation about that?

 

Thanks!

4 Replies
Highlighted

Having no knowledge of your organization's structure and infrastructure, all we can do is repeat the general recommendations. Write down your specific requirements and concerns, then do some research, or hire a consultant to go over it with you.

 

How does this relate to O365 btw? :)

Highlighted

Hi!

 

Now we are using a domain1.com for our enterprise. We are going to move some users and servers to a new domain (our enterprise is going to be separated in two). We use Office 365, but we have not sync with our internal Active Directory. In our desktops use internal AD account to login. And we put credentials when outlook connects to Office365. Same for Onedrive and another products.

 

So we will install a domain2.com, new Active Directory forest, create forest trust between domain1.com and domain2.com, migrate users...

 

As we can do it all from the beginning, we want to ask if it's better to use DNS split or use domain2.com to external connections and some like domain2.int for internal users.

 

Thanks!

Highlighted

I'm thinking more about this problem. I was forgetting a topic.
We have a domain domain1.com now but for email and for Office365 we have registered a domain newcompany.com
So on the one hand we have a domain1.com in the internal Active Directory that is used to log on to the computers.
The new domain would be called newcompany.com, with the Split DNS doubt.
But now we are in doubt: in Office 365 we have created users, with the domain newcompany.com
Would it be a possibility to install domain controllers on premises that synchronize and those Office 365 users?
Thank you!

Highlighted

Reading more about the internal DNS name to use, now we've registered newcompany.com at Office365.

If the recomendation is to put a subdomain as the internal forest, we can use internal.newdomain.com. We can deploy a new forest called internal.newdomain.com.

Is it a problem to sync with Office365 or it's better to use newdomain.com in the new forest?

 

Thanks!!