WVD with just Azure AD

%3CLINGO-SUB%20id%3D%22lingo-sub-382799%22%20slang%3D%22en-US%22%3ERe%3A%20WVD%20with%20just%20Azure%20AD%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-382799%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F305908%22%20target%3D%22_blank%22%3E%40Paranoid69%3C%2FA%3E%20%3A%20Thank%20you%20for%20your%20feedback.%20That%20is%20the%20current%20requirement.%20We%20will%20be%20introducing%20shortly%20a%20UserVoice%20forum%20to%20collect%20feedback%20like%20this%20where%20community%20can%20share%20their%20votes.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-382639%22%20slang%3D%22en-US%22%3ERe%3A%20WVD%20with%20just%20Azure%20AD%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-382639%22%20slang%3D%22en-US%22%3E%3CP%3EYes%2C%20why%20do%20we%20need%20AD%3F%26nbsp%3B%20This%20is%20a%20cloud%20solution%20and%20perfect%20for%20SMBs.%26nbsp%3B%20I%20have%20been%20waiting%20for%20this%20service%20to%20come%20in%20Public%20Preview%20since%20we%20did%20not%20make%20it%20in%20the%20private%20one%20and%20got%20my%20email%20yesterday%20morning.%20Super%20excited%2C%20couldn't%20sign%20in%20fast%20enough%20to%20fire%20it%20up%20and%20test%20it%20out%20as%20we%20have%20had%20talks%20with%20customers%20about%20it.%26nbsp%3B%20Followed%20the%20documentation%20and%20then%20went%20to%20create%20my%20pool%20and%20my%20excitement%20just%20drained%20away%20when%20an%20AD%20UPN%20and%20vnet%20was%20required%20to%20continue.%26nbsp%3B%20What%20a%20let%20down.%26nbsp%3B%20Just%20like%20the%20let%20down%20of%20the%20new%20security%20and%20compliance%20offers%20that%20are%20only%20available%20if%20you%20have%20M365%20E3.%20Is%20anyone%20at%20Microsoft%20paying%20attention%20to%20SMBs%3F%26nbsp%3B%20These%20products%20are%20a%20huge%20sell%20for%20them%20and%20for%20the%20first%20time%20they%20are%20not%20overpriced.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-477207%22%20slang%3D%22en-US%22%3ERe%3A%20WVD%20with%20just%20Azure%20AD%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-477207%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20all%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWhat%20is%20prerequisite%20for%20WVD.%20Azure%20AD%20or%20Azure%20AD%20DS%3F%3C%2FP%3E%3CP%3EI%20didn't%20find%20information%20anywhere.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ERegards%2C%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-481412%22%20slang%3D%22en-US%22%3ERe%3A%20WVD%20with%20just%20Azure%20AD%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-481412%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F52144%22%20target%3D%22_blank%22%3E%40Vladimir%20Stefanovic%3C%2FA%3E%26nbsp%3B%3A%20The%20requirement%20is%3A%3C%2FP%3E%0A%3CP%3E-%20an%20Azure%20Active%20Directory%26nbsp%3B%3C%2FP%3E%0A%3CP%3E-%20a%20Windows%20Server%20Active%20Directory%20that%20is%20in%20sync%20with%20it%2C%20which%20can%20be...%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%20--%20Windows%20Server%20Active%20Directory%20running%20on%20VMs%2C%20and%20synchronized%20to%20Azure%20AD%20with%20Azure%20AD%20Connect%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%20--%20Windows%20Server%20Active%20Directory%20running%20on%20VMs%20and%20federated%20to%20Azure%20AD%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%20--%20Azure%20AD%20Domain%20Services%20(which%20stands%20up%20a%20Windows%20Server%20Active%20Directory%20for%20you%20and%20lets%20you%20domain-join%20the%20machines)%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-481565%22%20slang%3D%22en-US%22%3ERe%3A%20WVD%20with%20just%20Azure%20AD%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-481565%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F305776%22%20target%3D%22_blank%22%3E%40christianmontoya%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThanks%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ESo%2C%20for%20cloud%20only%20companies%2C%20Azure%20AD%20DS%20in%20combination%20with%20Azure%20AD%20will%20be%20enough%2C%20if%20I%20understood%20well%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ERegards%2C%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-481590%22%20slang%3D%22en-US%22%3ERe%3A%20WVD%20with%20just%20Azure%20AD%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-481590%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F52144%22%20target%3D%22_blank%22%3E%40Vladimir%20Stefanovic%3C%2FA%3E%26nbsp%3B%3A%20Yes%2C%20exactly.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-484735%22%20slang%3D%22en-US%22%3ERe%3A%20WVD%20with%20just%20Azure%20AD%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-484735%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F305776%22%20target%3D%22_blank%22%3E%40christianmontoya%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThanks.%20One%20question%20more.%3C%2FP%3E%3CP%3EIf%20I%20have%20on-premise%20AD%2C%20do%20I%20need%20to%20configure%20only%20directory%20sync%20with%20AD%20Connect%2C%20or%20I%20need%20to%20enable%20Azure%20AD%20DS%20as%20well%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ERegards%2C%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-538668%22%20slang%3D%22en-US%22%3ERe%3A%20WVD%20with%20just%20Azure%20AD%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-538668%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F52144%22%20target%3D%22_blank%22%3E%40Vladimir%20Stefanovic%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThe%20Host%20VMs%20need%20to%20be%20able%20to%20join%20a%20Windows%20domain.%20So%20you%20either%20need%20hybrid%20domain%20join%20setup%20for%20on%20prem%20or%20AAD%20DS%20setup%20for%20the%20machines%20to%20connect%20to.%3C%2FP%3E%3CP%3EAs%20I%20understand%20it.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-571299%22%20slang%3D%22en-US%22%3ERe%3A%20WVD%20with%20just%20Azure%20AD%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-571299%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F52144%22%20target%3D%22_blank%22%3E%40Vladimir%20Stefanovic%3C%2FA%3E%26nbsp%3B%3A%20Confirming%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F336195%22%20target%3D%22_blank%22%3E%40Radfords-Kirk%3C%2FA%3E%26nbsp%3Bin%20that%20either%20approach%20to%20domain%20join%20the%20VMs%20works.%20You%20do%20not%20need%20to%20spin%20up%20Azure%20AD%20Domain%20Services%20if%20you're%20already%20in%20a%20hybrid%20mode%20with%20Azure%20such%20that%20your%20virtual%20network%20already%20has%20line-of-site%20to%20your%20Domain%20Controller.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-382518%22%20slang%3D%22en-US%22%3EWVD%20with%20just%20Azure%20AD%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-382518%22%20slang%3D%22en-US%22%3EIs%20WVD%20without%20the%20need%20for%20a%20non-Azure%20AD%20on%20the%20roadmap%3F%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1052238%22%20slang%3D%22en-US%22%3ERe%3A%20WVD%20with%20just%20Azure%20AD%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1052238%22%20slang%3D%22en-US%22%3E%3CP%3Ewe've%20been%20through%20this%20with%20a%20customer.%20they%20started%20up%20with%20classic%20on-prem%20AD%20w%2FAAD%20sync%20to%20Office365%2FAzure%20AD.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3Eafter%20a%20sync%20we%20broke%20this%20connection%20and%20made%20all%20users%20'cloud%20only'.%3C%2FP%3E%3CP%3Ethen%20deployed%20Azure%20AD%20DS%20and%20created%20the%20'application%20host%20group'%20with%202%20Win10%20w%2Fo365%3C%2FP%3E%3CP%3Ecustomer%20have%20now%20been%20running%20on%20this%20for%203%20weeks.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3Eand%20no%20its%20not%20as%20easy%20as%20it%20sounds%20in%20my%20description%20%3Ap%3C%2Fimg%3E%20and%20we%20still%20have%20issues%20with%20outlook%20and%20signing%20even%20tough%20i%20think%20we%20got%20a%20break%20yesterday%20night.%20so%20overall%20it%20looks%20good.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3Eremember%20that%20AAD%20--%26gt%3B%20AAD%20DS%20is%20oneway%20sync%20and%20your%20DC's%20are%20managed%20by%20engineers%20in%20US%20so%20you%20cant%20logon%20to%20them%20and%20cant%20access%20shares%2Fsysvol%20and%20such.%20You%20cant%20move%20users%20out%20of%20the%20AADCusers%20group%20(e.g.%20no%20OU%20segmentation)%20and%20have%20to%20put%20all%20GPO's%20in%20one%20OU%20and%20use%20security%20filtering...%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E
Highlighted
Occasional Visitor
Is WVD without the need for a non-Azure AD on the roadmap?
10 Replies
Highlighted

Yes, why do we need AD?  This is a cloud solution and perfect for SMBs.  I have been waiting for this service to come in Public Preview since we did not make it in the private one and got my email yesterday morning. Super excited, couldn't sign in fast enough to fire it up and test it out as we have had talks with customers about it.  Followed the documentation and then went to create my pool and my excitement just drained away when an AD UPN and vnet was required to continue.  What a let down.  Just like the let down of the new security and compliance offers that are only available if you have M365 E3. Is anyone at Microsoft paying attention to SMBs?  These products are a huge sell for them and for the first time they are not overpriced.

Highlighted

@Paranoid69 : Thank you for your feedback. That is the current requirement. We will be introducing shortly a UserVoice forum to collect feedback like this where community can share their votes.

 

Highlighted

Hi all,

 

What is prerequisite for WVD. Azure AD or Azure AD DS?

I didn't find information anywhere.

 

Regards,

Highlighted

@Vladimir Stefanovic : The requirement is:

- an Azure Active Directory 

- a Windows Server Active Directory that is in sync with it, which can be...

  -- Windows Server Active Directory running on VMs, and synchronized to Azure AD with Azure AD Connect

  -- Windows Server Active Directory running on VMs and federated to Azure AD

  -- Azure AD Domain Services (which stands up a Windows Server Active Directory for you and lets you domain-join the machines)

Highlighted

@christianmontoya 

 

Thanks,

 

So, for cloud only companies, Azure AD DS in combination with Azure AD will be enough, if I understood well?

 

Regards,

Highlighted

@Vladimir Stefanovic : Yes, exactly.

Highlighted

@christianmontoya 

 

Thanks. One question more.

If I have on-premise AD, do I need to configure only directory sync with AD Connect, or I need to enable Azure AD DS as well?

 

Regards,

Highlighted

@Vladimir Stefanovic 

The Host VMs need to be able to join a Windows domain. So you either need hybrid domain join setup for on prem or AAD DS setup for the machines to connect to.

As I understand it.

Highlighted

@Vladimir Stefanovic : Confirming @Radfords-Kirk in that either approach to domain join the VMs works. You do not need to spin up Azure AD Domain Services if you're already in a hybrid mode with Azure such that your virtual network already has line-of-site to your Domain Controller.

Highlighted

we've been through this with a customer. they started up with classic on-prem AD w/AAD sync to Office365/Azure AD.

 

after a sync we broke this connection and made all users 'cloud only'.

then deployed Azure AD DS and created the 'application host group' with 2 Win10 w/o365

customer have now been running on this for 3 weeks.

 

and no its not as easy as it sounds in my description :p and we still have issues with outlook and signing even tough i think we got a break yesterday night. so overall it looks good.

 

remember that AAD --> AAD DS is oneway sync and your DC's are managed by engineers in US so you cant logon to them and cant access shares/sysvol and such. You cant move users out of the AADCusers group (e.g. no OU segmentation) and have to put all GPO's in one OU and use security filtering...