Forum Discussion
Arya1028
Mar 24, 2020Copper Contributor
Azure AD Hybrid Setup
Hi Everyone,
I have multi forest environment that I would like to sync to Azure AD with AD connect, is it possible to achieve below:
1. Sync two domains to one Tenant.
2. SSO for the two domains.
3. Sync Devices to Azure AD and use Intune to manage, and how?
Thanks for your help in advance!
Arya
- Hi Arya,
1. Yes, you can sync directories. It should be under Add Directory in Ad Connect. You need to have s2s vpn between the domains.
Check Multiple forests single AD tenant.
https://docs.microsoft.com/en-us/azure/active-directory/hybrid/plan-connect-topologies
2. I recommend using Seamless SSO, easy to setup with AD-Connect.
https://docs.microsoft.com/bs-latn-ba/azure/active-directory/hybrid/tshoot-connect-sso
3. You can use GPO to enroll devices to MDM, you have some prerequisites like Intune license, Windows build version and Intune Cname setup etc.
https://docs.microsoft.com/en-us/windows/client-management/mdm/enroll-a-windows-10-device-automatically-using-group-policy#configure-the-auto-enrollment-group-policy-for-a-single-pc
Hope this helps!
Moe
- Moe_KinaniBronze ContributorHi Arya,
1. Yes, you can sync directories. It should be under Add Directory in Ad Connect. You need to have s2s vpn between the domains.
Check Multiple forests single AD tenant.
https://docs.microsoft.com/en-us/azure/active-directory/hybrid/plan-connect-topologies
2. I recommend using Seamless SSO, easy to setup with AD-Connect.
https://docs.microsoft.com/bs-latn-ba/azure/active-directory/hybrid/tshoot-connect-sso
3. You can use GPO to enroll devices to MDM, you have some prerequisites like Intune license, Windows build version and Intune Cname setup etc.
https://docs.microsoft.com/en-us/windows/client-management/mdm/enroll-a-windows-10-device-automatically-using-group-policy#configure-the-auto-enrollment-group-policy-for-a-single-pc
Hope this helps!
Moe