Forum Discussion

Arya1028's avatar
Arya1028
Copper Contributor
Mar 24, 2020
Solved

Azure AD Hybrid Setup

Hi Everyone,

 

I have multi forest environment that I would like to sync to Azure AD with AD connect, is it possible to achieve below:

 

1. Sync two domains to one Tenant.

2. SSO for the two domains.

3. Sync Devices to Azure AD and use Intune to manage, and how?

 

Thanks for your help in advance!

Arya

  • Hi Arya,

    1. Yes, you can sync directories. It should be under Add Directory in Ad Connect. You need to have s2s vpn between the domains.

    Check Multiple forests single AD tenant.
    https://docs.microsoft.com/en-us/azure/active-directory/hybrid/plan-connect-topologies


    2. I recommend using Seamless SSO, easy to setup with AD-Connect.

    https://docs.microsoft.com/bs-latn-ba/azure/active-directory/hybrid/tshoot-connect-sso

    3. You can use GPO to enroll devices to MDM, you have some prerequisites like Intune license, Windows build version and Intune Cname setup etc.

    https://docs.microsoft.com/en-us/windows/client-management/mdm/enroll-a-windows-10-device-automatically-using-group-policy#configure-the-auto-enrollment-group-policy-for-a-single-pc

    Hope this helps!
    Moe

1 Reply

  • Moe_Kinani's avatar
    Moe_Kinani
    Bronze Contributor
    Hi Arya,

    1. Yes, you can sync directories. It should be under Add Directory in Ad Connect. You need to have s2s vpn between the domains.

    Check Multiple forests single AD tenant.
    https://docs.microsoft.com/en-us/azure/active-directory/hybrid/plan-connect-topologies


    2. I recommend using Seamless SSO, easy to setup with AD-Connect.

    https://docs.microsoft.com/bs-latn-ba/azure/active-directory/hybrid/tshoot-connect-sso

    3. You can use GPO to enroll devices to MDM, you have some prerequisites like Intune license, Windows build version and Intune Cname setup etc.

    https://docs.microsoft.com/en-us/windows/client-management/mdm/enroll-a-windows-10-device-automatically-using-group-policy#configure-the-auto-enrollment-group-policy-for-a-single-pc

    Hope this helps!
    Moe

Resources