Mark Minasi's Tech Forum
Sign up Calendar Latest Topics
 
 
 


Reply
  Author   Comment  
Michael Pietrzak

New Friend (or an Old Friend who Built a New Account)
Registered:
Posts: 78
Reply with quote  #1 
I am reading, training with Pluralsight, and watching tons of youtube videos on all things Azure, Azure AD and O365.


I am confused about where are user accounts located? Azure, Azure Active Directory or 0365? I found a video where a gentleman explains how to create a tenet in 0365 and manages users in the Office 365 Admin Center

In another video, the demonstrator sets up an Azure tenant and uses the Azure AD Connecter to his Office 365 tenent.

And what about Azure AD DS? When and why would I want this versus Azure AD?

I am trying to set this up in a lab at home. I have the free trial to Azure in place. No tenent for Azure or O365 yet.

If I have a fictional business with on-premises Active Directory (my home lab), what pieces do I need to get my op-prem users into 0365 and Azure?

I want to learn topics like setting up vm's for my on-prem business. Set up blob storage for backups, single sign on etc.

Any thoughts would be greatly appreciated.

Regards,
Mike Pietrzak


0
rogerd2u

Still Checking the Forum Out
Registered:
Posts: 4
Reply with quote  #2 
Hi Michael,

The thing to remember is Azure AD is a separate database of users. It can be synchronized with your on-prem AD (users/passwords); when you do that, it becomes an extension of your on-prem identities (but both remain separate databases). To set synchronization up you need to install Azure AD Connect on a server in your on-prem environment. Azure AD Connect keeps track of changes in both databases (password changes, new users).

Here is what I used for testing single sign-on (SSO):
  • Set up synchronization from on-prem AD to Azure AD (see above)
  • Set up DropBox SSO through the Azure AD Enterprise Application (You can get a 30-day free evaluation for DropBox for Business)
  • Verify you can access your DropBox account using SSO (either with the client you can install on a VM, or just by going to dropbox.com and see if you're automatically logged in)

Azure AD DS is an offering where Azure installs/configures/maintains two domain controllers in the cloud. If you have a site-to-site VPN connection (or ExpressRoute, etc.) with your Azure tenant, you can then join machines to this domain just as you would if your DCs were on-prem. (After they are built you would need to set your DNS to point to these DCs, obviously, so you could join VMs to this domain, users could authenticate to the DCs, etc.) With this offering, however, you don't have full access to the domain controllers (you can't log into them directly, Microsoft patches them automatically, etc.). You access Group Policies, ADUC, etc., through a separate domain-joined machine (either on-prem or in the cloud; your choice). It costs around $110 per month for up to 25,000 users right now.
Benefits: Highly available solution for authentication; you don't need on-prem DCs; and the management part (patching) is taken care of by Azure

All this can be a bit daunting when you're trying to learn it...trust me, I've been doing just that for the last year or so myself. I still have a lot of learning to do. 

I love PluralSight. (John Savill is my favorite instructor and he has some great videos on YouTube you should watch if you haven't already regarding Azure.) I'm currently going through the Azure videos myself. I got my AZ-103 in July and am now working towards getting my AZ-500.

I hope this helps bridge some knowledge gaps. You are not alone in the struggle. Keep it up and you'll be very glad you did!

Roger

0
Michael Pietrzak

New Friend (or an Old Friend who Built a New Account)
Registered:
Posts: 78
Reply with quote  #3 
Thanks Roger!

This is very helpful! The folks over in the sysadmin group on Reddit have been helpful as well. Several folks there trying to learn this tech so it seems to be a common theme.

This thread helped me a great deal...

https://www.reddit.com/r/msp/comments/brplbt/windows_server_active_directory_azure_ad_azure_ad/

0
Michael Pietrzak

New Friend (or an Old Friend who Built a New Account)
Registered:
Posts: 78
Reply with quote  #4 
So hypothetically....I have a business that makes widgets. I have registered the domain name Michaelswidgets.com. We have on-prem AD and a simple website.

The boss wants to move services to Azure. Okay, do I create the O365 tenant first or the Azure tenant?

At what point do I implement the Azure AD connect to sync my users to Azure etc?

0
Michael Pietrzak

New Friend (or an Old Friend who Built a New Account)
Registered:
Posts: 78
Reply with quote  #5 
Can anyone tell me if I have on-premises AD now, do I create the O365 tenant or the AD tenant first?

I have received wildly different answers.
0
Previous Topic | Next Topic
Print
Reply

Quick Navigation:

Easily create a Forum Website with Website Toolbox.