SlideShare a Scribd company logo
Azure Active Directory Connect to a Single Domain
Published by Hector Ramos, Robert Roman on 7/13/2015
As I wrote earlier, Microsoft recently released a new version of the Connect tool that makes connection on
premise and cloud domain very easy. You can be on your way to a Hybrid cloud environment in no time.
Using one tool you can now configure Directory Sync, Password Sync, and Federation Services through a
wizard by simply providing credentials and checking a few boxes. The tool needs to be run on a computer that
is joined to the domain you wish to integrate. It will also install a few files and a local version of SQL express
unless you connect it to an existing SQL instance. You may want to install the tool to a dedicated server that
will run synchronization services. I'll demo how easy it was to integrate a single development domain to Azure
Active Directory.
You will first be prompted to select custom or express settings. The express option assumes that the current
user is an administrator for the domain. The customize option lets you specify an install location for files, SQL
server for metadata, service account to connect to the domain, and specific groups to synchronize. After
configuring your settings or selecting express, all of the pre-requisites will be installed on the machine.
After the file installation, you will be asked to determine how your users will sign in to your Hybrid domain.
Password synchronization will store password hashes (not actualpasswords) in your cloud domain. This
means that users can log in with domain credentials to your cloud domain in the event that you’re on premises
domain becomes unavailable. The Federation option will install and configure the AD FS role on a windows
2012 server so that users are redirected to the on-premises AD FS instance for signing in and authentication is
done on-premises. This option offers a little bit less resiliency if you’re on premise domain goes down. It also
requires some certificate configuration. Check the do not configure option if you will be using a third party
solution for federated sign-ins. For the demo I will select the password synchronization as it provides the
resiliency that I’m looking for.
After you select the password option, provide credentials to your azure active directory instance. The account
must be a global administrator in the active directory domain.
Then, enter credentials for an administrative account in the directory being synced with Azure and click the
Add Directory button to confirm.
You will subsequently have to configure properties that will uniquely identify your domain users. This can get
tricky if your user's are represented multiple times across domain but for our purposes the default options will
suffice. The important thing to note is that the Source Anchor should be mapped to a globally unique identifier
that will not change during the lifetime of the user and the User Principal Name maps to the property that users
enter to log in.
Now you can configure the subset of user's that will actually be synced to Azure AD. I selected the Domain
Users container.
Finally, you can check some boxes to further customize the integration process. There is an option for
Exchange hybrid deployments if you want to integrate with Exchange Online. The Azure AD app and attribute
filtering will simplify connectivity to Microsoft Online Applications such as Office 365, Exchange,
SharePoint, Lync, Dynamics, and others by allowing further granularity in attribute synchronization. The
password write back feature will allow users to change their password online and have it synced back to your
on premises domain. The user, Group, and Device write back options are self-explanatory.
Finally, you can kick back and relax as the Connect tool configures your hybrid environment. And, once the
first sync has completed you will see your user's in Azure AD.
Azure active directory connect to a single domain
This default configuration will use the DOMAIN.ONMICROSOFT.COM syntax for log in names until you
integrate your custom domain with Azure Active Directory.
This completes the demo of the Azure AD Connect tool. In subsequent posts, will be exploring more complex
scenarios such as integration with Office 365.

More Related Content

DOCX
SSO to Office365 using Active Directory Credentials
PPTX
Tspug 2015 dirsync_amit_v_momentum
PPTX
Connect to the Microsoft Cloud
PPTX
Azure role based access control (rbac)
PDF
Office 365 Directory Synchronization
PDF
Spsct15 power shell_csom - amit vasu
PPTX
Windows Server 2008 Active Directory
PPTX
How do i connect to that
SSO to Office365 using Active Directory Credentials
Tspug 2015 dirsync_amit_v_momentum
Connect to the Microsoft Cloud
Azure role based access control (rbac)
Office 365 Directory Synchronization
Spsct15 power shell_csom - amit vasu
Windows Server 2008 Active Directory
How do i connect to that

What's hot (20)

PPSX
SQL Saturday 411 - Migrating SharePoint Databases and Farm Configuration Usin...
PPTX
JAXSPUG April 2016 - Staying in the Know with Office 365
PPTX
The Who, What, Why and How of Active Directory Federation Services (AD FS)
PPTX
Active directory ds ws2008 r2
PDF
SPUnite17 External Sharing in SharePoint Online
PPTX
Sql Saturday 228 Rapid Data Integration Using SharePoint BCS
PPTX
Azure Active Directory Connect: Technical Deep Dive - EU Collab Summit 2018
DOCX
Ad ds rodc
PPTX
Breaking Down the Tools and Features in Office 365 - EU Collab Summit 2018
PPTX
Advanced BCS - Business Data Connectivity Models and Custom Connectors
PDF
Microsoft Solution Proposal with AD, Exchange & SC--Bill of Materials
PPT
Active Directory
PPT
Windows Server 2008 Active Directory Guide
PDF
Autodiscover flow in active directory based environment part 15#36
PPT
Active directory ii
PPTX
Building business applications using business connectivity services using sha...
PPTX
Understanding Office 365’s Identity Solutions: Deep Dive - EPC Group
PPTX
SPS Lisbon 2018 - Azure AD Connect Technical Deep Dive
PPTX
Azure Active Directory Connect: Technical Deep Dive - DWCAU 2018 Melbourne
PDF
Active Directory Proposal
SQL Saturday 411 - Migrating SharePoint Databases and Farm Configuration Usin...
JAXSPUG April 2016 - Staying in the Know with Office 365
The Who, What, Why and How of Active Directory Federation Services (AD FS)
Active directory ds ws2008 r2
SPUnite17 External Sharing in SharePoint Online
Sql Saturday 228 Rapid Data Integration Using SharePoint BCS
Azure Active Directory Connect: Technical Deep Dive - EU Collab Summit 2018
Ad ds rodc
Breaking Down the Tools and Features in Office 365 - EU Collab Summit 2018
Advanced BCS - Business Data Connectivity Models and Custom Connectors
Microsoft Solution Proposal with AD, Exchange & SC--Bill of Materials
Active Directory
Windows Server 2008 Active Directory Guide
Autodiscover flow in active directory based environment part 15#36
Active directory ii
Building business applications using business connectivity services using sha...
Understanding Office 365’s Identity Solutions: Deep Dive - EPC Group
SPS Lisbon 2018 - Azure AD Connect Technical Deep Dive
Azure Active Directory Connect: Technical Deep Dive - DWCAU 2018 Melbourne
Active Directory Proposal
Ad

Viewers also liked (9)

PPTX
70 533 - Module 02 : Implementing and Managing Virtual Networks
PPTX
70 533 - Module 01 - Introduction to Azure
PDF
Microsoft certification exams 70 533
PPTX
Introduction to Microsoft Azure 101
PPTX
Aws vs. Azure: 5 Things You Need To Know
PDF
Azure vs AWS Best Practices: What You Need to Know
PDF
The Layman's Guide to Microsoft Azure
PPTX
Microsoft Cloud Computing - Windows Azure Platform
PPTX
Microsoft Azure vs Amazon Web Services (AWS) Services & Feature Mapping
70 533 - Module 02 : Implementing and Managing Virtual Networks
70 533 - Module 01 - Introduction to Azure
Microsoft certification exams 70 533
Introduction to Microsoft Azure 101
Aws vs. Azure: 5 Things You Need To Know
Azure vs AWS Best Practices: What You Need to Know
The Layman's Guide to Microsoft Azure
Microsoft Cloud Computing - Windows Azure Platform
Microsoft Azure vs Amazon Web Services (AWS) Services & Feature Mapping
Ad

Similar to Azure active directory connect to a single domain (20)

PPTX
Use of the Azure AD connect for on prem device
PDF
Get your Hybrid Identity in 4 steps with Azure AD Connect
PPTX
70 346 Managing office 365 identities
PPTX
Office 365 MCSA TechEd
PPTX
Integrating your on-premises Active Directory with Azure and Office 365
PDF
Office 365 Identity Management - SMBNation 2015
PPTX
Análisis de riesgos en Azure y protección de la información
PDF
Microsoft Cloud Identity and Access Management Poster - Atidan
PPTX
CoLabora - Identity in a World of Cloud - June 2015
PPTX
[Noel] Azure AD Connect Technical Deep Dive
PDF
Understanding Azure AD Webinar Presentation
PPTX
O365-AzureAD Identity management
PPTX
Azure Global Bootcamp 2017 Azure AD Deployment
PPTX
Microsoft Azure Active Directory
PPTX
Microsoft Azure AD architecture and features
PPTX
Azure-AD.pptx
PPTX
Identity Management for Office 365 and Microsoft Azure
PPTX
Brian Desmond - Identity and directory synchronization with office 365 and wi...
PDF
MS Cloud Identity and Access Infographic 2015 (1)
PDF
Ms cloud identity and access infographic 2015
Use of the Azure AD connect for on prem device
Get your Hybrid Identity in 4 steps with Azure AD Connect
70 346 Managing office 365 identities
Office 365 MCSA TechEd
Integrating your on-premises Active Directory with Azure and Office 365
Office 365 Identity Management - SMBNation 2015
Análisis de riesgos en Azure y protección de la información
Microsoft Cloud Identity and Access Management Poster - Atidan
CoLabora - Identity in a World of Cloud - June 2015
[Noel] Azure AD Connect Technical Deep Dive
Understanding Azure AD Webinar Presentation
O365-AzureAD Identity management
Azure Global Bootcamp 2017 Azure AD Deployment
Microsoft Azure Active Directory
Microsoft Azure AD architecture and features
Azure-AD.pptx
Identity Management for Office 365 and Microsoft Azure
Brian Desmond - Identity and directory synchronization with office 365 and wi...
MS Cloud Identity and Access Infographic 2015 (1)
Ms cloud identity and access infographic 2015

Recently uploaded (20)

PPTX
How a Careem Clone App Allows You to Compete with Large Mobility Brands
PDF
Forouzan Book Information Security Chaper - 1
PDF
How to Confidently Manage Project Budgets
PDF
Addressing The Cult of Project Management Tools-Why Disconnected Work is Hold...
PPT
JAVA ppt tutorial basics to learn java programming
PPTX
ai tools demonstartion for schools and inter college
PPTX
AIRLINE PRICE API | FLIGHT API COST |
PDF
Understanding NFT Marketplace Development_ Trends and Innovations.pdf
PDF
Become an Agentblazer Champion Challenge
DOCX
The Five Best AI Cover Tools in 2025.docx
PDF
How to Choose the Most Effective Social Media Agency in Bangalore.pdf
PPTX
Save Business Costs with CRM Software for Insurance Agents
PDF
System and Network Administraation Chapter 3
PDF
Comprehensive Salesforce Implementation Services.pdf
PDF
Claude Code: Everyone is a 10x Developer - A Comprehensive AI-Powered CLI Tool
PDF
System and Network Administration Chapter 2
PDF
PTS Company Brochure 2025 (1).pdf.......
PDF
How to Migrate SBCGlobal Email to Yahoo Easily
PDF
Perfecting Gamer’s Experiences with Performance Testing for Gaming Applicatio...
PPTX
Presentation of Computer CLASS 2 .pptx
How a Careem Clone App Allows You to Compete with Large Mobility Brands
Forouzan Book Information Security Chaper - 1
How to Confidently Manage Project Budgets
Addressing The Cult of Project Management Tools-Why Disconnected Work is Hold...
JAVA ppt tutorial basics to learn java programming
ai tools demonstartion for schools and inter college
AIRLINE PRICE API | FLIGHT API COST |
Understanding NFT Marketplace Development_ Trends and Innovations.pdf
Become an Agentblazer Champion Challenge
The Five Best AI Cover Tools in 2025.docx
How to Choose the Most Effective Social Media Agency in Bangalore.pdf
Save Business Costs with CRM Software for Insurance Agents
System and Network Administraation Chapter 3
Comprehensive Salesforce Implementation Services.pdf
Claude Code: Everyone is a 10x Developer - A Comprehensive AI-Powered CLI Tool
System and Network Administration Chapter 2
PTS Company Brochure 2025 (1).pdf.......
How to Migrate SBCGlobal Email to Yahoo Easily
Perfecting Gamer’s Experiences with Performance Testing for Gaming Applicatio...
Presentation of Computer CLASS 2 .pptx

Azure active directory connect to a single domain

  • 1. Azure Active Directory Connect to a Single Domain Published by Hector Ramos, Robert Roman on 7/13/2015 As I wrote earlier, Microsoft recently released a new version of the Connect tool that makes connection on premise and cloud domain very easy. You can be on your way to a Hybrid cloud environment in no time. Using one tool you can now configure Directory Sync, Password Sync, and Federation Services through a wizard by simply providing credentials and checking a few boxes. The tool needs to be run on a computer that is joined to the domain you wish to integrate. It will also install a few files and a local version of SQL express unless you connect it to an existing SQL instance. You may want to install the tool to a dedicated server that will run synchronization services. I'll demo how easy it was to integrate a single development domain to Azure Active Directory.
  • 2. You will first be prompted to select custom or express settings. The express option assumes that the current user is an administrator for the domain. The customize option lets you specify an install location for files, SQL server for metadata, service account to connect to the domain, and specific groups to synchronize. After configuring your settings or selecting express, all of the pre-requisites will be installed on the machine. After the file installation, you will be asked to determine how your users will sign in to your Hybrid domain. Password synchronization will store password hashes (not actualpasswords) in your cloud domain. This means that users can log in with domain credentials to your cloud domain in the event that you’re on premises domain becomes unavailable. The Federation option will install and configure the AD FS role on a windows 2012 server so that users are redirected to the on-premises AD FS instance for signing in and authentication is done on-premises. This option offers a little bit less resiliency if you’re on premise domain goes down. It also requires some certificate configuration. Check the do not configure option if you will be using a third party
  • 3. solution for federated sign-ins. For the demo I will select the password synchronization as it provides the resiliency that I’m looking for. After you select the password option, provide credentials to your azure active directory instance. The account must be a global administrator in the active directory domain.
  • 4. Then, enter credentials for an administrative account in the directory being synced with Azure and click the Add Directory button to confirm.
  • 5. You will subsequently have to configure properties that will uniquely identify your domain users. This can get tricky if your user's are represented multiple times across domain but for our purposes the default options will suffice. The important thing to note is that the Source Anchor should be mapped to a globally unique identifier that will not change during the lifetime of the user and the User Principal Name maps to the property that users enter to log in.
  • 6. Now you can configure the subset of user's that will actually be synced to Azure AD. I selected the Domain Users container.
  • 7. Finally, you can check some boxes to further customize the integration process. There is an option for Exchange hybrid deployments if you want to integrate with Exchange Online. The Azure AD app and attribute filtering will simplify connectivity to Microsoft Online Applications such as Office 365, Exchange, SharePoint, Lync, Dynamics, and others by allowing further granularity in attribute synchronization. The password write back feature will allow users to change their password online and have it synced back to your on premises domain. The user, Group, and Device write back options are self-explanatory.
  • 8. Finally, you can kick back and relax as the Connect tool configures your hybrid environment. And, once the first sync has completed you will see your user's in Azure AD.
  • 10. This default configuration will use the DOMAIN.ONMICROSOFT.COM syntax for log in names until you integrate your custom domain with Azure Active Directory. This completes the demo of the Azure AD Connect tool. In subsequent posts, will be exploring more complex scenarios such as integration with Office 365.