Migrate from Exchange 2010 on premise to Office 365 using dirsync/sso/azure

We are migrating 600 users from on premise Exchange 2010 to Office 365

We are performing a cutover migration and want to remove our existing on premise Exchange (therefore no hybrid)
From all the scenarios to keep password sync from on premise to Office 365 we require ADFS/Dirsync.

We want redundancy but we do not want to keep more servers for Office 365 than we had for Exchange. ie 2 ADFS, 2 DIRSYNC, 2 DIRSYNC proxy

Can we just deploy the Windows Azure dirsync with password sync and will this replace the ADFS feature.

We only need the password sync option and the users should only login with their credentials once.

Who is Participating?
James HodgeConnect With a Mentor Managing DirectorCommented:

Active Directory Federation Services (ADFS) allows a user to authenticate only once (Single Sign On) and be able to successfully access resources on the Office 365 Federated Server.

Directory synchronisation (DirSync) now supports the synchronisation of passwords from the on-premise Active Directory to the Cloud. This means that the user can sign onto Office 365 services using the same credentials they used to login to their domain computer.

This is called ‘Same Sign On’; it is not the same as ‘Single Sign On’. Same Sign On means the user still has to type in their credentials when accessing resources at the cloud service.

The Same Sign On functionality provided by DirSync is a compromise solution. DirSync is easier to implement than ADFS and Single Sign On, but the user experience is not as seamless.

Good Luck

Vasil Michev (MVP)Connect With a Mentor Commented:
As James explained, dirsync password sync and ADFS are a bit different. It all depends on your requirements.

If you are going to use only Exchange Online, you can work around the Outlook password prompt by using the Credentials Manager (you will still get a prompt once the password is changed). If you are going to use more services, especially SharePoint, it might become a bit annoying for the users. If you set their expectations correctly, they might be OK with it :)

For detailed comparison between AD FS and dirsync password sync review these:


Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

All Courses

From novice to tech pro — start learning today.