Avatar of LA_Admin
LA_Admin
 asked on

Using Azure Domain Services with default domain name scheme

Hello everyone,

I am currently building a testing environment in Office 365/Azure to get a feel for Domain Services and how it can help our business. I currently have it setup with a <companyname>.onmicrosoft.com domain name. I am trying to configure LDAPS, and it requires me to create a DNS record with the external DNS provider so that the DNS name of the managed domain points to the external IP address that gets created during setup. (using steps listed here, under Task 5: Configure LDAPS)

My issue is that I am not using an external DNS provider, just what MS is providing. Is there something that I am doing wrong, or will I need to get ahold of an external DNS provider like NetSol?
DNSAzureActive Directory

Avatar of undefined
Last Comment
Jian An Lim

8/22/2022 - Mon
Mahesh

are you using contoso.onmicrosoft.com or your custom domain in azure

If you are using contoso.onmicrosoft.com, no dns entry is required, in fact you can't do it because you don't have control on that dns zone

If you are using custom domain, you would get custom dns zone for custom domain (public domain) where you can create required Host(A) record
I don't think this is your case
Further more, this step is optional and applicable only if you are accessing resources from managed domain over internet using LDAPS
SOLUTION
Jian An Lim

THIS SOLUTION ONLY AVAILABLE TO MEMBERS.
View this solution by signing up for a free trial.
Members can start a 7-Day free trial and enjoy unlimited access to the platform.
See Pricing Options
Start Free Trial
GET A PERSONALIZED SOLUTION
Ask your own question & get feedback from real experts
Find out why thousands trust the EE community with their toughest problems.
LA_Admin

ASKER
So I went and bought a .com domain. I was able to generate an A record for the external IP address for LDAPS access within NetSol. When I attempt to join a physical laptop to the domain, it tells me that it cannot find it. Also, when I attempt to connect Azure ADDS to an Amazon Workspace directory via AD Connector, I get the following message: "Connectivity issues detected: DNS unavailable (TCP Port 53) for IP X.X.X.X. Please ensure that the listed ports are available and retry the operation".
SOLUTION
Jian An Lim

THIS SOLUTION ONLY AVAILABLE TO MEMBERS.
View this solution by signing up for a free trial.
Members can start a 7-Day free trial and enjoy unlimited access to the platform.
See Pricing Options
Start Free Trial
⚡ FREE TRIAL OFFER
Try out a week of full access for free.
Find out why thousands trust the EE community with their toughest problems.
Mahesh

In addition to above the functionality you are trying to explore is available only with Windows 10 machines
Experts Exchange has (a) saved my job multiple times, (b) saved me hours, days, and even weeks of work, and often (c) makes me look like a superhero! This place is MAGIC!
Walt Forbes
Jian An Lim

this is Azure Active directory domain services, NOT azure AD.
AADDS allows any windows to join to domain, as long as they are in the same network.
Mahesh

Thanks Jian.

Not aware with this.
LA_Admin

ASKER
Ok, so it would appear that I misinterpreted the ability of AADDS. That is no problem. Any ideas about the Amazon Workspaces issue?
⚡ FREE TRIAL OFFER
Try out a week of full access for free.
Find out why thousands trust the EE community with their toughest problems.
Jian An Lim

what Amazon Workspaces issue?
as i said, do your both network (amazon and microsoft azure) are on the same (private) network, can they route via private IP?

AADDS is a domain controller, you never expose it directly via internet public IP address.
the only thing AADDS are exposing is the LDAPS that microsoft provided.
ALl other features (DOMAIN JOIN, kerberos and etc) required private IP address to function
LA_Admin

ASKER
From above:  "when I attempt to connect Azure ADDS to an Amazon Workspace directory via AD Connector, I get the following message: "Connectivity issues detected: DNS unavailable (TCP Port 53) for IP X.X.X.X. Please ensure that the listed ports are available and retry the operation"."
ASKER CERTIFIED SOLUTION
Jian An Lim

THIS SOLUTION ONLY AVAILABLE TO MEMBERS.
View this solution by signing up for a free trial.
Members can start a 7-Day free trial and enjoy unlimited access to the platform.
See Pricing Options
Start Free Trial
⚡ FREE TRIAL OFFER
Try out a week of full access for free.
Find out why thousands trust the EE community with their toughest problems.
LA_Admin

ASKER
Anyone else have any experience here?
This is the best money I have ever spent. I cannot not tell you how many times these folks have saved my bacon. I learn so much from the contributors.
rwheeler23
SOLUTION
Jian An Lim

THIS SOLUTION ONLY AVAILABLE TO MEMBERS.
View this solution by signing up for a free trial.
Members can start a 7-Day free trial and enjoy unlimited access to the platform.
See Pricing Options
Start Free Trial
⚡ FREE TRIAL OFFER
Try out a week of full access for free.
Find out why thousands trust the EE community with their toughest problems.
LA_Admin

ASKER
To answer your question about the IP address, I realized I was using an internal address, so no wonder it couldn't find it.

So I have attempted to configure a VPN between AWS and Azure. I have configured static gateways on both sides and tried to complete the connection, but so far the tunnels are still down. I have found walkthrough's that mention point to site VPN by spinning up a VM on one side or the other and installing RRAS, but I would like to avoid running a VM if at all possible.

I have configured site to site VPN connections in Azure, and feel confident that my config here is correct, but am green in AWS. Do you know if this is possible? Also, is there a way to export my AWS config so that I can share it?
SOLUTION
Jian An Lim

THIS SOLUTION ONLY AVAILABLE TO MEMBERS.
View this solution by signing up for a free trial.
Members can start a 7-Day free trial and enjoy unlimited access to the platform.
See Pricing Options
Start Free Trial
⚡ FREE TRIAL OFFER
Try out a week of full access for free.
Find out why thousands trust the EE community with their toughest problems.
Jian An Lim

There are no AAADS connectivty between Azure and AWS.
a VPN is required.