Microsoft Azure AD

ie0
ie0 used Ask the Experts™
on
I have a small network that I want to setup with all data storage to be on dropbox.
I want to have a domain structure for passwords, GPO, etc.
I do not want to have an on-premise server.
Can I sign up with Microsoft Azure and get active directory?
If so, how much is it per user?
Comment
Watch Question

Do more with

Expert Office
EXPERT OFFICE® is a registered trademark of EXPERTS EXCHANGE®
Distinguished Expert 2018
Commented:
No. Azure AD is a different beast. With windows 10, you would get centralized authentication, but nothing like group policy at all. At a minimum, you'd need an MDM solution like Intune for that.
ie0

Author

Commented:
Will the MDM solution work for laptops and desktops?
What is the pricing?
Thanks
Ensure you’re charging the right price for your IT

Do you wonder if your IT business is truly profitable or if you should raise your prices? Learn how to calculate your overhead burden using our free interactive tool and use it to determine the right price for your IT services. Start calculating Now!

Adam BrownSenior Systems Admin
Top Expert 2010
Commented:
As has been said, Azure AD can't replace on-prem DCs. You can replicate users from on-prem to cloud (and vice versa with Azure AD Premium) but devices can't authenticated to an entirely cloud-based AD. In order to be able to authenticate users against the Domain from a workstation, though, you would need an On-prem or Cloud-based VM DC. Adding a VM that is a DC to the Azure environment and syncing its AD info to Azure AD should give you most of what you need, but that DC still needs to have a VPN setup between it and your on-prem network to function.

If you're ok with only being able to manage the computers as Workgroup computers (not domain joined), then Azure AD premium would probably be a good solution for you. Intune should give you some level of management of computers, but not likely as much as Group Policy. If you're interested in doing that, I'd suggest looking at the Enterprise Mobility Suite for Azure, since it packages all the components you'd need to manage phones, laptops, and workstations from the cloud.
Distinguished Expert 2018
Commented:
"but devices can't authenticated to an entirely cloud-based AD"

Windows 10 certainly supports native Azure AD joining. It isn't a workgroup, but isnt like an on-prem domain either. It is a new sort of thing, but for new greenfield deployments, it can certainly be an option worth considering.
Distinguished Expert 2018
Commented:
Intune can certainly manage windows and mac laptops and desktops. Pricing is on their site as there are differences by region and features. I couldn't reasonably list them all here.
Adam BrownSenior Systems Admin
Top Expert 2010
Commented:
@Cliff - Being able to Join an Azure AD domain isn't the same thing as authenticating against it. MS doesn't currently provide domain authentication against Azure AD for workstations. You can join the domain, but it will function very differently, using the same methodology as the Microsoft Account login system in Windows 10. There is a lot of functionality that just doesn't work well over the Internet (Kerberos Authentication being the Big Thing).
Distinguished Expert 2018
Commented:
Apples and oranges. For someone not wanting an on-prem server, a native azure AD implementation for both users and azure AD joined machines is certainly workable and as dropbox supports SSO with AAD, this *is* a potential option for the OP, with the caveat that I initially pointed out that group policies aren't there and thus intune as a potential filler.

Don't get stuck trying to think of azure AD as an on-prem solution or technology. I know it isn't and never implied it was. But given the OPs post, it *is* possible, and may even be preferable. Microsoft made a ton of investments in Windows 10 1511/1607 and windows server 2016 to make azure AD an interesting contender for cloud -centric organizations.

Do more with

Expert Office
Submit tech questions to Ask the Experts™ at any time to receive solutions, advice, and new ideas from leading industry professionals.

Start 7-Day Free Trial