Solved

Azure AD Connect

Posted on 2016-09-28
10
23 Views
Last Modified: 2016-11-09
Hi,

I want to connect a clean windows server 2012 on a VPS to Azure AD. Do I have to create a domain first on the server 2012 before connecting? The reason is I want to install an SQL on the server 2012 in the cloud and have users logon to on-premise pc in the office and have access to all their online services.

Some help is appriciated.

Kind regards,
0
Comment
Question by:Lufaa
  • 5
  • 4
10 Comments
 
LVL 56

Accepted Solution

by:
Cliff Galiher earned 500 total points
ID: 41820819
That's the path of least resistance, yes.  Azure AD supports SAML and you could technically custom write code that ties into their APIs and get single sign-on as long as you have ADFS on-prem somewhere. But if you want to avoid coding or if you don't have ADFS, you are looking at some sort of coordination technology.
0
 
LVL 1

Author Comment

by:Lufaa
ID: 41820835
I don't think I quite understand what you are saying but now I am as far as that I cannot connect from my server 2012 with azure ad connect to my Azure AD
azure-ad-connect.JPG
0
 
LVL 56

Expert Comment

by:Cliff Galiher
ID: 41820868
AADConnect does exactly that. It "connects" ADDS (on-prem) to azure AD. Which means ADDS must be present a d accessible somewhere on the network (via layer 2, or VPN, or ezpressroute, or something.)

If you don't have ADDS then there is no reason to run AADConnect. You'd simply create new user accounts natively in azure AD.
0
 
LVL 1

Author Comment

by:Lufaa
ID: 41821226
Ok, so I created a AD on the new 2012 server. I was able, after some testing and trying, to run the AADConnect but I still don't see all the Azure AD users in my server? Seems like the sync has not completed. Anything I forgot to setup or make sure is ready before doing this?
0
Do email signature updates give you a headache?

Do you feel like you are constantly making changes to email signatures? Are the images not formatting how you want them to? Want high-quality HTML signatures on all devices, including on mobiles and Macs? Then, let Exclaimer solve all your email signature problems today.

 
LVL 56

Expert Comment

by:Cliff Galiher
ID: 41821274
Aadconnect syncs from server to Azure AD. Not the other way around. Your azure users will *never* suddenly appear on your server.
0
 
LVL 1

Author Comment

by:Lufaa
ID: 41821309
Ok, clear. What is the best way when creating a new user, for example for creating a user which has access to my SQL instance on the 2012 server? Because as I understood, my Office 365 users can logon to their Windows 10 Pro computers with their Office 365 account and with the server 2012 being connected the same users have single sign on feature for accessing the SQL server on this 2012 server.
0
 
LVL 56

Assisted Solution

by:Cliff Galiher
Cliff Galiher earned 500 total points
ID: 41821317
There's a lot of planning and moving peices to get that working. If you don't want to change users' workflow m, you are looking at joining the devices to azure AD, ADFS, and UPN matching all your on-prem accounts, at the very least.

Given your kevel of familiarity with azure AD and AADConnect I'd suggest hiring a local azure developer to work with.
0
 
LVL 1

Author Comment

by:Lufaa
ID: 41829732
Hi Cliff,

Do you know a good one I can hire?

Kind regards
0
 
LVL 56

Expert Comment

by:Cliff Galiher
ID: 41830250
For these kinds of projects, as I said, it is often beat to hire local. Since I don't know where you are, no, I don't know anyone. Although to be fair, my answer probably will be the same even if I knew where you were.
0

Featured Post

Why do Marketing keep bothering you?

Is your marketing department constantly asking for new email signature updates? Are they requesting a different design for every department? Do they need yet another banner added? Don’t let it get you down! There is an easy way to manage all of these requests...

Join & Write a Comment

OfficeMate Freezes on login or does not load after login credentials are input.
Veeam Backup & Replication has added a new integration – Veeam Backup for Microsoft Office 365.  In this blog, we will discuss how you can benefit from Office 365 email backup with the Veeam’s new product and try to shed some light on the needs and …
This tutorial will walk an individual through the process of installing the necessary services and then configuring a Windows Server 2012 system as an iSCSI target. To install the necessary roles, go to Server Manager, and select Add Roles and Featu…
how to add IIS SMTP to handle application/Scanner relays into office 365.

758 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

18 Experts available now in Live!

Get 1:1 Help Now