Solved

Azure AD Connect

Posted on 2016-09-28
10
26 Views
Last Modified: 2016-11-09
Hi,

I want to connect a clean windows server 2012 on a VPS to Azure AD. Do I have to create a domain first on the server 2012 before connecting? The reason is I want to install an SQL on the server 2012 in the cloud and have users logon to on-premise pc in the office and have access to all their online services.

Some help is appriciated.

Kind regards,
0
Comment
Question by:Lufaa
  • 5
  • 4
10 Comments
 
LVL 56

Accepted Solution

by:
Cliff Galiher earned 500 total points
ID: 41820819
That's the path of least resistance, yes.  Azure AD supports SAML and you could technically custom write code that ties into their APIs and get single sign-on as long as you have ADFS on-prem somewhere. But if you want to avoid coding or if you don't have ADFS, you are looking at some sort of coordination technology.
0
 
LVL 1

Author Comment

by:Lufaa
ID: 41820835
I don't think I quite understand what you are saying but now I am as far as that I cannot connect from my server 2012 with azure ad connect to my Azure AD
azure-ad-connect.JPG
0
 
LVL 56

Expert Comment

by:Cliff Galiher
ID: 41820868
AADConnect does exactly that. It "connects" ADDS (on-prem) to azure AD. Which means ADDS must be present a d accessible somewhere on the network (via layer 2, or VPN, or ezpressroute, or something.)

If you don't have ADDS then there is no reason to run AADConnect. You'd simply create new user accounts natively in azure AD.
0
 
LVL 1

Author Comment

by:Lufaa
ID: 41821226
Ok, so I created a AD on the new 2012 server. I was able, after some testing and trying, to run the AADConnect but I still don't see all the Azure AD users in my server? Seems like the sync has not completed. Anything I forgot to setup or make sure is ready before doing this?
0
Are your AD admin tools letting you down?

Managing Active Directory can get complicated.  Often, the native tools for managing AD are just not up to the task.  The largest Active Directory installations in the world have relied on one tool to manage their day-to-day administration tasks: Hyena. Start your trial today.

 
LVL 56

Expert Comment

by:Cliff Galiher
ID: 41821274
Aadconnect syncs from server to Azure AD. Not the other way around. Your azure users will *never* suddenly appear on your server.
0
 
LVL 1

Author Comment

by:Lufaa
ID: 41821309
Ok, clear. What is the best way when creating a new user, for example for creating a user which has access to my SQL instance on the 2012 server? Because as I understood, my Office 365 users can logon to their Windows 10 Pro computers with their Office 365 account and with the server 2012 being connected the same users have single sign on feature for accessing the SQL server on this 2012 server.
0
 
LVL 56

Assisted Solution

by:Cliff Galiher
Cliff Galiher earned 500 total points
ID: 41821317
There's a lot of planning and moving peices to get that working. If you don't want to change users' workflow m, you are looking at joining the devices to azure AD, ADFS, and UPN matching all your on-prem accounts, at the very least.

Given your kevel of familiarity with azure AD and AADConnect I'd suggest hiring a local azure developer to work with.
0
 
LVL 1

Author Comment

by:Lufaa
ID: 41829732
Hi Cliff,

Do you know a good one I can hire?

Kind regards
0
 
LVL 56

Expert Comment

by:Cliff Galiher
ID: 41830250
For these kinds of projects, as I said, it is often beat to hire local. Since I don't know where you are, no, I don't know anyone. Although to be fair, my answer probably will be the same even if I knew where you were.
0

Featured Post

Why won’t your email signature format correctly?

Struggling to get your corporate email signatures to format correctly? Does the logo keep resizing? Is the text appearing too big? What can you do to prevent this? Find out how you can save your signatures today.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Find out what Office 365 Transport Rules are, how they work and their limitations managing Office 365 signatures.
This is my first article on Expert Exchange on the Manual Method of Exporting Office 365 Mailboxes to PST format by using the eDiscovery mechanism of Office. Hope you will enjoy the article.
This Experts Exchange video Micro Tutorial shows how to tell Microsoft Office that a word is NOT spelled correctly. Microsoft Office has a built-in, main dictionary that is shared by Office apps, including Excel, Outlook, PowerPoint, and Word. When …
Internet Business Fax to Email Made Easy - With eFax Corporate (http://www.enterprise.efax.com), you'll receive a dedicated online fax number, which is used the same way as a typical analog fax number. You'll receive secure faxes in your email, fr…

911 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

27 Experts available now in Live!

Get 1:1 Help Now