?
Solved

Azure AD Connect

Posted on 2016-09-28
10
Medium Priority
?
42 Views
Last Modified: 2016-11-09
Hi,

I want to connect a clean windows server 2012 on a VPS to Azure AD. Do I have to create a domain first on the server 2012 before connecting? The reason is I want to install an SQL on the server 2012 in the cloud and have users logon to on-premise pc in the office and have access to all their online services.

Some help is appriciated.

Kind regards,
0
Comment
Question by:Lufaa
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 5
  • 4
10 Comments
 
LVL 59

Accepted Solution

by:
Cliff Galiher earned 2000 total points
ID: 41820819
That's the path of least resistance, yes.  Azure AD supports SAML and you could technically custom write code that ties into their APIs and get single sign-on as long as you have ADFS on-prem somewhere. But if you want to avoid coding or if you don't have ADFS, you are looking at some sort of coordination technology.
0
 
LVL 1

Author Comment

by:Lufaa
ID: 41820835
I don't think I quite understand what you are saying but now I am as far as that I cannot connect from my server 2012 with azure ad connect to my Azure AD
azure-ad-connect.JPG
0
 
LVL 59

Expert Comment

by:Cliff Galiher
ID: 41820868
AADConnect does exactly that. It "connects" ADDS (on-prem) to azure AD. Which means ADDS must be present a d accessible somewhere on the network (via layer 2, or VPN, or ezpressroute, or something.)

If you don't have ADDS then there is no reason to run AADConnect. You'd simply create new user accounts natively in azure AD.
0
Visualize your virtual and backup environments

Create well-organized and polished visualizations of your virtual and backup environments when planning VMware vSphere, Microsoft Hyper-V or Veeam deployments. It helps you to gain better visibility and valuable business insights.

 
LVL 1

Author Comment

by:Lufaa
ID: 41821226
Ok, so I created a AD on the new 2012 server. I was able, after some testing and trying, to run the AADConnect but I still don't see all the Azure AD users in my server? Seems like the sync has not completed. Anything I forgot to setup or make sure is ready before doing this?
0
 
LVL 59

Expert Comment

by:Cliff Galiher
ID: 41821274
Aadconnect syncs from server to Azure AD. Not the other way around. Your azure users will *never* suddenly appear on your server.
0
 
LVL 1

Author Comment

by:Lufaa
ID: 41821309
Ok, clear. What is the best way when creating a new user, for example for creating a user which has access to my SQL instance on the 2012 server? Because as I understood, my Office 365 users can logon to their Windows 10 Pro computers with their Office 365 account and with the server 2012 being connected the same users have single sign on feature for accessing the SQL server on this 2012 server.
0
 
LVL 59

Assisted Solution

by:Cliff Galiher
Cliff Galiher earned 2000 total points
ID: 41821317
There's a lot of planning and moving peices to get that working. If you don't want to change users' workflow m, you are looking at joining the devices to azure AD, ADFS, and UPN matching all your on-prem accounts, at the very least.

Given your kevel of familiarity with azure AD and AADConnect I'd suggest hiring a local azure developer to work with.
0
 
LVL 1

Author Comment

by:Lufaa
ID: 41829732
Hi Cliff,

Do you know a good one I can hire?

Kind regards
0
 
LVL 59

Expert Comment

by:Cliff Galiher
ID: 41830250
For these kinds of projects, as I said, it is often beat to hire local. Since I don't know where you are, no, I don't know anyone. Although to be fair, my answer probably will be the same even if I knew where you were.
0

Featured Post

Get your Conversational Ransomware Defense e‑book

This e-book gives you an insight into the ransomware threat and reviews the fundamentals of top-notch ransomware preparedness and recovery. To help you protect yourself and your organization. The initial infection may be inevitable, so the best protection is to be fully prepared.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

On Feb. 28, Amazon’s Simple Storage Service (S3) went down after an employee issued the wrong command during a debugging exercise. Among those affected were big names like Netflix, Spotify and Expedia.
There are times when we need to generate a report on the inbox rules, where users have set up forwarding externally in their mailbox. In this article, I will be sharing a script I wrote to generate the report in CSV format.
Migrating to Microsoft Office 365 is becoming increasingly popular for organizations both large and small. If you have made the leap to Microsoft’s cloud platform, you know that you will need to create a corporate email signature for your Office 365…
Access reports are powerful and flexible. Learn how to create a query and then a grouped report using the wizard. Modify the report design after the wizard is done to make it look better. There will be another video to explain how to put the final p…
Suggested Courses

752 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question