Link to home
Start Free TrialLog in
Avatar of Matthieu Thomas
Matthieu Thomas

asked on

Active Directory SMB Azure file share / External User / Active Directory Domain Controller over public IP ?

Hello,

Our project is to get rid of our ON-PREMISE NAS for file share and to move everything to AZURE FILE SHARE.
Also we have more and more external users and with the covid everyone is working from home.

For the moment we are using VPN + ONPREMISE MAPPING.

The project is to use AZURE FILE SHARE DIRECT MAPPING OVER SMB 3.1.1 and get rid of the VPN.

Everything works well for ON PREMISE USERS but EXTERNAL USERS can't connect because the need a validation from an AD CONTROLLER.

How bad it is to make the AD controller over public ip ? Which port shall I open ?

Mat
Avatar of Michael B. Smith
Michael B. Smith
Flag of United States of America image

I suggest you look at Direct Access.
Avatar of Matthieu Thomas
Matthieu Thomas

ASKER

Actually it won't work for me as we only use Windows 10 PRO.

he following is a complete list (as of this writing) of client operating systems that support DirectAccess.

Windows 10 Enterprise
Windows 10 Education
Windows 8.1 Enterprise
Windows 7 Enterprise
Windows 7 Ultimate
DirectAccess and Windows 10 Professional

If you are running a version of Windows that is not Enterprise edition (with the exception of Windows 7 Ultimate and Windows 10 Education) DirectAccess will not work. Be careful, because you can still provision non-Enterprise SKUs such as Windows 10 Professional for DirectAccess. All of the DirectAccess settings will be applied without issue and everything will look perfectly normal, but DirectAccess won’t work. The telltale sign on Windows 8.x and Windows 10 clients is that you won’t be able to start the Network Connectivity Assistant (NCA) service (NcaSvc). When you attempt to do so you will receive the following error message:

And creating a VM with an READ ONLY DOMAIN CONTROLLER ?
"Read only Active Directory
A read-only domain controller (RODC) is a server that hosts an Active Directory database's read-only partitions and responds to security authentication requests"
ASKER CERTIFIED SOLUTION
Avatar of Michael B. Smith
Michael B. Smith
Flag of United States of America image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial