{"id":2021,"date":"2020-03-03T01:00:00","date_gmt":"2020-03-03T01:00:00","guid":{"rendered":"http:\/\/inswwdev.azurewebsites.net\/au\/insights\/uncategorized\/aad-connect-and-beyond\/"},"modified":"2020-03-03T01:00:00","modified_gmt":"2020-03-03T01:00:00","slug":"aad-connect-and-beyond","status":"publish","type":"post","link":"https:\/\/www.insentragroup.com\/us\/insights\/geek-speak\/fasttrack\/aad-connect-and-beyond\/","title":{"rendered":"AAD Connect and Beyond"},"content":{"rendered":"<p>First came DirSync, then came AADSync and now it\u2019s and I\u2019m sure you\u2019ll agree with me that through each phase of Microsoft\u2019s identity synchronisation platform, we\u2019ve seen many changes for the greater good of mankind.<\/p>\n<p>Hey folks! Pure Awesomeness here and I\u2019m back again with a brand-new blog post about identity across the big wide world of Office 365 and Azure AD. You\u2019re probably wondering what more I can talk about as a follow up to my last blog \u2013 Identity \u2013 The Boss of All Bosses? Well, there\u2019s a new topic to talk about along the lines of identity synchronisation. You see, our good friends at Microsoft have been working on another way to synchronise identities to your Azure AD and although it\u2019s in preview mode, you, my fellow apprentice, can go through the configuration and deploy in your lab for testing. Do not under any circumstances deploy this new method in a production environment. It\u2019s exactly what the word \u201cpreview\u201d means. There are limitations with the product at the moment, so the best thing to do is:<\/p>\n<ul>\n<li>Deploy in a lab<\/li>\n<li>Test said deployment in a lab<\/li>\n<li>Try and break said deployment in a lab<\/li>\n<li>Provide feedback to Microsoft<\/li>\n<li>Sign up to Insentragram &#8211; oh you knew this was coming<\/li>\n<\/ul>\n<p>You can read more about the differences between Azure AD Connect and Azure AD Connect Cloud Provisioning <span><a rel=\"noopener nofollow\" href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/active-directory\/cloud-provisioning\/what-is-cloud-provisioning\" target=\"_blank\">here<\/a><\/span><\/p>\n<p>So, Pure Awesomeness, what is this new sync technology you keep talking about but haven\u2019t mentioned what it\u2019s called yet\u2026?<\/p>\n<p>Buckle up my apprentice. Here we go!<\/p>\n<h3 style=\"padding-bottom: 15px; margin-bottom: 30px; margin-top: 40px; border-bottom: 1px solid #f16020;\">Azure AD Connect Cloud Provisioning \u2013 easy to remember right?<\/h3>\n<p>So, what is it and how is it different to the other three sync technologies we\u2019ve been configuring over the years?<\/p>\n<p>With the huge adoption rate of Microsoft cloud services across the globe, it\u2019s only logical (admit it, you just read this out in Spock\u2019s voice) Microsoft will modernise the way identities are synchronised to the cloud. How do they envision this to be done? By removing the need for any heavy lifting from on-premises infrastructure to the cloud and replacing it with light weight agents. These agents communicate with Azure AD using the Azure AD Application Proxy to trigger the required sync jobs. Currently, this job relies solely on a single Azure AD Connect server installed in your on-premises network.<\/p>\n<p>What happens if this server were to go offline? If you had deployed another Azure AD Connect server in staging mode, excellent. You could leverage this bad boy to keep your identities in sync. If you had no staging server, uh oh (and yes, you just said this in the voice of the ICQ notification from way back in the day \u2013 shows my age!), you would have to implement a new Azure AD Connect server! And who has time for that???<\/p>\n<p>What does Azure AD Connect Cloud Provisioning bring to your organisation I hear you ask? At a first glance, High Availability (HA)! Installing multiple agents across your infrastructure will give your organisation the HA it needs to keep identity synchronisation ticking along in the event of an agent outage.<\/p>\n<p>Now, you purely awesome mad man, how do you go about deploying Azure AD Connect Cloud Provisioning? I thought you\u2019d never ask.<\/p>\n<p>The main thing to note is my lab contains a brand-new Active Directory forest and a brand-new Office 365 tenant. There are currently no identities being synchronised in any way, shape or form to the tenant.<\/p>\n<p>First thing\u2019s first; log into your Azure AD Admin Centre (aad.portal.azure.com) with your Global Administrator credentials and click on the Azure Active Directory blade from the list on the left-hand side and then navigate to the Azure AD Connect blade.<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.insentragroup.com\/wp-content\/uploads\/sites\/21\/2021\/02\/insentra_hambik_m_blogpost_02032020_img_01.jpg\" alt=\"\" data-udi=\"umb:\/\/media\/070a1de786644e81b38d8f7b2fb856af\" \/><\/p>\n<p>Next, click on Manage Provisioning (Preview)<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.insentragroup.com\/wp-content\/uploads\/sites\/21\/2021\/02\/insentra_hambik_m_blogpost_02032020_img_02.jpg\" alt=\"\" data-udi=\"umb:\/\/media\/324a1e72c9d04006884fad9292f22984\" \/><\/p>\n<p>Click on Download agent<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.insentragroup.com\/wp-content\/uploads\/sites\/21\/2021\/02\/insentra_hambik_m_blogpost_02032020_img_03.jpg\" alt=\"\" data-udi=\"umb:\/\/media\/2be75904fd914d3eb03d1ee809db44b0\" \/><\/p>\n<p>Before you proceed with the installation of the agent(s), ensure the following pre-requisites are met within your lab environment:<\/p>\n<ul>\n<li>Windows Server 2012 R2 or higher to install the agent on and yes, installing on a Domain Controller is supported<\/li>\n<li>.Net Framework 4.7.1 or higher<\/li>\n<li>Outbound TCP 80 and 443 access<\/li>\n<\/ul>\n<p>Now the fun part \u2013 installing and configuring the agent.<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.insentragroup.com\/wp-content\/uploads\/sites\/21\/2021\/02\/insentra_hambik_m_blogpost_02032020_img_04.jpg\" alt=\"\" data-udi=\"umb:\/\/media\/f6df6a529e104576927b66ad18ce623b\" \/><\/p>\n<p>When the agent has been installed, you\u2019ll be presented with the configuration wizard, which has less options than the Azure AD Connect wizard. The reason for this is the bulk of the configuration is completed within Azure AD. #winning<\/p>\n<p>To begin the wizard, enter in your Azure AD Global Admin credentials<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.insentragroup.com\/wp-content\/uploads\/sites\/21\/2021\/02\/insentra_hambik_m_blogpost_02032020_img_05.jpg\" alt=\"\" data-udi=\"umb:\/\/media\/fce51ad62e6e451da76661ad94595719\" \/><\/p>\n<p>Then, connect to your on-premises Active Directory environment<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.insentragroup.com\/wp-content\/uploads\/sites\/21\/2021\/02\/insentra_hambik_m_blogpost_02032020_img_06.jpg\" alt=\"\" data-udi=\"umb:\/\/media\/a7eece5f3b364c96a1cf96b7a347e45c\" \/><\/p>\n<p>Confirm the details and sit back and wait for the installation to complete<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.insentragroup.com\/wp-content\/uploads\/sites\/21\/2021\/02\/insentra_hambik_m_blogpost_02032020_img_07.jpg\" alt=\"\" data-udi=\"umb:\/\/media\/e8aa6816b8e84f8c8b7f3c16c6740652\" \/><\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.insentragroup.com\/wp-content\/uploads\/sites\/21\/2021\/02\/insentra_hambik_m_blogpost_02032020_img_08.jpg\" alt=\"\" data-udi=\"umb:\/\/media\/d0defb1aa4634b6587faca5a34f20a65\" \/><\/p>\n<p>Next on the list of tasks, review and make sure the agent has installed correctly and is reporting back with an active status. You can do this through the Review all agents tab.<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.insentragroup.com\/wp-content\/uploads\/sites\/21\/2021\/02\/insentra_hambik_m_blogpost_02032020_img_09.jpg\" alt=\"\" data-udi=\"umb:\/\/media\/defb3fa707e94013b1bbf993ec23d297\" \/><\/p>\n<p>Next, click on the New configuration tab to configure the newly installed agent<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.insentragroup.com\/wp-content\/uploads\/sites\/21\/2021\/02\/insentra_hambik_m_blogpost_02032020_img_10.jpg\" alt=\"\" data-udi=\"umb:\/\/media\/c6ee2bded2e843e6bea3a4dcf2a6f622\" \/><\/p>\n<p>Configure the options provided<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.insentragroup.com\/wp-content\/uploads\/sites\/21\/2021\/02\/insentra_hambik_m_blogpost_02032020_img_11.jpg\" alt=\"\" data-udi=\"umb:\/\/media\/501dcae3b67f416fbb07e19c163864f7\" \/><\/p>\n<p>The scope can be changed to one of the following:<\/p>\n<ul>\n<li>All users<\/li>\n<li>Selected security groups<\/li>\n<li>Selected organisational units<\/li>\n<\/ul>\n<p>When the configuration has been saved, you can then review the synchronisation logs to ensure successful jobs have occurred. You can also confirm by navigating to the Users blade in Azure AD. There, you will see your set of users \u00a0whic have successfully synced across based on the scope you selected in the configuration options above.<\/p>\n<p>But what about the HA functionality of the agents? Well, it\u2019s pretty straight forward. Given you\u2019ve already gone through and configured the sync settings for the first agent, all you need to do is download the agent on other servers within the domain and install it following the steps in this blog. Once the additional agents are installed successfully, they\u2019ll report back to Azure AD. The beauty of the additional agents is they deploy in an active\/active configuration. If one agent fails, the other takes over with the sync cycle!<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.insentragroup.com\/wp-content\/uploads\/sites\/21\/2021\/02\/insentra_hambik_m_blogpost_02032020_img_12.jpg\" alt=\"\" data-udi=\"umb:\/\/media\/f0bb993f1ecb4ae5a1281d0b6fc9324b\" \/><\/p>\n<p>\u00a0<span>Here\u2019s what you\u2019ll see when and if an agent goes offline:<\/span><\/p>\n<p><span><img decoding=\"async\" src=\"https:\/\/www.insentragroup.com\/wp-content\/uploads\/sites\/21\/2021\/02\/insentra_hambik_m_blogpost_02032020_img_13.jpg\" alt=\"\" data-udi=\"umb:\/\/media\/eb70ae86f0fa4e3bb627d2fcf73ea37a\" \/><\/span><\/p>\n<p>So, there you have it folks. Azure AD Connect Cloud Provisioning at a very high level. As it\u2019s still in preview mode, you\u2019re limited with what you can do with it for the time being but watch this space, as it matures, there will come a point where it could very well replace Azure AD Connect as a whole.<\/p>\n<p>Until next time, Pure Awesomeness signing off!<\/p>\n<p><em>\u00a0\u201cIf you want to live a happy life, tie it to a goal, not to people or things.\u201d \u2013 Albert Einstein <\/em><\/p>\n<p>\u00a0<\/p>\n","protected":false},"excerpt":{"rendered":"<p>First came DirSync, then came AADSync and now it\u2019s and I\u2019m sure you\u2019ll agree with me that through each phase of Microsoft\u2019s identity synchronisation platform, we\u2019ve seen many changes for the greater good of mankind. Hey folks! Pure Awesomeness here and I\u2019m back again with a brand-new blog post about identity across the big wide&hellip; <a class=\"more-link\" href=\"https:\/\/www.insentragroup.com\/us\/insights\/geek-speak\/fasttrack\/aad-connect-and-beyond\/\">Continue reading <span class=\"screen-reader-text\">AAD Connect and Beyond<\/span><\/a><\/p>\n","protected":false},"author":52,"featured_media":2022,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"content-type":"","footnotes":""},"categories":[23],"tags":[],"class_list":["post-2021","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-fasttrack","entry"],"_links":{"self":[{"href":"https:\/\/www.insentragroup.com\/us\/wp-json\/wp\/v2\/posts\/2021","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.insentragroup.com\/us\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.insentragroup.com\/us\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.insentragroup.com\/us\/wp-json\/wp\/v2\/users\/52"}],"replies":[{"embeddable":true,"href":"https:\/\/www.insentragroup.com\/us\/wp-json\/wp\/v2\/comments?post=2021"}],"version-history":[{"count":0,"href":"https:\/\/www.insentragroup.com\/us\/wp-json\/wp\/v2\/posts\/2021\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.insentragroup.com\/us\/wp-json\/wp\/v2\/media\/2022"}],"wp:attachment":[{"href":"https:\/\/www.insentragroup.com\/us\/wp-json\/wp\/v2\/media?parent=2021"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.insentragroup.com\/us\/wp-json\/wp\/v2\/categories?post=2021"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.insentragroup.com\/us\/wp-json\/wp\/v2\/tags?post=2021"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}