AAD dilemma: Replace local AD or sync/federate between local AD & AAD

Sebring 41 Reputation points
2021-08-03T04:31:03.713+00:00

Background

Currently the customer is running everything on premise ie local AD, DC, Exchange2010 and Payroll system. Customer wish to migrate their Exchange to exchange Onlne however concerned how their other existing stuff will work. Staff currently VPN into corp LAN and access their domain with their DC before authenticating via their local AD to access their payroll system.

Dilemma

Could AAD replace their local AD to do all above tasks? Or must Sync or federate AAD & local AD?

Thank you in advance:)

Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
19,436 questions
0 comments No comments
{count} votes

Accepted answer
  1. AmanpreetSingh-MSFT 56,306 Reputation points
    2021-08-03T07:24:40.887+00:00

    Hi @Sebring · Thank you for reaching out.

    The recommendation is to sync the identities from On-premises AD to Azure AD first. Even for federation between AAD & local AD to work, identities must be synchronized.

    For payroll system, you need to first check which authentication protocols it support. If it supports modern authentication protocols, such as SAML, OAuth/OIDC etc., it can directly be federated and get authenticated with Azure AD. If it supports only the legacy authentication protocols, such as Kerberos or NTLM, you need to either keep local AD in place or choose to go with Azure AD Domain Services, which will consume the amount from your Azure Subscription.

    -----------------------------------------------------------------------------------------------------------

    Please "Accept the answer" if the information helped you. This will help us and others in the community as well.


2 additional answers

Sort by: Most helpful
  1. Sebring 41 Reputation points
    2021-08-24T06:48:02.057+00:00

    Hi Amanpreet,

    I've read thru and it makes sense now. Your info is particular important as alot of customers are now forced into a hybrid working environment due to lockdown.

    0 comments No comments

  2. Sebring 41 Reputation points
    2021-08-26T09:05:22.593+00:00

    Hi Amanpreet,

    If devices need to be hybrid joined (ie registered with AAD) then does it also require MDM (Intune or 3rd party)?

    Link below suggest you need MDM.

    https://learn.microsoft.com/en-us/windows/client-management/mdm/azure-active-directory-integration-with-mdm

    Many Thanks.