Can OnPrem servers use Azure AD for authentication??

Lukáš Adamík 1 Reputation point
2021-10-07T08:35:58.913+00:00

I'm considering if we can remove completely OnPrem AD and use only Azure AD for clients and Server authentication.. We want to have some terminal servers OnPrem but completely decommission OnPrem AD (AD DS).. Any suggestions??

Windows Server
Windows Server
A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.
12,122 questions
Active Directory
Active Directory
A set of directory-based technologies included in Windows Server.
5,851 questions
Microsoft Entra
0 comments No comments
{count} votes

3 answers

Sort by: Most helpful
  1. Paul van Berlo 821 Reputation points
    2021-10-07T08:41:48.36+00:00

    Hello @Lukáš Adamík and welcome to Q&A!

    Technically this can be done by leveraging Azure AD DS and extending access to On Prem servers using some kind of site to site VPN like ExpressRoute. Azure AD DS provides a managed experience which resembles Windows AD.


  2. Alan Kinane 16,786 Reputation points MVP
    2021-10-07T08:48:48.47+00:00

    If you are using terminal server/RDS then you will still need AD for authentication and most likely for other things like group policies, NTFS permissions on SMB shares etc. There are many organisations looking to remove AD but it's often quite challenging unless you are moving fully to the cloud.


  3. Limitless Technology 39,351 Reputation points
    2021-10-08T07:46:39.447+00:00

    Hello,

    Thank you for your question.

    You can remove completely OnPrem AD , if you do not have any OnPrem clients or if you are not using any Local AD related roles for example. DFS, DNS, File shares, Hyper-V , Group policies etc.

    Azure Active Directory is not designed to be the cloud version of Active Directory. It is not a domain controller or a directory in the cloud that will provide the exact same capabilities with AD. It actually provides many more capabilities in a different way.

    Please also note that removing of completely OnPrem AD domain will required some additional configurations on network and configuring Azure VPN which will chargable.

    Please have a look on below Microsoft threads and articles.

    https://techcommunity.microsoft.com/t5/azure-active-directory-identity/migrating-on-prem-ad-to-azure-ad-and-doing-away-completely-with/m-p/1226118

    https://learn.microsoft.com/en-us/answers/questions/50525/moving-on-prem-ad-ds-to-aad-ds-migration-required.html

    -------------------------------------------------------------------------------------------------------------------------

    --If the reply is helpful, please Upvote and Accept as answer--

    0 comments No comments