question

Brunsky-9289 avatar image
0 Votes"
Brunsky-9289 asked ·

How to achieve high availability in ADFS across Azure and On Prem Data centre

I am currently looking for a solution to achieve high availability for ADFS between a disaster recovery site in Azure and our core data centre on premise.

The ADFS is currently configured with split brain DNS so the internal users do not go through the WAP servers and go direct to the ADFS servers. I need to maintain this separation but in the event of a failure to my core site, i need the users to be redirected to Azure.

I am looking at Azure traffic manager to carry out the task, however, as the internal ADFS servers are not publicly accessible my understanding is that the probes will not work.

Has anybody got an experience with this scenario. Assistance would be greatly appreciated

azure-active-directoryazure-ad-domain-services
10 |1000 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

KAREDD-MSFT avatar image
0 Votes"
KAREDD-MSFT answered ·

@Brunsky-9289 You are correct. Azure traffic manager will not work in this scenario.

AFAIK, this has to be done manually. None of the Azure services available currently support this requirement. You can use the default ADFS probe to check the status continuously and trigger a script that updates the DNS towards your Azure site.

· Share
10 |1000 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

LukasBeran avatar image
1 Vote"
LukasBeran answered ·

I am not sure about your network design/architecture, but we do it with our customers like this. They have one/multiple onprem ADFS and WAP servers. And they have site-to-site (ExpressRoute) connectivity to Azure VNET, so the Azure VNET appears as their internal network. So they also have one/multiple ADFS and WAP servers in Azure. And in front of their ADFS and WAP servers they have Azure Traffic Managers (one in front of ADFS servers, one in front of WAP servers) that are used to monitor the health of the endpoints and provide automatic failover when an endpoint goes down.

Hope it helps.

· Share
10 |1000 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.