question

MarkosParaskevopulos-3855 avatar image
0 Votes"
MarkosParaskevopulos-3855 asked JamesHamil-MSFT answered

Azure AD - AD Connect existing tenant or new one?

Hi.
We're currently using AAD for M365 E3 (for emails and so on) on our primary company internet domain (let's call it company.com).
We have on-premise Active Directory domain ad.company.com and we want to configure Azure MFA for the on-premise AD (users). My question is, when connecting the on-prem AD with AAD using AD Connect, should I use the existing tenant with the company.com primary domain (and add another domain (in this case the ad.company.com) and sync to that (what will happen to the existing AAD users in this case?) or create a new tenant specifically for this?
If I should create new tenant, will we have to buy additional licenses to get conditional access for the synced users or will they be covered by the E3 subscription?

Thanks in advance

azure-active-directory
· 3
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

Hi, we are investigating your issue and will update you shortly.

Best,
James

0 Votes 0 ·

Hi @MarkosParaskevopulos-3855 , excuse me if I misunderstood the question but you already have an AAD domain and wish to sync it with your on-premise domain? If you just want to sync the 2 you don't need to create a new domain. Please let me know and I can help you further :)

Best,
James

0 Votes 0 ·

Hello James,
the thing is I do not want to sync on-prem AD with AAD per se, but as far as I'm aware, it's a requirement of Azure MFA (https://docs.microsoft.com/en-us/azure/active-directory/authentication/howto-mfa-getstarted#prerequisites), which we want to implement for the on-prem AD users to increase security for RDP logons to our infrastructure (using the scenario described here https://docs.microsoft.com/en-us/azure/active-directory/authentication/howto-mfa-nps-extension-rdg).

Since there are some concerns when syncing on-prem AD to AAD with existing users (https://docs.microsoft.com/en-us/azure/active-directory/hybrid/how-to-connect-install-existing-tenant), I was wondering what is the best practice in this scenario.

Again, current tenant (AAD) is used by our M365 E3 subscription and the primary domain is set to our company.com domain, on which we have emails.

0 Votes 0 ·

1 Answer

JamesHamil-MSFT avatar image
0 Votes"
JamesHamil-MSFT answered

Hi @MarkosParaskevopulos-3855 , given your environment you should look into integrating your on-prem AD domains with Azure AD. This guide details the process.

For your existing AAD users this document details what will happen: https://docs.microsoft.com/en-us/azure/active-directory/hybrid/how-to-connect-install-existing-tenant#sync-with-existing-users-in-azure-ad

I hope this helps!

If this answer helped you please mark it as "Verified" so other users may reference it.

Thank you,
James


5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.