Folks,
I have a couple of questions about AADDS:
Does Azure Active Directory Domain Services (AADDS) support custom schema extensions?
Would you describe AADDS as a globally shared AD Forest with a managed domain for my org?
Lisa
Folks,
I have a couple of questions about AADDS:
Does Azure Active Directory Domain Services (AADDS) support custom schema extensions?
Would you describe AADDS as a globally shared AD Forest with a managed domain for my org?
Lisa
Hello Lisa ,
Please find the answers. Azure AD domain services is a managed Active Directory instance with the main goal to provide Legacy authentication capabilities (for legacy apps which use Kerberos , NTLM) in the cloud so that anyone who would like to completely migrate to Azure and remove on-premise active directory could life and shift the on-prem application servers as is , and have the benefits of legacy auth protocols in the cloud. So as for your answer , please find the below.
No , It does not support custom schema extensions. Extending schema is not a permitted operation on the AAD Domain Services instance.
Not exactly . Each instance is unique to one customer and part of a larger globally shared AD in the backend. Whenever you enable Azure AD domain services, a new restricted Domain Controller for the domain name you have provided during initial configuration , is created. The difference from on-premise AD is that you do not get complete flexibility to change and modify the domain controller settings as you would be able to do in your on-prem Domain controller. This is because it was never created for making it a feature-by-feature replacement for on-premise AD. If you require completely similar control in the cloud then we suggest you to create Azure VMs and promote them to domain controllers . You may have to setup a site-to-site VPN for the same between your on-prem location and the Azure using Azure gateway / Azure VPN.
Hope this clarifies your queries. I have added some links to my answer , please check the same. Also I would encourage you to go through the complete FAQ for the Azure AD domain Services and I am sure a lot of your queries could get answered automatically. In case the above information in the post helps you , please do mark it as answer so that it can help others in the community searching for same answers.
Thank you.
@LisaLownds-9214 Please let us know if the above answers your query. In case it dos , please do mark it as answer . In case you have any related query , we will be happy to help . for any other issue we would request you to open a new thread and we will gladly help you.
9 people are following this question.
Azure AD joined devices // ADSystemInfo call cannot locate DC
error to finish install AD CONNECT
What is the difference between Azure Active Directory and Azure Active Directory Domain Services?
Domain Controller in Azure also need FW rules to allow on-premises authentications
How to achieve high availability in ADFS across Azure and On Prem Data centre