question

NamlessShelter-6097 avatar image
0 Votes"
NamlessShelter-6097 asked sikumars commented

Move Azure AD Connect to a different server

Dear Friends,

Currently, we have a dedicated Azure AD Sync server set up in a WIndow server 2012 R2 box for Directory sync (1600 + users and SCCM & InTune Co-managed Computers) to Office 365 and Azure services.

Now we would like move this service to another server 2019 box. Should we just install AzureADConnect.exe on server 2019, and set it up to point to our Tenant? And remove the old Azure AD sync service on the old server and power off? What else need to be done?

Thanks a lot,
ML

azure-ad-connect
· 1
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

@NamlessShelter-6097,
Just checking in to see if the below answer helped. If this answers your query, please don’t forget to click "Accept the answer" and Up-Vote for the same, which might be beneficial to other community members reading this thread. And, if you have any further query do let us know.

0 Votes 0 ·
CristianSPIRIDON72 avatar image
1 Vote"
CristianSPIRIDON72 answered NamlessShelter-6097 commented

Hi NamlessShelter-6097,

What you need to do is install the other server în staging mode. Please, see following tutorial about how the set it up and how to switch between the two:

https://docs.microsoft.com/en-us/azure/active-directory/hybrid/how-to-connect-sync-staging-server

Hope this helps!

· 4
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

Staging Server sounds good. So I guess I have to make the old server into staging as well during cut over, and cancel the staging for the new server? Is this the right order?

Also, how much down time is allowed if we lost both Sync servers? Office 365 will move everything into "retention"?

Thanks,
ML

0 Votes 0 ·

Hi,

Regarding switch over you stated the right order: move the old server into staging and cancel staging
from the new one.

During the switch you will not be able to sych changes between on prem and Azure. As explained by @sikumars-msft everything else will work as normal.

Hope this helps!

1 Vote 1 ·

Hi It does certainly thanks very much,

this is what I did:

Install Azure AD syn connector on the new server DS02, make it staging server, import all configs from old server DS01. I can tell it has created a new user Sync_DS02_xxxx....The old user is Sync_DS01_xxxxx

And I Changed the old Sync server into Staging server and powered it off.

Now on my Office 365 user management, it is still syncing with this user Sync_DS01_ , why is this?

Thanks
ML

0 Votes 0 ·

Also, if we change our Domain Controller's roles to a different DC server, it will not affect Azure Sync, am I right?

Thanks

0 Votes 0 ·
sikumars avatar image
0 Votes"
sikumars answered sikumars commented

Hello @NamlessShelter-6097,

Thanks for reaching out.

Yes, as @CristianSPIRIDON72 mentioned, you need to setup stagging server and ensure configurations are same on both the servers using CSAnalyzer and then you can switch over the older server into staging and new server as production.

In addition, there's no retention specific with synchronized objects when Azure AD connect servers are idle but new users onboarding to Azure AD and Sync server-dependent services would be impacted during downtime such as writeback functionality including SSPR , Hybrid device registration to with Azure AD (Only new devices). However, existing users and device objects continue to experience SSO as expected without any issue. Hope this helps.


Please "Accept the answer" if the information helped you. This will help us and others in the community as well.

· 5
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

Thanks for that.

Also, how I can export from old Azure AD connect, and import to the new AD connect server?

Thanks
Mang

0 Votes 0 ·

Dont worry I found it. Now I set up the new Server as Staging.

So what I will do for the rest is to delete AD sync service from old Server, and cancel staging on the server? Am I right?

Thanks
ML

0 Votes 0 ·

Also, if we change our Domain Controller's roles to a different DC server, it will not affect Azure Sync, am I right?

Thanks

0 Votes 0 ·

Any response?

Thanks
ML

0 Votes 0 ·
sikumars avatar image sikumars NamlessShelter-6097 ·

@ @NamlessShelter-6097,

Sorry for delayed response. Please find my inline answers. Feel free to tag me if you have any questions. Happy to help.


So what I will do for the rest is to delete AD sync service from old Server, and cancel staging on the server? Am I right?

Yes, you are right.

if we change our Domain Controller's roles to a different DC server, it will not affect Azure Sync, am I right?

Yes, changing Domain Controller's roles to a different DC server shouldn't impact Azure AD connect functionality as long as Azure AD connect has connection with working DC in given forest.


0 Votes 0 ·