Source Environment Expectations

When you use the FastTrack Center Benefit for Enterprise Mobility + Security (EMS) to get Microsoft Azure Active Directory Premium and Microsoft Intune ready for use, your environment needs to meet the expectations described in the following sections.

You may already have Microsoft Active Directory on-premises in your current environment that you want to integrate with EMS or any of its individual services for leveraging rich identity management from a single console. The FastTrack Center Benefit includes helping you integrate Azure AD with your existing on-premises implementation. If integration is required, your source environment must meet the minimum level for that application.

The following table shows expectations for your existing source environment for onboarding.

Activity Source environment expectation
Core onboarding Active Directory forests with the functional forest level set to Windows Server 2008 or above, with the following forest configuration:

- Single Active Directory forest
- Multiple Active Directory forests

Note: For all multiple forests configurations, Active Directory Federation Services (AD FS) deployment is out of scope for the FastTrack Center Benefit.
Azure AD Premium onboarding The on-premises Active Directory and its environment have been prepared for Azure AD Premium, which includes remediation of identified issues that prevent integration with Azure AD and Azure AD Premium features.
Intune, cloud only or integrated with System Center Configuration Manager, onboarding For device management with Configuration Manager 2012 R2 or later, connected with Intune, IT admins need to follow the Administrator Checklist: Configuring Configuration Manager to Manage Mobile Devices by Using Microsoft Intune.
Note: The service benefit doesn't include assistance for setting up or upgrading Configuration Manager to the minimum requirements needed for Microsoft Intune integration with Configuration Manager.

For WiFi and VPN profile deployment, IT admins need to have existing Certificate Authority, WiFi and VPN infrastructures already working in their production environments.

Note: The service benefit doesn’t include assistance for setting up or configuring Certificate Authorities, WiFi or VPN infrastructures.
Intune in Azure administration experience In December 2016, Microsoft Intune announced the public preview of its new Intune admin experience in the Azure Portal (, commonly referred to as Intune on Azure.

During the public preview period, onboarding support for Intune on Azure will be provided as a best effort only. Full onboarding support will continue for the existing administrative console (

FastTrack will fully support the Intune on Azure experience once it’s made generally available later this year.

Want to learn more?

Enterprise Mobility + Security