教學課程:將 Windows Server 虛擬機器加入 Azure Active Directory Domain Services 受控網域Tutorial: Join a Windows Server virtual machine to an Azure Active Directory Domain Services managed domain

Azure Active Directory Domain Services (Azure AD DS) 提供受控網域服務,例如:網域加入、群組原則、LDAP、Kerberos/NTLM 驗證,與 Windows Server Active Directory 完全相容。Azure Active Directory Domain Services (Azure AD DS) provides managed domain services such as domain join, group policy, LDAP, Kerberos/NTLM authentication that is fully compatible with Windows Server Active Directory. 使用 Azure AD DS 受控網域,您就可以在 Azure 中提供虛擬機器 (VM) 的網域加入功能和管理。With an Azure AD DS managed domain, you can provide domain join features and management to virtual machines (VMs) in Azure. 此教學課程說明如何建立 Windows Server VM,然後將其加入受控網域。This tutorial shows you how to create a Windows Server VM then join it to a managed domain.

在本教學課程中,您會了解如何:In this tutorial, you learn how to:

  • 建立 Windows Server VMCreate a Windows Server VM
  • 將 Windows Server VM 連線到 Azure 虛擬網路Connect the Windows Server VM to an Azure virtual network
  • 將 VM 加入受控網域Join the VM to the managed domain

如果您沒有 Azure 訂用帳戶,請先建立帳戶再開始。If you don't have an Azure subscription, create an account before you begin.

必要條件Prerequisites

若要完成此教學課程,您需要下列資源:To complete this tutorial, you need the following resources:

如果您已經有想要加入網域的 VM,請跳至將 VM 加入受控網域一節。If you already have a VM that you want to domain-join, skip to the section to join the VM to the managed domain.

登入 Azure 入口網站Sign in to the Azure portal

在此教學課程中,您會使用 Azure 入口網站建立 Windows Server VM,以加入您的受控網域。In this tutorial, you create a Windows Server VM to join to your managed domain using the Azure portal. 若要開始使用,請先登入 Azure 入口網站To get started, first sign in to the Azure portal.

建立 Windows Server 虛擬機器Create a Windows Server virtual machine

為了解如何將電腦加入受控網域,讓我們建立 Windows Server VM。To see how to join a computer to a managed domain, let's create a Windows Server VM. 此 VM 會連線到可與受控網域連線的 Azure 虛擬網路。This VM is connected to an Azure virtual network that provides connectivity to the managed domain. 加入受控網域的程序,與加入一般內部部署 Active Directory Domain Services 網域的程序相同。The process to join a managed domain is the same as joining a regular on-premises Active Directory Domain Services domain.

如果您已經有想要加入網域的 VM,請跳至將 VM 加入受控網域一節。If you already have a VM that you want to domain-join, skip to the section to join the VM to the managed domain.

  1. 從 Azure 入口網站功能表或 [首頁] 頁面,選取 [建立資源]****。From the Azure portal menu or from the Home page, select Create a resource.

  2. 從 [開始使用]**** 中,選擇 [Windows Server 2016 Datacenter]****。From Get started, choose Windows Server 2016 Datacenter.

    選擇在 Azure 入口網站中建立 Windows Server 2016 Datacenter VM

  3. 在 [基本]**** 視窗中,設定虛擬機器的核心設定。In the Basics window, configure the core settings for the virtual machine. 保留 [可用性選項]、[映像] 及 [大小]** 的預設設定。Leave the defaults for Availability options, Image, and Size.

    參數Parameter 建議的值Suggested value
    資源群組Resource group 選取或建立資源群組,例如 myResourceGroupSelect or create a resource group, such as myResourceGroup
    虛擬機器名稱Virtual machine name 輸入 VM 的名稱,例如 myVMEnter a name for the VM, such as myVM
    區域Region 選擇要在其中建立 VM 的區域,例如「美國東部」**Choose the region to create your VM in, such as East US
    使用者名稱Username 輸入要在 VM 上建立之本機系統管理員帳戶的使用者名稱,例如 azureuserEnter a username for the local administrator account to create on the VM, such as azureuser
    密碼Password 輸入要在 VM 上建立的本機系統管理員安全密碼,然後確認。Enter, and then confirm, a secure password for the local administrator to create on the VM. 請勿指定網域使用者帳戶的認證。Don't specify a domain user account's credentials.
  4. 根據預設,您可以使用 RDP 從網際網路存取 Azure 中所建立的 VM。By default, VMs created in Azure are accessible from the Internet using RDP. 啟用 RDP 時,可能會發生自動化登入攻擊,這可能會因為多次失敗的後續登入嘗試而停用具有一般名稱 (例如 adminadministrator) 的帳戶。When RDP is enabled, automated sign in attacks are likely to occur, which may disable accounts with common names such as admin or administrator due to multiple failed successive sign in attempts.

    RDP 應該只在必要時啟用,而且僅限於一組已授權的 IP 範圍。RDP should only be enabled when required, and limited to a set of authorized IP ranges. 此設定可協助改善 VM 的安全性,並減少潛在攻擊的範圍。This configuration helps improve the security of the VM and reduces the area for potential attack. 或者,請建立和使用只允許透過 TLS 從 Azure 入口網站存取的 Azure Bastion 主機。Or, create and use an Azure Bastion host that allows access only through the Azure portal over TLS. 在此教學課程的下一個步驟中,您需要使用 Azure Bastion 主機安全地連線到 VM。In the next step of this tutorial, you use an Azure Bastion host to securely connect to the VM.

    在 [公用輸入連接埠]**** 底下,選取 [無]**。Under Public inbound ports, select None.

  5. 完成時,請選取 [下一步:**** 磁碟]。When done, select Next: Disks.

  6. 從 [OS 磁碟類型]**** 的下拉式功能表中,選擇 [標準 SSD]**,然後選取 [下一步:**網路]** 。From the drop-down menu for OS disk type, choose Standard SSD, then select Next: Networking.

  7. 您的 VM 必須連線到可與受控網域部署所在子網路通訊的 Azure 虛擬網路子網路。Your VM must connect to an Azure virtual network subnet that can communicate with the subnet your managed domain is deployed into. 我們建議將受控網域部署到其自身的專用子網路。We recommend that a managed domain is deployed into its own dedicated subnet. 請勿將您的 VM 部署在與受控網域相同的子網路中。Don't deploy your VM in the same subnet as your managed domain.

    有兩種主要方式可部署您的 VM,並連線到適當的虛擬網路子網路:There are two main ways to deploy your VM and connect to an appropriate virtual network subnet:

    • 在與受控網域部署所在相同的虛擬網路中建立子網路或選取現有的子網路。Create a, or select an existing, subnet in the same the virtual network as your managed domain is deployed.
    • 使用 Azure 虛擬網路對等互連,在 Azure 虛擬網路中選取與其連線的子網路。Select a subnet in an Azure virtual network that is connected to it using Azure virtual network peering.

    如果您選取的虛擬網路子網路未連線到受控網域的子網路,您就無法將 VM 加入受控網域。If you select a virtual network subnet that isn't connected to the subnet for your managed domain, you can't join the VM to the managed domain. 在此教學課程中,我們將在 Azure 虛擬網路中建立新的子網路。For this tutorial, let's create a new subnet in the Azure virtual network.

    在 [網路]**** 窗格中,選取受控網域部署所在的虛擬網路,例如 aaads-vnetIn the Networking pane, select the virtual network in which your managed domain is deployed, such as aaads-vnet

  8. 在此範例中,會顯示受控網域連線至的現有 aaads-subnetIn this example, the existing aaads-subnet is shown that the managed domain is connected to. 請勿將您的 VM 連線到此子網路。Don't connect your VM to this subnet. 若要建立 VM 的子網路,請選取 [管理子網路設定]****。To create a subnet for the VM, select Manage subnet configuration.

    選擇以在 Azure 入口網站中管理子網路設定

  9. 在虛擬網路視窗的左側功能表中,選取 [位址空間]****。In the left-hand menu of the virtual network window, select Address space. 建立虛擬網路時,會使用預設子網路所使用的單一位址空間 10.0.2.0/24The virtual network is created with a single address space of 10.0.2.0/24, which is used by the default subnet. 其他適用於工作負載或 Azure Bastion 等的子網路也可能已經存在。Other subnets, such as for workloads or Azure Bastion may also already exist.

    將額外的 IP 位址範圍新增至虛擬網路。Add an additional IP address range to the virtual network. 此位址範圍的大小以及要使用的實際 IP 位址範圍,取決於已部署的其他網路資源。The size of this address range and the actual IP address range to use depends on other network resources already deployed. IP 位址範圍不應與您 Azure 或內部部署環境中任何現有的位址範圍重疊。The IP address range shouldn't overlap with any existing address ranges in your Azure or on-premises environment. 請確定您的 IP 位址範圍大小足以容納預期要部署到子網路中的 VM 數目。Make sure that you size the IP address range large enough for the number of VMs you expect to deploy into the subnet.

    在下列範例中,會新增額外的 IP 位址範圍 10.0.5.0/24In the following example, an additional IP address range of 10.0.5.0/24 is added. 在準備就緒時,選取 [儲存]****。When ready, select Save.

    在 Azure 入口網站中新增額外的虛擬網路 IP 位址範圍

  10. 接下來,在虛擬網路視窗的左側功能表中選取 [子網路]****,然後選擇 [+ 子網路]**** 以新增子網路。Next, in the left-hand menu of the virtual network window, select Subnets, then choose + Subnet to add a subnet.

  11. 選取 [+ 子網路]****,然後輸入子網路的名稱,例如 managementSelect + Subnet, then enter a name for the subnet, such as management. 提供 [位址範圍 (CIDR 區塊)]****,例如 10.0.5.0/24Provide an Address range (CIDR block), such as 10.0.5.0/24. 請確定此 IP 位址範圍不會與任何其他現有的 Azure 或內部部署位址範圍重疊。Make sure that this IP address range doesn't overlap with any other existing Azure or on-premises address ranges. 保留其他選項的預設值,然後選取 [確定]****。Leave the other options as their default values, then select OK.

    在 Azure 入口網站中建立子網路設定

  12. 建立子網路需要幾秒鐘的時間。It takes a few seconds to create the subnet. 建立之後,請選取 [X]** 以關閉子網路視窗。Once it's created, select the X to close the subnet window.

  13. 回到 [網路]**** 窗格以建立 VM,從下拉式功能表中選擇您建立的子網路,例如 managementBack in the Networking pane to create a VM, choose the subnet you created from the drop-down menu, such as management. 再次強調,請務必選擇正確的子網路,而且不要將 VM 部署在與受控網域相同的子網路中。Again, make sure you choose the correct subnet and don't deploy your VM in the same subnet as your managed domain.

  14. 對於公用 IP,請從下拉式功能表中選取 [無]**;因為您使用 Azure Bastion 連線到管理,因此不需要指派公用 IP 位址。For Public IP, select None from the drop-down menu, as you use Azure Bastion to connect to the management and don't need a public IP address assigned.

  15. 將其他選項保留為預設值,然後選取 [管理]****。Leave the other options as their default values, then select Management.

  16. 將 [開機診斷]**** 設定為 [關閉]**。Set Boot diagnostics to Off. 將其他選項保留為預設值,然後選取 [檢閱 + 建立]****。Leave the other options as their default values, then select Review + create.

  17. 檢閱 VM 設定,然後選取 [建立]****。Review the VM settings, then select Create.

建立 VM 需要幾分鐘的時間。It takes a few minutes to create the VM. Azure 入口網站會顯示部署的狀態。The Azure portal shows the status of the deployment. VM 準備就緒後,選取 [前往資源]****。Once the VM is ready, select Go to resource.

成功建立後,請移至 Azure 入口網站中的 VM 資源

連線到 Windows Server VMConnect to the Windows Server VM

若要安全地連線到 VM,請使用 Azure Bastion 主機。To securely connect to your VMs, use an Azure Bastion host. 使用 Azure Bastion 時,受控主機會部署至您的虛擬網路,並提供對於 VM 的 Web 型 RDP 或 SSH 連線。With Azure Bastion, a managed host is deployed into your virtual network and provides web-based RDP or SSH connections to VMs. VM 不需要公用 IP 位址,而且您不需要為外部遠端流量開啟網路安全性群組規則。No public IP addresses are required for the VMs, and you don't need to open network security group rules for external remote traffic. 您可以從網頁瀏覽器使用 Azure 入口網站來連線到 VM。You connect to VMs using the Azure portal from your web browser.

若要使用 Bastion 主機來連線到 VM,請完成下列步驟:To use a Bastion host to connect to your VM, complete the following steps:

  1. 在 VM 的 [概觀]**** 窗格中,依序選取 [連線]**** 和 [Bastion]****。In the Overview pane for your VM, select Connect, then Bastion.

    在 Azure 入口網站中使用 Bastion 連線到 Windows 虛擬機器

  2. 輸入您在上一節為 VM 指定的認證,然後選取 [連線]****。Enter the credentials for your VM that you specified in the previous section, then select Connect.

    在 Azure 入口網站中透過 Bastion 主機連線

如有需要,請允許網頁瀏覽器開啟快顯視窗以便顯示 Bastion 連線。If needed, allow your web browser to open pop-ups for the Bastion connection to be displayed. 需要幾秒鐘的時間才能連線到 VM。It takes a few seconds to make the connection to your VM.

將 VM 加入受控網域Join the VM to the managed domain

使用 Azure Bastion 建立了 VM 與 Web 型 RDP 連線之後,現在讓我們將 Windows Server 虛擬機器加入受控網域。With the VM created and a web-based RDP connection established using Azure Bastion, now let's join the Windows Server virtual machine to the managed domain. 此程序與連線到一般內部部署 Active Directory Domain Services 網域的電腦相同。This process is the same as a computer connecting to a regular on-premises Active Directory Domain Services domain.

  1. 如果 [伺服器管理員]**** 在您登入 VM 時並未預設為開啟狀態,請選取 [開始]**** 功能表,然後選擇 [伺服器管理員]****。If Server Manager doesn't open by default when you sign in to the VM, select the Start menu, then choose Server Manager.

  2. 在 [伺服器管理員]**** 視窗的左窗格中,選取 [本機伺服器]****。In the left pane of the Server Manager window, select Local Server. 在右窗格的 [屬性]**** 下,選擇 [工作群組]****。Under Properties on the right pane, choose Workgroup.

    在 VM 上開啟 [伺服器管理員] 並編輯工作群組屬性

  3. 在 [系統屬性]**** 視窗中,選取 [變更]**** 來加入受控網域。In the System Properties window, select Change to join the managed domain.

    選擇以變更工作群組或網域屬性

  4. 在 [網域]**** 方塊中,指定受控網域的名稱 (例如 aaddscontoso.com**),然後選取 [確定]****。In the Domain box, specify the name of your managed domain, such as aaddscontoso.com, then select OK.

    指定要加入的受控網域

  5. 輸入網域認證以加入網域。Enter domain credentials to join the domain. 請使用屬於受控網域一部分之使用者的認證。Use the credentials for a user that's a part of the managed domain. 帳戶必須是受控網域的一部分,或 Azure AD 租用戶。與您的 Azure AD 租用戶相關聯之外部目錄中的帳戶,在網域加入程序期間無法正確地進行驗證。The account must be part of the managed domain or Azure AD tenant - accounts from external directories associated with your Azure AD tenant can't correctly authenticate during the domain-join process. 帳戶認證可以利用下列其中一種方式來指定:Account credentials can be specified in one of the following ways:

    • UPN 格式 (建議) - 輸入 Azure AD 中所設定使用者帳戶的使用者主體名稱 (UPN) 尾碼。UPN format (recommended) - Enter the user principal name (UPN) suffix for the user account, as configured in Azure AD. 例如,使用者 contosoadmin 的 UPN 尾碼會是 contosoadmin@aaddscontoso.onmicrosoft.comFor example, the UPN suffix of the user contosoadmin would be contosoadmin@aaddscontoso.onmicrosoft.com. 有幾個常見的使用案例,其中 UPN 格式可以可靠地用來登入網域,而不是使用 SAMAccountName 格式:There are a couple of common use-cases where the UPN format can be used reliably to sign in to the domain rather than the SAMAccountName format:
      • 如果使用者的 UPN 前置詞太長 (例如 deehasareallylongname),就可能自動產生 SAMAccountNameIf a user's UPN prefix is long, such as deehasareallylongname, the SAMAccountName may be autogenerated.
      • 如果您的 Azure AD 租用戶中有多個使用者擁有相同的 UPN 前置詞 (例如 dee),則其 SAMAccountName 格式可能會自動產生。If multiple users have the same UPN prefix in your Azure AD tenant, such as dee, their SAMAccountName format might be autogenerated.
    • SAMAccountName 格式 - 以 SAMAccountName 格式輸入帳戶名稱。SAMAccountName format - Enter the account name in the SAMAccountName format. 例如,使用者 contosoadminSAMAccountName 會是 AADDSCONTOSO\contosoadminFor example, the SAMAccountName of user contosoadmin would be AADDSCONTOSO\contosoadmin.
  6. 需要幾秒鐘的時間才能加入受控網域。It takes a few seconds to join to the managed domain. 完成時,會有下列訊息歡迎您加入網域:When complete, the following message welcomes you to the domain:

    歡迎加入網域

    選取 [確定] **** 以繼續操作。Select OK to continue.

  7. 若要完成加入受控網域的程序,請重新啟動 VM。To complete the process to join to the managed domain, restart the VM.

提示

您可以使用 PowerShell 搭配 Add-Computer Cmdlet,將 VM 加入網域。You can domain-join a VM using PowerShell with the Add-Computer cmdlet. 下列範例會加入 AADDSCONTOSO** 網域,然後重新啟動 VM。The following example joins the AADDSCONTOSO domain and then restarts the VM. 出現提示時,請輸入屬於受控網域一部分之使用者的認證:When prompted, enter the credentials for a user that's a part of the managed domain:

Add-Computer -DomainName AADDSCONTOSO -Restart

若要在未連線的情況下將 VM 加入網域,並手動設定連線,您可以使用 Set-AzVmAdDomainExtension Azure PowerShell Cmdlet。To domain-join a VM without connecting to it and manually configuring the connection, you can use the Set-AzVmAdDomainExtension Azure PowerShell cmdlet.

Windows Server VM 重新啟動之後,在受控網域中套用的任何原則都會推送至 VM。Once the Windows Server VM has restarted, any policies applied in the managed domain are be pushed to the VM. 您現在也可以使用適當的網域認證來登入 Windows Server VM。You can also now sign in to the Windows Server VM using appropriate domain credentials.

清除資源Clean up resources

在下一個教學課程中,您會使用此 Windows Server VM 來安裝可讓您管理受控網域的管理工具。In the next tutorial, you use this Windows Server VM to install the management tools that let you administer the managed domain. 如果您不想要繼續進行此系列教學課程,請檢閱下列清除步驟來刪除 VMIf you don't want to continue in this tutorial series, review the following clean up steps to delete the VM. 否則,請繼續下一個教學課程Otherwise, continue to the next tutorial.

讓 VM 退出受控網域Un-join the VM from the managed domain

若要從受控網域中移除 VM,請再次執行下列步驟,將 VM 加入網域To remove the VM from the managed domain, follow through the steps again to join the VM to a domain. 這次請加入工作群組 (例如預設的 WORKGROUP),而不是加入受控網域。Instead of joining the managed domain, choose to join a workgroup, such as the default WORKGROUP. VM 重新開機之後,電腦物件就會從受控網域中移除。After the VM has rebooted, the computer object is removed from the managed domain.

如果您未先退出網域即刪除 VM,則孤立的電腦物件將會留在 Azure AD DS 中。If you delete the VM without unjoining from the domain, an orphaned computer object is left in Azure AD DS.

刪除 VMDelete the VM

如果您不打算使用此 Windows Server VM,請使用下列步驟來刪除 VM:If you're not going use this Windows Server VM, delete the VM using the following steps:

  1. 從左側功能表,選取 [資源群組]****From the left-hand menu, select Resource groups
  2. 選擇您的資源群組,例如 myResourceGroupChoose your resource group, such as myResourceGroup.
  3. 選擇您的 VM (例如 myVM),然後選取 [網路]****。Choose your VM, such as myVM, then select Delete. 選取 [是]**** 以確認刪除資源。Select Yes to confirm the resource deletion. 刪除 VM 需要幾分鐘的時間。It takes a few minutes to delete the VM.
  4. 刪除 VM 時,請選取具有 myVM- 首碼的 OS 磁碟、網路介面卡與任何其他資源,並將它們刪除。When the VM is deleted, select the OS disk, network interface card, and any other resources with the myVM- prefix and delete them.

針對網域加入問題進行疑難排解Troubleshoot domain-join issues

Windows Server VM 應該成功加入受控網域,其方式與一般內部部署電腦加入 Active Directory Domain Services 網域相同。The Windows Server VM should successfully join to the managed domain, the same way as a regular on-premises computer would join an Active Directory Domain Services domain. 如果 Windows Server VM 無法加入受控網域,則表示有連線能力或認證相關問題。If the Windows Server VM can't join the managed domain, that indicates there's a connectivity or credentials-related issue. 請參閱下列疑難排解小節,以成功加入受控網域。Review the following troubleshooting sections to successfully join the managed domain.

連線能力問題Connectivity issues

如果您未收到要求認證以加入網域的提示,表示發生連線問題。If you don't receive a prompt that asks for credentials to join the domain, there's a connectivity problem. VM 無法連線到虛擬網路上的受控網域。The VM can't reach the managed domain on the virtual network.

嘗試下列每個疑難排解步驟之後,請再次嘗試將 Windows Server VM 加入受控網域。After trying each of these troubleshooting steps, try to join the Windows Server VM to the managed domain again.

  • 確認 VM 已連線至已啟用 Azure AD DS 的相同虛擬網路,或具有對等互連網路連線。Verify the VM is connected to the same virtual network that Azure AD DS is enabled in, or has a peered network connection.
  • 嘗試 ping 受控網域的 DNS 網域名稱,例如 ping aaddscontoso.comTry to ping the DNS domain name of the managed domain, such as ping aaddscontoso.com.
    • 如果偵測要求失敗,請嘗試 ping 受控網域的 IP 位址,例如 ping 10.0.0.4If the ping request fails, try to ping the IP addresses for the managed domain, such as ping 10.0.0.4. 當您從 Azure 資源清單選取受控網域時,您的環境的 IP 位址會顯示在 [屬性]** 頁面上。The IP address for your environment is displayed on the Properties page when you select the managed domain from your list of Azure resources.
    • 如果您可以 ping 該 IP 位址,但無法 ping 網域,則表示 DNS 的設定可能不正確。If you can ping the IP address but not the domain, DNS may be incorrectly configured. 確認受控網域的 IP 位址是否設定為虛擬網路的 DNS 伺服器。Confirm that the IP addresses of the managed domain are configured as DNS servers for the virtual network.
  • 請嘗試使用 ipconfig /flushdns 命令排清虛擬機器上的 DNS 解析程式快取。Try to flush the DNS resolver cache on the virtual machine using the ipconfig /flushdns command.

如果您收到要求認證以加入網域的提示,但在您輸入那些認證之後發生錯誤,則 VM 可以連線到受控網域。If you receive a prompt that asks for credentials to join the domain, but then an error after you enter those credentials, the VM is able to connect to the managed domain. 您提供的認證不會讓 VM 加入受控網域。The credentials you provided don't then let the VM join the managed domain.

嘗試下列每個疑難排解步驟之後,請再次嘗試將 Windows Server VM 加入受控網域。After trying each of these troubleshooting steps, try to join the Windows Server VM to the managed domain again.

  • 確定您所指定的使用者帳戶屬於受控網域。Make sure that the user account you specify belongs to the managed domain.
  • 確認帳戶屬於受控網域或 Azure AD 租用戶。Confirm that the account is part of the managed domain or Azure AD tenant. 與您的 Azure AD 租用戶相關聯之外部目錄中的帳戶,在網域加入程序期間無法正確地進行驗證。Accounts from external directories associated with your Azure AD tenant can't correctly authenticate during the domain-join process.
  • 嘗試使用 UPN 格式來指定認證,例如 contosoadmin@aaddscontoso.onmicrosoft.comTry using the UPN format to specify credentials, such as contosoadmin@aaddscontoso.onmicrosoft.com. 如果您的租用戶中有許多使用者具有相同的 UPN 前置詞,或您的 UPN 前置詞太長,系統可能就會自動為您的帳戶產生 SAMAccountNameIf there are many users with the same UPN prefix in your tenant or if your UPN prefix is overly long, the SAMAccountName for your account may be autogenerated. 在這些情況下,您帳戶的 SAMAccountName 格式可能會與您在內部部署網域中預期或使用的格式不同。In these cases, the SAMAccountName format for your account may be different from what you expect or use in your on-premises domain.
  • 確認您已為受控網域啟用密碼同步化Check that you have enabled password synchronization to your managed domain. 如果沒有此設定步驟,所需的密碼雜湊就不會出現在受控網域中,以正確地驗證您的登入嘗試。Without this configuration step, the required password hashes won't be present in the managed domain to correctly authenticate your sign in attempt.
  • 等待密碼同步完成。Wait for password synchronization to be completed. 當使用者帳戶的密碼變更時,來自 Azure AD 的自動背景同步處理會更新 Azure AD DS 中的密碼。When a user account's password is changed, an automatic background synchronization from Azure AD updates the password in Azure AD DS. 需要一些時間,密碼才能用於加入網域。It takes some time for the password to be available for domain-join use.

後續步驟Next steps

在本教學課程中,您已了解如何:In this tutorial, you learned how to:

  • 建立 Windows Server VMCreate a Windows Server VM
  • 將 Windows Server VM 連線到 Azure 虛擬網路Connect to the Windows Server VM to an Azure virtual network
  • 將 VM 加入受控網域Join the VM to the managed domain

若要管理受控網域,請使用 Active Directory 管理中心 (ADAC) 設定管理 VM。To administer your managed domain, configure a management VM using the Active Directory Administrative Center (ADAC).