Active Directory Consolidation

Tim Chapman 6 Reputation points Microsoft Employee
2021-09-29T00:35:47.473+00:00

The customer is a finance provider who has multiple Azure tenants across Direct (PAYG) and CSP. The Azure Active Directory is currently replicated from on-premise to the CSP tenant where a number of application and database services are located. The customer would like to consolidate their Azure AD domains services under a new domain in the direct PAYG tenant and has requested architetural guidance on best practice implementation.

Current and future state architecture diagrams are available and will be provided seperately.

Azure FastTrack
Azure FastTrack
Azure: A cloud computing platform and infrastructure for building, deploying and managing applications and services through a worldwide network of Microsoft-managed datacenters.FastTrack: This tag is no longer in use. Please use 'Azure Startups' instead.
75 questions
0 comments No comments
{count} vote

1 answer

Sort by: Most helpful
  1. Ravi Bakamwar 11 Reputation points
    2021-09-29T08:38:33.34+00:00

    Hi Tim,

    Apologies for responding with questions on your question :). Would like to clarify few things.

    By multiple tenants do you mean, they have multiple Azure subscriptions (CSP/PAYG) associated with different tenants ? (very common for CSP customers, where CSP sub is associated with CSPs own tenant (aka directory) and Cx's PAYG with their own tenants).

    When you say "Azure Active Directory is currently replicated from on-premise to the CSP tenant", I am assuming you mean the on-prem (traditional) Active Directory is synced to this tenant perhaps?

    Regarding the consolidation question, "Azure AD Domain Service (AADDS)" is a managed version of traditional AD. Do they have this AADDS instance in CSP tenant and the ask is to move to PAYG tenant ?

    Just for the sake of clarity:
    AD = Traditional AD (which provides LDAP/Kerberos/GPO etc etc)
    AAD = Tenant which is used for IAM for Azure/Office365 etc - Azure Subscriptions are associated with a tenant. (can only be linked to one AAD at a time)
    AADDS = a Managed version of traditional AD running in Azure where we (Microsoft) manages domain controllers and offers the traditional AD Service.

    What aspects of the identity services above needs to be consolidated ?

    1 person found this answer helpful.