Azure AD and On Prem AD

Jeff Garrison 1 Reputation point
2022-01-04T18:32:30.38+00:00

Okay...new year, new project.
The setup - some on prem users needing access to corp resources, some external users needing access to email only, running Azure AD Sync, Azure Azure Active Directory Premium P1

My question - do I even need to set up the external users in the on prem AD? The only thing they will need access to is their email. They will not need access to the corp network. My assumption is that I will continue setting up the the users that need corp access the way I currently do....New User, Proxy attributes, sync.

If I'm putting those external users in Azure, I shouldn't need to AAD P1 licenses either, correct?

If my thinking is correct, how do I move the external users from on prem to AAD while retaining all of their information?

Thanks.

Windows for business | Windows Client for IT Pros | Directory services | Active Directory
Microsoft Security | Microsoft Entra | Microsoft Entra ID
0 comments No comments
{count} votes

2 answers

Sort by: Most helpful
  1. Limitless Technology 39,926 Reputation points
    2022-01-05T14:00:15.927+00:00

    Hello @Jeff Garrison

    First you will need to activate the Azure AD Sync for the created AD, from the left pane select Active Directory, then in the Active Directory page, click the Azure AD and select the DIRECTORY INTEGRATION menu. Then click ACTIVATED and finally click SAVE to confirm the changes.

    Then Download and Install Azure AD Sync tool in on-premise AD:

    1. From your on-premise windows server, login to windows azure management console.
    2. Now from the left pane select Active Directory, then in the Active Directory page, click the Azure AD and select the DIRECTORY INTEGRATION menu.
    3. In the DIRECTORY INTEGRATION menu, scroll to bottom section and download the Directory Sync tool.
    4. Both the installation and setup process are very intuitive.

    Last, test your AD synchronization, for example creating a new user in your onprem AD and it should be in Azure ID Active Directory > Azure AD > Users

    Also, here is a list of attributes that will be replicated between AD and AAD:
    https://social.technet.microsoft.com/wiki/contents/articles/19901.dirsync-list-of-attributes-that-are-synced-by-the-azure-active-directory-sync-tool.aspx

    Hope this helps with your query,

    ----------

    --If the reply is helpful, please Upvote and Accept as answer--

    1 person found this answer helpful.
    0 comments No comments

  2. Vasil Michev 119.7K Reputation points MVP Volunteer Moderator
    2022-01-05T07:17:04.003+00:00

    "External users" (Guests) cannot have a mailbox in Exchange Online, you need a regular user account for that. There's no requirement to have it created in on-premises AD though, you can do so directly in Azure AD. No need for AAD P1 either, just Exchange Online license.

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.