Azure AD Connect swing migration when using ADFS

Ruslan Nalivaika 106 Reputation points
2023-01-20T11:54:50.6566667+00:00

Hi, one of my customers runs an old version of Azure AD Connect with ADFS. I were planing to build a new AADC server and set it to staging mode to do a "swing" migration.

But when configuring new AADC, I am presented with a list of UPN suffixes used in the domain and I have to choose which one to federate with Azure AD. I was not expecting this, as all the UPN suffixes in the list are already federated by using the old AADC server. Is it safe to just let the wizard federate again, or will this break federation activated on the old server? Or is the process for swing migration when using ADFS different than when not using ADFS? Switching away from ADFS to other authentication is not relevant yet. Thanks, Ruslan

Active Directory Federation Services
Active Directory Federation Services
An Active Directory technology that provides single-sign-on functionality by securely sharing digital identity and entitlement rights across security and enterprise boundaries.
1,221 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
20,491 questions
0 comments No comments
{count} vote

2 answers

Sort by: Most helpful
  1. Thameur-BOURBITA 32,626 Reputation points
    2023-01-20T18:26:00.87+00:00

    Hi @Ruslan Nalivaika

    For your information, in a hybrid environment, you can install only one or two adconnect servers for each azure tenant.

    Instaling 2 adconnect servers is required to ensure the high availability.

    The both adconnect servers must have the same configuration, however you must keep only one active server ( with disabled staging mode).
    In case of a problem on the active server you can switch to the second server (with enabled staging mode) by deactivating the staging mode.

    Regarding your question, you must keep the same ADFS configuration, there will be no conflict between the two adconnect servers since the second server is always in staging mode and when you switch to second server (by disabling staging mode on second server and enabling it on old server) you will keep the same configuration adconnect for synchronisation and federation. Import and export Azure AD Connect configuration settings

    Please don't forget to mark helpful answer as accepted

    0 comments No comments

  2. Mark Morowczynski 251 Reputation points Microsoft Employee
    2023-01-21T01:26:00.5633333+00:00

    [https://learn.microsoft.com/en-us/azure/active-directory/hybrid/how-to-connect-sync-staging-server is how to setup the staging server.

    What is requiring you to keep using ADFS?

    0 comments No comments