Azure AD Connect swing migration when using ADFS

Ruslan Nalivaika 101 Reputation points
2023-01-20T11:54:50.6566667+00:00

Hi, one of my customers runs an old version of Azure AD Connect with ADFS. I were planing to build a new AADC server and set it to staging mode to do a "swing" migration.

But when configuring new AADC, I am presented with a list of UPN suffixes used in the domain and I have to choose which one to federate with Azure AD. I was not expecting this, as all the UPN suffixes in the list are already federated by using the old AADC server. Is it safe to just let the wizard federate again, or will this break federation activated on the old server? Or is the process for swing migration when using ADFS different than when not using ADFS? Switching away from ADFS to other authentication is not relevant yet. Thanks, Ruslan

Active Directory Federation Services
Active Directory Federation Services
An Active Directory technology that provides single-sign-on functionality by securely sharing digital identity and entitlement rights across security and enterprise boundaries.
955 questions
Azure Active Directory
Azure Active Directory
An Azure enterprise identity service that provides single sign-on and multi-factor authentication.
12,713 questions
No comments
{count} votes

2 answers

Sort by: Most helpful
  1. BOURBITA Thameur 12,241 Reputation points Microsoft MVP
    2023-01-20T18:26:00.87+00:00

    Hi @Ruslan Nalivaika

    For your information, in a hybrid environment, you can install only one or two adconnect servers for each azure tenant.

    Instaling 2 adconnect servers is required to ensure the high availability.

    The both adconnect servers must have the same configuration, however you must keep only one active server ( with disabled staging mode).
    In case of a problem on the active server you can switch to the second server (with enabled staging mode) by deactivating the staging mode.

    Regarding your question, you must keep the same ADFS configuration, there will be no conflict between the two adconnect servers since the second server is always in staging mode and when you switch to second server (by disabling staging mode on second server and enabling it on old server) you will keep the same configuration adconnect for synchronisation and federation. Import and export Azure AD Connect configuration settings

    Please don't forget to mark helpful answer as accepted

    No comments

  2. Mark Morowczynski 171 Reputation points Microsoft Employee
    2023-01-21T01:26:00.5633333+00:00

    [https://learn.microsoft.com/en-us/azure/active-directory/hybrid/how-to-connect-sync-staging-server is how to setup the staging server.

    What is requiring you to keep using ADFS?

    No comments