Entra AADDS Model for an almost 100% remote workforce.

Eddie F 0 Reputation points
2024-03-23T19:45:49.5433333+00:00

Hey All,

Long time listener, first time caller.

My question is regarding a situation I'm put in. I have always worked in an on-prem or hybrid environment. The company I'm in, has an almost 100% remote workforce. They brought me in to create a 100% cloud environment.

The first roadblock I'm encountering is joining all users to a domain. I have set up an Entra AADDS, and created a site-to-site VPN. I've managed to communicate with the DC VM that I created in Azure. I'm able to even test-join a VM that I created on-prem with the DC in the cloud.

What I haven't been able to do is join a non-prem machine to the cloud. I've created a VPN to HQ (fortigate) for the remote users, but they cannot seem to reach the DC. I can ping the DC, but it does not want to join the domain.

Is it something that's not supported? Do I have to do Azure Join? I much rather do domain join, because it much easier to manage than the mess in configuring InTune. I can't deal with the group policies that way. It's so frustrating.

I know that Entra has improved a lot with some the issues that ADDS used to have. I do not have plans or budget to put in an on-prem DC.

Any assistance would be helpful.

Azure VPN Gateway
Azure VPN Gateway
An Azure service that enables the connection of on-premises networks to Azure through site-to-site virtual private networks.
1,389 questions
Active Directory
Active Directory
A set of directory-based technologies included in Windows Server.
5,909 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
19,595 questions
{count} votes

2 answers

Sort by: Most helpful
  1. Marcin Policht 11,470 Reputation points MVP
    2024-03-23T19:54:31.5533333+00:00

    In short, you cannot join non-Azure hosted systems to Entra Domain Services domain. This is exclusively for Azure VMs


    hth

    Marcin


  2. Marcin Policht 11,470 Reputation points MVP
    2024-03-23T19:56:39.01+00:00

    If you don't intend to have AD DS in your on-premises environment, you'll need to resort to Entra join (or registration) instead


    hth

    Marcin