A cloud-based identity and access management service for securing user authentication and resource access
You can also have Entra connect installed in one AD forest and the other AD forests use Cloud Sync and all sync into one tenant.
This browser is no longer supported.
Upgrade to Microsoft Edge to take advantage of the latest features, security updates, and technical support.
Hi, we have the following infrastructure - 3 on-prem AD forests isolated to one another (no forest trust) with one of them synced to Entra ID tenant (Windows 11 devices are Entra Hybrid Joined). Plan is to decommission that forest and leave Windows 11 devices "only" Entra Joined.
Is it technically feasible to "sync" other 2 AD forests to existing Entra ID tenant and use cloud-only accounts in Entra ID (previously synced from decommissioned on-prem AD forest) to access resources in these 2 AD forests (accounts must exist in both AD forests but with the same UPN? - what about passwords then)? Also, how Entra Private Access fits here (accessing resources in both AD forests from our Entra Joined Windows 11 devices without VPN), is that feasible as well?
Depending on answer, I might have more questions.
A cloud-based identity and access management service for securing user authentication and resource access
You can also have Entra connect installed in one AD forest and the other AD forests use Cloud Sync and all sync into one tenant.
If I got it right: