Moving on Premise Active Directory to Azure AD

Reez Ali 21 Reputation points
2021-08-10T22:31:19.913+00:00

Hello,

Our company is looking to move from On-Premise Active Directory to Azure Active Directory, we are only looking to move only Active Directory to Azure. We are not looking for a Hybrid solution.

1) What are the steps involved in doing that?
2) I read few forums and it confused me little. Forum mentiones that it has to be done though Corss Forest Migration.
3) Please help me to see if this are the correct steps
* Sync On Premise AD to Azure AD through Azure AD Connect
* After Sync Create Azure AD DS and Sync to Azure AD (for Which VM needs to be created which will have role of Domain Services
* Part of above process we need to create a Virtual Network and 2 Subnets one for Azure AD DS and other for VM server.
4) Does it mean we can remove the on premise Domain Services after that process.

Will really appreciate your help with this.

Microsoft Security Microsoft Entra Microsoft Entra ID
0 comments No comments
{count} votes

Accepted answer
  1. AmanpreetSingh-MSFT 56,866 Reputation points Moderator
    2021-08-11T08:17:07.283+00:00

    Hi @Reez Ali • Thank you for reaching out.

    Yes, the steps you have mentioned are correct. Just to add to the text in red below, the VM will just have the binaries to manage Active Directory, it won't be promoted as a Domain Controller.

    When Azure AD DS is deployed, 2 domain controllers are deployed in the backend and access to the VMs of those domain controllers is not provided.

    1. Sync On Premise AD to Azure AD through Azure AD Connect
    2. After Sync Create Azure AD DS and Sync to Azure AD ( for Which VM needs to be created which will have role of Domain Services )
    3. Part of above process we need to create a Virtual Network and 2 Subnets one for Azure AD DS and other for VM server.

    Note: In case of Azure ADDS, you won't have Enterprise administrator privileges, due to which you might not be able to perform all the tasks that you can perform in on-premises AD.
    Also, keep in mind that schema extension and geo-distributed deployment is not supported with Azure AD DS.

    -----------------------------------------------------------------------------------------------------------

    Please "Accept the answer" if the information helped you. This will help us and others in the community as well.

    3 people found this answer helpful.

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.