Can OnPrem servers use Azure AD for authentication??

Anonymous
2021-10-07T08:35:58.913+00:00

I'm considering if we can remove completely OnPrem AD and use only Azure AD for clients and Server authentication.. We want to have some terminal servers OnPrem but completely decommission OnPrem AD (AD DS).. Any suggestions??

Windows for business | Windows Client for IT Pros | Directory services | Active Directory
Windows for business | Windows Server | User experience | Other
Microsoft Security | Microsoft Entra | Other
0 comments No comments
{count} votes

3 answers

Sort by: Most helpful
  1. Paul van Berlo 826 Reputation points
    2021-10-07T08:41:48.36+00:00

    Hello @Anonymous and welcome to Q&A!

    Technically this can be done by leveraging Azure AD DS and extending access to On Prem servers using some kind of site to site VPN like ExpressRoute. Azure AD DS provides a managed experience which resembles Windows AD.


  2. Alan Kinane 16,951 Reputation points MVP Volunteer Moderator
    2021-10-07T08:48:48.47+00:00

    If you are using terminal server/RDS then you will still need AD for authentication and most likely for other things like group policies, NTFS permissions on SMB shares etc. There are many organisations looking to remove AD but it's often quite challenging unless you are moving fully to the cloud.


  3. Limitless Technology 39,926 Reputation points
    2021-10-08T07:46:39.447+00:00

    Hello,

    Thank you for your question.

    You can remove completely OnPrem AD , if you do not have any OnPrem clients or if you are not using any Local AD related roles for example. DFS, DNS, File shares, Hyper-V , Group policies etc.

    Azure Active Directory is not designed to be the cloud version of Active Directory. It is not a domain controller or a directory in the cloud that will provide the exact same capabilities with AD. It actually provides many more capabilities in a different way.

    Please also note that removing of completely OnPrem AD domain will required some additional configurations on network and configuring Azure VPN which will chargable.

    Please have a look on below Microsoft threads and articles.

    https://techcommunity.microsoft.com/t5/azure-active-directory-identity/migrating-on-prem-ad-to-azure-ad-and-doing-away-completely-with/m-p/1226118

    https://learn.microsoft.com/en-us/answers/questions/50525/moving-on-prem-ad-ds-to-aad-ds-migration-required.html

    -------------------------------------------------------------------------------------------------------------------------

    --If the reply is helpful, please Upvote and Accept as answer--

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.