Schema extensions

Lisa Lownds 66 Reputation points
2020-01-12T15:28:20.327+00:00

Folks,
I have a couple of questions about AADDS:

  1. Does Azure Active Directory Domain Services (AADDS) support custom schema extensions?
  2. Would you describe AADDS as a globally shared AD Forest with a managed domain for my org?

Lisa

Microsoft Security | Microsoft Entra | Microsoft Entra ID
Microsoft Security | Microsoft Entra | Other
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Shashi Shailaj 7,636 Reputation points Microsoft Employee Moderator
    2020-01-13T02:54:06.253+00:00

    Hello Lisa ,

    Please find the answers. Azure AD domain services is a managed Active Directory instance with the main goal to provide Legacy authentication capabilities (for legacy apps which use Kerberos , NTLM) in the cloud so that anyone who would like to completely migrate to Azure and remove on-premise active directory could life and shift the on-prem application servers as is , and have the benefits of legacy auth protocols in the cloud. So as for your answer , please find the below.

    • Does Azure Active Directory Domain Services (AADDS) support custom schema extensions
    • Would you describe AADDS as a globally shared AD Forest with a managed domain for my org?
      • Not exactly . Each instance is unique to one customer and part of a larger globally shared AD in the backend. Whenever you enable Azure AD domain services, a new restricted Domain Controller for the domain name you have provided during initial configuration , is created. The difference from on-premise AD is that you do not get complete flexibility to change and modify the domain controller settings as you would be able to do in your on-prem Domain controller. This is because it was never created for making it a feature-by-feature replacement for on-premise AD. If you require completely similar control in the cloud then we suggest you to create Azure VMs and promote them to domain controllers . You may have to setup a site-to-site VPN for the same between your on-prem location and the Azure using Azure gateway / Azure VPN.

    Hope this clarifies your queries. I have added some links to my answer , please check the same. Also I would encourage you to go through the complete FAQ for the Azure AD domain Services and I am sure a lot of your queries could get answered automatically. In case the above information in the post helps you , please do mark it as answer so that it can help others in the community searching for same answers.

    Thank you.

    1 person found this answer helpful.

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.