Can we set up on-premise Domain Controller to sync to Domain Controller in Azure (Hybrid)

Reez Ali 21 Reputation points


We have on-premise Domain Controller; we want to sync that to Azure by setting up Domain Controller in Azure (Hybrid)

  1. Can you please help me to know steps in setting up second Domain Controllers i.e. in Azure
  2. If On-premise Domain Controller is down, can user still authenticate to Domain Controller in Azure?

In our current environment we are syncing Users and Devices to Azure because of Office 365 Subscription.

Please let me know if you have any counter questions

Thank you,

Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
18,622 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. MaximM 6 Reputation points

    You absolutely can setup a domain controller in that manner if you already have S2S VPN or express route connectivity to the vnet which you intend to deploy the Azure Domain Controller into.

    A good place to start is here: , with the managability considerations being especially important.

    In regards to question 2: You'd have to create a new site, ensure that your users have visibility to it from network perspective and that DNS srv records are created for the new site. One thing to consider is where the PDC is and how you'd move that around in the event of a localized issue with the current PDC.

    1 person found this answer helpful.
    0 comments No comments