Hi all
I've been asked why we can't do away from on-prem AD to just use Azure AD and want to ensure i understand all the Reasons before i go back to my senior managment.
the situation is this we currently have 12 Ad domain controllers in 7 locations.
we have 3000 devices currently co-managed ~(sccm/intune currently) but moving to Intune only in the near future.
150+ servers still on-prem but that number is shrinking.
we are in an exchange hybrid step-up but all mailboxes are in O365 with on-prem exchane no used purely for management.
DNS is provided by AD
we are using ADFS and AADconnect to synchronise the environments currently.
my understanding is that azure AD needs to have a directory service linked to exist (this maybe an old understanding,) but that you can now use an azure AD DS webservice to fill this need.
I'm not sure if the On-prem servers can join that and that research says azure AD direct join isn't supported by servers currently (but that it's coming in the future for new OS versions).
Making the on-prem machines the first road block.
the second I foresee is the hybrid exchange environment. We were advised when we put it in that as long as we have mailboxes from the on-prem environment in O365 we would need to maintain at least one on-prem exchange server and a domain controller to provide full functionality/control of those old mailboxes. (we often had to manage older mailboxes from on-prem as the options are greyed out in O365)
we have approximately 1000 shared mailboxes that existed before the migration so that's a lot of recreation if necessary.
is my understanding correct? is there another road blocks i'm missing?
i'm trying to read up but this is a fast changing area so it's hard to understand.
My current suggestion to the business if to upgrade from our 2012r2 environments to the most up to date versions. as this will help with any future migrations and review from there.