Share via


Azure AD Users Sync:Install Azure AD Connect on Windows Server in AWS

Introduction

In this article, we are going to discuss two items:

  1. 1. Creating users in AWS Windows Server Active Directory and 
  2. 2. Installing Azure AD connect.

  First, you should have basic knowledge of virtual machine creation in AWS and Installation and configuration Active directory in windows server. If not, I would recommend you read my previous article.

Prerequisites

  1. Virtual machine creation in AWS
  2. Installation and configuration Active directory in windows server

Azure AD Connect is a tool and guided experience for connecting an on-premises identity infrastructure to Microsoft Azure AD. The wizard deploys and configures pre-requisites and components required for the connection, including sync and sign on.

Source: Wikipedia

Steps

Step 1

Download and Install the Azure AD Connect in AWS’s virtual machine (In this article we are using windows server 2012)

Step 2

Choose installation type. (In this article we are using express settings)

Express Settings

  1. Set everything to be the default
  2. You will not be able to choose sync account and groups in AD
  3. You will not be able to choose the SQL server, by default SQL Expression edition will be installed

Customize

  1. By default AD connect will be installed in “C:\Program Files\Microsoft Azure AD Sync” but you are able to set custom installation location
  2. By giving Server name and Instance name you able to use existing SQL server
  3. You can able to the existing service account
  4. You can able to select custom sync group like,
    1. Administrators
    2. Operators
    3. Browse
    4. Password Reset

https://csharpcorner-mindcrackerinc.netdna-ssl.com/article/azure-aws-ad-users-sync-up-install-azure-ad-connect-in-windows-server/Images/Azure%20AWS%20AD%20Users%20Sync%20Up%20Install%20Azure%20AD%20Connect%20in%20Windows%20Server01.jpg 

https://csharpcorner-mindcrackerinc.netdna-ssl.com/article/azure-aws-ad-users-sync-up-install-azure-ad-connect-in-windows-server/Images/Azure%20AWS%20AD%20Users%20Sync%20Up%20Install%20Azure%20AD%20Connect%20in%20Windows%20Server02.gif  

Step 3

Both AWS and Azure Domain Controllers should trust each other,

Connect to Azure AD

https://csharpcorner-mindcrackerinc.netdna-ssl.com/article/azure-aws-ad-users-sync-up-install-azure-ad-connect-in-windows-server/Images/Azure%20AWS%20AD%20Users%20Sync%20Up%20Install%20Azure%20AD%20Connect%20in%20Windows%20Server03.jpg 

  1. Provide username & password of Azure AD User (User Should be part of Global Administrator Role)
  2. Login into Azure Portal and then in right side blade click on the Azure Active Directory
  3. Click on the User under Manage Menu
  4. Click on the New User button
  5. Fill in the name and User Name. Password will be generated by default, so make sure you have noted the password, by using the same you will be able to log in the portal.
  6. Once the user is generated, the same will be reflected in the users section. In that select the user and then select Directory role and the Click on the Add button.
  7. Select the Global administrator role, without this the user will not be able to connect from the On-Premises AD then click on the Select button.
  8. Login to the Azure portal with newly created AD user’s credential, for the first login the system will ask us to reset the password.

https://csharpcorner-mindcrackerinc.netdna-ssl.com/article/azure-aws-ad-users-sync-up-install-azure-ad-connect-in-windows-server/Images/Azure%20AWS%20AD%20Users%20Sync%20Up%20Install%20Azure%20AD%20Connect%20in%20Windows%20Server04.jpg 

https://csharpcorner-mindcrackerinc.netdna-ssl.com/article/azure-aws-ad-users-sync-up-install-azure-ad-connect-in-windows-server/Images/Azure%20AWS%20AD%20Users%20Sync%20Up%20Install%20Azure%20AD%20Connect%20in%20Windows%20Server05.jpg  

 

 https://csharpcorner-mindcrackerinc.netdna-ssl.com/article/azure-aws-ad-users-sync-up-install-azure-ad-connect-in-windows-server/Images/Azure%20AWS%20AD%20Users%20Sync%20Up%20Install%20Azure%20AD%20Connect%20in%20Windows%20Server06.jpg  

Connect to AD DS (On Premises)

  1. Provider Domain\ User Name and Password of On-Premises local system.
  2. Click on install to complete the setup.

https://csharpcorner-mindcrackerinc.netdna-ssl.com/article/azure-aws-ad-users-sync-up-install-azure-ad-connect-in-windows-server/Images/Azure%20AWS%20AD%20Users%20Sync%20Up%20Install%20Azure%20AD%20Connect%20in%20Windows%20Server07.jpg 

https://csharpcorner-mindcrackerinc.netdna-ssl.com/article/azure-aws-ad-users-sync-up-install-azure-ad-connect-in-windows-server/Images/Azure%20AWS%20AD%20Users%20Sync%20Up%20Install%20Azure%20AD%20Connect%20in%20Windows%20Server08.jpg

 

  https://csharpcorner-mindcrackerinc.netdna-ssl.com/article/azure-aws-ad-users-sync-up-install-azure-ad-connect-in-windows-server/Images/Azure%20AWS%20AD%20Users%20Sync%20Up%20Install%20Azure%20AD%20Connect%20in%20Windows%20Server09.jpg   

Step 4

Create New AD User, Open Server Manager then click Tools, Select Active Directory User and Computers option,

  1. Select your own domain, Right-click on the User folder, select New and then User

  2. Enter the User login name and then click the next button

  3. Set Password for the new user and click finish.

  4. Then newly created users will be displayed on the User Folder

    https://csharpcorner-mindcrackerinc.netdna-ssl.com/article/azure-aws-ad-users-sync-up-install-azure-ad-connect-in-windows-server/Images/Azure%20AWS%20AD%20Users%20Sync%20Up%20Install%20Azure%20AD%20Connect%20in%20Windows%20Server10.jpg

    https://csharpcorner-mindcrackerinc.netdna-ssl.com/article/azure-aws-ad-users-sync-up-install-azure-ad-connect-in-windows-server/Images/Azure%20AWS%20AD%20Users%20Sync%20Up%20Install%20Azure%20AD%20Connect%20in%20Windows%20Server11.jpg

    https://csharpcorner-mindcrackerinc.netdna-ssl.com/article/azure-aws-ad-users-sync-up-install-azure-ad-connect-in-windows-server/Images/Azure%20AWS%20AD%20Users%20Sync%20Up%20Install%20Azure%20AD%20Connect%20in%20Windows%20Server12.jpg

    https://csharpcorner-mindcrackerinc.netdna-ssl.com/article/azure-aws-ad-users-sync-up-install-azure-ad-connect-in-windows-server/Images/Azure%20AWS%20AD%20Users%20Sync%20Up%20Install%20Azure%20AD%20Connect%20in%20Windows%20Server13.jpg

    https://csharpcorner-mindcrackerinc.netdna-ssl.com/article/azure-aws-ad-users-sync-up-install-azure-ad-connect-in-windows-server/Images/Azure%20AWS%20AD%20Users%20Sync%20Up%20Install%20Azure%20AD%20Connect%20in%20Windows%20Server14.jpg

    https://csharpcorner-mindcrackerinc.netdna-ssl.com/article/azure-aws-ad-users-sync-up-install-azure-ad-connect-in-windows-server/Images/Azure%20AWS%20AD%20Users%20Sync%20Up%20Install%20Azure%20AD%20Connect%20in%20Windows%20Server15.jpg