ESX Virtualization

VMware ESXi, vSphere, VMware Backup, Hyper-V... how-to, videos....

Nakivo Backup and Replication - #1 Backup solution for Virtual, physical, cloud, NAS and SaaS

Menu
  • Certification
      • VCP-DCV vSphere 8
          • vcp2024-125.
        • Close
    • Close
  • VMware
    • Configuration Maximums
    • vSphere
      • vSphere 8.0
      • vSphere 7.0
      • vSphere 6.7
      • vSphere 6.5
      • vSphere 6.0
      • Close
    • VMworld
      • VMware EXPLORE 2024
      • VMware EXPLORE 2023
      • VMware EXPLORE 2022
      • VMworld 2019
      • VMworld 2018
      • VMworld 2017
      • VMworld 2016
      • VMworld 2015
      • VMworld 2014
      • VMworld 2013
      • VMworld 2012
      • VMworld 2011
      • Close
    • Close
  • Microsoft
    • Windows Server 2012
    • Windows Server 2016
    • Windows Server 2019
    • Close
  • Categories
    • Tips – VMware, Microsoft and General IT tips and definitions, What is this?, How this works?
    • Server Virtualization – VMware ESXi, ESXi Free Hypervizor, VMware vSphere Server Virtualization, VMware Cloud and Datacenter Virtualization
    • Backup – Virtualization Backup Solutions, VMware vSphere Backup and ESXi backup solutions.
    • Desktop Virtualization – Desktop Virtualization, VMware Workstation, VMware Fusion, VMware Horizon View, tips and tutorials
    • How To – ESXi Tutorials, IT and virtualization tutorials, VMware ESXi 4.x, ESXi 5.x and VMware vSphere. VMware Workstation and other IT tutorials.
    • Free – Free virtualization utilities, ESXi Free, Monitoring and free backup utilities for ESXi and Hyper-V. Free IT tools.
    • Videos – VMware Virtualization Videos, VMware ESXi Videos, ESXi 4.x, ESXi 5.x tips and videos.
    • Home Lab
    • Reviews – Virtualization Software and reviews, Disaster and backup recovery software reviews. Virtual infrastructure monitoring software review.
    • Close
  • Partners
    • NAKIVO
    • StarWind
    • Zerto
    • Xorux
    • Close
  • This Web
    • News
    • ESXi Lab
    • About
    • Advertise
    • Archives
    • Disclaimer
    • PDFs and Books
    • Close
  • Free
  • Privacy policy

Azure Active Directory (AAD) – An Ultimate AD placement for Hybrid Scenarios?

By Vladan SEGET | Last Updated: October 16, 2017

Shares

Active Directory (AD) is one of the core services in every company. Authentication has always been crucial for IT admins, for the clients opening their sessions, or for the external IT consultants which need to work within the client's environments. Active Directory is kind of a “holy grail”, a standard if you ask me. The usual protection of AD is to have a multi site environment and replicate the AD between different DCs. But this is not always the case for very small businesses, which have sometimes only single server. So how about to switch the authentication and move the “responsibility” of your local Domain controllers, to an Azure cloud? Or to go hybrid? Does it mean that you simply install an additional DC within an Azure cloud and replicate your existing environment? No, there is something else that I want to talk today. It is an AAD Domain services which support Kerberos, Windows Integrated Authentication, and NTLM. Also Group Policy Objects (GPO) or Lightweight Directory Access Protocol (LDAP).

There is several ways which you could leverage AD within a hybrid environment with Microsoft Azure. Some of them are too complex, some of them are paid ones. Basically, to implement Azure Active Directory (AAD) Domain services:

  • You don't need to install a domain controller (DC) in the cloud.
  • You don't need to sett up ExpressRoute (It's a paid service – “service that enables you to create private connections between Azure datacenters and infrastructure that’s on your premises or in a colocation environment. ExpressRoute connections do not go over the public Internet, and offer more reliability, faster speeds, lower latencies and higher security than typical connections over the Internet.”). Basically, to create an ExpressRoute, you need your ISP to support it.
  • You don't need to create a VPN to connect on-premises DCs to Azure.

This is rather encouraging, right? At first, what do you need to know is that AAD doesn’t support all the services provided by Windows Server AD. (Not yet, but Microsoft is progressively adding new features). And also you should know that this service is “in preview” for now… so I'd suggest to test it on a separate domain, other than your production AD first !!!

But yes, it is very promising technology, supporting already native domain-join, Group Policy, Kerberos and NTLM authentication, and Lightweight Directory Access Protocol (LDAP) access to the directory.

3 Editions of AAD are currently available:

  • Free – limited to 500.000 user objects
  • Basic – supports group-based access management, branding of login pages
  • Premium Edition – supports self-service password reset, group-based access management and federation with your existing environment.

Image courtesy of Microsoft…

Microsoft Azure Active Directory

You can find more information about different editions here.

When I connect to my Azure Account and select AAD, I can see the message saying that the AAD is in preview…

Microsoft Azure Active Directory (AAD)

the implementation of AAD is (apparently) simple. Only four clicks is necessary.

Quote from Microsoft:

With just four clicks, Azure AD can be integrated with an existing Windows Server Active Directory, giving organizations the ability to leverage their existing on-premises identity investments to manage access to cloud-based SaaS applications.

For now, the service is in preview…

Azure AAD is certainly interesting from DR perspective. It is something that very small businesses could use for their DR strategies. Businesses, which usually runs an “all-in-one” server with several roles, including the DC, but they don't usually have DR plan in case their office catches fire. , and they, of course, do not have another remote site (with an additional DC). Sometimes they do have a kind of a backup solution, but how difficult is to maintain (and protect) this kind of installation?

And sometimes, of course, they do not have another remote site (with an additional DC), or a backup solution for their physical host. They kind of taking a risk where they can simply lose their AD…

Windows Server 2016 recommended posts:

  • Windows Server 2016 Active Directory Installation Guide
  • Windows Server 2016 Active Directory Improvements
  • Windows Server 2016 Telemetry Details
  • Windows Server 2016 Essentials vs Standard
  • Windows Server 2016 – How to configure data deduplication
  • Windows Server 2016 – What is the difference between Standard and Datacenter Edition (Hot!)
  • Windows Server 2016 licensing moves from per Socket to per core licensing model
Shares
4.5/5 - (2 votes)

| Filed Under: Windows Server 2016 Tagged With: Azure Active Directory (AAD)

About Vladan SEGET

This website is maintained by Vladan SEGET. Vladan is as an Independent consultant, professional blogger, vExpert x16, Veeam Vanguard x9, VCAP-DCA/DCD, ESX Virtualization site has started as a simple bookmarking site, but quickly found a large following of readers and subscribers.

Connect on: Facebook. Feel free to network via Twitter @vladan.

Private Sponsors

Featured

  • Thinking about HCI? G2, an independent tech solutions peer review platform, has published its Winter 2023 Reports on Hyperconverged Infrastructure (HCI) Solutions.
  • Zerto: One Platform for Disaster Recovery, Backup & Cloud Mobility: Try FREE Hands-On Labs Today!
Click to Become a Sponsor

Most Recent

  • Veeam Backup & Replication v13 Beta: A Game-Changer with Linux
  • What is Veeam Data Cloud Vault and how it can help SMBs
  • Nakivo Backup and Replication – Malware Scan Feature
  • Zerto 10 U7 released with VMware NSX 4.2 Support
  • XorMon NG 1.9.0 Infrastructure Monitoring – now also with Veeam Backup Support
  • Heartbeat vs Node Majority StarWind VSAN Failover Strategy
  • Vulnerability in your VMs – VMware Tools Update
  • FREE version of StarWind VSAN vs Trial of Full version
  • Commvault’s Innovations at RSA Conference 2025 San Francisco
  • VMware ESXi FREE is FREE again!

Get new posts by email:

 

 

 

 

Support us on Ko-Fi

 

 

Buy Me a Coffee at ko-fi.com

Sponsors

Free Trials

  • DC Scope for VMware vSphere – optimization, capacity planning, and cost management. Download FREE Trial Here.
  • Augmented Inline Deduplication, Altaro VM Backup v9 For #VMware and #Hyper-V – Grab your copy now download TRIAL.

VMware Engineer Jobs

VMware Engineer Jobs

YouTube

…

Find us on Facebook

ESX Virtualization

…

Copyright © 2025 ·Dynamik-Gen · Genesis Framework · Log in