Picking which Azure AD Synchronization Technology! AAD Connect vs Cloud Sync
Ғылым және технология
In this video I explore Azure AD Connect and Azure AD Connect Cloud Sync as means to synchronize your Active Directory with Azure AD. What they can do, what they can't and how to pick!
#azuread #johnsavillstechnicaltraining #onboardtoazure
▬▬▬▬▬▬ T I M E S T A M P S ⏰ ▬▬▬▬▬▬
0:00 - Intro
0:27 - Active Directory and Azure AD
2:20 - Azure AD Connect basics
4:40 - AAD Connect tooling
7:40 - Key topology rules
9:32 - Staging instances
11:58 - Link of AAD to AD object
15:00 - Rule 3!
16:00 - Multi AAD Connect scenarios
20:30 - Azure AD Connect Cloud Sync
23:12 - Rule 3 still applies
23:30 - Azure-based management
25:09 - Combinations
25:55 - Choosing a solution
31:54 - Summary of how to pick
34:13 - Pilot cloud sync
34:55 - Summary and close
▬▬▬▬▬▬ K E Y L I N K S 🔗 ▬▬▬▬▬▬
► My random stuff repo for AAD object script:
🔗 github.com/johnthebrit/Random...
► Azure AD Connect Cloud Sync video:
🔗 • New Solution for Azure...
► AAD Connect Supported Topologies:
🔗 docs.microsoft.com/en-us/azur...
► Multi-cloud AAD support statement:
🔗 docs.microsoft.com/en-us/azur...
► AAD Connect Cloud Sync Supported Topoligies:
🔗 docs.microsoft.com/en-us/azur...
► AAD Connect vs Cloud Sync features:
🔗 docs.microsoft.com/en-us/azur...
► Hybrid deployment pilot:
🔗 docs.microsoft.com/en-us/azur...
▬▬▬▬▬▬ Want to learn more? 🚀 ▬▬▬▬▬▬
📅 Weekly Azure Update ► • Azure Infrastructure U...
☁ Azure Master Class ► • Microsoft Azure Master...
⚙ DevOps Master Class ► • DevOps Master Class
💻 PowerShell Master Class ► • PowerShell Master Class
🎓 Certification Cram Videos ► • Microsoft Certificatio...
❔ Question about my setup? ► • My Setup
🔎 Looking for content on a particular topic? Search the channel. If I have something it will be there!
SUBSCRIBE ✅ / @ntfaqguy
Пікірлер: 65
I'd be lost at times without the great explanations you provide 👍👍
@NTFAQGuy
2 жыл бұрын
Thank you, very kind
Awesome Explanation I've ever seen. All my doubts are crystal clear now & finally got the solution. Thanks a Ton John. Appreciated a lot.!
@boomandcrashsyntheticindic3781
Ай бұрын
same here
Great explanation, love every bit of it. Thank you John 👍👍👍👍
great video John. Thankyou - super clear
I learned a lot! You transfer Your knowledge in such a clear way. Thank You
@NTFAQGuy
5 ай бұрын
Glad it was helpful!
Amazing KT. Great content 👍
nice overview! I configured cloud sync in my lab environment after seeing your first vid on it. To see what it can do now and be able to test new features when the become available. cant wait for cloud sync to be able to provision new users in in on premises active directory :)
@NTFAQGuy
2 жыл бұрын
It can as part of an HR flow. Been possible for a long time but not AAD to AD.
@matiashuartamendia7977
2 жыл бұрын
I thought u were able to do that from what was seen in the vid haha
Thanks John, excellent video.
@NTFAQGuy
2 жыл бұрын
Glad you enjoyed it
I find your explanations easy to follow. I don’t know how you keep up with all you do though. Hats off and many thanks
@NTFAQGuy
2 жыл бұрын
Glad you like them!
enjoying this video for today learning, thanks a lot!
Thanks for the great explanation!
Very well explained, IN DEPTH 👌. I sooooo like your videos 🙏.
@NTFAQGuy
2 жыл бұрын
Thank you!
Thanks John, as usual your Awesome :)
Nice overview, another great video
@NTFAQGuy
2 жыл бұрын
Thanks
i have to say i really enjoyed the lesson. I am looking to ssetup azure AD connect. But i have couple hurdles I need to work out.
Thank you so much, great vid
Thank you for this video . very detailled
@NTFAQGuy
11 ай бұрын
Glad it was helpful!
Superb video as always John! I visualise using a combination of these 2 tools for a company that has separate domains but want to share a single AAD instance - however if both have Exchange on-premise that would scupper Hybrid for Cloud Sync. I could PST migrate or cutover using a 3rd party tool for the AD forest that i plan to use Cloud Sync for to get around this until Cloud Sync matures. Does that sound about right (hyperthetically ignoring the Exchange Hybrid server for AAD Connect Microsoft Support matrix currently)?
@NTFAQGuy
2 жыл бұрын
Glad you enjoy the video. I would just validate features needed against the table
Excellent examples
@NTFAQGuy
11 ай бұрын
Thank you!
Great vid John thanks. How about a migration from 1 to the other? Say I've got a AADC sync for M365 users and I want to shift to AADCCS - is that a thing or are we talking net-new for the use cases?
@NTFAQGuy
2 жыл бұрын
Yes you can migrate and you can start with pilot as I said in video and linked document then switch
Thanks for vid. What about monitoring/reporting of sync (problems) with cloud sync? The regular AAD Connect provides that via the GUI tool.
@NTFAQGuy
2 жыл бұрын
there are various monitors and alerting options available.
Great video!
@NTFAQGuy
2 жыл бұрын
Thanks!
It is absolute great video ...
@NTFAQGuy
2 жыл бұрын
Thank you
Great video..!
@NTFAQGuy
2 жыл бұрын
Thanks!
Microsoft should let you make these videos before they release new features , would make life easier for lot of people :) .
@NTFAQGuy
2 жыл бұрын
Lol
Thanks a lot!!!!
One of the first top 10 commenters ;). Great video John.
Great Video John! Please can you also share link for the whiteboard.
@NTFAQGuy
2 жыл бұрын
If it’s not in description means I didn’t save it. I only save the bigger, more complex ones.
@3232gb
2 жыл бұрын
@@NTFAQGuy Thanks John for confirmation! Will take screen grab then, even that is gold :)
John, as part of AD Connect sync, some domain information is synchronized to AAD and allows Azure AD Joined devices to SSO to on-premises resources using the Primary Refresh Token containing the info and requesting Kerberos ticket to a domain controller. Do you know if Cloud Sync synchronizes the same info utilized in this process just as AADC does?
@NTFAQGuy
2 жыл бұрын
No, it does not as that is write back.
I suppose that cloud sync does not support hybrid exchange. Is that something one would need to consider? And also: thanks for the video.
@NTFAQGuy
2 жыл бұрын
All covered in the doc I referenced in the video and link in the description. It has exchange hybrid writeback as a line item.
Thanks
@NTFAQGuy
8 ай бұрын
Welcome
GREMLINS HAHAHAAH YOU ARE THE BEST JOHN 😂🥳😄
@NTFAQGuy
Жыл бұрын
Lol
Can you place your azure ad connect server in azure to perform on ‘prem to azure syncs’ rather then having it on premise?
@NTFAQGuy
Жыл бұрын
yes, e.g. in iaas vm but have close to a DC, e.g. a DC in IaaS vm as well.
Thanks, John! Never can understand MS logic - we have good tools, we are updating it weekly, but we will not do a perfect tool, we will create new one, and you will need to choose a perfect tool for your scenario (but they both not perfect).
@NTFAQGuy
2 жыл бұрын
Tools take time to create and don’t instantly have all features.
@daltonculp2721
2 жыл бұрын
Microsoft saw the approach Okta and other best of breed IDP’s were using for the last 10 years to solve these problems and “tried” to implement that same approach.
I’m still flummoxed by the need to have an exchange server on premise to manage user cloud mailboxes after the account is synced to Azure. We migrated from GSuite to O365. Never had exchange on premise. Green field local AD. If I synch a pilot account we have to either install a local exchange management server or use ADSI edit to do things like add secondary email addresses. We kind of stumbled into it by noticing that when a test account synced from AD and matched to the cloud account it wiped out all of the secondary email addresses that were previously on the cloud account. Then we had to adsi edit them on the AD side and synch again to get them back. Is there any other solution?
@NTFAQGuy
2 жыл бұрын
If you sync accounts from AD then AD is the source of truth and you have to manage them from on-premises AD. If you don't want to manage them from AD and only want in cloud then use cloud accounts.
@lostinpa-dadenduro7555
2 жыл бұрын
@@NTFAQGuy Thanks for the reply. That’s what I figured. Unfortunately a local AD environment was created and all the users and machines attached to it prior to my coming on board. Would have been great to do this cloud only with Azure AD users, Intune and Autopilot. Next upgrade cycle perhaps. 😀👍
MIGHTY SUPERMAN RELEASED IT A YEAR AGO, AND MS PUBLISHED 5 MIN VIDEO TODAY, THIS IS WHAT I CALL A REAL "CHRISTMAS CAROL" 😁🎅🎄🎁 #IRONAZUREMAN 🤩😎