3. Azure AD Connect
•Azure AD Global Administrator account
•Enterprise Administrator account for your local
Active Directory
•SQL Server database to store identity data
•Meet server version and hardware requirements
@DivineOps
Synchronization - This part is made up of the the components and functionality previously released as Dirsync and AAD Sync.
AD FS - This is an optional part of Azure AD Connect and can be used to setup a hybrid environment using an on-premises AD FS infrastructure, to address complex deployments that include such things as domain join SSO, enforcement of AD login policy etc.
Health Monitoring - For complex deployments using AD FS, Azure AD Connect Health can provide robust monitoring of your federation servers and provide a central location in the Azure portal to view this activity.
By default a SQL Server 2012 Express LocalDB (a light version of SQL Server Express) is installed and the service account for the service is created on the local machine. SQL Server Express has a 10GB size limit that enables you to manage approximately 100.000 objects.
Azure AD Connect must be installed on Windows Server 2008 or later. This server may be a domain controller or a member server.
The AD schema version and forest level must be Windows Server 2003 or later. The domain controllers can run any version as long as the schema and forest level requirements are met.
If Active Directory Federation Services is being deployed, the servers where AD FS will be installed must be Windows Server 2012 R2 or later.
Create new Azure Active Directory
Create a user account in the Global Admin role (required for AD sync)
Sign in to Azure with the new global admin account and change the password
Ignore the error above – this means that this particular account has no access to any Azure subscriptions, which is OK
Install Azure AD Connect and proceed with Express settings
Default options when re-configuring the AD sync
New Azure AD Sync task has been created in Task Scheduler.
By default it is configured to run every 3 hours.
Task Action: Start a Program
"C:\Program Files\Microsoft Azure AD Sync\Bin\DirectorySyncClientCmd.exe"
After the synchronization is complete, the local Users will show in Azure AD
After the synchronization is complete, the local Groups will show in Azure AD