U
U
user.2020-02-27 11:04:38
Active Directory
user., 2020-02-27 11:04:38

Where and how to start a phased migration of AD to the cloud?

Good afternoon,

I will listen to the opinion and advice of people who have experience with AD on how and specifically from what stages it is correct to start the process of migrating AD to the cloud.

Answer the question

In order to leave comments, you need to log in

6 answer(s)
V
Vadim Choporov, 2020-02-27
@nekolov

I would start by defining what you want as an output? What are your goals? What are you talking about, the ability to log in using your domain accounts in the cloud / service, or a complete transfer of AD DS (domain services)? Different cloud providers have different options.
The most common answer, based on the data of the question:
Raise a VPN tunnel, or otherwise build a network connection with the cloud, get a controller there, wait for the data replication to finish, and that's it, you have your domain controller in the cloud, with your AD.

S
Sergey Gornostaev, 2020-02-27
@sergey-gornostaev

AD is not a service that should be moved to the cloud.

M
Mnemonic0, 2020-02-28
@Mnemonic0

You here:
https://habr.com/ru/company/microsoft/blog/475738/

N
nApoBo3, 2020-02-27
@nApoBo3

AzureAD. All the necessary manuals are there. But we must understand that this is not quite the same as the local AD.

E
Eugene, 2020-02-28
@zloy_zaya

Take a test tenant in Azure and try to migrate in a test environment. Be prepared that Azure is an underdeveloped AD, i.e. there will not be some services that are on-prem. Download the Adfix utility from the Microsoft website and run it. It will show you bottlenecks, for example, duplicate accounts.

D
Denys Dmytrenko, 2020-03-05
@Silmaril451

I see several options here that fit the description of "migration of AD to the cloud."
1. Fairly simple. Hybridize Current AD, Sink Users to Azure AD Using Azure AD Connect . In doing so, you keep local AD DCs (at least one). With which the Azure AD tenant will sync.
2. Variation of the first option - First we perform all the steps from point 1, then we kill the local AD and turn your users into cloud-only. Voila, your AD is now "in the cloud" - In Azure AD.
3. Another variation of the first option - what the comrades mentioned above - we raise a new DC virtual machine in Azure (after building a VPN, etc.), we get another hybrid option. If necessary, kill on-premise DC(s).
4. And the last, bonus option :) Migration to the Azure AD DS mentioned above . AzureAD. Details of the implementation and its limitations\opportunities - read the link.
It is impossible to add something or recommend one without having more specifically formed tasks / goals.

Didn't find what you were looking for?

Ask your question

Ask a Question

731 491 924 answers to any question