Friday, June 21, 2024

Configure Azure AD Connect

In the last few sections we talked about setting up the Office 365 tenant from scratch and them applying the external domain to it. It is now ready to go but we now need to add the users/groups/contact etc from your Active Directory On Premises into the new Azure AD and Office 365 configuration. To do this you are going to need the following.

  1. A server in your organization that can see the local DC’s and GC servers.
  2. That server will need outbound internet access.
  3. An account setup (service account) for the sync of the accounts.
  4. Admin address to the Office 365 tenant.

Firstly lets take a look at the local Active Directory structure for the Light Blue Frog organization. The AD is relatively new and was thought out well in advance. This is not normally the case in most AD deployments so I recommend using the following tool – idfix – which is available from Microsoft using this link. This will tell you what remediation needs to be done on the domain before you sync to Office 365.

UPN – Discussion. It is an important factor to think about what ID your users will login to the cloud services with. The UPN (User Principal Name) is in Active Directory and I will speak more on this later. In the mean time have a look at this to assist – Why your UPN should match your email address

You also need to think about what you actually want to sync, as later on we will pick out the OU’s that will go up to the cloud. Below is a layout of the Light Blue Frog domain structure.

Now let’s login to the AAD Connect Server and install the Azure AD Connect software. This can be found at this link. This needs to be installed on the AAD Connect server. Download the software and start the installation process. Before we do that it might be worth having a quick look at this Microsoft article that talks about what you can/can’t do with AAD Connect.

On the first run through of AAD Connect when you start you will get the normal Welcome screen and get the opportunity to do an Express or Custom Install. I will select the custom install because I want to specify the account that AAD uses to connect to Active Directory. Let’s go ahead an put in the account ‘svc_aadconnect’ which is a privileged account in Active Directory. It is relevant to show what the Azure AD looks like before we start. We do need to create a Service Account that the AAD Connect software will use to synchronize the data. The screenshot below shows this configuration.

After this, the user list will look very simple. With just the Admin user we created at the start and the Service Account for the Sync.

Now we can go ahead on the local server and start the installation process.

Hit Continue and the configuration process will start.

Mark Rochester
Mark Rochester
Mark currently works in the cloud space assisting large companies to migrate from either on premises to the cloud, or cloud to cloud. His experience with Enterprise migrations spans more than 25 years which basically makes him old. However, with all the oldness creeping up he still finds technology massively exciting. Please reach out for a chat anytime you would like. :-)

Related Articles

Migrate Microsoft 365 Mailboxes to Google Workspace

This is not a very common subject to talk about as most of the migrations that get performed are people moving into the Microsoft...

Microsoft 365 Discovery Report

If you are working with a Microsoft 365 tenant, whether it is for your own or for a client, it is often necessary to...

Batches Paused in ‘Needs Approval’ Status

When you are using the native Microsoft tools to migrate from Google Workspace (Gmail) into Microsoft 365 the tool works very well. It does...

Stay Connected

- Advertisement -

Latest Articles