Info Security Memo
  • Blog
  • Sitemap
    • Categories
  • Contact
  • About
  • Resources
  • Tools
  • 51sec.org

Build Confidence

Focusing on Information Security 

Info Security Notes

Setup Hybrid Azure Active Directory Join For Managed Domains

11/6/2021

0 Comments

 
Setup Hybrid Azure Active Directory Join For Managed Domains

After you configured your on-prem domain (Local AD DS) to sync with Azure Active Directory (AAD), next step is to get your clients to choose which one to log in, you can use only local AD or only Azure AD or both.

By default, after you completed your ADConnect setup, as instructed in previous post "Set Up On-Prem Domain For Identity Synchronization With Azure AD (AAD)", you will not be in Hybrid mode, which means you only can choose either local AD or AAD to log in, but not both as shown below screenshot:



In this post, I am going to show you the steps how you can enable this Hybrid AD login for your client machines.

More details can be found from Microsoft doc: Tutorial: Configure hybrid Azure Active Directory join for managed domains

Basically if you have an on-premises Active Directory (AD) environment and you want to join your AD domain-joined computers to Azure AD, you can accomplish this by doing hybrid Azure AD join. 


Pre-requisites

This is assume ADConnect configuration has been completed, user is able to log in with AAD account.

Following post shows all steps to configure on-prem domain to sync with AAD.
  • "Set Up On-Prem Domain For Identity Synchronization With Azure AD (AAD)"


Since Hybrid mode has been enabled, if you machine has not been joined into local AD, you should be able to directly join into AAD like shows in following screenshot:


If you joined into domain already, you might want to dis-join it from local ad first, then join into AAD. Vice versa for the machine already joined AAD, you will disconnect from AAD to join into local AD. Not having both joined at the same time, since hybrid mode not enabled.


Enable Hybrid Mode

To configure a hybrid Azure AD join by using Azure AD Connect:

  1. Start Azure AD Connect, and then select Configure.



  2. In Additional tasks, select Configure device options, and then select Next. This will configure device registration (Hybrid Azure AD join) and synchronization (device writeback).

    Additional tasks

  3. In Overview, select Next.

  4. In Connect to Azure AD, enter the credentials of a global administrator for your Azure AD tenant.

  5. In Device options, select Configure Hybrid Azure AD join, and then select Next.

    Device options

  6. In Device operating systems, select the operating systems that devices in your Active Directory environment use, and then select Next.

    Device operating system

  7. In SCP configuration, for each forest where you want Azure AD Connect to configure the SCP, complete the following steps, and then select Next.

    1. Select the Forest.
    2. Select an Authentication Service.
    3. Select Add to enter the enterprise administrator credentials.

    SCP

  8. In Ready to configure, select Configure.

  9. In Configuration complete, select Exit.


Get Machine Join into AAD and Local AD

No matter if you machine has joined into AAD or local AD or none of them, you can get your machine to join into both and use both of them to log in. 

After joined into both, you can switch to either one of log in methods to log into your machine.


If they are same user, you will use same profile after logged in. If they are different user, they will use different profile.


References

  • Tutorial: Configure hybrid Azure Active Directory join for managed domains
  • Set Up On-Prem Domain For Identity Synchronization With Azure AD (AAD)






via Blogger http://blog.51sec.org/2021/11/setup-hybrid-azure-active-directory.html
November 06, 2021 at 08:01PM Cloud
0 Comments



Leave a Reply.

    Categories

    All
    Architecture
    Blog
    Checkpoint
    Cisco
    Cloud
    CyberArk
    F5
    Fortigate
    Guardium
    Juniper
    Linux
    Network
    Others
    Palo Alto
    Qualys
    Raspberry Pi
    Security
    SIEM
    Software
    Vmware
    VPN
    Wireless

    Archives

    March 2024
    February 2024
    January 2024
    December 2023
    November 2023
    October 2023
    September 2023
    August 2023
    July 2023
    June 2023
    May 2023
    April 2023
    March 2023
    February 2023
    January 2023
    December 2022
    November 2022
    October 2022
    September 2022
    August 2022
    July 2022
    June 2022
    May 2022
    April 2022
    March 2022
    February 2022
    January 2022
    December 2021
    November 2021
    October 2021
    September 2021
    August 2021
    July 2021
    June 2021
    May 2021
    April 2021
    March 2021
    February 2021
    January 2021
    December 2020
    November 2020
    October 2020
    September 2020
    August 2020
    July 2020
    October 2019
    September 2019
    June 2019
    July 2018
    May 2018
    December 2017
    August 2017
    April 2017
    March 2017
    January 2017
    December 2016
    November 2016
    October 2016
    September 2016
    August 2016
    July 2016
    June 2016
    May 2016
    April 2016
    March 2016
    February 2016
    January 2016
    December 2015
    November 2015
    October 2015
    September 2015
    August 2015
    July 2015
    June 2015
    May 2015
    April 2015
    March 2015

    Print Page:

    RSS Feed

    Email Subscribe
Powered by Create your own unique website with customizable templates.
  • Blog
  • Sitemap
    • Categories
  • Contact
  • About
  • Resources
  • Tools
  • 51sec.org