Install and configure Azure AD connect in server 2019

Azure AD Connect is a tool for identity synchronization between on-premise AD and Azure AD.

Windows Articles

How to analyze the network with IP Tools for Android

Hi! If you want to analyze and adjust the network almost professionally, then this post is for you. Indeed, IP Tools is...

How to install GNU Fortran on Ubuntu 20.04 / 18.04?

Not everything old is bad. This is how it is. Well, while it is true that there are many programming languages today, there are...

How to install Unity Desktop on Ubuntu 20.04?

Unity Desktop was for a long time the default desktop environment in Ubuntu. Thanks to this, Ubuntu gained a great personality and...

How to install Android on a PC with Phoenix OS

Hello! Android is the most widely used mobile operating system in the world. Indeed, this Linux-based system has a large market share....

How to install Apache Maven on OpenSUSE 15.2 / 15.1?

In this post, we will show you how to install Apache Maven on OpenSUSE 15.2 / 15.1. To manage projects done in Java, there is...

Azure AD Connect is a tool for identity synchronization between on-premise AD and Azure AD. Azure Ad connect supports hybrid authentication which includes Password hash authentication (PHA), Pass-through authentication(PTA) and federation (ADFS). Hybrid authentication methods provide single-sign on capabilities.

Azure AD connect is completely free to use and synchronize even if we don’t own any cloud subscriptions. It is an upgraded version of Azure AD sync and Dirsync.

Requirement for Azure AD connect

  1. Azure AD tenant. (domainname.onmicrosoft.com)
  2. AD schema version and forest functional level (FFL) must be set to Server 2003 or higher.
  3. Domain Admin credential.
  4. Global Admin of the tenant.
  5. Add and verify the domain.
  6. Update the UPN name of the users in local AD to match the public domain name verified in the cloud. (UPN suffix to be updated from user@domain.local to user@domain.com)
  7. SQL database (optional- To manage 100,000+ objects)
  8. Ports to be allowed in firewall – https://docs.microsoft.com/en-us/azure/active-directory/hybrid/reference-connect-ports

Microsoft recommends to use Idfix Dirsync error remediation tool before initial sync to remediate the object errors in the Active Directory preparation.

Installation of Azure AD connect

1. Download the latest Azure AD connect and double-click on the installed file for installation.

2. Read the license agreement and click ‘Continue’ if you agree.

3. Azure AD connect is available to install as ‘Custom installation‘ and ‘Express installation‘. Click ‘Customize‘ to enter custom installation.

  • Custom installation provides option to specify custom location, sync only the selected OU, adding the SQL server instance. Proceed with custom installation to sync users only from the selected OU.
  • Express installation is recommended by Microsoft for single server forest. By default, password hash sync and auto upgrade is enabled with express settings. Proceed with express installation to sync the entire domain. In this example, we installing with express install option.

4. Enter the credential of the Azure AD Global admin and click ‘Next‘.

5. Enter enterprise admin credential of on premise AD and click ‘Next’

6. In Next step, AD connect will verify that UPN suffix of local AD matches with added custom Azure AD domain. Verify your domain and click ‘Next’.

7. Configure: Select ‘Synchronization process’ to start sync immediately. Select ‘Exchange hybrid deployment’ if planning to migrate mailboxes (Recommended). Click ‘Install’

8. AD connect will install synchronization service and initiate sync between local AD and Azure AD.

9. Congrats! Configuration is completed successfully. 

10. Verify the configuration : Login in to Microsoft 365 admin center – https://admin.microsoft.com with global admin credential to verify initial sync.

  • Also verify the login of  https://portal.office.com using on premise AD user credential.
  • By default, sync between local AD and Azure AD occurs in every 30 minutes. To force AD sync Open Windows Azure Active directory powershell and run following commands:
    Import-module Adsync
    Start-ADSyncSyncCycle -PolicyType Delta          # To initiate Delta Sync
    < or > 
    Start-ADSyncSyncCycle -PolicyType Delta       # To initiate Full Sync
  • An Azure AD tenant allows by default 50K objects and increased to 300K objects on domain verification.

More articles

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Latest article

How to analyze the network with IP Tools for Android

Hi! If you want to analyze and adjust the network almost professionally, then this post is for you. Indeed, IP Tools is...

How to install GNU Fortran on Ubuntu 20.04 / 18.04?

Not everything old is bad. This is how it is. Well, while it is true that there are many programming languages today, there are...

How to install Unity Desktop on Ubuntu 20.04?

Unity Desktop was for a long time the default desktop environment in Ubuntu. Thanks to this, Ubuntu gained a great personality and...

How to install Android on a PC with Phoenix OS

Hello! Android is the most widely used mobile operating system in the world. Indeed, this Linux-based system has a large market share....

How to install Apache Maven on OpenSUSE 15.2 / 15.1?

In this post, we will show you how to install Apache Maven on OpenSUSE 15.2 / 15.1. To manage projects done in Java, there is...