Travis Roberts
Travis Roberts
  • 240
  • 2 520 883
Entra Domain Services and Windows AD Password Hash Synchronization
Entra Domain Services (Entra DS) is an Active Directory Domain Services (AD DS) compatible managed service hosted in Azure. Windows AD-sourced users can replicate to Entra ID with Entra Connect Sync. Legacy NTLM password hashes can also be replicated from Windows AD to Entra DS for the same sign-on experience between the on-premises and managed domains. This video covers configuring Entra Connect Sync to enable legacy NTLM password hash synchronization.
00:00 - Start
03:22 - Test Login with Sync Disabled
05:20 - Enable NTLM Hash Sync
09:25 - Verify Login for Windows AD Users
Zero to Hero with Azure Virtual Desktop
www.udemy.com/course/zero-to-hero-with-windows-virtual-desktop/?referralCode=B2FE49E6FCEE7A7EA8D4
Hybrid Identity with Windows AD and Azure AD
www.udemy.com/course/hybrid-identity-and-azure-active-directory/?referralCode=7F62C4C6FD05C73ACCC3
Windows 365 Enterprise and Intune Management
www.udemy.com/course/windows-365-enterprise-and-intune-management/?referralCode=4A1ED105341D0AA20D2E
Blog Post
www.ciraltos.com/entra-domain-services-and-windows-ad-password-hash-synchronization/
Example Code
learn.microsoft.com/en-us/entra/identity/domain-services/tutorial-configure-password-hash-sync?WT.mc_id=AZ-MVP-5004159#enable-synchronization-of-password-hashes
zhlédnutí: 307

Video

Deploy Entra Domain Service and Join a Server to the Domain
zhlédnutí 1,2KPřed 14 dny
Wow, I missed updating the slide deck from Azure AD to Entra ID! Too late to change it now. In this video, we review deploying Microsoft Entra Domain Services (Entra DS) and configuring replication with Entra ID. The video starts by outlining the requirements and features of the Entra DS service, including password hash synchronization. Then we create a virtual network (VNet) for the service an...
Don't Use Entra Domain Services to Replace Windows Active Directory
zhlédnutí 2,6KPřed měsícem
Correction: Entra DS now supports a two-way trust. Entra Domain Services (Entra DS) is a Windows AD-compatible service managed by Microsoft. Some may see it as a better alternative to self-hosting Windows AD. However, there are limitations to Entra DS that should be considered before using it to replace domain controllers. This video and accompanying blog post go over those limitations and outl...
How to Deploy Azure Managed Grafana
zhlédnutí 1,1KPřed měsícem
Grafana is a full-featured data visualization platform for Linux and Windows. With Azure Managed Grafana, we can host Grafana dashboards in Azure without the hassle of deploying and managing an Azure virtual machine. This video reviews the different options for Azure Managed Grafana Essential, Standard, and Grafana Enterprise. Then we walk through deploying Managed Grafana Standard in Azure. 00...
Geo-Redundancy for Azure Standard File Shares
zhlédnutí 869Před 3 měsíci
Many organizations rely on geo-replicated Azure storage as part of their disaster Recovery strategy. However, not all storage in Azure supports geo-redundant storage (GRS) or geo-zone-redundant storage (GZRS). This video reviews a new feature that supports geo-replicated storage for Azure standard file shares with large file support enabled, along with a demonstration of how to enable the new f...
Limit Clipboard Transfer Direction in Azure Virtual Desktop!
zhlédnutí 865Před 3 měsíci
Azure Virtual Desktop offers feature-rich options for hosting desktops in the cloud. Recently, a new preview feature was announced to control the direction of clipboard copy and paste actions. We can now control the direction and data types that can be transferred via clipboard from the local client to the session host and/or from the remote session host to the local client. This video reviews ...
Don’t Let Antivirus Impact FSLogix Performance
zhlédnutí 1,1KPřed 4 měsíci
FSLogix is the go-to solution for managing profiles in AVD and many other VDI environments. Configuring FSLogix is relatively simple, but there is one configuration setting that’s often overlooked and can cause performance problems that impact the end users. This video goes over configuring antivirus exclusions for FSLogix with the goal of increasing stability and performance with FSLogix. Link...
Advanced Conditional Access Policies for AVD
zhlédnutí 1,3KPřed 4 měsíci
Entra ID Conditional Access Policies are an excellent option for managing Multifactor Authentication, but there is more to it than MFA. This video follows a previous video on using Conditional Access policies to require MFA when accessing AVD. We expand on the concepts of the previous video by configuring the policy for different conditions, such as hybrid Entra ID joined devices and logging in...
How to Configure a Conditional Access Policy for AVD
zhlédnutí 1,5KPřed 4 měsíci
Enabling multi-factor authentication is one of the first steps any organization should take to secure the environment. But, not all applications are created equally. You may need to provide different requirements based on who logs in and to a given application. This video demonstrates how to configure a conditional access policy in Entra ID that applies to users logging into Azure Virtual Deskt...
How to Send Entra ID Logs to Log Analytics
zhlédnutí 1,2KPřed 5 měsíci
We can view Entra ID log data from the portal, but that is only available for 30 days. We may want to store important log data like sign in activity and risky user actions for more than 30 days. Or we may need to send that data to other systems for future analysis and storage. This video goes over how to send Entra ID logs to Log Analytics. It starts with setting up a new Log Analytics workspac...
How to Review and Search AVD Insights Data
zhlédnutí 634Před 5 měsíci
You deployed AVD Insights and are collecting data, now what? This video is a guide to reviewing and searching the AVD insights workbooks available in Azure Virtual Desktop. We start with AVD Insights at Scale to get an aggregated view of data across your host pools. Then we review Session Host data in Insights at the host pool level. Finally, we look at an example of how to search for data rela...
Migrate AVD Insights to the New Azure Monitor Agent
zhlédnutí 2,7KPřed 5 měsíci
The legacy Microsoft Monitor Agent (MMA) for Log Analytics retires in August of 2024. Many have already deployed the MMA agent to collect data for AVD insights. This video reviews two options to move an Azure Virtual Desktop host pool from the MMA client to the new Azure Monitor Agent (AMA). 00:00 - Start 03:48 - Review AMA Migration Helper 05:01 - Create a Data Collection Rule 07:19 - Remove t...
Getting Started With AVD Insights and the Azure Monitor Agent
zhlédnutí 2,1KPřed 5 měsíci
Monitoring is important for any infrastructure, including AVD. Microsoft provides a tool for managing AVD called AVD Insights. This tool uses Log Analytics to store performance and event information sent from the host pool, workspace and session host VM’s. This video reviews how to configure AVD Insights using the Azure Monitoring Agent (AMA). 00:00 - Start 04:09 - Create a Log Analytics Worksp...
What you need to know about Azure Premium SSD V2 Disks
zhlédnutí 989Před 6 měsíci
Microsoft recently announced the availability of Azure Premium SSD V2 disks. These are a great and economical option for high-performance workloads in Azure. This video starts with a description of the problem Premium SSD V2 disk solve, then we compare the price and configuration with Premium SSD Disks. We also review how to deploy a VM with a Premium SSD V2 disk and how to create one to attach...
What are RBAC Roles in Azure and How to Use Them
zhlédnutí 2,2KPřed 6 měsíci
It is important to understand how security works in Microsoft Cloud Services. Role Based Access Control (RBAC) is at the core of protecting Entra ID, Azure and Microsoft 365 products. This video starts with an overview of Authentication and Authorization, then moves into explaining the different ways to secure Microsoft Entra and Azure resources with RBAC roles. Next, we review how scopes work ...
Create a Virtual Switch and Virtual Machine in Hyper-V
zhlédnutí 5KPřed 6 měsíci
Create a Virtual Switch and Virtual Machine in Hyper-V
Bare Metal Install Windows Server and Hyper-V
zhlédnutí 7KPřed 7 měsíci
Bare Metal Install Windows Server and Hyper-V
Can a PIN be safer than a Password?
zhlédnutí 2KPřed 7 měsíci
Can a PIN be safer than a Password?
How to Create a Static Website in Azure Storage
zhlédnutí 2,3KPřed 7 měsíci
How to Create a Static Website in Azure Storage
What is Entra ID, Entra Domain Services, and Windows AD?
zhlédnutí 13KPřed 8 měsíci
What is Entra ID, Entra Domain Services, and Windows AD?
Azure Update Manager with Azure Policies
zhlédnutí 9KPřed 9 měsíci
Azure Update Manager with Azure Policies
How to Add an EXE App to Intune and Deploy to Windows
zhlédnutí 12KPřed 9 měsíci
How to Add an EXE App to Intune and Deploy to Windows
How to Add an MSI Application to Intune and Deploy to Windows
zhlédnutí 6KPřed 9 měsíci
How to Add an MSI Application to Intune and Deploy to Windows
How to Configure Intune Clients with Configuration Profiles
zhlédnutí 6KPřed 10 měsíci
How to Configure Intune Clients with Configuration Profiles
The Impact of Live and Online IT Events for Career Development With Guest Simon Binder
zhlédnutí 194Před 10 měsíci
The Impact of Live and Online IT Events for Career Development With Guest Simon Binder
Keep Windows Secure with Intune Compliance Policies
zhlédnutí 4,9KPřed 10 měsíci
Keep Windows Secure with Intune Compliance Policies
Landing Your First IT Job with Guest Keith Enright
zhlédnutí 188Před 11 měsíci
Landing Your First IT Job with Guest Keith Enright
Join Me at the US AVD User Group
zhlédnutí 864Před 11 měsíci
Join Me at the US AVD User Group
User-Initiated Intune Enrollment and Azure AD Join
zhlédnutí 3,1KPřed 11 měsíci
User-Initiated Intune Enrollment and Azure AD Join
Intune Auto Enrollment with Windows Group Policy
zhlédnutí 16KPřed 11 měsíci
Intune Auto Enrollment with Windows Group Policy

Komentáře

  • @user-sm6rn3ku3u
    @user-sm6rn3ku3u Před 15 hodinami

    Jai ho

  • @TimDAnnecy
    @TimDAnnecy Před 2 dny

    Straightforward vid--Thank you!

  • @kayoutube690
    @kayoutube690 Před 3 dny

    Is this the best solution for hub and spoke network??

  • @chauhan785
    @chauhan785 Před 4 dny

    Thanks Sir, I did the same steps for my new staging server. One thing I noticed, on both the servers if I run get-adsyncconnector ! Fl name,identifier, I am getting the same AD domain connector GUID . Is this correct? Or not?

  • @Doctair
    @Doctair Před 5 dny

    Thanks for this great video. You mention you need windows 10 or 11 specific ADMX Templates but its no longer the case. Per Microsoft, as of 21/07/23, You can now use the new Windows 11 ADMX files (download from Microsoft Download Center) to maintain Windows 11 and Windows 10 clients. Hope that helps others troubling shooting the gpo deployment.

  • @bosstechsupport
    @bosstechsupport Před 6 dny

    does the vpn needs to be enabled all the time for the shares to have access? i need to install the vpn on all users? can i not do it with a vpn if i am inside my company network?

  • @patrickwasp
    @patrickwasp Před 6 dny

    Can you log into windows using entra?

  • @johnthompson3530
    @johnthompson3530 Před 7 dny

    Excellent video. Thanks very much for this.

  • @rest822
    @rest822 Před 7 dny

    Excellent video. Question: How do we move the lock.hcl file back to our ADO repository ?

  • @kevinjackson5191
    @kevinjackson5191 Před 7 dny

    The problem with this is that it sets up the user as an “Administrator’. That’s a big no-no for most organisations who simply want their devices hybrid AAD joined without elevating a standard users permissions.

  • @erickmartinez5112
    @erickmartinez5112 Před 7 dny

    Thank you, Travis Very usefull an clear

  • @alwinm5179
    @alwinm5179 Před 8 dny

    Awesome Video. This the video I tried to find for a while and finally found it. Thanks for making this.

  • @GregThomson
    @GregThomson Před 8 dny

    Thanks for another great video! Entra DS is all about taking those last few apps that depend on Kerberos for authentication and getting them out of the data center. It would be nice to see the next step of setting up app proxy and Kerberos constrained delegation. It would be interesting in a cloud native, passwordless world to see what's possible. Do we still need to reset passwords?

  • @chrisbaffour1341
    @chrisbaffour1341 Před 10 dny

    What if you already have existing servers? How do you add those servers to the newly created domain etc?

  • @packraftprasant3619
    @packraftprasant3619 Před 11 dny

    How can I integrate DNS proxy if I am using AD integrated DNS with proxy which points to the AD DNS hosted on the cloud. Will it cause the loop>

  • @zeinzubedi
    @zeinzubedi Před 11 dny

    Hi Travis, quick question how do you upgrade Windows 10-Inplace upgrade to Windows 11 AVD, from Gen 1 to Gen 2?

  • @papajohnscookie
    @papajohnscookie Před 12 dny

    Great walkthrough, thank you very much

  • @FirstChallenge-uf2uq
    @FirstChallenge-uf2uq Před 13 dny

    Thanks Travis. What if i select both of authentication methods? Then do i have to set password and ssh private key both?

  • @Boxpeoplez
    @Boxpeoplez Před 13 dny

    This video is really good. I was able to understand VNet concept and your demonstration of VNet peering. Thank you so much.

  • @cheslei2011
    @cheslei2011 Před 13 dny

    The way you explained things made it easier for me to understand Terraform. Thanks!

  • @mikedqin
    @mikedqin Před 14 dny

    Hey Travis, Your Azure Video is super good in quality. I love them all. Helped me a lot. Thank you so much.

  • @dukephuongnguyen2053
    @dukephuongnguyen2053 Před 14 dny

    Thank you Travis for your amazing video. It has helped so much in learning about Azure automation

  • @gurub5773
    @gurub5773 Před 14 dny

    13:37 at this moment the client address panel top we have TRSURFACE instead of ip address how to change ip address to custom name on client top blue colour panel. I aware public ip dns name can be reflected but it should come with some .com. I want to display only some custom name on the ip address panel. How i can do that

  • @diabilliq
    @diabilliq Před 15 dny

    list of reasons to use entra domain services: 1.

  • @joethompson297
    @joethompson297 Před 16 dny

    Travis, I've found, if I deploy EIDDS to a spoke identity network, I have to add routing back to the hub firewall, or resources can't resolve dns. Resources can query dns on EIDDS, but EIDDS doesn't have a route back to the resources for resolution. Have you seen this?

  • @fbifido2
    @fbifido2 Před 16 dny

    I have a Server 2022 VM that i Entra-ID joined, but under domain is still say workgroup? how can i change it to say "Entra-ID Joined" or do i have to create a workgroup call that?

  • @fbifido2
    @fbifido2 Před 16 dny

    Will Azure also provide an "Entra Enterprise CA" like service ??? - with auto-enrollment & renewals for the VM & connected devices?

  • @fbifido2
    @fbifido2 Před 16 dny

    if we add the VM ip-address when creating the VM, or in the portal, then that IP address becomes a DHCP reserved address for that VM. - is it possible to access that DHCP service using the RSAT tools?

    • @Ciraltos
      @Ciraltos Před 16 dny

      Azure VM's get their IP from the WireServer IP, not from Windows DHCP. The only way to set a static private IP in Azure VM's is by setting it on the virtual NIC in Azure.

  • @fbifido2
    @fbifido2 Před 16 dny

    How does one manually add DNS entry??? How to add a TXT/A/AAA/CNAME record, or a SRV record when using Entra-DS?

    • @Ciraltos
      @Ciraltos Před 16 dny

      Add the DNS Server tools to the management computer; it's a feature that is not part of the AD DS tools. DNS on the managed domain can be managed from there.

  • @KasperBoLarsen
    @KasperBoLarsen Před 17 dny

    Nice overview 😊 Do you know why there there is no Azure Entra GUI for adding permissions to Enterprise Apps, and we have to use PowerShell?

  • @SalmiMohamed27
    @SalmiMohamed27 Před 17 dny

    This is amazing and easy to understand. This solved many confusions I had in my skull. Thank for the content Travis. Great Job.

  • @hugaotv
    @hugaotv Před 18 dny

    Hi guys, m having a lot of trouble with join with my account, and i kinda know that is because i dont have all the permissions that i should have... Someone can asnwer to me what is the license that i need to? (sorry for my bad english, im brazilian)

  • @theitpro4688
    @theitpro4688 Před 18 dny

    please d

  • @DanielSzarszewski
    @DanielSzarszewski Před 19 dny

    Not working :/

  • @ksas323
    @ksas323 Před 20 dny

    Thank you so much!

  • @KumarAshish-zh9iq
    @KumarAshish-zh9iq Před 20 dny

    👌 awsm

  • @phanindran4399
    @phanindran4399 Před 21 dnem

    Hi @travis, Have one question. How to ensure the powershell commands used in runbook are signed ?How do I execute signed powershell commands in runbook

  • @curranp3892
    @curranp3892 Před 22 dny

    Hi Travis love your stuff didnt realize famous you are !

  • @curranp3892
    @curranp3892 Před 22 dny

    This guy i swear i recognize his voice he has courses on cloud academy he is a celebrity

  • @antonkhantil8970
    @antonkhantil8970 Před 22 dny

    Very good tutorial! Waiting for new one about Scrum project. thx

  • @SmallvilleJW
    @SmallvilleJW Před 23 dny

    Awesome overview, Travis! Thank you so much for providing excellent Azure content. 😎

  • @raymondcolijn8130
    @raymondcolijn8130 Před 25 dny

    Hi Travis, B4 you missed it. MS is changing the cloud apps inclusion/exclusion in Entra Conditional Access with AVD. You have to add Windows Cloud Login

  • @itlabs2351
    @itlabs2351 Před 26 dny

    for the uninstall command why was % used in path name?

  • @77zishan
    @77zishan Před 26 dny

    Thanks again for this video! Love it

  • @kristopherleslie8343
    @kristopherleslie8343 Před 27 dny

    Seems like a convoluted offering

  • @77zishan
    @77zishan Před 27 dny

    Thanks a lot for the explanation; I really enjoyed the video

  • @acocietocioto
    @acocietocioto Před měsícem

    Great video, thank you!

  • @TechyTubeDotCom
    @TechyTubeDotCom Před měsícem

    "Talk nerdy to me"😁 love you Travis thank you for all the videos that you do, clear, concise and to the point. And extremely useful.

  • @almaholt299
    @almaholt299 Před měsícem

    Excellent video!!! Thank you so much!!!

  • @D-Weezy2284
    @D-Weezy2284 Před měsícem

    I really appreciate this playlist. I've watched many videos on how to learn Terraform and your examples and explanations have worked wonders for me in understanding the material and able to retain and work on it on my own.