New Solution for Azure AD Synchronization with AAD Cloud Sync

Sdílet
Vložit
  • čas přidán 24. 07. 2024
  • In this video I dive into the new way to synchronize your AD objects to Azure AD with a cloud-based engine, Azure AD Cloud Sync! Complete whiteboard of solution and demo.
    Pilot documentation - docs.microsoft.com/en-us/azur...
    Pre-reqs - docs.microsoft.com/en-us/azur...
    Comparison - docs.microsoft.com/en-us/azur...
    00:00 Introduction
    00:25 AD and AAD Connect refresher
    04:40 AAD Cloud Sync intro
    08:00 Multi-purpose local lightweight agent
    09:25 Synchronization interval
    11:15 AAD Connect and AAD Cloud Sync together
    14:35 On-demand provisioning
    15:50 AAD Cloud Sync deployment
    20:11 Viewing logs
    21:05 AAD Connect OR AAD Cloud Sync?
    24:20 Close and next steps
  • Věda a technologie

Komentáře • 117

  • @ankitsharma-nd1dd
    @ankitsharma-nd1dd Před 3 lety +2

    You are amazing John! Thank you for getting these great informative videos and helping us understand these concepts/features/services.

  • @agreenexperience
    @agreenexperience Před 3 lety +4

    Thanks John, as always your videos are extremely informative.

  • @rajsyed729
    @rajsyed729 Před 2 lety

    This video is just amazing, Thank you for making this so clear!!

  • @d7oomy5500
    @d7oomy5500 Před rokem

    Thanks, John, for the explanation

  • @abdulwajid3652
    @abdulwajid3652 Před 2 lety

    A gem you are Jhon. Thank you for this.

  • @sep27061985
    @sep27061985 Před rokem

    Thank you so much for your awesome explanation! :)

  • @yansroll.h9285
    @yansroll.h9285 Před 3 lety

    Great video John, very useful as always. Thank you

  • @martincayer2615
    @martincayer2615 Před 3 lety

    Another great video. Thank you John!

  • @James-sc1lz
    @James-sc1lz Před 3 lety

    Very informative as always. Thanks John

  • @Mr-Not-Applicable
    @Mr-Not-Applicable Před 3 lety +1

    I came looking for a Jane Fonda's workout yet here I stayed for the whole video and learned a few things! Thank you for the great content!

  • @oranais3074
    @oranais3074 Před 3 lety

    Thank you mate. As usual an excellent presentation.

  • @yulaw3289
    @yulaw3289 Před 2 měsíci

    enjoying this video for today learning, thanks a lot!

  • @schillaci5590
    @schillaci5590 Před 3 lety

    Marvelous, I'm going to sound like a right expert in tomorrow's workshop

  • @carolinacadenas7524
    @carolinacadenas7524 Před 3 lety

    Excelent explanation. Many thanks

  • @Depstha
    @Depstha Před 2 lety

    You are doing a wonderful job !!

  • @Semtx552
    @Semtx552 Před 3 lety +1

    This is incredibly helpful, thanks a lot!

  • @allthebeesaredead188
    @allthebeesaredead188 Před 3 lety

    You explain stuff so well!

  • @HealthyMBS1
    @HealthyMBS1 Před 3 lety

    great video. I was getting my hopes up the entire video because I was hoping the cloud sync could be used for device objects, but I saw the comparison chart finally and it isn't yet supported (so you now know I watched all the way to the end!) We can't get regular sync to move devices so they show up in Azure as Hybrid-Azure AD joined for some reason. Back to the troubleshooting...

    • @NTFAQGuy
      @NTFAQGuy  Před 3 lety

      you'll see it reach feature parity eventually. This is v1

  • @carlosalbertofernandezlara219

    it's brilliant the way you explain about technology. Thanks a lot. It helped me a lot.

  • @tony6626
    @tony6626 Před 3 lety

    Amazing explanation as always John - thanks for the knowledge share.

    • @NTFAQGuy
      @NTFAQGuy  Před 3 lety

      Glad you enjoyed it

    • @tony6626
      @tony6626 Před 3 lety

      @@NTFAQGuy Just working through one of your Pluralsight courses (great btw!) - is this the same as the AAD Connect Provisioning Agent (for linking HRM systems to auto create on-premise accounts)?

    • @NTFAQGuy
      @NTFAQGuy  Před 3 lety

      @@tony6626 yes, i do mention that in the video.

  • @inarizic4945
    @inarizic4945 Před 2 lety

    Very well explained. Thank you so much!

    • @NTFAQGuy
      @NTFAQGuy  Před 2 lety +1

      You're very welcome!

    • @inarizic4945
      @inarizic4945 Před 2 lety

      @@NTFAQGuy any plans for a deep dive on cloud app security or identity management in Azure?

    • @NTFAQGuy
      @NTFAQGuy  Před 2 lety

      @@inarizic4945 there is an entire aad playlist

  • @charleshobbs9034
    @charleshobbs9034 Před 3 lety

    Nicely done!

  • @TDelux
    @TDelux Před 3 lety

    Excellent vid sir, you just got a new subscriber.

    • @NTFAQGuy
      @NTFAQGuy  Před 3 lety

      Awesome, thank you!

    • @TDelux
      @TDelux Před 3 lety

      @@NTFAQGuy do you have suggestion on setting up AAD as the main identity manager and on premises server just a member to provide credential access to local resources (local software or network access devices).

  • @sameermalwad8970
    @sameermalwad8970 Před 2 lety

    @John, As usual loved the content, But more than that loved the T-Shirt my fav :)

  • @waqaskhan010
    @waqaskhan010 Před 2 lety

    Amazing as always. Keep the good work going. Just wondering who is that one person who always dislikes your videos🤔 Can't you identify and block?

    • @NTFAQGuy
      @NTFAQGuy  Před 2 lety +1

      Lol no you can’t see :) haters gonna hate :)

  • @CarlosRivera-tb9fk
    @CarlosRivera-tb9fk Před 3 lety +2

    Really helpful video. I’m really trying to determine if I can get away without deploying AD and just use Azure AD, this way I only worried about one thing. The environment has Windows and Macs.

  • @mohammedbendarghate8389

    Hello John,
    Thank you for all the effort on providing us with the quality content both here on youtube and also on PluralSight.
    I have a question if you dont mind :
    We are currenty preparing to sync all the users from AD on premise to Azure AD,so far nothing special but once I knew that the company is already using a differente Identity for O365 (full cloud ) in the same time as the on premise Identity . the role of using the AZure Ad connect is to avoir the creation of new identities and exploite what we already have onpremise .
    Can you please suggest the best way to sync the on premise identities without losing what we already have online ?
    Thank you in advance

    • @NTFAQGuy
      @NTFAQGuy  Před 3 lety +1

      If you have existing objects the AAD Connect will try and find a match and connect them and will take over the AAD object. Check the docs for hybrid scenarios.

  • @jimfowler4924
    @jimfowler4924 Před 3 lety

    Thanks for the video, very well done, nice and clear. I have a question if you don't mind - We are currently using AAD Connect for password sync and have an on-prem Exchange for management but don't really want that. Can we use Cloud Sync for the password sync and ditch the on-prem Exchange, managing all Exchange attributes through O365 please?

    • @NTFAQGuy
      @NTFAQGuy  Před 3 lety

      I don’t focus on exchange so not sure if there are special considerations but if you become o365 only and ditch exchange on prem then I would expect everything possible via aad.

  • @kauffmann101
    @kauffmann101 Před 3 lety

    Thanks for your video, John. Is it support running both AAD connect and AAD cloud sync in the same AD forest environment with the same tenant ?

    • @NTFAQGuy
      @NTFAQGuy  Před 3 lety +2

      I covered this in the video

  • @cdm297
    @cdm297 Před 3 lety

    Excellent video John. Keep up the great work🙏. Does it support single AD forest to multiple Azure AD tenant? Eg OU A syncing to Azure AD tenant A and OU B syncing to Azure AD Tenant B, with different UPN and SMTP?

    • @NTFAQGuy
      @NTFAQGuy  Před 3 lety +1

      Supported scenarios are documented at docs.microsoft.com/en-us/azure/active-directory/cloud-sync/plan-cloud-sync-topologies

  • @thepoliticalstartrek
    @thepoliticalstartrek Před 3 lety

    We are moving most of our documents to Teams. Heard there is something on the way to mount these shares more like Network shares and drive mappings.

  • @550891
    @550891 Před 2 lety

    thank you john. that is excellent explanation. what happens if one of the company you are merging with already is part of another tenant but you want to merge it or including it to your tenant ? i just want only one azure AD tenant than multiple ones ?

    • @NTFAQGuy
      @NTFAQGuy  Před 2 lety +1

      There are documents walking through merger scenarios. Maybe I’ll do a video on that at some point. It’s not something I can answer in comments

  • @ZX48K
    @ZX48K Před 3 lety +1

    Great video. When this new method has matured and AAD Connect is depreciated, will there be an upgrade path to AAD Sync? Is it simply turn off AAD Connect and turn on AAD Sync?

    • @NTFAQGuy
      @NTFAQGuy  Před 3 lety

      I'm sure yes there will be a published way to migrate cleanly.

  • @jonathanroundy924
    @jonathanroundy924 Před 3 lety

    Do you have plans on unpacking the HRM Provisioning? I saw you explain some of how it works. Is this something that works with Dynamics365 HR or would we have to be using WorkDay or one of the one's mentioned particularly in the Microsoft Docs?

    • @NTFAQGuy
      @NTFAQGuy  Před 3 lety +1

      No current plan but who knows. :-)

  • @AquibQureshi
    @AquibQureshi Před 3 lety

    Hey John, you use tool to highlight specific control, a red rectangle or square comes up when you do screeshare and highlight. which tool is it?
    13:59

  • @jasoncummings7052
    @jasoncummings7052 Před 2 lety

    Thank you for this and all the other presentations. Very well done. (L+S)
    What are your thoughts on just using the AAD Sync agent in Azure to replace on-prem ADConnect?

    • @NTFAQGuy
      @NTFAQGuy  Před 2 lety

      i have another video where i look at options.

  • @felixmintah8632
    @felixmintah8632 Před 3 lety +1

    Thanks John for the interesting video. I believe you wanted to direct us to another video at 4:21 but no link or video showed. It's actually something I'm looking forward to get an insight of. If you'd be so kind to share in the comment, it'd be appreciated greatly.

    • @NTFAQGuy
      @NTFAQGuy  Před 3 lety

      OK there should have been a "i" in the corner but moved the clip so should be even more prominent now.
      Thanks

  • @tony6626
    @tony6626 Před 2 lety

    Just revisiting this after your AAD Connect V2 Video. With this Cloud Sync, am i right that you can continue using normal AAD Connect and use Cloud Sync for separate AD Forests to popular a single M365 tenant (such as for a merger or acquistion scenario)?

  • @MMTheWGA
    @MMTheWGA Před 3 lety

    @John Savill
    As always, very informative and well explained.
    What application do you use to create the recordings and how do you get those rectangular boxes around the text, is it a feature of the recording app?
    Thank you, am never going to get off this train! :-)

    • @NTFAQGuy
      @NTFAQGuy  Před 3 lety

      Have a playlist of my setup. Thx

    • @MMTheWGA
      @MMTheWGA Před 3 lety

      @@NTFAQGuy Thanks. Are the red rectangular boxes in the demos a feature of OBS Studio or a mouse setting that allows you to do that?

    • @NTFAQGuy
      @NTFAQGuy  Před 3 lety +1

      @@MMTheWGA zoomit

    • @MMTheWGA
      @MMTheWGA Před 3 lety

      @@NTFAQGuy Thank you :-)

  • @thepoliticalstartrek
    @thepoliticalstartrek Před 3 lety

    What they really need is a tool that moves the AD profiles to the AAD profile. Older tools have some issues.

  • @mqtt07
    @mqtt07 Před 3 lety

    What is a "tier zero type of machine"? I search for it and it looks like it is fast storage, but not sure it is the same meaning used in 7:16 in the video

    • @NTFAQGuy
      @NTFAQGuy  Před 3 lety

      No tier 0 refers to security and lock down of the machine.

  • @magnusgullo
    @magnusgullo Před 3 lety +1

    🤙🏻

  • @mikeycrawford8476
    @mikeycrawford8476 Před 3 lety

    Could you copy an on prem user out of an OU synced by AAD Connect and in to an OU synced by AAD Connect Cloud Sync without issues?

    • @mikeycrawford8476
      @mikeycrawford8476 Před 3 lety

      by issues, I mean not losing the O365 user account as it is no longer synced via AAD Connect.

    • @NTFAQGuy
      @NTFAQGuy  Před 3 lety

      it should not care how its sync'd but test first lol

  • @miken4022
    @miken4022 Před 2 lety

    I have a need to synchronize all of Active Directory to one Azure AD and also synchronize all of Active Directory to a second Azure AD. If AD already has an Azure AD Connect synchronizing to Azure AD, can Azure AD Cloud Sync synchronize the same objects to a second Azure AD?

    • @NTFAQGuy
      @NTFAQGuy  Před 2 lety

      I do not believe so if it’s the same users. A user can only be replicated once. Check the supported scenarios document.

  • @jjuant
    @jjuant Před 3 lety +1

    Muchas Gracias Profe, contigo hacia el AZ-104....
    Just Remember,.... Convención Universal de Nombres (UNC), This Format, This Format, This Format, This Format,
    Unidad Organizativa
    OU=UOUsersAADcloudConnect, DC=avmnet, DC=algmal, DC=com
    Group
    CN=GS_Admin, DC=avmnet, DC=algmal, DC=com
    Aprovisioning user
    CN=Meg Griffin, OU=UOUsersAADcloudConnect, DC=avmnet, DC=algmal, DC=com

  • @salmaanfarish
    @salmaanfarish Před 3 lety

    Does this Sync only user accounts and not computer objects from On-perm to Cloud?

  • @zueyyy
    @zueyyy Před 2 lety

    Tricky one here I'm hoping you can clarify. Environment A is an onpremise AD forest (called company.local) and is syncing to an Azure AD tenant with AAD connect.
    Environment B (a completely separate and isolated onpremise AD also called company.local that someone has smartly named with the exact same forest name as Environment A).
    Can Azure AD cloud sync be used to sync objects from Environment B into the same tenant even though the two separate onpremise active directory domain forests are named the same thing?

    • @NTFAQGuy
      @NTFAQGuy  Před 2 lety

      I would check the docs for requirements and limitations. I've never even thought about this scenario.

  • @grahamdunne5690
    @grahamdunne5690 Před 3 lety

    Hey John - and fellow viewers, I have a query based on all of this. All the current tools seem to be built around the flow of synching on-prem AD objects to Azure AD. In our situation we cloud native but we now have a need to run legacy apps that don't support modern auth, SAML or OIDC. We don't want to suddenly start using AD for things that we are presently using Azure AD for and we want the minimum of 'stuff' to run to enable us to have an on-prem identity source for the legacy apps - If the AAD Cloud Sync coudl be configured to sync FROM Azure AD only that would be great but unless I'm missing something that is not the case? Are there any other good alternatives that can do what we want? We're even investigating using OpenLDAP and custom scripts to do this, but surely MS have thought of this scenario? Or some other party in the MS ecosystem? Any tips gratefully received!

    • @NTFAQGuy
      @NTFAQGuy  Před 3 lety +1

      No. Only way would be azure ad domain services.

    • @grahamdunne5690
      @grahamdunne5690 Před 3 lety

      @@NTFAQGuy Yeah I though as much. We have ADDS setup so we'll see how far we can get with that. Seems like a use case others might have, so we'll also look around at third party stuff that might exist. Thanks for checking back and giving an answer!

  • @GaintArrow
    @GaintArrow Před 3 lety +1

    When we install cloud sync it looks machine is domain controller

    • @NTFAQGuy
      @NTFAQGuy  Před 3 lety

      It can be but does not need to be and not really recommended. Just another tier 0 box

  • @jaimedpcaus1
    @jaimedpcaus1 Před 2 lety

    I like the TV and ability to write on it. What is it called?

    • @NTFAQGuy
      @NTFAQGuy  Před 2 lety

      There is a playlist of the setup

    • @jaimedpcaus1
      @jaimedpcaus1 Před 2 lety

      @@NTFAQGuy k. Will review the video description.

  • @Saqibss
    @Saqibss Před 3 lety +2

    No Password write back? So no SSPR for cloud sync users.
    Great video, well explained, keep them coming.

    • @NTFAQGuy
      @NTFAQGuy  Před 3 lety +2

      not yet.

    • @Saqibss
      @Saqibss Před 3 lety

      @@NTFAQGuy once write back turns up I'll be recommending this. Thanks again.

    • @tilikumtim5562
      @tilikumtim5562 Před 3 lety +1

      No device sync either, so doesn't look like it can be used for hybrid joined devices which is a shame.

  • @gopeisho
    @gopeisho Před 3 lety

    It has too many things missing at this point. We run Hybrid Exchange and some of the other features that it doesn't have yet.

    • @NTFAQGuy
      @NTFAQGuy  Před 3 lety

      Yep, then for now you stay on AAD Connect :-) All about features used and what makes most sense.

  • @ssbtravelshots5589
    @ssbtravelshots5589 Před 3 lety

    Unless it is at par with Azure AD Connect, i don't think many customers will be interested into this. This is like IaaS to PaaS migration with reduced feature set as of now. But in future, as it develops, it will be a replacement for AADC for sure.

    • @NTFAQGuy
      @NTFAQGuy  Před 3 lety +1

      Lol. People use different capabilities. Each org will weigh independently but obviously you can have your opinion :)

  • @Timmy-Hi5
    @Timmy-Hi5 Před 3 lety

    🇬🇧 JSuperman 🎹 🚵‍♀️ great new tool , let's play

  • @MyJapaneseLife
    @MyJapaneseLife Před 3 lety

    The video's color is darker than usual

  • @fosternostrand1597
    @fosternostrand1597 Před 2 lety

    Dude is the most buff sysadmin I've ever encountered!

    • @NTFAQGuy
      @NTFAQGuy  Před 2 lety

      lol, camera adds 10lbs ;-)

    • @fosternostrand1597
      @fosternostrand1597 Před 2 lety

      @@NTFAQGuy Yeah It's never added it to my biceps!

    • @NTFAQGuy
      @NTFAQGuy  Před 2 lety

      @@fosternostrand1597 special lens ;-)