Synchronizing On-premises Active Directory with Azure AD
Last updated
Last updated
In this tutorial, we'll guide you through the process of synchronizing your on-premises Active Directory (AD) with Azure AD. My domain for this exercise, harchitlocal.online, will be used for both our on-premises and Azure environments. Using the same domain name simplifies the synchronization process. Additionally, the domain has been purchased through GoDaddy, which will manage our DNS records.
Step 1: Subscribe to Microsoft 365 for Business
1.
To enhance comprehension throughout the process, try to use a domain name that closely aligns with your actual domain name. Additionally, you will have the option to save your login credentials for easier access.
After entering the necessary credentials and information, click on "Start Trial" to begin.
Now, let's access the Microsoft 365 Admin Center. Upon login, you'll be directed to a configuration page. Simply click "Continue" to proceed.
To view your domain settings, first switch to the Dashboard view. Then, navigate to the Settings menu and select the Domain option.
Step 2- Making an Azure AD domain
To add a domain, navigate to Settings and select the Domain section. Then, click on the Add Domain button.
Enter your domain name, then select "Use this domain."
Microsoft 365 recognizes that this domain name has been bought from GoDaddy thus we can verify that in this option. Click on Verify
A dialog box requesting credential verification appears. Please sign in by entering your credentials.
Click Connect
After the page loads, select Continue to proceed.
Click Add DNS Records. My DNS records already exists because of GoDaddy
Since GoDaddy has already configured our DNS records, there's no need to set them up manually. click "Connect" to proceed.
Our Domain setup is successfully complete. Click Done
Step 3: Synchronizing our Azure AD domain with on-premises domain
Click on Users and then Active Users where I have two users present. Click on three dots on the right and then select Directory Synchronization
We currently have 0 hybrid users. Click Next
In this scenario, we are conducting a continuous synchronization. Please click 'Next' to proceed.
The utilization of IdFix is not required if your on-premises domain name matches your Azure AD domain name which is the case for us. Click Next
Select Microsoft Entra Connect Sync and then click next
Download Microsoft Entra Connect Sync and put it in your domain controller .
Click Done. Next, we will configure the Entra Connect Sync.
Step 4: Installing and Configuring AzureADConnect on my on-premises domain controller
Click on AzureADConnect
Click Continue on Welcome to Azure AD Connect
To enhance our learning process, we are tailoring our configurations. Please choose "Customize".
Enable single sign-on and Password Hash Syncronization and then select Next
Enter your Azure AD global administrator username and password and then click next
Select Add Directory on Connect your directories page
To create a new Active Directory (AD) account, click on 'Create a new AD account'. Then, enter the desired Admin Username. Click OK to proceed.
Our directory has been added. Click next to proceed
In the Azure AD sign-in configuration, select UserPrincipalName and click Next
By default, the synchronization process includes all domains and organizational units (OUs). For this setup, we'll focus on synchronizing the on-premises IT OU specifically. To do so, choose Sync selected domains and OUs, select the IT OU, and click
Click Next without changing the default setting on Uniquely identifying your users page
Select Synchronize all users and devices and click next
In the Optional features, let's select the Password writeback option. Password writeback is a feature that allows password changes made in a cloud environment to be written back to an on-premises Active Directory (AD) environment. Click Next
When the "Ready to Configure" page appears, click on "Start Synchronization Process" upon configuration completion, then select "Install."
Our synchronization has successfully completed, press exit
Returning to the Microsoft 365 Admin Center, we now observe the inclusion of a new user in the active users list, namely Barry Bonds, associated with the IT Organizational Unit (OU). Additionally, the sync status reveals distinctions between cloud-based and on-premises users.
On the homepage of the Microsoft Admin Center, you can view the status of the successful Azure AD synchronization.