Don't Use Entra Domain Services to Replace Windows Active Directory

Поділитися
Вставка
  • Опубліковано 1 чер 2024
  • Correction: Entra DS now supports a two-way trust.
    Entra Domain Services (Entra DS) is a Windows AD-compatible service managed by Microsoft. Some may see it as a better alternative to self-hosting Windows AD. However, there are limitations to Entra DS that should be considered before using it to replace domain controllers. This video and accompanying blog post go over those limitations and outline how they could impact an organization.
    Links
    Free Azure guide! Subscribe to the newsletter
    subscribepage.io/rbsIjt
    Zero to Hero with Azure Virtual Desktop
    www.udemy.com/course/zero-to-...
    Hybrid Identity with Windows AD and Azure AD
    www.udemy.com/course/hybrid-i...
    Windows 365 Enterprise and Intune Management
    www.udemy.com/course/windows-...
    Entra ID, Windows AD and Entra DS video
    • What is Entra ID, Entr...
  • Наука та технологія

КОМЕНТАРІ • 17

  • @SmallvilleJW
    @SmallvilleJW Місяць тому

    Awesome overview, Travis! Thank you so much for providing excellent Azure content. 😎

  • @mysticsilent
    @mysticsilent 2 місяці тому

    Thanks for this nice guide!

  • @Wilhelmcook
    @Wilhelmcook 2 місяці тому

    Thanks for this explanation. Very Helpful.

  • @patrick__007
    @patrick__007 2 місяці тому

    Great and clear to me!

  • @77zishan
    @77zishan Місяць тому

    Thanks again for this video! Love it

  • @curranp3892
    @curranp3892 Місяць тому

    Hi Travis love your stuff didnt realize famous you are !

  • @alexmags
    @alexmags 2 місяці тому +1

    Limitation: Lack of cloud Kerberos trust, in Entra Domain Services, blocks sign in to domain joined' resources in Entra DS from Entra Joined desktops.
    Would you loose directory event logs in Defender for Identity (which is amazing) if you can't install it's agent/Defender for Endpoint?

  • @shahabpouladiankari4958
    @shahabpouladiankari4958 Місяць тому

    What if we had done it and got stuck in all those limitations? I have three tenants like this. And i am looking for a solution to move to windows AD or a hybrid with least down time.

  • @curranp3892
    @curranp3892 Місяць тому

    This guy i swear i recognize his voice he has courses on cloud academy he is a celebrity

  • @JonathanIsrael708
    @JonathanIsrael708 2 місяці тому

    I'm confused by your Intune Enrollment limitation point. Wouldn't devices be Entra joined, so the auto enrollment would still work?

    • @Ciraltos
      @Ciraltos  2 місяці тому +1

      Devices joined to Entra DS are not Entra joined. Auto-enrollment with Windows AD joined devices requires Entra Connect Sync for Hybrid join. Entra Connect Sync is not supported with Entra DS. learn.microsoft.com/en-us/windows/client-management/enroll-a-windows-10-device-automatically-using-group-policy

  • @igoo5851
    @igoo5851 Місяць тому

    We are at the moment on a journey to replace Active Directory, but it will take years and lots of effort

    • @Ciraltos
      @Ciraltos  Місяць тому

      Windows AD has been in most businesses for over 20 years; it will take some time to remove all dependencies. It's good to recognize that at the beginning. Good luck!

  • @kristopherleslie8343
    @kristopherleslie8343 Місяць тому

    Seems like a convoluted offering

  • @jackharper6448
    @jackharper6448 20 днів тому

    I work in the IT industry and Microsoft is telling it’s clients to replace Active Directory with Entra ID so you’re 100% wrong. Microsoft is in the process of phasing out Active Directory. My organization already started the process of migrating. You should consult with Microsoft first before making videos like this. It’s false information.

    • @Ciraltos
      @Ciraltos  19 днів тому +2

      Please understand that Entra ID and Entra Domain Services (what the video is about) are two different services.