Active Directory in Azure

Поділитися
Вставка
  • Опубліковано 14 лип 2024
  • In this video I walk through extending your Active Directory into Azure in addition to understanding where Azure AD and Azure AD Domain Services may play a part.
  • Наука та технологія

КОМЕНТАРІ • 43

  • @rogerosb2u
    @rogerosb2u 4 роки тому +1

    I really appreciate you explaining your thoughts/logic behind how to best set up AD in Azure. This is an excellent video!

    • @NTFAQGuy
      @NTFAQGuy  4 роки тому

      My pleasure. Glad its useful.

  • @Tefty
    @Tefty 4 роки тому

    I love the statement "trust is what it boils down to". 9/10 times it's cost!
    Great video and explanation.

  • @dosto-evsky
    @dosto-evsky 4 роки тому +1

    Awesome, simplified... thank you Sir.

  • @crltech8093
    @crltech8093 2 роки тому

    Great Video and explanations- wish I had found this a few weeks ago to save me hours of trawling knowledge articles and half baked explanations of the differences between those technologies 👍

    • @NTFAQGuy
      @NTFAQGuy  2 роки тому

      Glad you found it 😉

  • @sateg
    @sateg 3 роки тому

    Exceptional, great video. Finally i understood what kind of AD is stuitable for what kind of scenarios.

    • @NTFAQGuy
      @NTFAQGuy  3 роки тому +1

      Great. I just posted the line between ad and aad video as well which may help as well. 🤙

    • @sateg
      @sateg 3 роки тому +1

      @@NTFAQGuy super, i am going to check it out :)

  • @pa1089
    @pa1089 4 роки тому

    Hello John. Thank you for the video. Very clear explanation. Your teaching is just amazing. Cheers

  • @loctranvan5121
    @loctranvan5121 2 роки тому

    great work, very useful!!

  • @BelugaMike
    @BelugaMike 2 роки тому

    Thanks for another one Big J

  • @oliviermalfroidt6405
    @oliviermalfroidt6405 4 роки тому

    Wonderfull video which describe very all the differences. Really thank you.

    • @NTFAQGuy
      @NTFAQGuy  4 роки тому

      Glad it was helpful!

  • @yulaw3289
    @yulaw3289 2 місяці тому

    enjoying this video for today learning, thanks a lot!

  • @TechSimplifiedAI
    @TechSimplifiedAI 4 роки тому +1

    Another awesome 👏🏾 video!

  • @Deepak9728
    @Deepak9728 4 роки тому

    Hi John , Great video keep it up , pls see if you can make some videos of use cases in Azure based on your experience with different customers.

  • @MMTheWGA
    @MMTheWGA 4 роки тому +2

    Thanks John, really well explained as always! A RO-DC in the Restroom?! I hope they were doing an "ipconfig /flushdns" regularly!! ;-)

    • @NTFAQGuy
      @NTFAQGuy  4 роки тому

      OMG, that's awesome. A challenge coin is yours if you want one. :-)

    • @MMTheWGA
      @MMTheWGA 4 роки тому +1

      @@NTFAQGuy Yes please. Cannot say no to that! I am a big Fan! :-)

    • @NTFAQGuy
      @NTFAQGuy  4 роки тому

      @@MMTheWGA Email me an address and i'll pop a challenge coin in the mail!

    • @MMTheWGA
      @MMTheWGA 4 роки тому

      @@NTFAQGuy Have sent you a message on LinkedIn, Thank you :-)

  • @satishmulayrama7963
    @satishmulayrama7963 3 роки тому

    Great work John. What would you suggest for a lab setup in Azure to play with Active Directory, Azure AD, ADFS with minimum infrastructure. Thanks in advance!

    • @NTFAQGuy
      @NTFAQGuy  3 роки тому

      If just for learning go as cheap as you can with a couple of B series VMs and make up an AAD tenant. Remember to shut down the VMs when not using them. A trial subscription would be fine for learning.

  • @dosto-evsky
    @dosto-evsky 4 роки тому +1

    Hi John, would you say @ 21:00 seems to be common to small and medium businesses and would you call this a Hybrid setup as it seems....thanks for sharing.

    • @NTFAQGuy
      @NTFAQGuy  4 роки тому +1

      I don’t think it’s size specific. It could be you don’t have any AD. You are cloud native so just aad with cloud accounts. Then you need to deploy something that needs ad so aadds can solve that. You may also be a huge company that just won’t put ad in some special cloud situation. It’s one tool in your belt. If you already have ad though most likely you just extend it to azure for most scenarios but good to have options ;)

  • @pdaniaful
    @pdaniaful 3 роки тому +1

    In all the scenarios that you described, is it implied that you have to have VPN connectivity between your on-premises and the cloud?

    • @NTFAQGuy
      @NTFAQGuy  3 роки тому

      if you are hybrid then s2s vpn or expressroute private peering

  • @miguelrincon2083
    @miguelrincon2083 3 роки тому +1

    Hi John, thank you for the amazing video, I learned a lot, but wanted to ask some specific questions about deploying AD in the cloud:
    So my company does not have an on-prem location, therefore we don't have an AD DC already in place. We telework and will be getting company laptops soon, so I have the task of figuring out how to join the computers to a domain deployed in the cloud (DCs would be in the cloud).
    I won't put public IPs into my DCs for secuirty reasons like you mentioned in the video. To connect the laptops and the Vnet where the DCs are, I deployed a P2S VPN which will authenticate them using a the DCs as RADIUS servers for authentication.
    I have not tried to authenticate using RADIUS or joined any laptops yet (I will comment below once I do just to see how that turned out), but my questions for now are:
    Do you think (or know) if it is possible to manage remote devices (company laptops) with group policies, OUs, etc using the AD DCs in Azure?
    If I managed to make the laptops connect to the P2S connection at startup using a .bat file (not completely sure if it would work or if that would be secure) do you think users could be asked to authenticate through kerberos before getting access to the laptop (like on premises)?
    Thank you very much, I appreciate any feedback.

    • @NTFAQGuy
      @NTFAQGuy  3 роки тому +1

      if you are starting fresh unless really needed use azure ad join instead.

    • @miguelrincon2083
      @miguelrincon2083 3 роки тому

      @@NTFAQGuy Thanks, I will look into it.

  • @emmanuelatala4043
    @emmanuelatala4043 4 роки тому +1

    Great video! Are there issues with computers objects like the Trust relationship error like we see in AD onprem with Azure AD?

    • @NTFAQGuy
      @NTFAQGuy  4 роки тому +1

      It's just AD. If the computer account does not update as the machine is off etc you will have same issues.

    • @dosto-evsky
      @dosto-evsky 4 роки тому +1

      I would use on the local machine this PS cmd Test-ComputerSecureChannel with -repair parameter for computer objects to establish the authentication again.

  • @gurupa686
    @gurupa686 2 роки тому

    If one use azure ADDS, compared to the active directory on the cloud and no utilise the group policies and OU hierarchy from the on-premise, are we doing configuration twice? Once in on-prem AD and another on the Azure ADDS? Why would one limit and do double work with azure ADDS vs creating a active directory on the cloud? Just for the kerberos authentication?

    • @NTFAQGuy
      @NTFAQGuy  2 роки тому

      Azure ADDS is completely different from on-premises so complete separate everything. Generally you would just extend AD from on-premises into Azure if thats what you do.

  • @muhammadhassansiddiqui9129
    @muhammadhassansiddiqui9129 3 роки тому +1

    Hi John, please WVD and migration of existing physical machine

    • @NTFAQGuy
      @NTFAQGuy  3 роки тому

      I already did an overview of WVD. Migration I will cover in my upcoming master class.

  • @andreasbrantholm3100
    @andreasbrantholm3100 4 роки тому

    An interesting/challenge to all this would be this - docs.microsoft.com/en-us/azure/active-directory-domain-services/overview
    As it is now the only flaw is that it's not multi region able - docs.microsoft.com/en-us/azure/active-directory-domain-services/network-considerations
    Removing all onprem/cloud domain controllers and still offer the functionality without need of patching and so forth? Tempting thought indeed...

    • @NTFAQGuy
      @NTFAQGuy  4 роки тому

      I cover azure ad ds in the video.