Honestly I watched this video more of a refresher but John I just wanted to let you know your videos have actually inspired me to create my blog/training videos long term as well. This stuff gives me life, and I really appreciate you taking the immense amount of time to train/enlighten/inspire us.
This is the BEST explanation out there on Azure AD and on-prem AD!! I stumbled upon your channel recently and I must say, it's GOLD!! Thank you for creating such informative videos.
When i get my 305 John i’m seriously gonna owe you a drink! I have no clue if you can see how many hours i’ve spent watching your videos but it’s gotta be 1000s of hours! Appreciate all you do man!
You can really tell the best UA-cam stuff from the worst when the word Great is used so genuinely from so many people. Thank you John. Another fantastic piece of work.
thanks John. Great content, well structured and presented with care. Thought I had this subject matter mastered but refreshed me. I appreciate this channel and your commitment to the Azure Community.
@@NTFAQGuy It's amazing. I'm working on a massive enterprise centralized IDP solution for a client at the moment, and you basically gave me the tools I need to complete the architecture. I feel like I owe you a huge debt.
Thank you for sharing. As an older tech guy, sometimes nicknamed "the legacy guy" at my company as I often try to solve problems using locally existing tech, I find it very helpful to watch your videos covering this modern thing called Azure and AAD. Not sure I'll ever change the way I solve things but with you sharing all of this, at least I can understand now what the younger ones are talking about. For that I am grateful. And please keep the videos at least as long as this one. The tempo is already high. 😵💫
Awesome video! This provides a clear roadmap to help understand the delineation between the services. Now for a video on decommissioning on site servers and relying only on AAD and AADS, maybe a possible migration approach as well :-) . I may be in the minority as I interact with several clients, but quite a few are ready to dump on-premise servers (and AD) and embrace full cloud. Some still require AD services for a few of their cloud virtualized machines. They've done their diligence in setting up replication to AAD, but since they have the on-prem AD, they have servers that are required to manage accounts (e.g. Aliases for Exchange Online mailboxes for users sourced on premise). Self-managed AD provides some benefits (your variation on option 1), but doesn't feel like a step forward and would still require an exchange management server.
You are a wealth of knowledge and your lectures are an absolute joy to watch! Thank you very much for putting in the effort you put in, you make everything very understandable!
Look at this content! Even if it is something that I know I like to watch your videos, I always get a few bits here and there. I don't know how you are not an MVP. I will buzz a few friends to referral you.
You could easily setup your own paid channel and we would have subscribed it happily. See your magnanimity ,your kind heart, charity you are providing these high quality, every bit full of knowledge free of cost. Really really with bottom of heart Thank You appreciated ❤️🙏💗
1st vid i watched of your channel as an IT pro. You must be lecturing a lot with lots of arm/hand movements to build those kind of python(muscles) wow! LOL. Your technique of teaching is clear and concise thanks for the explanation here :)
Really Great video !!! I was used to your expertise in your IT books, now I see you live ... (Does AAD expand your muscles too ?!!! ;) I'm a good AD expert and an IT Trainer but definitively not a Cloud Expert ... I've been resisting to these new cloud schemes for a while but now In 2021, battle is over ... So thank you so much, John, your video gave me, in less than an hour, a sharp overview of these AD, AAD and Cloud evolutions ... I understand better what skills I should improve as an old IT Trainer to be still good enough to do my job till the end ...
Great content, especially found the conditional access section intriguing. Had a question about external identities. If I have 2 tenants, under separate accounts, is there some way to have an AAD group from one domain/tenant be usable as a group in the other domain/tenant? Imagine one is my real tenant and other a test tenant. Basically like external users, but instead external groups (of external users), without having to register each individual external user and keep that list in sync?
Very nice and concise walk through of Azure AD and the evolution from on-prem AD. In todays setup, on-prem AD will always be the master in a hybrid setup. For Azure AD Domain Services this is actually the other way around. When do you think Microsoft will make us able to let Azure AD also be the master source for the on-prem AD integration?
Mr.John thanks for great content. I wanna get your opinion, what is the best practice when creating Managed Domain in Azure - using AADDS or AD in IaaS VM? Could you explain?
If there are no on-premise applications and all the application for a small enterprise is cloud based, then does it makes more sense to be on AAD purely? There will be 40 users and there laptops can be managed by InTune?
Good stuff, great content! I have couple of questions maybe you can help with when thinking about option 2 (replicating AAD to a managed AD DS instance). 1. Could you domain join a member server and use the admin tools from there? Group Policies? 2. Can you domain join clients to this domain? (Via s2s vpn to external site) Thanks, always fantastic videos!
Yes, you can use a number of admin tools. You just don't have enterprise admin type permissions. For external remember you need DNS resolution to FIND the DCs then an IP path. The s2s vpn gives you IP path but your DNS would need to be able to resolve Azure DNS which is not possible unless you add a forwarder in your azure vnet that the on-premises DNS server forwards to. Never tried it. I have a video on Azure DNS where I walk through all the things about DNS.
You never know they might be in Australia..........but failing that I'd like to see them explain everything John covered in 50 minutes or less with such simplicity. Another excellent job from John as far as I'm concerned. Always concise and accurate information. He's literally been my go to Azure tutorial resource for...God am I that old? Years!
I'm a senior systems engineer that has worked for IBM, MS, some of the biggest names in the industry. Is it me or is Johns arms bigger than his head? He must be one of the strongest IT staff in the world. Is John using a fish eye lens?
Hi Jonh, I shall be greatfull if you provide solution on : I have two Azure AD . Now need to get attendance report from Azure AD1 to Azure AD2 i.e. person in Azure AD1 who call a meeting and user from Azure AD2 participate that meeting .
that really depends totally on the meeting solution. For teams you can invite external people (as can most solutions). If you actually want an object look at external identities. I have a video on that (B2B)
if it was just AD in the cloud you would have none of the benefits of talking cloud native, conditional access etc. It would be very limited. If you need AD in Azure use AADDS :-)
Not sure why UA-cam has not recommended me this one! Absolutely awesome explanation!
Honestly I watched this video more of a refresher but John I just wanted to let you know your videos have actually inspired me to create my blog/training videos long term as well. This stuff gives me life, and I really appreciate you taking the immense amount of time to train/enlighten/inspire us.
very kind, thank you and congrats for starting!
This is the BEST explanation out there on Azure AD and on-prem AD!! I stumbled upon your channel recently and I must say, it's GOLD!! Thank you for creating such informative videos.
Wow, thank you! That is very kind 🤙
When i get my 305 John i’m seriously gonna owe you a drink! I have no clue if you can see how many hours i’ve spent watching your videos but it’s gotta be 1000s of hours! Appreciate all you do man!
good luck! I like Dr Pepper Zero lol
@@NTFAQGuy 1 Shirley temple and 1 Dr Pepper Zero coming up! Thanks for everything John!
ROFL
This content is leagues above the content I've paid money for
Best in the game! concise but you always go into enough detail to get thorough understanding of each teaching.
You can really tell the best UA-cam stuff from the worst when the word Great is used so genuinely from so many people. Thank you John. Another fantastic piece of work.
Wow, thank you!
thanks John. Great content, well structured and presented with care. Thought I had this subject matter mastered but refreshed me. I appreciate this channel and your commitment to the Azure Community.
Much appreciated!
Fantastic video John, you really took a huge, complicated relationship and did a wonderful job of boiling it down to what is important. Amazing stuff.
Glad you enjoyed it
@@NTFAQGuy It's amazing. I'm working on a massive enterprise centralized IDP solution for a client at the moment, and you basically gave me the tools I need to complete the architecture. I feel like I owe you a huge debt.
@@alpinejonny Glad it helped! Good luck!
Thank you for sharing. As an older tech guy, sometimes nicknamed "the legacy guy" at my company as I often try to solve problems using locally existing tech, I find it very helpful to watch your videos covering this modern thing called Azure and AAD. Not sure I'll ever change the way I solve things but with you sharing all of this, at least I can understand now what the younger ones are talking about. For that I am grateful. And please keep the videos at least as long as this one. The tempo is already high. 😵💫
glad you enjoy the content, thanks for watching!
Great overview of how it works. It's definitly a lot but thanks to your chapters I can always come back if I need a refresher on the topic :)
Been watching your stuff for several years, always great content and well presented. Thanks for continuing to put these out there!
Much appreciated!
Awesome video! This provides a clear roadmap to help understand the delineation between the services. Now for a video on decommissioning on site servers and relying only on AAD and AADS, maybe a possible migration approach as well :-) .
I may be in the minority as I interact with several clients, but quite a few are ready to dump on-premise servers (and AD) and embrace full cloud. Some still require AD services for a few of their cloud virtualized machines. They've done their diligence in setting up replication to AAD, but since they have the on-prem AD, they have servers that are required to manage accounts (e.g. Aliases for Exchange Online mailboxes for users sourced on premise). Self-managed AD provides some benefits (your variation on option 1), but doesn't feel like a step forward and would still require an exchange management server.
Thank you so much. The answer I was looking for was Intune as a replacement for Group Policy.
Best explanation I've ever had of the differences between AAD and AD. You have a talent to make sense out of things. Thanks a mil for this!
Glad it was helpful!
Thank you John! In-between contracts at the moment and thought I'd check in for a quick refresher, as you do.. (Azure do). Top stuff as always sir!
This may be from 2 years ago, but it's still a great video for providing insite between AD DS and the now Entra ID. 👍
I would love to see a guide on how to completely get off of On premise AD and migrate it all over to Entra and cut over to Entra ID.
You are a wealth of knowledge and your lectures are an absolute joy to watch! Thank you very much for putting in the effort you put in, you make everything very understandable!
So nice of you
Thank you John for this wonderful overview of AAD and AD. Keep teaching us!
Very welcome
Best AAD/AD/AADDS explanation I’ve seen. Thank you
Wow, thanks!
Keep going back to these brilliant vids
Look at this content! Even if it is something that I know I like to watch your videos, I always get a few bits here and there. I don't know how you are not an MVP. I will buzz a few friends to referral you.
I was an mvp for 11 years but lost when took role at MS (unrelated to this channel which is my free time hobby 😀). Glad you enjoy!
@@NTFAQGuy This explains a lot. I didn't know that you work at MS. Thanks again for sharing this great content on your free time hobby. Cheers!
Impressive. Best explanation I’ve heard. Thanks a lot John!
Glad you enjoyed it!
You did it again.... This is being shown to every single one of my customers....
hehe, thanks :-)
You could easily setup your own paid channel and we would have subscribed it happily. See your magnanimity ,your kind heart, charity you are providing these high quality, every bit full of knowledge free of cost. Really really with bottom of heart Thank You appreciated ❤️🙏💗
Very welcome. Thank you 🙏
You are so energetic and have great presentation skills 👍 super like
I can understand for making these videos you are doing very hard work because it's not easy task.Keep it up.
Thanks!
I’m going to make this required reading for all my RBAC Admins in Azure. Thanks John.
I’m sorry :)
@@NTFAQGuy no need to be sorry 😀. I’m happy to make this required viewing. It will give everyone a view I see everyday.
Your videos are top notch.
keep up the good work.
Thank you very much for this Video, this has cleared a lot of churn about AAD and AD. Presentation is just amazing.
Very kind, thank you
Great stuff John very useful, simple, but lots of content view of AD & AAD - thanks.
Glad you enjoyed it
Outstanding explanations John . Thank you!
Great Video. Clearly explained. Thankyou
Thankyou Guru one day i will be humble and teach like you.
Great Video thank you for taking the time to make it!
My pleasure!
a little late on this but still a top class presentation - thanks!
1st vid i watched of your channel as an IT pro. You must be lecturing a lot with lots of arm/hand movements to build those kind of python(muscles) wow! LOL. Your technique of teaching is clear and concise thanks for the explanation here :)
Really Great video !!!
I was used to your expertise in your IT books, now I see you live ... (Does AAD expand your muscles too ?!!! ;)
I'm a good AD expert and an IT Trainer but definitively not a Cloud Expert ... I've been resisting to these new cloud schemes for a while but now In 2021, battle is over ...
So thank you so much, John, your video gave me, in less than an hour, a sharp overview of these AD, AAD and Cloud evolutions ...
I understand better what skills I should improve as an old IT Trainer to be still good enough to do my job till the end ...
Great, happy to help and good luck in your learning! I have a full Azure Master Class playlist that is about 20 hours with no adverts that may help.
Great. Thank you John. Good and practial overview
Glad you enjoyed it
Generic comment to show my appreciation. Keep winning John!
John, great video. Keep up the great work.
Will do, thank you.
This was great! Really helped clear up several questions I had.
Brilliant again, thanks John
Thank you!
Great content, especially found the conditional access section intriguing. Had a question about external identities. If I have 2 tenants, under separate accounts, is there some way to have an AAD group from one domain/tenant be usable as a group in the other domain/tenant? Imagine one is my real tenant and other a test tenant. Basically like external users, but instead external groups (of external users), without having to register each individual external user and keep that list in sync?
No, there is no ability to make groups available to another tenant. You could write something or use something like MIM to replicate membership etc.
thnks buddy, awesomelly explained
Great video, thank you John !!
Glad you enjoyed it
Keep doing that man. Thanks!!!!
You bet!
Perfect explaination :) , awesome
Glad you liked it!
Great Video :) . Was waiting for the same. Thanks again.
Glad you liked it!
thanks a lot, for this great content, great presentation.
You're very welcome!
Very nice and concise walk through of Azure AD and the evolution from on-prem AD.
In todays setup, on-prem AD will always be the master in a hybrid setup. For Azure AD Domain Services this is actually the other way around. When do you think Microsoft will make us able to let Azure AD also be the master source for the on-prem AD integration?
No idea about future change to source of truth.
Mr.John thanks for great content. I wanna get your opinion, what is the best practice when creating Managed Domain in Azure - using AADDS or AD in IaaS VM? Could you explain?
That is too involved for a comment but I have another video on ad in azure where touch on it
Thanks john
John, what kind of display you're using to write on ? I am interested to get the similar for my work-station setup.
Thank you.
there is a playlist of setup.
Great Explanation!!!
BTW, you seem to be a DC fan...are you?
I am :)
If there are no on-premise applications and all the application for a small enterprise is cloud based, then does it makes more sense to be on AAD purely? There will be 40 users and there laptops can be managed by InTune?
John - great video - can I get your whiteboard pic? :)
it's linked in the description ;-)
@@NTFAQGuy - I guess I need to pay attn to the "more" button...more... Thanks!
@@huberisme hehe :-D
Well done!
Thank you
Good stuff, great content! I have couple of questions maybe you can help with when thinking about option 2 (replicating AAD to a managed AD DS instance).
1. Could you domain join a member server and use the admin tools from there? Group Policies?
2. Can you domain join clients to this domain? (Via s2s vpn to external site)
Thanks, always fantastic videos!
Yes, you can use a number of admin tools. You just don't have enterprise admin type permissions.
For external remember you need DNS resolution to FIND the DCs then an IP path. The s2s vpn gives you IP path but your DNS would need to be able to resolve Azure DNS which is not possible unless you add a forwarder in your azure vnet that the on-premises DNS server forwards to. Never tried it. I have a video on Azure DNS where I walk through all the things about DNS.
Contrast looks a bit high in this video IMO, but great content as usual.
No clue what has changed.
great video
Thanks!
Excelent!!!
Whoever disliked this video should be thrown into the Gulag to fight John 1:1...
Learn from the loss, Failure is a proper teacher
LOL, there is always one ;-)
@@NTFAQGuy And he is AWS bot ...who just Dislikes all Azure videoes :D
@@golu9014 lol
You never know they might be in Australia..........but failing that I'd like to see them explain everything John covered in 50 minutes or less with such simplicity. Another excellent job from John as far as I'm concerned. Always concise and accurate information. He's literally been my go to Azure tutorial resource for...God am I that old? Years!
Hi sir just want to ask do you think there will be an azure admin expert certification since my focus is in the infra thanks!
No idea. I wouldn’t think so but that’s just guessing.
I'm a senior systems engineer that has worked for IBM, MS, some of the biggest names in the industry. Is it me or is Johns arms bigger than his head? He must be one of the strongest IT staff in the world. Is John using a fish eye lens?
yes, its a special lens and i have little fake inflatable arm cushions I apply before each recording :-)
Hi Jonh, I shall be greatfull if you provide solution on : I have two Azure AD . Now need to get attendance report from Azure AD1 to Azure AD2 i.e. person in Azure AD1 who call a meeting and user from Azure AD2 participate that meeting .
that really depends totally on the meeting solution. For teams you can invite external people (as can most solutions). If you actually want an object look at external identities. I have a video on that (B2B)
I think small to midsize business would be quicker to adopt Azure if it was just AD in the cloud. I want my OU's !
if it was just AD in the cloud you would have none of the benefits of talking cloud native, conditional access etc. It would be very limited. If you need AD in Azure use AADDS :-)
John, do you have any paid service to hire you for few hours to help us with a strategy discussions? If yes, how can I contact you ?
I don’t offer that.
For the algorithm! 😁
Holy arms!!
Lol
You present well. I think some of your videos are too long. Up to an hour i don't mind but anything over i have to watch in a couple of takes.
Whatever works :)
Ur biceps are hindering my view
🤷♂️
Great content John. thank you for clearly laying it all out.