The Line Between AD and Azure AD!

Поділитися
Вставка
  • Опубліковано 23 чер 2024
  • In this video we explore the detail about the difference between AD and Azure AD. When to use which and how to use together!
    NOTE - Azure AD DOES not have native Kerberos for certain scenarios. I link via a card in the video.
    Whiteboard at github.com/johnthebrit/Random....
    00:00 Introduction
    00:54 Active Directory overview
    05:17 Cloud apps usage
    07:27 Federation
    12:45 Enter Azure AD
    16:30 AAD as federation broker
    21:55 Conditional access
    27:50 Other enterprise AAD features
    28:35 External identities
    32:25 Azure AD is NOT AD in Azure
    33:20 Hybrid with AD and AAD
    37:33 Modern desktop management
    39:18 Working together and federation migrations
    41:00 AAD features for AD
    43:00 What if you NEED AD in Azure?
    45:45 Azure AD Domain Services
    48:30 Summary and close
  • Наука та технологія

КОМЕНТАРІ • 139

  • @justinlord6194
    @justinlord6194 3 роки тому +5

    Been watching your stuff for several years, always great content and well presented. Thanks for continuing to put these out there!

  • @didierfolly
    @didierfolly 3 роки тому +1

    Thank you John for this wonderful overview of AAD and AD. Keep teaching us!

  • @Maphew69
    @Maphew69 3 роки тому +18

    thanks John. Great content, well structured and presented with care. Thought I had this subject matter mastered but refreshed me. I appreciate this channel and your commitment to the Azure Community.

  • @tedm8492
    @tedm8492 3 роки тому +12

    Honestly I watched this video more of a refresher but John I just wanted to let you know your videos have actually inspired me to create my blog/training videos long term as well. This stuff gives me life, and I really appreciate you taking the immense amount of time to train/enlighten/inspire us.

    • @NTFAQGuy
      @NTFAQGuy  3 роки тому

      very kind, thank you and congrats for starting!

  • @reapertheunique
    @reapertheunique Рік тому +1

    Great overview of how it works. It's definitly a lot but thanks to your chapters I can always come back if I need a refresher on the topic :)

  • @henriquealexandreh
    @henriquealexandreh 2 роки тому

    Best explanation I've ever had of the differences between AAD and AD. You have a talent to make sense out of things. Thanks a mil for this!

    • @NTFAQGuy
      @NTFAQGuy  2 роки тому

      Glad it was helpful!

  • @jeevandeep7823
    @jeevandeep7823 Рік тому

    Not sure why UA-cam has not recommended me this one! Absolutely awesome explanation!

  • @alpinejonny
    @alpinejonny 3 роки тому +9

    Fantastic video John, you really took a huge, complicated relationship and did a wonderful job of boiling it down to what is important. Amazing stuff.

    • @NTFAQGuy
      @NTFAQGuy  3 роки тому

      Glad you enjoyed it

    • @alpinejonny
      @alpinejonny 3 роки тому

      @@NTFAQGuy It's amazing. I'm working on a massive enterprise centralized IDP solution for a client at the moment, and you basically gave me the tools I need to complete the architecture. I feel like I owe you a huge debt.

    • @NTFAQGuy
      @NTFAQGuy  3 роки тому

      @@alpinejonny Glad it helped! Good luck!

  • @vitalhostage1719
    @vitalhostage1719 3 роки тому +1

    You can really tell the best UA-cam stuff from the worst when the word Great is used so genuinely from so many people. Thank you John. Another fantastic piece of work.

  • @robberttruijens6552
    @robberttruijens6552 11 місяців тому

    You are a wealth of knowledge and your lectures are an absolute joy to watch! Thank you very much for putting in the effort you put in, you make everything very understandable!

    • @NTFAQGuy
      @NTFAQGuy  11 місяців тому

      So nice of you

  • @Kunkel5
    @Kunkel5 3 роки тому

    This was great! Really helped clear up several questions I had.

  • @redamaleki
    @redamaleki 3 роки тому +5

    Awesome video! This provides a clear roadmap to help understand the delineation between the services. Now for a video on decommissioning on site servers and relying only on AAD and AADS, maybe a possible migration approach as well :-) .
    I may be in the minority as I interact with several clients, but quite a few are ready to dump on-premise servers (and AD) and embrace full cloud. Some still require AD services for a few of their cloud virtualized machines. They've done their diligence in setting up replication to AAD, but since they have the on-prem AD, they have servers that are required to manage accounts (e.g. Aliases for Exchange Online mailboxes for users sourced on premise). Self-managed AD provides some benefits (your variation on option 1), but doesn't feel like a step forward and would still require an exchange management server.

  • @maxdrach860
    @maxdrach860 2 роки тому +1

    Impressive. Best explanation I’ve heard. Thanks a lot John!

    • @NTFAQGuy
      @NTFAQGuy  2 роки тому

      Glad you enjoyed it!

  • @tusharb9
    @tusharb9 9 місяців тому

    This is the BEST explanation out there on Azure AD and on-prem AD!! I stumbled upon your channel recently and I must say, it's GOLD!! Thank you for creating such informative videos.

    • @NTFAQGuy
      @NTFAQGuy  9 місяців тому

      Wow, thank you! That is very kind 🤙

  • @TheHoradricTube
    @TheHoradricTube 2 роки тому +1

    Thank you John! In-between contracts at the moment and thought I'd check in for a quick refresher, as you do.. (Azure do). Top stuff as always sir!

  • @luciantrif7868
    @luciantrif7868 2 роки тому

    Outstanding explanations John . Thank you!

  • @Random_-Dude
    @Random_-Dude 2 роки тому

    Great stuff John very useful, simple, but lots of content view of AD & AAD - thanks.

    • @NTFAQGuy
      @NTFAQGuy  2 роки тому

      Glad you enjoyed it

  • @jahmed_cloud
    @jahmed_cloud 3 роки тому

    Thank you very much for this Video, this has cleared a lot of churn about AAD and AD. Presentation is just amazing.

    • @NTFAQGuy
      @NTFAQGuy  3 роки тому +1

      Very kind, thank you

  • @jmsz85
    @jmsz85 2 роки тому

    Best AAD/AD/AADDS explanation I’ve seen. Thank you

  • @rodneydias9586
    @rodneydias9586 2 роки тому

    Keep going back to these brilliant vids

  • @jerrolmossel
    @jerrolmossel 3 роки тому

    Great. Thank you John. Good and practial overview

    • @NTFAQGuy
      @NTFAQGuy  3 роки тому

      Glad you enjoyed it

  • @drewconley6444
    @drewconley6444 Рік тому

    Thank you so much. The answer I was looking for was Intune as a replacement for Group Policy.

  • @Philb666666
    @Philb666666 Рік тому

    Great Video. Clearly explained. Thankyou

  • @aman2424
    @aman2424 Рік тому

    This content is leagues above the content I've paid money for

  • @ZATennisFan
    @ZATennisFan 3 роки тому

    You did it again.... This is being shown to every single one of my customers....

  • @lillilblurkin
    @lillilblurkin Рік тому

    When i get my 305 John i’m seriously gonna owe you a drink! I have no clue if you can see how many hours i’ve spent watching your videos but it’s gotta be 1000s of hours! Appreciate all you do man!

    • @NTFAQGuy
      @NTFAQGuy  Рік тому

      good luck! I like Dr Pepper Zero lol

    • @lillilblurkin
      @lillilblurkin Рік тому

      @@NTFAQGuy 1 Shirley temple and 1 Dr Pepper Zero coming up! Thanks for everything John!

    • @NTFAQGuy
      @NTFAQGuy  Рік тому +1

      ROFL

  • @doseofanu.chathu
    @doseofanu.chathu Рік тому

    Your videos are top notch.
    keep up the good work.

  • @DeTudoUmPouco12651
    @DeTudoUmPouco12651 3 роки тому

    Look at this content! Even if it is something that I know I like to watch your videos, I always get a few bits here and there. I don't know how you are not an MVP. I will buzz a few friends to referral you.

    • @NTFAQGuy
      @NTFAQGuy  3 роки тому +1

      I was an mvp for 11 years but lost when took role at MS (unrelated to this channel which is my free time hobby 😀). Glad you enjoy!

    • @DeTudoUmPouco12651
      @DeTudoUmPouco12651 3 роки тому

      @@NTFAQGuy This explains a lot. I didn't know that you work at MS. Thanks again for sharing this great content on your free time hobby. Cheers!

  • @Cloudgyan87
    @Cloudgyan87 2 роки тому

    I can understand for making these videos you are doing very hard work because it's not easy task.Keep it up.

  • @patrickmelton5877
    @patrickmelton5877 3 роки тому

    John, great video. Keep up the great work.

    • @NTFAQGuy
      @NTFAQGuy  3 роки тому

      Will do, thank you.

  • @martinmccrorie2184
    @martinmccrorie2184 3 роки тому

    Great Video thank you for taking the time to make it!

  • @MR-vj8dn
    @MR-vj8dn 2 роки тому +1

    Thank you for sharing. As an older tech guy, sometimes nicknamed "the legacy guy" at my company as I often try to solve problems using locally existing tech, I find it very helpful to watch your videos covering this modern thing called Azure and AAD. Not sure I'll ever change the way I solve things but with you sharing all of this, at least I can understand now what the younger ones are talking about. For that I am grateful. And please keep the videos at least as long as this one. The tempo is already high. 😵‍💫

    • @NTFAQGuy
      @NTFAQGuy  2 роки тому

      glad you enjoy the content, thanks for watching!

  • @gopeisho
    @gopeisho 3 роки тому

    I’m going to make this required reading for all my RBAC Admins in Azure. Thanks John.

    • @NTFAQGuy
      @NTFAQGuy  3 роки тому

      I’m sorry :)

    • @gopeisho
      @gopeisho 3 роки тому +1

      @@NTFAQGuy no need to be sorry 😀. I’m happy to make this required viewing. It will give everyone a view I see everyday.

  • @PawanKumar-kd5ey
    @PawanKumar-kd5ey Рік тому +1

    You are so energetic and have great presentation skills 👍 super like

  • @gallyjane2012
    @gallyjane2012 Рік тому

    thnks buddy, awesomelly explained

  • @stephenjordan8712
    @stephenjordan8712 3 місяці тому

    This may be from 2 years ago, but it's still a great video for providing insite between AD DS and the now Entra ID. 👍

    • @johnharrison712
      @johnharrison712 3 місяці тому

      I would love to see a guide on how to completely get off of On premise AD and migrate it all over to Entra and cut over to Entra ID.

  • @FunkyDream91
    @FunkyDream91 3 роки тому

    Really Great video !!!
    I was used to your expertise in your IT books, now I see you live ... (Does AAD expand your muscles too ?!!! ;)
    I'm a good AD expert and an IT Trainer but definitively not a Cloud Expert ... I've been resisting to these new cloud schemes for a while but now In 2021, battle is over ...
    So thank you so much, John, your video gave me, in less than an hour, a sharp overview of these AD, AAD and Cloud evolutions ...
    I understand better what skills I should improve as an old IT Trainer to be still good enough to do my job till the end ...

    • @NTFAQGuy
      @NTFAQGuy  3 роки тому +1

      Great, happy to help and good luck in your learning! I have a full Azure Master Class playlist that is about 20 hours with no adverts that may help.

  • @RabbitJnr
    @RabbitJnr 3 роки тому

    Great video, thank you John !!

    • @NTFAQGuy
      @NTFAQGuy  3 роки тому

      Glad you enjoyed it

  • @arunnair8915
    @arunnair8915 3 роки тому

    Great Video :) . Was waiting for the same. Thanks again.

    • @NTFAQGuy
      @NTFAQGuy  3 роки тому

      Glad you liked it!

  • @mojou2325
    @mojou2325 6 місяців тому

    Perfect explaination :) , awesome

    • @NTFAQGuy
      @NTFAQGuy  6 місяців тому

      Glad you liked it!

  • @kieranpatel2192
    @kieranpatel2192 2 роки тому

    Thankyou Guru one day i will be humble and teach like you.

  • @neilhogan1742
    @neilhogan1742 3 роки тому

    Brilliant again, thanks John

  • @maneesh981
    @maneesh981 2 роки тому

    You could easily setup your own paid channel and we would have subscribed it happily. See your magnanimity ,your kind heart, charity you are providing these high quality, every bit full of knowledge free of cost. Really really with bottom of heart Thank You appreciated ❤️🙏💗

    • @NTFAQGuy
      @NTFAQGuy  2 роки тому

      Very welcome. Thank you 🙏

  • @corpuzone
    @corpuzone Місяць тому

    1st vid i watched of your channel as an IT pro. You must be lecturing a lot with lots of arm/hand movements to build those kind of python(muscles) wow! LOL. Your technique of teaching is clear and concise thanks for the explanation here :)

  • @sylviawylie9218
    @sylviawylie9218 Місяць тому

    Generic comment to show my appreciation. Keep winning John!

  • @koala59230
    @koala59230 2 роки тому

    thanks a lot, for this great content, great presentation.

    • @NTFAQGuy
      @NTFAQGuy  2 роки тому +1

      You're very welcome!

  • @renatobertolaccini3242
    @renatobertolaccini3242 2 роки тому

    Keep doing that man. Thanks!!!!

  • @leeebbrell9
    @leeebbrell9 2 роки тому

    Thanks john

  • @JonnyHjortland
    @JonnyHjortland 3 роки тому

    Very nice and concise walk through of Azure AD and the evolution from on-prem AD.
    In todays setup, on-prem AD will always be the master in a hybrid setup. For Azure AD Domain Services this is actually the other way around. When do you think Microsoft will make us able to let Azure AD also be the master source for the on-prem AD integration?

    • @NTFAQGuy
      @NTFAQGuy  3 роки тому

      No idea about future change to source of truth.

  • @chadsowald
    @chadsowald 3 роки тому +1

    Great content, especially found the conditional access section intriguing. Had a question about external identities. If I have 2 tenants, under separate accounts, is there some way to have an AAD group from one domain/tenant be usable as a group in the other domain/tenant? Imagine one is my real tenant and other a test tenant. Basically like external users, but instead external groups (of external users), without having to register each individual external user and keep that list in sync?

    • @NTFAQGuy
      @NTFAQGuy  3 роки тому +1

      No, there is no ability to make groups available to another tenant. You could write something or use something like MIM to replicate membership etc.

  • @tantecnologicoscomohumanos
    @tantecnologicoscomohumanos 2 роки тому

    Excelent!!!

  • @loualleluia6353
    @loualleluia6353 3 роки тому

    Well done!

  • @CarlosRuiz1
    @CarlosRuiz1 3 роки тому +1

    Good stuff, great content! I have couple of questions maybe you can help with when thinking about option 2 (replicating AAD to a managed AD DS instance).
    1. Could you domain join a member server and use the admin tools from there? Group Policies?
    2. Can you domain join clients to this domain? (Via s2s vpn to external site)
    Thanks, always fantastic videos!

    • @NTFAQGuy
      @NTFAQGuy  3 роки тому +1

      Yes, you can use a number of admin tools. You just don't have enterprise admin type permissions.
      For external remember you need DNS resolution to FIND the DCs then an IP path. The s2s vpn gives you IP path but your DNS would need to be able to resolve Azure DNS which is not possible unless you add a forwarder in your azure vnet that the on-premises DNS server forwards to. Never tried it. I have a video on Azure DNS where I walk through all the things about DNS.

  • @anarabdullayev264
    @anarabdullayev264 2 роки тому

    Mr.John thanks for great content. I wanna get your opinion, what is the best practice when creating Managed Domain in Azure - using AADDS or AD in IaaS VM? Could you explain?

    • @NTFAQGuy
      @NTFAQGuy  2 роки тому

      That is too involved for a comment but I have another video on ad in azure where touch on it

  • @jackgleeson8321
    @jackgleeson8321 2 роки тому

    great video

  • @paddyland74
    @paddyland74 3 роки тому

    Great Explanation!!!
    BTW, you seem to be a DC fan...are you?

  • @NeaBea
    @NeaBea 2 роки тому

    John, what kind of display you're using to write on ? I am interested to get the similar for my work-station setup.
    Thank you.

    • @NTFAQGuy
      @NTFAQGuy  2 роки тому

      there is a playlist of setup.

  • @unchartedm9413
    @unchartedm9413 3 роки тому

    Hi sir just want to ask do you think there will be an azure admin expert certification since my focus is in the infra thanks!

    • @NTFAQGuy
      @NTFAQGuy  3 роки тому

      No idea. I wouldn’t think so but that’s just guessing.

  • @aayushseth69
    @aayushseth69 Рік тому

    If there are no on-premise applications and all the application for a small enterprise is cloud based, then does it makes more sense to be on AAD purely? There will be 40 users and there laptops can be managed by InTune?

  • @altanetluke
    @altanetluke 3 роки тому +1

    Contrast looks a bit high in this video IMO, but great content as usual.

    • @NTFAQGuy
      @NTFAQGuy  3 роки тому

      No clue what has changed.

  • @michaelrobertson8216
    @michaelrobertson8216 3 роки тому +1

    John, what is the monitor/pen your using?

    • @NTFAQGuy
      @NTFAQGuy  3 роки тому

      I have a playlist on my setup.

    • @michaelrobertson8216
      @michaelrobertson8216 3 роки тому

      @@NTFAQGuy I meant, make model of touch monitor and pen?

    • @NTFAQGuy
      @NTFAQGuy  3 роки тому

      @@michaelrobertson8216 Yep, that is covered in the video where I talk about the setup :-D

  • @huberisme
    @huberisme 3 роки тому +1

    John - great video - can I get your whiteboard pic? :)

    • @NTFAQGuy
      @NTFAQGuy  3 роки тому +1

      it's linked in the description ;-)

    • @huberisme
      @huberisme 3 роки тому

      @@NTFAQGuy - I guess I need to pay attn to the "more" button...more... Thanks!

    • @NTFAQGuy
      @NTFAQGuy  3 роки тому

      @@huberisme hehe :-D

  • @rcboathandbook7709
    @rcboathandbook7709 2 роки тому

    I'm a senior systems engineer that has worked for IBM, MS, some of the biggest names in the industry. Is it me or is Johns arms bigger than his head? He must be one of the strongest IT staff in the world. Is John using a fish eye lens?

    • @NTFAQGuy
      @NTFAQGuy  2 роки тому

      yes, its a special lens and i have little fake inflatable arm cushions I apply before each recording :-)

  • @TimGoodrich0528
    @TimGoodrich0528 3 роки тому +10

    Whoever disliked this video should be thrown into the Gulag to fight John 1:1...

    • @Rzkjr
      @Rzkjr 3 роки тому

      Learn from the loss, Failure is a proper teacher

    • @NTFAQGuy
      @NTFAQGuy  3 роки тому +1

      LOL, there is always one ;-)

    • @golu9014
      @golu9014 3 роки тому +2

      @@NTFAQGuy And he is AWS bot ...who just Dislikes all Azure videoes :D

    • @NTFAQGuy
      @NTFAQGuy  3 роки тому

      @@golu9014 lol

    • @vitalhostage1719
      @vitalhostage1719 3 роки тому

      You never know they might be in Australia..........but failing that I'd like to see them explain everything John covered in 50 minutes or less with such simplicity. Another excellent job from John as far as I'm concerned. Always concise and accurate information. He's literally been my go to Azure tutorial resource for...God am I that old? Years!

  • @Bubu020174
    @Bubu020174 2 роки тому

    Hi Jonh, I shall be greatfull if you provide solution on : I have two Azure AD . Now need to get attendance report from Azure AD1 to Azure AD2 i.e. person in Azure AD1 who call a meeting and user from Azure AD2 participate that meeting .

    • @NTFAQGuy
      @NTFAQGuy  2 роки тому +1

      that really depends totally on the meeting solution. For teams you can invite external people (as can most solutions). If you actually want an object look at external identities. I have a video on that (B2B)

  • @michaelpietrzak2067
    @michaelpietrzak2067 3 роки тому

    I think small to midsize business would be quicker to adopt Azure if it was just AD in the cloud. I want my OU's !

    • @NTFAQGuy
      @NTFAQGuy  3 роки тому

      if it was just AD in the cloud you would have none of the benefits of talking cloud native, conditional access etc. It would be very limited. If you need AD in Azure use AADDS :-)

  • @AleksandarIvanov69
    @AleksandarIvanov69 2 роки тому

    For the algorithm! 😁

  • @roughryder5
    @roughryder5 2 роки тому

    Holy arms!!

  • @nickbrights9436
    @nickbrights9436 2 роки тому

    John, do you have any paid service to hire you for few hours to help us with a strategy discussions? If yes, how can I contact you ?

    • @NTFAQGuy
      @NTFAQGuy  2 роки тому

      I don’t offer that.

  • @scott2495
    @scott2495 3 роки тому

    You present well. I think some of your videos are too long. Up to an hour i don't mind but anything over i have to watch in a couple of takes.

  • @pakodasingh
    @pakodasingh 2 роки тому

    Ur biceps are hindering my view