Moving Migrating from DirSync or FIM to Azure Active Directory Connect sync

Sharing is caring!

<p>Azure AD Connect sync is the successor of DirSync&comma; Azure AD Sync&comma; and Forefront Identity Manager with the Azure Active Directory Connector configured&period; This allows you to provide a common identity for your users for Office 365&comma; Azure&comma; and SaaS applications integrated with Azure AD&period; It provides the following features&colon;<&sol;p>&NewLine;<ul>&NewLine;<li><strong>Synchronization <&sol;strong>&&num;8211&semi; This component is responsible for creating users&comma; groups&comma; other objects and identity information&period; It is responsible for synchronizing password hashes with Azure AD&period;<&sol;li>&NewLine;<li><strong>AD FS and federation integration <&sol;strong>&&num;8211&semi; Federation is an optional part of Azure AD Connect and can be used to configure a hybrid environment using an on-premises AD FS infrastructure&period;<&sol;li>&NewLine;<li><strong>Pass-through Authentication<&sol;strong> &&num;8211&semi; An optional component that allows users to use the same password on-premises and in the cloud&period;<&sol;li>&NewLine;<li><strong>Health Monitoring<&sol;strong><strong> <&sol;strong>&&num;8211&semi; Azure AD Connect Health can provide robust monitoring and provide a central location in the Azure portal to view this activity&period;<&sol;li>&NewLine;<&sol;ul>&NewLine;<h2>Planning&colon;<&sol;h2>&NewLine;<p>Before you start to Download the latest AD Connect Sync and read through the requirements particularly pay attention to the following point&period;<&sol;p>&NewLine;<ul>&NewLine;<li>The required version of &period;Net and PowerShell&period; Newer versions are required to be on the server than what DirSync needed&period;<&sol;li>&NewLine;<li>The proxy server configuration&period; If you use a proxy server to reach the internet&comma; this setting must be configured before you upgrade&period; DirSync always used the proxy server configured for the user installing it&comma; but Azure AD Connect uses machine settings instead&period;<&sol;li>&NewLine;<li>The URLs required to be open in the proxy server&period; For basic scenarios&comma; those scenarios also supported by DirSync&comma; the requirements are the same&period; If you want to use any of the new features included with Azure AD Connect&comma; some new URLs must be opened&period;<&sol;li>&NewLine;<&sol;ul>&NewLine;<h2>Design&colon;<&sol;h2>&NewLine;<p>The most common topology is a single on-premises forest&comma; with one or multiple domains&comma; and a single Azure AD tenant&period; When you have multiple forests&comma; all forests must be reachable by a single Azure AD Connect sync server&period; You don&&num;8217&semi;t have to join the server to a domain&period; If necessary to reach all forests&comma; you can place the server in a perimeter network &lpar;also known as DMZ&comma; demilitarized zone&comma; and screened subnet&rpar;&period;<&sol;p>&NewLine;<pre>Having multiple Azure AD Connect sync servers connected to the same Azure AD tenant is not supported<&sol;pre>&NewLine;<p><img class&equals;"aligncenter size-medium wp-image-304" src&equals;"http&colon;&sol;&sol;www&period;thecloudxperts&period;co&period;uk&sol;wp-content&sol;uploads&sol;2018&sol;10&sol;multiforestsingledirectory-300x171&period;png" alt&equals;"" width&equals;"300" height&equals;"171" &sol;><&sol;p>&NewLine;<p>&nbsp&semi;<&sol;p>&NewLine;<h2>Installation<&sol;h2>&NewLine;<p>The first time you run the Azure AD Connect installation wizard&comma; it walks you through how to configure your installation&period; If you run the installation wizard again&comma; it offers options for maintenance&period; Prepare and Install AD Sync&period;<&sol;p>&NewLine;<p><img class&equals;"aligncenter size-medium wp-image-305" src&equals;"http&colon;&sol;&sol;www&period;thecloudxperts&period;co&period;uk&sol;wp-content&sol;uploads&sol;2018&sol;10&sol;viewconfig-300x211&period;png" alt&equals;"" width&equals;"300" height&equals;"211" &sol;><&sol;p>&NewLine;<p>&nbsp&semi;<&sol;p>&NewLine;<p>The Synchronization Rules Editor is used to see and change the default configuration&period; You can find it on the <strong>Start<&sol;strong> menu under the <strong>Azure AD Connect<&sol;strong> group &comma; can create custom rules and<&sol;p>&NewLine;<h2><&sol;h2>&NewLine;<h2 id&equals;"import-and-synchronize" class&equals;"heading-with-anchor">Import and Synchronize<&sol;h2>&NewLine;<ol>&NewLine;<li>Select <strong>Connectors<&sol;strong>&comma; and select the first Connector with the type <strong>Active Directory Domain Services<&sol;strong>&period; Click on Run&comma; select Full import&comma; and OK&period; Do this for all Connectors of this type&period;<&sol;li>&NewLine;<li>Select the Connector with <strong>type Windows Azure Active Directory &lpar;Microsoft&rpar;&period;<&sol;strong> Click on <strong>Run<&sol;strong>&comma; select <strong>Full import<&sol;strong>&comma; and <strong>OK<&sol;strong>&period;<&sol;li>&NewLine;<li>Make sure <strong>Connectors<&sol;strong> is still selected and for each Connector with type <strong>Active Directory Domain Services<&sol;strong>&comma; click <strong>Run<&sol;strong>&comma; select <strong>Delta Synchronization<&sol;strong>&comma; and <strong>OK<&sol;strong>&period;<&sol;li>&NewLine;<li>Select the Connector with type <strong>Windows Azure Active Directory &lpar;Microsoft&rpar;<&sol;strong>&period; Click <strong>Run<&sol;strong>&comma; select <strong>Delta Synchronization<&sol;strong>&comma; and then <strong>OK<&sol;strong>&period;<&sol;li>&NewLine;<&sol;ol>&NewLine;<p>We have now staged export changes to Azure AD and on-premises AD if you are using Exchange hybrid deployment&period; The next steps will allow you to inspect what is about to change before you actually start the export to the directories&period;<&sol;p>&NewLine;<h2 id&equals;"switch-from-dirsync-or-fim" class&equals;"heading-with-anchor">Switch from DirSync or FIM<&sol;h2>&NewLine;<ol>&NewLine;<li>Turn off the DirSync&sol;FIM server so it is not exporting to Azure AD&period;<&sol;li>&NewLine;<li>On the AADSync server&comma; start <strong class&equals;"x-hidden-focus">Task Scheduler<&sol;strong> and find <strong>Azure AD Sync Scheduler<&sol;strong>&period; Select to <strong>enable<&sol;strong> this task&period;<&sol;li>&NewLine;<&sol;ol>&NewLine;

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.