garethEds Posted January 9, 2015 Posted January 9, 2015 Afternoon, So since before Christmas I have been having problems connecting our onsite AD to the Azure AD using DirSync. The credentials are correct but the DirSync application cannot communicate with the AzureAD service. I've checked the TechNet document which tells me ports 443 and 80 need to be open for DirSync (Ports and protocols used by Office 365) But still the problem is there. So I am wondering maybe domains are blocked by our LEA Smoothwall server. Simple question - does anyone have a list of domains that need to be allowed through the Smoothwall server for this DirSync to work? Can they send them through? I cannot find them online. Thank you Gareth
EduTech Posted January 10, 2015 Posted January 10, 2015 Hi Gareth, It is recommend that you open all of the “Office 365 portal and Identity “ mentioned in the article below. Office 365 URLs and IP address ranges Don’t forget to allow client computers to access the Certificate Revocation Lists (CRLs) over TCP 80 from both Microsoft crl.microsoft.com, and third parties such as *.verisign.com, *.symcb.com, *.verisign.net, *.geotrust.com, and *.public-trust.com. I hope that helps, James. 1
garethEds Posted January 12, 2015 Author Posted January 12, 2015 Right - all domains added. Still cannot see the AzureAD service. Yet it's clearly seeing the server and authenticating because when I enter the wrong password it is giving me a different message. The LEA tell me the DirSync software is not supported by then so I have to wait until it goes to a special team. GJE
garethEds Posted January 15, 2015 Author Posted January 15, 2015 Just a quick report back here. After a Chat with Microsoft we put the server onto a clean internet (unauthenticated) feed - and it it connected straight away to the Azure Service. So that answered that connection. The next issue raised it's head - we are not Enterprise Admins on the LEA AD. We are Domain Admins on our part of the OU. So the whole thing falls down there and then. Apparently you have to be an Enterprise Admin to do this. GJE
EduTech Posted January 15, 2015 Posted January 15, 2015 Just a quick report back here. After a Chat with Microsoft we put the server onto a clean internet (unauthenticated) feed - and it it connected straight away to the Azure Service. So that answered that connection. The next issue raised it's head - we are not Enterprise Admins on the LEA AD. We are Domain Admins on our part of the OU. So the whole thing falls down there and then. Apparently you have to be an Enterprise Admin to do this. GJE Use AAD Sync instead of DirSync, you shouldn't need to be an Enterprise Admin James.
garethEds Posted January 16, 2015 Author Posted January 16, 2015 (edited) Use AAD Sync instead of DirSync, you shouldn't need to be an Enterprise Admin James. Obvious next question - what is the difference between DirSync and AAD Sync? Cannot find much online about AAD Sync - but plenty about DirSync. I'm all Sync'ed out. @EduTech : If you are free I wouldn't mind some help configuring it. All I want at the moment is to synchronise usernames/passwrds to pupils and staff can access Office 365 and their download. I do not want anything else working for now. Gareth Edited January 16, 2015 by garethedmondson
garethEds Posted January 16, 2015 Author Posted January 16, 2015 @EduTech : Got this from MS Support today. Gutted: You will still need Enterprise Admin rights even for AAD sync tool as it is a tool that you can use for multiple forests. The sync is similar to the existing DirSync tool that you are currently using. This tool is different in the sense that you can now use it for multiple forests where as the current version only one instance can run in one forest.
EduTech Posted January 16, 2015 Posted January 16, 2015 Hi, You do not need to be an Enterprise Administrator, so that is inaccurate information. If you want to configure Password Sync then you do need to ensure that the account has some more permissions and you just need to ensure that these are granted. You can see for yourself by viewing the following article: Install the AADSync Service See Part: Create an AD account to connect to AD DS Thanks, James.
garethEds Posted January 16, 2015 Author Posted January 16, 2015 Hi, You do not need to be an Enterprise Administrator, so that is inaccurate information. If you want to configure Password Sync then you do need to ensure that the account has some more permissions and you just need to ensure that these are granted. You can see for yourself by viewing the following article: Install the AADSync Service See Part: Create an AD account to connect to AD DS Thanks, James. You Sir are amazing. Thank you. Just waiting for the LEA to re-open the clean feed now. Gareth
garethEds Posted February 9, 2015 Author Posted February 9, 2015 So we've been now working with the LEA to get this sorted and have managed to get all the way through to the 'Configure' part of the ADSync tool. I click configure and the following error appears: Unable to establish a connection to the authentication service. Contact Technical Support No idea where to go from there. Any ideas? Also - just to check what do people have set on the User Matching dialogue box? I only want a certain user prefix moved over (those starting with ygg-) - as every school in Swansea has a user account on this AD and they are all sorted into OUs. Any advice and help appreciated. Many thanks Gareth
garethEds Posted February 12, 2015 Author Posted February 12, 2015 I'm tearing my hair out with this now. We still cannot get a connection to the AzureAD during the Configuration stage of using ADSync. We can go through the whole process but it fails at the configure option. Today I spent over an hour on the phone with Microsoft working through things. We even managed to convince the LEA to open incoming ports 80 and 443 on the firewall for testing. Yet still it hasn't worked - all based on what Microsoft advised. So at the moment there is nothing in the way of the server and the internet on ports 80 and 443 - which I see from the MS Technet document is what I need open. What are the chances that the Azure setup has gone wrong somewhere? We tried some Powershell connection script today and it connected without issue. Anybody? Many thanks Gareth
snagrat Posted February 12, 2015 Posted February 12, 2015 Do you require a proxy to access the Internet?
garethEds Posted February 12, 2015 Author Posted February 12, 2015 Do you require a proxy to access the Internet? Yes - but for testing we have removed this from the line. We bypass it. Microsoft told us to bypass this to start with. So we did. We got further Then we couldn't connect from the configuration window in AADSync. So they asked us to open the firewall - never going to happen in an LEA setup. Outbound 80 and 443 are open so today the LEA opened up 80 and 443 incoming. Still isn't working. Gareth GJE
garethEds Posted February 13, 2015 Author Posted February 13, 2015 HOOOORRRAAAYYYYY - It's finally connected and the staff users have been moved across to AzureAD and have an Office 365 account. Now for some more questions... 1. Is there a way to configure a structure in the AzureAD/Office365 window so that it mimics the local AD. I've looked at 'Configure Provisioning Hierarchy' and set it to OU - but I'm not sure that was the right thing to do. 2. For some reason it has not set the default domain when syncing the users. Instead of our sch.uk domain it has given every user the onmicrosoft.com domain. I'll research this now - and I bet it's something simple I've missed. Gareth
Edu-IT Posted February 13, 2015 Posted February 13, 2015 What was the fix? Or did it just start working? In Office 365 did you set the default domain? https://support.office.com/client/change-the-default-domain-name-1bd69e1c-9598-49ce-b341-9ac895dbe681
rich_tech Posted February 14, 2015 Posted February 14, 2015 It took a bit of jiggery pokery from our LEA team with the firewall and traffic, 80 and 443 were open but the traffic wasn't coming back to our server, once that was sorted it connected without problem.
ellsandell Posted February 14, 2015 Posted February 14, 2015 Have you set the UPN in as to match the main domain?
garethEds Posted February 25, 2015 Author Posted February 25, 2015 Just thought I'd come back in here to say that it is all finally working - of sorts. The way things are setup through our Smoothwall etc etc the LEA wanted us to setup the AADSync software as a service running under a different accout name - so we had to use all the command switches when installing. We had to install an SQL server (we started with SQL Express 2012) and then install direct to that with the database instance being set under the new runAs service account. SQLExpress didn't want to work so we built an SQL Server and had the AADSync software use that for it's storage. Finally today it worked - the service installed and this specific uer was allowed through the firewall with restriced permissions. The password sync is still not working, but that will do for today. This has been 4/5 weeks of work and frustration with a Microsoft tool which isn't as point and click as the various blogs make you believe. If you have a domain and a clean feed internet connection then it seems that it will work - otherwise it does not. Thank you everyone who has helped. GJE
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now