Jump to content

Recommended Posts

Posted

Afternoon,

 

So since before Christmas I have been having problems connecting our onsite AD to the Azure AD using DirSync. The credentials are correct but the DirSync application cannot communicate with the AzureAD service.

 

I've checked the TechNet document which tells me ports 443 and 80 need to be open for DirSync (Ports and protocols used by Office 365)

 

But still the problem is there.

 

So I am wondering maybe domains are blocked by our LEA Smoothwall server.

 

Simple question - does anyone have a list of domains that need to be allowed through the Smoothwall server for this DirSync to work? Can they send them through? I cannot find them online.

 

Thank you

 

Gareth

Posted

Hi Gareth,

 

It is recommend that you open all of the “Office 365 portal and Identity “ mentioned in the article below.

 

Office 365 URLs and IP address ranges

 

Don’t forget to allow client computers to access the Certificate Revocation Lists (CRLs) over TCP 80 from both Microsoft crl.microsoft.com, and third parties such as *.verisign.com, *.symcb.com, *.verisign.net, *.geotrust.com, and *.public-trust.com.

 

I hope that helps,

James.

  • Thanks 1
Posted

Right - all domains added. Still cannot see the AzureAD service. Yet it's clearly seeing the server and authenticating because when I enter the wrong password it is giving me a different message.

 

The LEA tell me the DirSync software is not supported by then so I have to wait until it goes to a special team.

 

GJE

Posted

Just a quick report back here. After a Chat with Microsoft we put the server onto a clean internet (unauthenticated) feed - and it it connected straight away to the Azure Service. So that answered that connection.

 

The next issue raised it's head - we are not Enterprise Admins on the LEA AD. We are Domain Admins on our part of the OU. So the whole thing falls down there and then. Apparently you have to be an Enterprise Admin to do this.

 

GJE

Posted
Just a quick report back here. After a Chat with Microsoft we put the server onto a clean internet (unauthenticated) feed - and it it connected straight away to the Azure Service. So that answered that connection.

 

The next issue raised it's head - we are not Enterprise Admins on the LEA AD. We are Domain Admins on our part of the OU. So the whole thing falls down there and then. Apparently you have to be an Enterprise Admin to do this.

 

GJE

 

Use AAD Sync instead of DirSync, you shouldn't need to be an Enterprise Admin

 

James.

Posted (edited)
Use AAD Sync instead of DirSync, you shouldn't need to be an Enterprise Admin

 

James.

 

Obvious next question - what is the difference between DirSync and AAD Sync? Cannot find much online about AAD Sync - but plenty about DirSync.

 

I'm all Sync'ed out.

@EduTech : If you are free I wouldn't mind some help configuring it. All I want at the moment is to synchronise usernames/passwrds to pupils and staff can access Office 365 and their download. I do not want anything else working for now.

 

Gareth

Edited by garethedmondson
Posted

@EduTech : Got this from MS Support today. Gutted:

 

You will still need Enterprise Admin rights even for AAD sync tool as it is a

tool that you can use for multiple forests. The sync is similar to the existing

DirSync tool that you are currently using. This tool is different in the sense

that you can now use it for multiple forests where as the current version only

one instance can run in one forest.

Posted

Hi,

 

You do not need to be an Enterprise Administrator, so that is inaccurate information. If you want to configure Password Sync then you do need to ensure that the account has some more permissions and you just need to ensure that these are granted.

 

You can see for yourself by viewing the following article: Install the AADSync Service

 

See Part: Create an AD account to connect to AD DS

 

Thanks,

James.

Posted
Hi,

 

You do not need to be an Enterprise Administrator, so that is inaccurate information. If you want to configure Password Sync then you do need to ensure that the account has some more permissions and you just need to ensure that these are granted.

 

You can see for yourself by viewing the following article: Install the AADSync Service

 

See Part: Create an AD account to connect to AD DS

 

Thanks,

James.

 

You Sir are amazing. Thank you. Just waiting for the LEA to re-open the clean feed now.

 

Gareth

  • 4 weeks later...
Posted

So we've been now working with the LEA to get this sorted and have managed to get all the way through to the 'Configure' part of the ADSync tool. I click configure and the following error appears:

 

Unable to establish a connection to the authentication service. Contact Technical Support

 

No idea where to go from there. Any ideas?

 

Also - just to check what do people have set on the User Matching dialogue box? I only want a certain user prefix moved over (those starting with ygg-) - as every school in Swansea has a user account on this AD and they are all sorted into OUs.

 

Any advice and help appreciated.

 

Many thanks

 

Gareth

Posted

I'm tearing my hair out with this now. We still cannot get a connection to the AzureAD during the Configuration stage of using ADSync.

 

We can go through the whole process but it fails at the configure option. Today I spent over an hour on the phone with Microsoft working through things. We even managed to convince the LEA to open incoming ports 80 and 443 on the firewall for testing. Yet still it hasn't worked - all based on what Microsoft advised.

 

So at the moment there is nothing in the way of the server and the internet on ports 80 and 443 - which I see from the MS Technet document is what I need open.

 

What are the chances that the Azure setup has gone wrong somewhere? We tried some Powershell connection script today and it connected without issue.

 

Anybody?

 

Many thanks

 

Gareth

Posted
Do you require a proxy to access the Internet?

 

Yes - but for testing we have removed this from the line. We bypass it.

 

Microsoft told us to bypass this to start with. So we did.

We got further

Then we couldn't connect from the configuration window in AADSync.

 

So they asked us to open the firewall - never going to happen in an LEA setup. Outbound 80 and 443 are open so today the LEA opened up 80 and 443 incoming.

 

Still isn't working.

 

Gareth

 

GJE

Posted

HOOOORRRAAAYYYYY - It's finally connected and the staff users have been moved across to AzureAD and have an Office 365 account. Now for some more questions...

 

1. Is there a way to configure a structure in the AzureAD/Office365 window so that it mimics the local AD. I've looked at 'Configure Provisioning Hierarchy' and set it to OU - but I'm not sure that was the right thing to do.

 

2. For some reason it has not set the default domain when syncing the users. Instead of our sch.uk domain it has given every user the onmicrosoft.com domain. I'll research this now - and I bet it's something simple I've missed.

 

Gareth

Posted
It took a bit of jiggery pokery from our LEA team with the firewall and traffic, 80 and 443 were open but the traffic wasn't coming back to our server, once that was sorted it connected without problem.
  • 2 weeks later...
Posted

Just thought I'd come back in here to say that it is all finally working - of sorts. The way things are setup through our Smoothwall etc etc the LEA wanted us to setup the AADSync software as a service running under a different accout name - so we had to use all the command switches when installing.

 

We had to install an SQL server (we started with SQL Express 2012) and then install direct to that with the database instance being set under the new runAs service account. SQLExpress didn't want to work so we built an SQL Server and had the AADSync software use that for it's storage. Finally today it worked - the service installed and this specific uer was allowed through the firewall with restriced permissions.

 

The password sync is still not working, but that will do for today. This has been 4/5 weeks of work and frustration with a Microsoft tool which isn't as point and click as the various blogs make you believe. If you have a domain and a clean feed internet connection then it seems that it will work - otherwise it does not.

 

Thank you everyone who has helped.

 

GJE

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...