garethEds Posted June 29, 2016 Posted June 29, 2016 (edited) Evening all, Chatting with a colleague this evening and discussing it is possible to get users to authenticate against an Office 365 account but then pull in GPOs and settings from a local DC. Anyone done this? So the users would log into their Welsh Hwb 365 account bit pick up gpos and drive mappings/printers etc from the LEA network. If this worked - it could possibly solve a lot of issues. Gareth Edited June 29, 2016 by garethedmondson
MatthewL Posted June 29, 2016 Posted June 29, 2016 Not sure on the authenticate to O365 as its not something I've looked into but presume there would need to be some sort of trust in place? I have done similar with others domains not in my forest and on the GPO as well as authenticated users we added in domain\security group of group of users and it pulled our policy onto their other domain account, similar principle I suppose but not sure how you could authenticate an external domain.
garethEds Posted June 29, 2016 Author Posted June 29, 2016 Not sure on the authenticate to O365 as its not something I've looked into but presume there would need to be some sort of trust in place? I have done similar with others domains not in my forest and on the GPO as well as authenticated users we added in domain\security group of group of users and it pulled our policy onto their other domain account, similar principle I suppose but not sure how you could authenticate an external domain. From what I gather, it's built into Windows 10. It's not that bit I am worried about - it's pulling the GPOs down from the LAN. Thanks for getting in touch. Gareth
MicrodigitUK Posted June 30, 2016 Posted June 30, 2016 You can do this, but I think you need to have a link between the LocalAD and AzureAD using AzureAD Connect and possibly ADFS at the same time (so usernames and UPN need to match in local and Azure). We use the AzureAD join on our Windows 10 mobile devices (so the other way round to what you want), but because of our setup I have noticed if staff log onto a local AD win 10 PC with there full email address, it adds the PC to there devices on AzureAD. Not really investigated why, just a side effect of our setup for the mobile devises that are AzureAD joined.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now