Jump to content

Recommended Posts

Posted (edited)

Evening all,

 

Chatting with a colleague this evening and discussing it is possible to get users to authenticate against an Office 365 account but then pull in GPOs and settings from a local DC. Anyone done this?

 

So the users would log into their Welsh Hwb 365 account bit pick up gpos and drive mappings/printers etc from the LEA network.

 

If this worked - it could possibly solve a lot of issues.

 

Gareth

Edited by garethedmondson
Posted
Not sure on the authenticate to O365 as its not something I've looked into but presume there would need to be some sort of trust in place? I have done similar with others domains not in my forest and on the GPO as well as authenticated users we added in domain\security group of group of users and it pulled our policy onto their other domain account, similar principle I suppose but not sure how you could authenticate an external domain.
Posted
Not sure on the authenticate to O365 as its not something I've looked into but presume there would need to be some sort of trust in place? I have done similar with others domains not in my forest and on the GPO as well as authenticated users we added in domain\security group of group of users and it pulled our policy onto their other domain account, similar principle I suppose but not sure how you could authenticate an external domain.

 

From what I gather, it's built into Windows 10. It's not that bit I am worried about - it's pulling the GPOs down from the LAN.

 

Thanks for getting in touch.

 

Gareth

Posted
You can do this, but I think you need to have a link between the LocalAD and AzureAD using AzureAD Connect and possibly ADFS at the same time (so usernames and UPN need to match in local and Azure). We use the AzureAD join on our Windows 10 mobile devices (so the other way round to what you want), but because of our setup I have noticed if staff log onto a local AD win 10 PC with there full email address, it adds the PC to there devices on AzureAD. Not really investigated why, just a side effect of our setup for the mobile devises that are AzureAD joined.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...