Jump to content
EduGeek EdSec 2026 is Go! 27th Oct in Derby! Join us for a day of EdTech security focused talks, networking, and an evening social ×

Recommended Posts

Posted

I have a situation where I need to have 2 Azure Active Directory tenants, each syncing to their own on-site domains, at different schools.

 

I already have one working, and syncing as it should, for setting up Office 365 for the school here, but I can't set up AD Connect with the second on their system - it tries to sync to the original AD tenant, completely ignoring the second.

 

Is what I'm wanting to do possible? Or am I going to have to set up a second Azure account and set up Azure AD for the second school in there?

Posted

I'm a bit confused by your question - of course when setting up Azure Connect, you're prompted for local AD credentials, as well as credentials of your new tenant. The sync then begins.

 

If you're trying to create users in Tennant B instead of Tennant A, you'd need a new/different domain extension, whatever that will be, as of course domains can only be registered to one tenant at a time.

Posted

OK. Seems I derped here. The issue being that it required a username specifically set up in the new tenant (not the one it uses by default, the overall admin account, as that one is tied to the original Azure AD).

 

I have created this account, and logged in OK with Azure Connect now.

 

The next issue I have is the domain verification step. How on Earth do I get it to verify? Does the domain need to have public DNS registration? It's only an internal domain you see.

Posted
AFAIK it needs to have some public DNS relationship for both verification and underlying function. Otherwise, you'll have to register your internal name with a registrar.
Posted

As above, it needs to be a public domain with the relevant DNS and MX records and anything else it needs. To make it internal, you'd just apply Mail Rules afterwards to block anything external.

 

If you think about it, this does make some sense given that O365 is an external service also. Even if you applied Mail Rules, mail would still leave site and then come back again, unless you have an Exchange Server.

Posted
As above, it needs to be a public domain with the relevant DNS and MX records and anything else it needs. To make it internal, you'd just apply Mail Rules afterwards to block anything external.

If you think about it, this does make some sense given that O365 is an external service also. Even if you applied Mail Rules, mail would still leave site and then come back again, unless you have an Exchange Server.

 

It isn't for O365 though. It is for single sign on with third party services (MLS in this case). This is gonna be difficult, as I doubt somerset.gov.uk are going to set up a subdomain for them (all schools down here use a subdomain of that as their internal domain!).

Posted
It isn't for O365 though. It is for single sign on with third party services (MLS in this case). This is gonna be difficult, as I doubt somerset.gov.uk are going to set up a subdomain for them (all schools down here use a subdomain of that as their internal domain!).

 

Sounds like it's linking to Azure, however the same rule applies (best to my knowledge), as O365 and Azure are heavily integrated. From what you're saying, a new domain would be the best route. Unfortunately I fear that some Local Authorities implement such configurations as to 'lock' the school, making it more difficult to move to another solution.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...