Liam Posted April 25, 2017 Posted April 25, 2017 Ok, so my idea.. As part of a MAT we are looking at becoming joining systems / services together. Im looking at the possiblity of... Creating a DC VM in Azure to sync the sites together (once i have them both in a position to do this)- this will also run azure ad connect to sync with Azure for O365 purposes. Creating a link to each site using azure networking technologies e.g express route or a VPN gateway Creating an ADFS server VM in Azure / using Azure AD connect SSO technology A) Would thid work? B) Has anyone done anything like this? C) If you have done it what have are the costs? D) Do i have other alternatives - with the exception of site to site VPN or PWAN 1
HPlum78 Posted April 25, 2017 Posted April 25, 2017 I guess you have right now 2 disparate AD forests? and you want to combine these in to one? so the first place I will point you is here https://technet.microsoft.com/en-us/library/cc974335(v=ws.10).aspx you could do this with an azure DC but you would probably be best to just do this with onsite hardware, when you have a continuous forest you can then just use the tools available to sync up to azure AD. There is no way with azure AD to sync dissipate forests.
HPlum78 Posted April 25, 2017 Posted April 25, 2017 I will add this IaaS solutions are more expensive than SaaS solutions, so if you are setting up a VM to run a service that exists as a SaaS offering you will pay for it, and in the case of AD unless you have an absolute need to have your entire AD structure replicated to an offsite VM then I would in the first instance steer away from it. That said there are circumstances where this configuration is desirable but you should make sure that the business need really requires it, and that you make sure you get you AD structure setup accordingly. As for express route its still a little expensive and that's about as much as I can say on that.
Wave9_Lee Posted April 25, 2017 Posted April 25, 2017 Hi Liam Looks sensible, there are several options within this to look at - i.e. express route not really necessary, and a bit expensive currently, and there are arguments for on-prem/off-prem and hybrid. If you want a no obligation chat, let me know I can arrange this. regards Lee
RJohnson91 Posted April 25, 2017 Posted April 25, 2017 This is exactly what we are looking to do also, post subbed
jaminben Posted April 25, 2017 Posted April 25, 2017 Same for us... following this thread with interest.
HPlum78 Posted April 25, 2017 Posted April 25, 2017 If any of you want to contact me directly feel free, give me some background about what you are trying to achieve and some detail around your current setups and I will try point you in the right direction. 3
dhicks Posted April 25, 2017 Posted April 25, 2017 Creating a DC VM in Azure to sync the sites together We plan something similar, but probably in an AWS Virtual Private Cloud rather than in Azure (depends on pricing). We would also add a VM to sync our MIS data.
HPlum78 Posted April 26, 2017 Posted April 26, 2017 I am going to correct something that I said yesterday around Azure AD not being able to accept disparate domains, after talking to a college last night and doing some digging I see that it is now possible to achieve this using AD connect. There are a number of idiosyncrasies around accomplishing this mainly around how you treat these forests/ domains outside of the connection to Azure AD.
Liam Posted April 26, 2017 Author Posted April 26, 2017 I am going to correct something that I said yesterday around Azure AD not being able to accept disparate domains, after talking to a college last night and doing some digging I see that it is now possible to achieve this using AD connect. There are a number of idiosyncrasies around accomplishing this mainly around how you treat these forests/ domains outside of the connection to Azure AD. Are you referring to the possibility of having multiple (completely seperate) domains sync'ing with one azure ad platform. I was under the assumption that you can only have one azure ad connect instance for azure ad. Referring to this.. https://docs.microsoft.com/en-us/azure/active-directory/connect/active-directory-aadconnect-topologies
HPlum78 Posted April 26, 2017 Posted April 26, 2017 That document is absolutely correct and outlines the possible ways to get your users synced with Azure AD, and outlines the very idiosyncrasies that I was taking about that need to be decided on before you start. So any of the Multiple forests approaches, and the one you chose will be dependent on a number of factors complexity, manageability, the speed you need to deliver a solution, if you have an appetite to support multiple Exchange/ Skype environments so and forth.
Popular Post Wave9_Matt Posted April 26, 2017 Popular Post Posted April 26, 2017 Hi Liam As has been mentioned there is a lot of interest in this kind of approach, especially from MAT's who are coming together and are seeking to bring services under a level of centralised control. The best architecture will be dependent on many factors including (but not limited to), the number of schools you have in your MAT, how large it is envisaged to grow, staff mobility requirements, how IT will be managed within the MAT, device and application strategy, backup and DR strategies, existing IT infrastructure within each school, finance and budgets etc. Most of these points constitute a much more involved discussion than can be encompassed within the scope of this thread. To provide you with some thoughts on your questions: A) Would this work? From a high level perspective yes, but the devil is always in the detail, as has been picked up on by some of the other respondents. If you have the ability to rebuild each of the schools AD then you have the option to create child domains from your Azure AD DS VM forest root. You'll need to be careful around the limitations of the Azure VPN gateway for the number of site to site VPN's and NAT Traversal etc, though most of this can be circumvented by using a third party Firewall VM (Sophos XG , Barracuda etc) hosted in Azure. Where you can't rebuild AD then trust relationships can be established between disparate schools and your forest root in Azure. In certain circumstances it is worth looking at a 2 DC per school with one on prem and the other in Azure - provides for a backup and DR quite nicely, though clearly each school would be picking up the cost of running that VM. It is worth considering elements of System Centre if you are going to have a light IT team supporting multiple primaries etc. We are increasingly seeing SCCM Primary site servers hosted in Azure with distribution points on local infrastructure within the school, it give you a central point of control for applications, updates and operating system deployment. Love or hate it, there is also SCEP which can be managed via SCCM for your entire MAT and the CAL's are wrapped up your O.VS Education Desktop CAL pac .If you go down the route of a Config Mgr hierarchy then you need to consider the network addressing at each school site to ensure that your addressing and consequently boundary groups are unique B) Has anyone done anything like this? Yes :-) C) If you have done it what have are the costs? This isn't a simple question to answer as it depends on the number and provisioning of VM's, qty and type of storage, ingress / egress traffic through VPN Gateway etc etc. The best way to approach this is scope the scale of Azure services for the size of your MAT and cost them up based on the publicly available pricing. The important consideration is how will it be paid, what is the MAT model, paid centrally or each school pays a proportion, does each member school pay centrally for all IT services?? Budgeting for Azure, as a consumption based service is more tricky as there are variables which will alter charges daily. Also be careful 'cloud lock in' wrt price changes and your IT budgets - Azure hiked its prices 15-20% Jan this year to 'align the GBP'. D) Do i have other alternatives - with the exception of site to site VPN or PWAN Communication from remote sites need to be secured, if you remove the option for site to site VPN over the public internet or a private WAN service such as MPLS and / or Express route then there isn't much left. Again this comes down to the shape of the MAT, if you have one secondary (combined with multiple feeder primaries) with a decent fibre connection and server room then you can do a lot of it yourself with your MAT / Team. Site to Site VPN's are easy enough to setup and if you select the right solution then you can manage the entire estate of UTM's centrally, useful for giving you visibility of remote site uptime as well as controlling trust wide filtering. You also have the option to work with a service provider who can deliver you a private cloud solution, this can give you more flexibility and a more predicable cost model than Azure alone. Anyway, I hope there is something in this response that is of value to you. Regards Matt 5
Liam Posted April 26, 2017 Author Posted April 26, 2017 Very helpful thanks.. I think I have considered most of your points as part of my planning . There are so many different ways to achieve this I know, and I will cover each of them as part of the project. Great help though thanks
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now