Jump to content

Recommended Posts

Posted

Hi All

I am looking for advice.

I have 2 schools that share the same building and have 1 shared IT suite with 1 server between them. At present I use AD and NTFS to separate files and folders so each school can only see their own stuff, however each school wish to purchase a Microsoft 365 tenant northumberland.school1.org.uk and cumbria.school2.org.uk. my issues is they use the same pc's so how do i hook them up to two different tenants.

 

i wondered if they could be hybrid networks with newcastle.org.uk as the top level domain and northumberland.school1.newcastle.org.uk as sub domain and cumbria.school2.newcastle.org.uk as subdomain2, my problem with this is i don't know if they could login with [email protected] or would it have to be [email protected]. the PC's would be joined to the newcastle.org.uk domain and pick up group policy from that.

 

or is there a better option maybe without hybrid domains.

 

anyone any ideas please. i have been given 5 days to configure everything from when we start and they would like to start Friday I want to leave it a while.

 

thanks

 

ian

Posted

ok ive done some TESTING on this or something similar (be aware this was a test environment not for actual use just to see if it worked at all)

 

if you are going 100% cloud its not much of an issue user types in [email protected] as login and they can login on any pc (theoretically in the world) and you can have multiple domain names on 1 tenant in fact unless you are using the default @on microsoft.com address you already have 2 names.

 

if you want to use ad as your master user database its still possible. if you have 2 domains as long as they trust each other you install ad connect on 1 (and only 1) server and it can sync multiple domains they dont even need to be in the same forest (but it would probably be easier). If they are 1 domain with 2 "domain names" of users you just add domain suffixes as appropriate and make sure users from school 1/2 have the domain suffix you want applied to them and when you sync with ad connect thats what their account will be (so you can have one ad domain with 3 names say pizza, sarnie and pie and if the user fred has a domain suffix of pizza then their email account will be created in the pizza domain on 365. you just need to make sure all domains are setup before you try and sync and that all users have the correct suffix on their account

Posted

@sted is correct.

 

If you have 2 domain unique names registered on a single tennant you could set up 2 domain aliases in your AD.

These can be synced separately or together whilst performing an AD sync. Auto assign the licenses in Azure Active Directory.

 

You can set the domain alias on either their domain suffix on the Account tab in AD or in the Attribute Editor ----> Proxy Address.... SMTP: [email protected]

  • 2 weeks later...
Posted

do not do different tenants. You can have hundreds of domains in the same tenant and have different GALs and so on.

 

That said, you can sync a single AD to two tenants, you just cannot sync the same UPN to more than one tenant, nor the same user account to more than one tenant

 

Pick a tenant name that's a little bland as sometimes its a little visible to users.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...