TJ-Diggers Posted February 3, 2020 Posted February 3, 2020 I am moving into a new MAT and want to migrate all the schools from exchange on-prem to O365 Exchange Online.Currently, there are 6 AD's but I am thinking of having 1 Office 365 tenant for the Trust so it is easier to manage but also they can share resources using SharePoint.Has anyone got a similar setup up? Can you have Azure AD Connect running on each AD pointing to the 1 o365 tenant?Also if anyone has different setups....... please share!
SparkySX Posted February 3, 2020 Posted February 3, 2020 You won't be able to sync more than one AD server with a single O365 tenant, without settings up trusts etc. This page is some good, light, reading regarding syncing and supported topologies: https://docs.microsoft.com/en-us/azure/active-directory/hybrid/plan-connect-topologies
TJ-Diggers Posted February 3, 2020 Author Posted February 3, 2020 I was just having a read of this.... This is going to be an interested project!
SVM Posted February 3, 2020 Posted February 3, 2020 You can have 1 Azure AD Connect server that syncs multiple forests, as long as there is a VPN setup between sites as the DCs need comms to the Azure AD connect server, trusts not needed 1
SparkySX Posted February 3, 2020 Posted February 3, 2020 You could have more than one domain (.com) on a single tenant and share resources as you would like to. You'd only have to have Azure AD Connect if you need password sync/SSO
TJ-Diggers Posted February 3, 2020 Author Posted February 3, 2020 I do want password sync / SSO I would need AD connect to sync all users from AD otherwise I would need to manually create on O365?
chaplic Posted February 4, 2020 Posted February 4, 2020 You absolutely can do what you want, and should do it with PHS and Seamless SSO, many of my clients do just this to bring various parts of their company together in one AD. I am fairly certain trusts are not even required for Azure AD connect you give each connection to AD a separate account to use Conversely, multiple O365 tennants sucks, having to have guest access and so on is a pain. Single tennant, bring identity in as-in and look to de-emphasize the ADs over time.
arh1a Posted September 28, 2020 Posted September 28, 2020 I am moving into a new MAT and want to migrate all the schools from exchange on-prem to O365 Exchange Online.Currently, there are 6 AD's but I am thinking of having 1 Office 365 tenant for the Trust so it is easier to manage but also they can share resources using SharePoint.Has anyone got a similar setup up? Can you have Azure AD Connect running on each AD pointing to the 1 o365 tenant?Also if anyone has different setups....... please share! I'm looking at doing the same, how did you migrate all the schools into one? Did you use any migration software for mailboxes, SharePoint data etc? What worries me is any downtime for the users.
psydii Posted September 28, 2020 Posted September 28, 2020 https://docs.microsoft.com/en-us/azure/active-directory/hybrid/plan-connect-topologies#:~:text=When%20you%20have%20multiple%20forests%2C%20all%20forests%20must,known%20as%20DMZ%2C%20demilitarized%20zone%2C%20and%20screened%20subnet%29. Once you are syncing identities, migrate mailboxes asap per domain, then follow up with 'My Documents' / known folders to OneDrive (per domain) , and then shared Drives to Teams/SharePoint (per domain). There is basically no downtime, as you can run the sync/migration for each stage / user / groups of users and then cut over when ready. Exchange has built in tools, and for OneDrive and SharePoint you can use the SharePoint Migration Tool (simplest) or Mover. Once you have everybody sync'd to the cloud and their documents in SharePoint/OneDrive you can look at moving their On-Prem AD accounts to a single forest - but consolidating forests involved dramatic changes to how you manage workstation and user policy. This is probably the hardest part. 1
arh1a Posted November 3, 2020 Posted November 3, 2020 https://docs.microsoft.com/en-us/azure/active-directory/hybrid/plan-connect-topologies#:~:text=When%20you%20have%20multiple%20forests%2C%20all%20forests%20must,known%20as%20DMZ%2C%20demilitarized%20zone%2C%20and%20screened%20subnet%29. Once you are syncing identities, migrate mailboxes asap per domain, then follow up with 'My Documents' / known folders to OneDrive (per domain) , and then shared Drives to Teams/SharePoint (per domain). There is basically no downtime, as you can run the sync/migration for each stage / user / groups of users and then cut over when ready. Exchange has built in tools, and for OneDrive and SharePoint you can use the SharePoint Migration Tool (simplest) or Mover. Once you have everybody sync'd to the cloud and their documents in SharePoint/OneDrive you can look at moving their On-Prem AD accounts to a single forest - but consolidating forests involved dramatic changes to how you manage workstation and user policy. This is probably the hardest part. Thanks, I'm glad to hear it is possible without any down time. All the schools currently have Azure AD Sync on each of there domain controllers and Hybrid AD setup too.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now