ltaylor Posted October 9, 2020 Posted October 9, 2020 Hi, We're in the process of moving from individual AD accounts and Office 365 accounts to connecting them with Azure AD sync. All our teachers have laptops connected to Azure AD, managed by Intune and log in with their Azure AD synced accounts which works fine. The vast majority of our students are still using normal AD on computers in labs. The issue we're having is that teachers don't seem to be automatically authenticating reliably after logging in which is causing endless phone calls from teachers saying they can't show their videos etc. We have Active Directory and Azure AD linked as directories (see attached picture) and have assigned the groups. Does the fact that AD is above Azure AD in the directory listings matter? If so what's the consequences for the students if we were to put AzureAD above AD? Any help with this would be greatly appreciated. Thanks
5tu Posted October 9, 2020 Posted October 9, 2020 Not sure I can totally answer your question but I can tell you what we've got configured which is working well for us. Our AD accounts are all synced via Azure AD Connect. All desktop computers and staff laptops are Hybrid AD joined. Student laptops are Azure AD joined only and managed entirely by Intune. On these devices we push out the Smoothwall Cloud Filter browser extension so that filtering is done on the client whether the device is on-site or off-site which works great for supporting students isolating at home. Like you we have Azure AD and Local AD directories configured in Smoothwall but have Azure AD at the top of the list. All users get the correct policies regardless of what device type they're using. 2
ltaylor Posted October 9, 2020 Author Posted October 9, 2020 Thanks gybe We've still got 'old fashioned' labs with too much legacy software on them for my liking which makes managing them by Intune a bit more difficult. I'd like to make all machines Azure AD joined at some point to make all this easier but it's always a time issue. We're slowly syncing all our accounts with Azure Hybrid Connect but it's been delayed a bit due to a very busy September and people finally settling in and not wanting to rattle the cage again too much too soon. I'm hesitant to move our AzureAD above AD in the directory as I'm unsure what's going to happen to the student's authentication but I might just have to bite the bullet and do it at some point. Thanks for your response.
ibpalle Posted October 16, 2020 Posted October 16, 2020 With Azure AD we can currently only lookup users and groups. We cannot validate password yet. I'd suggest a support call as the auth methods may need to be adjusted for the dual environment. 1
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now