Jump to content

Recommended Posts

Posted

Hi,

 

We're in the process of moving from individual AD accounts and Office 365 accounts to connecting them with Azure AD sync. All our teachers have laptops connected to Azure AD, managed by Intune and log in with their Azure AD synced accounts which works fine. The vast majority of our students are still using normal AD on computers in labs.

 

The issue we're having is that teachers don't seem to be automatically authenticating reliably after logging in which is causing endless phone calls from teachers saying they can't show their videos etc. We have Active Directory and Azure AD linked as directories (see attached picture) and have assigned the groups.

Smoothwall.png

 

Does the fact that AD is above Azure AD in the directory listings matter? If so what's the consequences for the students if we were to put AzureAD above AD? Any help with this would be greatly appreciated.

 

Thanks

Posted

Not sure I can totally answer your question but I can tell you what we've got configured which is working well for us.

 

Our AD accounts are all synced via Azure AD Connect. All desktop computers and staff laptops are Hybrid AD joined.

 

Student laptops are Azure AD joined only and managed entirely by Intune. On these devices we push out the Smoothwall Cloud Filter browser extension so that filtering is done on the client whether the device is on-site or off-site which works great for supporting students isolating at home.

 

Like you we have Azure AD and Local AD directories configured in Smoothwall but have Azure AD at the top of the list. All users get the correct policies regardless of what device type they're using.

  • Thanks 2
Posted

Thanks gybe

 

We've still got 'old fashioned' labs with too much legacy software on them for my liking which makes managing them by Intune a bit more difficult. I'd like to make all machines Azure AD joined at some point to make all this easier but it's always a time issue. We're slowly syncing all our accounts with Azure Hybrid Connect but it's been delayed a bit due to a very busy September and people finally settling in and not wanting to rattle the cage again too much too soon.

 

I'm hesitant to move our AzureAD above AD in the directory as I'm unsure what's going to happen to the student's authentication but I might just have to bite the bullet and do it at some point.

 

Thanks for your response.

Posted
With Azure AD we can currently only lookup users and groups. We cannot validate password yet. I'd suggest a support call as the auth methods may need to be adjusted for the dual environment.
  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...