e-class Posted January 31, 2021 Posted January 31, 2021 Slight quandary here ... We have a single M365 tenant but have both our Primary and Secondary schools using it. Both are on different sites with no connectivity between the two and both have different Active Directory domains. So Azure AD connect is not supported with two separate on-prem AD which do not have any connectivity. But there is something called Azure AD Cloud Sync, which does support the above scenario. So has anyone used this? This is a pre-cursor to moving home drives to OneDrive for all our users. Without this I'm thinking we will have separate credentials for on-prem AD and M365, so if we do move home drives to OneDrive there's a potential users won't log in to OneDrive leaving files locally on their PC ... Potentially data loss if the PC goes 'pop'? Do people specify where they keep OneDrive files locally? Can these even be moved to a network location i.e. server share? Or use files on demand? I think there's two questions above, one about cloud sync and then the second whether people are using OneDrive without sync'ing their on-prem and M365 accounts. Thanks again! Any advice?
Steve21 Posted January 31, 2021 Posted January 31, 2021 In regards to the sync side, is there no option of having a link between sites? Surely even something like a VPN connection between sites would enable AADC to access both servers and sync them to the same tenant? (Also depending on your internet connection a lot will let you link them together, most companies can do that for free if they're on same connections etc) Thinking long term wise are these schools going to be using the same logins etc? As in is now the time to consider merging domains etc to enable cross-links during the work? Or are they going to be separate entities still as such? Steve
MatthewL Posted January 31, 2021 Posted January 31, 2021 You say there is no link between sites, both have internet connections why not just create a VPN between the two of them?
HPlum78 Posted January 31, 2021 Posted January 31, 2021 Or stand the AAD Connect server up in Azure and connect it to each site.
e-class Posted January 31, 2021 Author Posted January 31, 2021 All, thanks. Yes, both have internet so we could VPN them both and host the sync server at one of the sites. Longer term plan was to bring them to a single AD which would need them to be linked. I guess, I was wondering if this new Azure Cloud Sync was being used by anyone yet?
Sylv3r Posted February 1, 2021 Posted February 1, 2021 It sounds like we have a similar setup to you. We have 8 schools currently in our Azure using the Azure Cloud Sync tool - we have 48 schools in our trust but for whatever reason I can't get any more schools added - I am not sure if there's a limit or there's something else wrong - in theory we've done nothing different. This is our initial plan especially if it worked - other than that we will have to revert to a single server running AAD Connect and then linking all of the AD's that way. The long term plan is a single domain, but that's a while away. 1
e-class Posted February 2, 2021 Author Posted February 2, 2021 That sounds pretty much like what we want to do. Was the cloud sync bit easy? No gotchas? If you can share anything e.g. instructions, docs etc. that would be great. DM me if you prefer. Many thanks. It sounds like we have a similar setup to you. We have 8 schools currently in our Azure using the Azure Cloud Sync tool - we have 48 schools in our trust but for whatever reason I can't get any more schools added - I am not sure if there's a limit or there's something else wrong - in theory we've done nothing different. This is our initial plan especially if it worked - other than that we will have to revert to a single server running AAD Connect and then linking all of the AD's that way. The long term plan is a single domain, but that's a while away.
HPlum78 Posted February 2, 2021 Posted February 2, 2021 (edited) I have not used Azure Cloud Sync but from what I have just read its an entirely different solution to AAD Connect. You will still need to sync your local AD directories to your single cloud tenant. And as noted above you are going to need to do this via a single AADC server on one site or another (or as I say in Azure for what it's worth!). This will then let you assign the required office licences to your users (and give them One Drive). Azure Cloud Sync looks as if its adds a cloud tier of storage to your local file share solution (so departmental file share areas (D drive) for talking sake) and share them using the same/ already well understood technology along with leveraging ACL's that are under pinned by your local AD infrastructure. That's how I have read it in my real quick skim this morning (there could be more to it) So in summary AAD Connect is for syncing local AD objects to Azure (then this is synced to your M365 tenant and sharepoint, blah bla blah..) the other seems to be associated with syncing/ extending file shares on to cloud storage. I could have got the wrong end of the stick here tho... Edited February 2, 2021 by HPlum78
Sylv3r Posted February 2, 2021 Posted February 2, 2021 That sounds pretty much like what we want to do. Was the cloud sync bit easy? No gotchas? If you can share anything e.g. instructions, docs etc. that would be great. DM me if you prefer. Many thanks. Not much to it to - download the client from Azure (it helps you use the very latest version) then just follow the wizard. You'll need to add your O365 admin credentials (may have to be a global admin) Add your domain admin credentials From within Azure, you will then be able to enable password hash, filter by OU and then enable it. Obviously your users within AD will need to match the domain syntax that you are going want to use in O365.
e-class Posted February 2, 2021 Author Posted February 2, 2021 Thanks, will give it a go. There's no licencing needed for the cloud sync? Thanks Not much to it to - download the client from Azure (it helps you use the very latest version) then just follow the wizard. You'll need to add your O365 admin credentials (may have to be a global admin) Add your domain admin credentials From within Azure, you will then be able to enable password hash, filter by OU and then enable it. Obviously your users within AD will need to match the domain syntax that you are going want to use in O365.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now