Ok, so now the site-to-site VPN is in place, I can sync my local Active Directory (AD) lab.damen-online.nl with my Azure Active Directory (AAD). To do this I first need to register this domain within my Azure subscription (as this is registered with another domain). To do this I go to Azure Active Directory in my Azure Portal
data:image/s3,"s3://crabby-images/9c7cf/9c7cf1ff2b700a92911fdbbd8249cc30cfecf0e1" alt=""
Within AAD I go to Custom Domain Names
data:image/s3,"s3://crabby-images/502d4/502d4bd48f8f666d6b3fb194864b20a52190fce0" alt=""
and I click on + Add custom domain
data:image/s3,"s3://crabby-images/edce8/edce8c88d4a685d99682c9406c7447314f2d360d" alt=""
I provide my domain name and click Add
data:image/s3,"s3://crabby-images/04328/0432861475b8534af80a28eb7141f636ff8dd310" alt=""
After hitting the button a message appears that I need to create a TXT record with my domain registrar, using the info provided.
data:image/s3,"s3://crabby-images/5ebdc/5ebdcf8b96328573c8e805d98547f21f044c209c" alt=""
So opening up the admin page of my registrar to add the TXT record as mentioned (I have a Dutch registrar, hence the Dutch language).
data:image/s3,"s3://crabby-images/02792/02792f494c2cc6793b6bc3a53eeb42bd9bc6adde" alt=""
After adding the TXT record I will switch back and verify the domain. As you can see the domain is now verified, so good to go.
data:image/s3,"s3://crabby-images/6ead4/6ead4f56e5bdc5245bee1da0b1ebed673e53b2d0" alt=""
Now I can install AAD Connect. I open the custom domain (lab.damen-online.nl) and click Download Azure AD Connect
data:image/s3,"s3://crabby-images/0aec9/0aec926ae3421741ff2c193519f8286659aed301" alt=""
A new website opens where I can download Microsoft Azure Active Directory Connect
data:image/s3,"s3://crabby-images/1a6f2/1a6f26a04514e2ad2d2f8437edbbd71b167092e0" alt=""
After downloading I start the installation wizard. I agree to the license terms and privacy notice and click Continue
data:image/s3,"s3://crabby-images/c0376/c03769b4fe94017b7c96f8b2736118c6262f675b" alt=""
As I have a single domain, I can use the Express Settings so I select Use Express Settings
data:image/s3,"s3://crabby-images/fda38/fda3800be0cb09c37d191b46c8d72a5cae71f118" alt=""
I need to connect to Azure AD using my Azure AD global administrator credentials. So I provide these and click Next
data:image/s3,"s3://crabby-images/c4624/c46242e5b3361a55777017b472601081fd718783" alt=""
Next screen, next credentials… Now I need to provide the enterprise admin credentials for the local domain, before clicking Next
data:image/s3,"s3://crabby-images/a27b0/a27b08c12cbf27098dee3485df74d7439a601995" alt=""
I get an overview of what the wizard will do, and I leave the “Start the synchronisation process when the configuration completes checked” and click Install
data:image/s3,"s3://crabby-images/c386d/c386d4ad6729b68535c386b701dab372e39ca1f7" alt=""
The configuration completes in a couple of minutes, so my AD is synced with AAD. I get a message that my AD recycle Bin hasn’t been enabled (so will do that in the next section), and another message stating that AAD is configured to use AD attribute ms-DS-ConsistencyGuid as the source anchor attribute. After reading this article it’s clear this attribute will act as the immutable ID and is system generated. The configuration is done, so I click Exit
data:image/s3,"s3://crabby-images/a3ad5/a3ad5b84bbfc51e10a11a78fe5852065b3c31f79" alt=""
I enabled the recycle bin on my Active Directory (as recommended) and created some test accounts within my AD (I used some brands from the client I work for, so they might look familiar to some of you) . After a while these are synchronised to AAD, so mission accomplished (Azure AD connect is working), up for the next bit.
data:image/s3,"s3://crabby-images/52763/5276372e702719a71959789a495b5ef0a44e659b" alt=""