Site icon TechGit

Set Up Azure Active Directory Connect Pass-Through Authentication

cloudconnectivityhero-1280x743-2849298

 

cloudconnectivityhero-1280x743-2849298

Microsoft has recently made it easier to securely connect Windows Server Active Directory (AD) to Azure AD, without needing to set up and maintain Active Directory Federation Services (ADFS). In this Ask the Admin, I will show you how to set up Azure AD Connect pass-through authentication (PTA).

A couple of weeks back on Petri, I wrote about how Microsoft added PTA to Azure AD Connect. This is the tool that replaced DirSync for connecting on-premises Windows Server AD to cloud-based Azure AD. ADFS provides federated identities with true single sign-on (SSO). Password hashes are never synchronized to the cloud but ADFS is complicated to set up. PTA provides the main benefits of ADFS, such as storing password hashes on-premises and high availability, without the complexity. Password synchronization is also an option in Azure AD Connect but as the name suggests, password hashes are stored in Azure AD.

If you missed it, you can read the details in Azure Active Directory Connect Makes Cloud Single Sign-On Easy on Petri.

It is worth remembering that at this stage PTA is a preview. This means that it is not supported by Microsoft and should not be configured in production environments. If you want to test it in a lab, you can download the latest version of Azure AD Connect and run the wizard.

The setup process for connecting Windows Server AD to Azure AD using PTA does not differ much from password synchronization. There are some key points you should keep in mind:

Set Up Azure Active Directory Connect PTA

In this example, I will install Azure AD Connect on a Windows Server 2016 domain controller. For detailed information about the requirements and supported scenarios, see Microsoft’s website.

figure1-3-4320501

Select Pass-Through Authentication in Azure Active Directory Connect (Image Credit: Russell Smith)

figure2-2-2518905

Connect Windows Server Active Directory to Azure Active Directory (Image Credit: Russell Smith)

figure3-2-2942547

Verify a UPN Suffix (Image Credit: Russell Smith)

For more information on how to add a UPN suffix to AD, see How to Add UPN Suffixes in Active Directory on Petri.

figure4-2-8873793

Select One or More OUs to Synchronize (Image Credit: Russell Smith)

figure5-1280x838-7859873

Check that Windows Server Active Directory Accounts are Synchronized to Azure Active Directory (Image Credit: Russell Smith)

In this article, I showed you how to configure Azure AD Connect using PTA. In a future article, I will cover installing additional agents for high availability, more complex configuration options in the Azure AD Connect wizard, password writeback, self-service password resets, and more.

The post Set Up Azure Active Directory Connect Pass-Through Authentication appeared first on Petri.

FacebookTwitterTumblrRedditLinkedInHacker NewsDiggBufferGoogle ClassroomThreadsXINGShare
Exit mobile version