Score:0

Deploying Windows Server AD DS as IaaS (VM) in Azure?

pk flag

I'm currently seeking some advice and guidance whether deploying additional Windows Server 2019 VM in Azure to run Active Directory Domain Controller / Global Catalog in separate AD sites called 'Azure' is really have any benefits or not?

At the moment my AD domain is just single forest AD, spread across multiple geographical locations throughout Asia Pacific.

Azure AD Connect runs Password Hash Sync to Azure AD, since we are still using Hybrid Exchange 2016-Office 365.

What are the benefits and the caveats when deploying one more AD DS as IaaS in Azure to serve the AD Sites called 'Azure' that is for the IP Subnet of the VNET I peered from Azure to OnPremise?

Score:1
ng flag

If you want to run domain-joined VMs in your Azure virtual network, the best practice is for them to have a "local" Domain Controller (or two) available, running as another Azure VM; otherwise, they will need to reach out to one of your on-premises Domain Controllers every time they need to query DNS or AD (i.e. continuously).

Of course, if you don't want to run domain-joined VMs in your Azure virtual network, having a Domain Controller there would be quite useless.

Senior Systems Engineer avatar
pk flag
I've got ExpressRoute circuit already established too and peered to the VNET - OnPremise DataCenter
Massimo avatar
ng flag
The same applies. You should treat your Azure VNet just like an additional site in your network. If you want to use your AD domain there, it's better to have a local DC.
Senior Systems Engineer avatar
pk flag
that's great, thank you @massimo
mangohost

Post an answer

Most people don’t grasp that asking a lot of questions unlocks learning and improves interpersonal bonding. In Alison’s studies, for example, though people could accurately recall how many questions had been asked in their conversations, they didn’t intuit the link between questions and liking. Across four studies, in which participants were engaged in conversations themselves or read transcripts of others’ conversations, people tended not to realize that question asking would influence—or had influenced—the level of amity between the conversationalists.