- Mastering Identity and Access Management with Microsoft Azure
- Jochen Nickel
- 181字
- 2021-07-02 12:57:25
Multi-Azure Active Directory Integration
Sometimes you need to have multiple Azure Active Directories, for example if parts of your organization are based in China or you need to follow government regulations. For each Azure AD directory, you'll need one Azure AD Connect installation.
In a single-forest filtering scenario to multiple Azure ADs, the following needs to be done:
- Azure AD Connect must be configured for filtering
- DNS domain registration is only possible in a single Azure AD
- UPNs of the users on-premises must use separate namespaces
- Federation configuration needs to be customized
- One Azure AD directory can enable Exchange hybrid with the on-premises AD
- Global Address List synchronization needs to be performed through MIM 2016
- Windows 10 devices can only be with one Azure AD tenant
- The SSO option with the password hash synchronization and pass-through authentication activated can work only with one Azure AD tenant
- Group and device write-back scenarios are possible
The following diagram shows the multiple Azure AD situation:

Connecting multiple Azure AD to one AD forest
It's unsupported to sync the same user to multiple Azure ADs.
推薦閱讀
- unidbg逆向工程:原理與實(shí)踐
- INSTANT Netcat Starter
- 工業(yè)互聯(lián)網(wǎng)安全
- 黑客攻防與電腦安全從新手到高手(微視頻+火力升級版)
- 網(wǎng)絡(luò)安全技術(shù)與實(shí)訓(xùn)(第4版)(微課版)
- 云原生安全技術(shù)實(shí)踐指南
- Digital Forensics with Kali Linux
- Advanced Penetration Testing for Highly:Secured Environments(Second Edition)
- 軟件安全保障體系架構(gòu)
- 無線傳感器網(wǎng)絡(luò)安全與加權(quán)復(fù)雜網(wǎng)絡(luò)抗毀性建模分析
- 網(wǎng)絡(luò)空間安全導(dǎo)論
- 計(jì)算機(jī)網(wǎng)絡(luò)安全實(shí)驗(yàn)指導(dǎo)
- INSTANT Kali Linux
- Web安全攻防從入門到精通
- Metasploit 5.0 for Beginners