{"id":2424,"date":"2016-12-02T15:00:32","date_gmt":"2016-12-02T13:00:32","guid":{"rendered":"http:\/\/blog.hosebei.ch\/?p=2424"},"modified":"2016-12-02T15:00:32","modified_gmt":"2016-12-02T13:00:32","slug":"azure-ad-domain-services-what-you-can-do-and-what-you-cant-do","status":"publish","type":"post","link":"https:\/\/blog.hosebei.ch\/?p=2424","title":{"rendered":"Azure AD Domain Services &#8211; What you can do, and what you can&#8217;t do"},"content":{"rendered":"<p>Since Microsoft has Released Azure AD Domain Services, many questions are coming up, and the top one of them might be: Can I join my Windows 10 Client through the internet to my Domain and receive Group Policies? No, you can&#8217;t.<br \/>\nBut besides this, there are other questions that remains to be answered, and I will try to do so.<br \/>\nThe first thing is to explain, what is required to get the Azure AD Domain Services (AAD DS) up and running:<br \/>\n1. Create a group in Azure AD called &#8220;AAD DC Administrators&#8221;<br \/>\n2. Create a VNET in Azure if not already existent<br \/>\n3. Activate the AAD DS in the Azure Portal:<br \/>\n<a href=\"http:\/\/blog.hosebei.ch\/wp-content\/uploads\/2016\/12\/azureaddomainservices01.png\"><img loading=\"lazy\" decoding=\"async\" src=\"http:\/\/blog.hosebei.ch\/wp-content\/uploads\/2016\/12\/azureaddomainservices01.png?w=300\" alt=\"Active Azure AD Domain Services\" width=\"300\" height=\"182\" class=\"aligncenter size-medium wp-image-2425\" srcset=\"https:\/\/blog.hosebei.ch\/wp-content\/uploads\/2016\/12\/azureaddomainservices01.png 930w, https:\/\/blog.hosebei.ch\/wp-content\/uploads\/2016\/12\/azureaddomainservices01-300x182.png 300w, https:\/\/blog.hosebei.ch\/wp-content\/uploads\/2016\/12\/azureaddomainservices01-768x465.png 768w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a><br \/>\n4. Update DNS Settings for the specific VNET<br \/>\nAnd now, you are ready to go, for a more detailed explanation refer to this Microsoft <a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/active-directory-domain-services\/active-directory-ds-getting-started\" target=\"_blank\">Article<\/a>.<\/p>\n<p><!--more--><br \/>\nNow you are able to:<\/p>\n<li>Join Virtual Machines hosted on Azure IaaS to this Domain<\/li>\n<li>Edit Group Policy for those Virtual Machines hosted in Azure and joined the Domain<\/li>\n<li>Configure the DNS Zones on the Domain Controllers, which the Virtual Machines hosted in Azure are using<\/li>\n<li>On those Virtual Machines, you can Login with your Synchronized On-Prem or with Azure AD Credentials<\/li>\n<li>Create own Organizational Unit (OU) Structures (more Details on this Microsoft <a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/active-directory-domain-services\/active-directory-ds-admin-guide-create-ou\" target=\"_blank\">Description<\/a>)<\/li>\n<li>You can Join Linux Machines to you AAD DS (see this <a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/active-directory-domain-services\/active-directory-ds-admin-guide-join-rhel-linux-vm\" target=\"_blank\">Article<\/a>)<\/li>\n<p>But you are not able to:<\/p>\n<li>Join Windows 10 Devices to this Domain and receive Group Policies<\/li>\n<li>Create multiple Domains for a Single Azure AD<\/li>\n<li>Connect to the Domain Controllers which are used for AAD DS and operated as a Service by Microsoft<\/li>\n<li>Run this Service for free (See <a href=\"https:\/\/azure.microsoft.com\/de-de\/pricing\/details\/active-directory-ds\/\" target=\"_blank\">AAD DS Pricing<\/a>)<\/li>\n<li>Create your own Group Polcies, this means you can only use the two GPOs that are created by Default<\/li>\n<p>If everything is set up, and you want to join your first machine to your Azure AD Domain Services, make sure that you can ping your selected Domain Name. See this guide from Microsoft to Join a AAD DS Domain: <a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/active-directory-domain-services\/active-directory-ds-admin-guide-join-windows-vm\" target=\"_blank\">Join a Windows Server virtual machine to a managed domain<\/a><br \/>\nIf you receiving the error, that your username and Password is incorrect when you are joining the Domain, check the following two Options:<br \/>\n1. When using an Azure AD Account, change the password of the Account, by doing this, Azure AD can sync the hash of the Password to the AAD DS (outlined <a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/active-directory-domain-services\/active-directory-ds-getting-started-password-sync\" target=\"_blank\">here<\/a>)<br \/>\n2. When using a synced On-Prem AD Account, make sure that password sync is enabled within Azure AD Connect, and the passwords are successfully synced<\/p>\n<p>Now let&#8217;s have a look how you can configure the Azure AD Domain Service, just install the Remote Server Administration Tools an a virtual machine that is joined to the AAD DS, and login with an AAD DS Admin onto this machine. Afterwards you can start your Management Tools and you are able to Manage the AAD DS, here is a view of the ADUC:<br \/>\n<a href=\"http:\/\/blog.hosebei.ch\/wp-content\/uploads\/2016\/12\/azureaddomainservices02.png\"><img loading=\"lazy\" decoding=\"async\" src=\"http:\/\/blog.hosebei.ch\/wp-content\/uploads\/2016\/12\/azureaddomainservices02.png?w=300\" alt=\"AAD DS ADUC\" width=\"300\" height=\"176\" class=\"aligncenter size-medium wp-image-2428\" srcset=\"https:\/\/blog.hosebei.ch\/wp-content\/uploads\/2016\/12\/azureaddomainservices02.png 633w, https:\/\/blog.hosebei.ch\/wp-content\/uploads\/2016\/12\/azureaddomainservices02-300x176.png 300w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a><br \/>\nHere is the DNS Console:<br \/>\n<a href=\"http:\/\/blog.hosebei.ch\/wp-content\/uploads\/2016\/12\/azureaddomainservices03.png\"><img loading=\"lazy\" decoding=\"async\" src=\"http:\/\/blog.hosebei.ch\/wp-content\/uploads\/2016\/12\/azureaddomainservices03.png?w=300\" alt=\"AAD DS DNS\" width=\"300\" height=\"158\" class=\"aligncenter size-medium wp-image-2429\" srcset=\"https:\/\/blog.hosebei.ch\/wp-content\/uploads\/2016\/12\/azureaddomainservices03.png 757w, https:\/\/blog.hosebei.ch\/wp-content\/uploads\/2016\/12\/azureaddomainservices03-300x158.png 300w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a><br \/>\nAnd this screenshot shows the Group Policy Management Console (gpmc.msc) for the Azure Active Directory Domain Services:<br \/>\n<a href=\"http:\/\/blog.hosebei.ch\/wp-content\/uploads\/2016\/12\/azureaddomainservices04.png\"><img loading=\"lazy\" decoding=\"async\" src=\"http:\/\/blog.hosebei.ch\/wp-content\/uploads\/2016\/12\/azureaddomainservices04.png?w=300\" alt=\"AAD DS GPMC\" width=\"300\" height=\"129\" class=\"aligncenter size-medium wp-image-2430\" srcset=\"https:\/\/blog.hosebei.ch\/wp-content\/uploads\/2016\/12\/azureaddomainservices04.png 987w, https:\/\/blog.hosebei.ch\/wp-content\/uploads\/2016\/12\/azureaddomainservices04-300x129.png 300w, https:\/\/blog.hosebei.ch\/wp-content\/uploads\/2016\/12\/azureaddomainservices04-768x330.png 768w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a><br \/>\nYou can&#8217;t create any own GPOs, and you are not Domain Admin:<br \/>\n<a href=\"http:\/\/blog.hosebei.ch\/wp-content\/uploads\/2016\/12\/azureaddomainservices05.png\"><img loading=\"lazy\" decoding=\"async\" src=\"http:\/\/blog.hosebei.ch\/wp-content\/uploads\/2016\/12\/azureaddomainservices05.png?w=300\" alt=\"AAD DS GPOs\" width=\"300\" height=\"256\" class=\"aligncenter size-medium wp-image-2436\" srcset=\"https:\/\/blog.hosebei.ch\/wp-content\/uploads\/2016\/12\/azureaddomainservices05.png 777w, https:\/\/blog.hosebei.ch\/wp-content\/uploads\/2016\/12\/azureaddomainservices05-300x256.png 300w, https:\/\/blog.hosebei.ch\/wp-content\/uploads\/2016\/12\/azureaddomainservices05-768x656.png 768w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a><br \/>\nThis is very solid and usable in certain circumstances where a Domain Controller is required to serve within Azure Infrastructure as a Service.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Since Microsoft has Released Azure AD Domain Services, many questions are coming up, and the top one of them might be: Can I join my Windows 10 Client through the internet to my Domain and receive Group Policies? No, you can&#8217;t. But besides this, there are other questions that remains to be answered, and I [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2,7,43],"tags":[],"class_list":["post-2424","post","type-post","status-publish","format-standard","hentry","category-active-directory","category-azure-ad","category-windows-10"],"_links":{"self":[{"href":"https:\/\/blog.hosebei.ch\/index.php?rest_route=\/wp\/v2\/posts\/2424","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blog.hosebei.ch\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.hosebei.ch\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.hosebei.ch\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.hosebei.ch\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2424"}],"version-history":[{"count":0,"href":"https:\/\/blog.hosebei.ch\/index.php?rest_route=\/wp\/v2\/posts\/2424\/revisions"}],"wp:attachment":[{"href":"https:\/\/blog.hosebei.ch\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2424"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.hosebei.ch\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2424"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.hosebei.ch\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2424"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}