Planning and preparing Azure AD Connect is important. I created a YouTube video on this topic. In this article I link to the most important sources and documentation articles. I also created a decision tree for finding the right Azure AD Connect architecture.
Azure AD Connect Decision Tree
Free download (.pdf, .png, .drawio)
Further Reading
- Supported and unsupported Azure AD Connect topologies: Topologies for Azure AD Connect (docs.microsoft.com)
- Hardware requirements for the Azure AD Connect server: Prerequisites for Azure AD Connect - Hardware requirements for Azure AD Connect (docs.microsoft.com)
- Azure AD Connect cloud provisioning / features and limitations: What is Azure AD Connect cloud provisioning? (docs.microsoft.com)
- Network ports for Azure AD Connect: Hybrid Identity Required Ports and Protocols (docs.microsoft.com)
- Office 365 IP addresses and URLs for precise firewall rules: Office 365 URLs and IP address ranges (docs.microsoft.com)
- Microsoft IdFix for checking AD objects: IdFix : Directory Synchronization Error Remediation Tool (github.com)
- Guide to Microsoft IdFix / common errors IdFix finds and how to fix them: Prepare directory attributes for synchronization with Office 365 by using the IdFix tool (docs.microsoft.com)
- PowerShell code snippet to set the UPN for all users: Prepare a non-routable domain for directory synchronization - You can also use Windows PowerShell to change the UPN suffix for all users (docs.microsoft.com)
- Create a Group Policy for Seamless Single Sign-On: Azure Active Directory Seamless Single Sign-On: Quickstart - Roll out the feature (docs.microsoft.com)
