可能的解决方案可用于部分复制AD而不是在Azure上具有完全可写DC [英] Possible solutions available to have partial replica of AD instead of having full writable DC on Azure
问题描述
我们正在扩展我们的基础架构上的云,并就以下几点有关AD扩展的请求提出建议。
1.   用于对服务器进行身份验证/授权的云扩展到云的最佳做法,应用程序SSO。
2.   可用的解决方案可用于部分复制AD而不是在Azure云上具有完全可写DC。
PKS007,
这是您应该关注的文章。 。 (但如果这些限制都不适合您,那么您可以继续执行仅限云目录。)
希望这会有所帮助!
We are extending our infra on Azure cloud and requesting your recommendations on the following points about AD extension.
1. Best practices for AD extension to cloud for authentication/authorization to infra servers, Applications SSO.
2. Possible solutions available to have partial replica of AD instead of having full writable DC on Azure cloud.
Hi PKS007,
This is the article that you should be looking at. https://docs.microsoft.com/en-us/azure/security/azure-ad-choose-authn
You may find this decision tree particularly helpful:
You will most likely want a hybrid solution in your scenario. While you can technically have a cloud-only infrastructure with Azure AD, the product is not really intended as a replacement for your on-premises environment because there are certain limitations that it has. (But if none of those limitations are relevant for you then you can go ahead and do a cloud-only directory.)
Hope this helps!
这篇关于可能的解决方案可用于部分复制AD而不是在Azure上具有完全可写DC的文章就介绍到这了,希望我们推荐的答案对大家有所帮助,也希望大家多多支持IT屋!