Deploy Entra Domain Service and Join a Server to the Domain

preview_player
Показать описание
Wow, I missed updating the slide deck from Azure AD to Entra ID! Too late to change it now.
In this video, we review deploying Microsoft Entra Domain Services (Entra DS) and configuring replication with Entra ID. The video starts by outlining the requirements and features of the Entra DS service, including password hash synchronization. Then we create a virtual network (VNet) for the service and deploy Entra DS. Once deployed, we join a server to the Entra DS managed domain and add the remote administration RSAT tools to manage the directory.

00:00 - Start
06:23 - Create the VNet
08:20 - Deploy Entra DS
13:31 - Update DNS Settings
16:20 - Reset User Password
18:34 - Add a Management Computer to the Domain
20:48 - Add RSAT Tools

Links
Free Azure guide! Subscribe to the newsletter

Zero to Hero with Azure Virtual Desktop

Hybrid Identity with Windows AD and Azure AD

Windows 365 Enterprise and Intune Management

Entra ID, Windows AD and Entra DS video
Рекомендации по теме
Комментарии
Автор

Hi, thanks for the Video Tutorial. I however have a problem. I noticed that the AD DS and AD LDS tools after I installed them... I get Access Denied when I try to make basic changes to users in the Active Directory Users and Computers container. I am very certain the User I am logged into is part of the AAD DC Administrators group. Any assistance or pointers will be appreciated.

DenisGWahome
Автор

Thanks for another great video! Entra DS is all about taking those last few apps that depend on Kerberos for authentication and getting them out of the data center. It would be nice to see the next step of setting up app proxy and Kerberos constrained delegation. It would be interesting in a cloud native, passwordless world to see what's possible. Do we still need to reset passwords?

GregThomson
Автор

I have a Server 2022 VM that i Entra-ID joined, but under domain is still say workgroup?
how can i change it to say "Entra-ID Joined" or do i have to create a workgroup call that?

fbifido
Автор

Travis, I've found, if I deploy EIDDS to a spoke identity network, I have to add routing back to the hub firewall, or resources can't resolve dns. Resources can query dns on EIDDS, but EIDDS doesn't have a route back to the resources for resolution. Have you seen this?

joethompson
Автор

if we add the VM ip-address when creating the VM, or in the portal, then that IP address becomes a DHCP reserved address for that VM.
- is it possible to access that DHCP service using the RSAT tools?

fbifido
Автор

How does one manually add DNS entry???
How to add a TXT/A/AAA/CNAME record, or a SRV record when using Entra-DS?

fbifido
Автор

Will Azure also provide an "Entra Enterprise CA" like service ???
- with auto-enrollment & renewals for the VM & connected devices?

fbifido
Автор

list of reasons to use entra domain services:

1.

diabilliq