What are the 4 types of Microsoft Active Directory? (2024)

We do our best to keep our articles updated. Please note that Microsoft Active Directory has been renamed to Microsoft Entra ID.

At BEMO we’re masters of migrating Domain Controllers to Azure. During our discovery calls with the customers, it's obvious there's a lot of confusion about all the different options aroundActive Directory (AD) which is now known as Microsoft Entra ID. Below we'll explain their differences to help you decide what you need.

  • Active Directory (AD)
  • Azure Active Directory (AAD)
  • Hybrid Azure Active Directory (Hybrid AAD)
  • Azure Active Directory Domain Services (AADDS).

Active Directory (AD)

NOW MICROSOFT ENTRA ID

Microsoft Active Directory (most often referred to as a domain controller) is the de facto directory system used today in most organizations. Active Directory is excellent for managing the authentication and authorization functions for users and computers within an organization.

Its reliance upon member computers permanently joined to a domain and protocols such as LDAP for directory querying and Kerberos for directory authentication are no longer suitable for the modern Internet-centric, mobile style of work environment becoming the norm today.

Think of Active Directory as on-premise only, which means all of your authentication infrastructure is running on hardware in house.

Azure Active Directory (AAD)

Azure Active Directory (AAD) is a version of directory services “in the cloud” hosted on Microsoft Azure. AAD does have quite different capabilities and features compared to Windows Server Active Directory (AD). Its primary function at the moment is to manage users and the myriad of devices (Windows, Apple and Linux PC’s, tablets and smartphones, etc.) that users are employing in their work and social lives, particularly for remote users.

AAD is blurring the distinction between “on-premise" and “remote” users. AAD is the authentication and authorization mechanism for not only Azure, Office 365 and Intune, but is capable of tying in many other third-party authentication systems.

Think of Azure Active Directory as cloud only, which means if you have legacy software you will need to go with Hybrid Azure AD (HAAD).

Hybrid Azure AD (Hybrid AAD)

Hybrid Azure AD is used when you have your local Active Directory (domain controller) on-premise and want to synchronize your data to Azure Active Directory. Instead of having two sets of credentials in two different places, you can add it in the ‘onsite’ domain controller, and it will replicate to Azure AD with the help of a Microsoft software add-on called Azure AD Connect.

Hybrid Azure AD is the first step in achieving one single identity. Today, most of our clients have one set of credentials to log on to their laptop and one set of credentials to log on to their email hosted on Office 365. With Hybrid Azure AD, you can set up the synchronization to Office 365 and manage the users on-premise, using your existing local Domain Controller.

You have two options:

Option #1: You keep your ‘on-premise’ domain controller within your physical location, and install AD Connect to synchronize your users, and their passwords, with Azure AD.

Option #2: Move your existing ‘on-premise’ domain controller into a virtual machine hosted on Azure, install AD Connect to synchronize with Azure AD, and create a VPN connection between your office and the Azure datacenter where your domain controller is now hosted.

What are the 4 types of Microsoft Active Directory? (1)

Azure Active Directory Domain Services (AAD DS)

Azure Active Directory Domain Services (AAD DS) is a standalone service in Azure that enables a domain controller for virtual machines in Azure, without setting up a standalone server as a domain controller. It creates a domain controller as a service, so you don’t need to worry about downtime, patching or other things.

What it does is that it syncs users, groups, and passwords from Azure AD to makes it available for the virtual computers in an Azure network.

You can use the Active Directory Administrative Center or Active Directory PowerShell to administer managed domains. With AADDS,

  • You will not need any virtual machine to host your Active Directory
  • You can use the same groups and users as in your Azure tenant for your virtual machines.
  • Passwords from your Azure tenant are replicated to your domain.
  • Your Azure AD Domain Services managed domain is deployed in the same Azure region as the virtual network you choose to enable the service.
  • AADDS is a continually billable service (you cannot turn it off).

AADDS is not Active Directory as you know it. AADDS:

  • Does not support replication.
  • Cannot set up as a trusted domain to other domains
  • No Domain/Enterprise admin privilege
  • Schema extensions are not supported
  • AD domain/forest trusts not supported
  • LDAP write not supported.
  • Certificate/Smartcard based authentication is not supported by Azure AD Domain Services.
  • Does not support managed service accounts

AAD DS is great for virtual machines hosted in Azure, simple to set up and works well with your Azure AD. AAD DS does NOT replace a proper domain controller and does not work with managing users and computers like with Windows Server Active Directory. AAD DS works great if you plan on a cloud-only strategy with limited users, and not GPOs.

What are the 4 types of Microsoft Active Directory? (2)Diagram from Microsoft's article on how to deploy AD DS in Azure virtual network. Click here to visit it.

To date, we mostly implement Hybrid Azure Active Directory by moving our clients’ existing on-premise domain controller into a virtual machine hosted on Azure, using an availability set for fail-over and redundancy capability, install AD Connect to synchronize with Azure AD and create a VPN connection between their office and the Azure datacenter. With this option, you can leverage the power of Azure while making sure your legacy application will still run.

Questions? Schedule a free meeting with us by clicking the button below:

What are the 4 types of Microsoft Active Directory? (3)

What are the 4 types of Microsoft Active Directory? (2024)
Top Articles
XRP’s Roadmap To Success: Analyst Forecast A Strong Bullish Turn In 2024
Learn More About Forex and Stocks Trading - HowToTrade.com
Diario Las Americas Rentas Hialeah
Jackerman Mothers Warmth Part 3
Lifewitceee
Arrests reported by Yuba County Sheriff
Emmalangevin Fanhouse Leak
Here's how eating according to your blood type could help you keep healthy
Waive Upgrade Fee
Zachary Zulock Linkedin
Myql Loan Login
6th gen chevy camaro forumCamaro ZL1 Z28 SS LT Camaro forums, news, blog, reviews, wallpapers, pricing – Camaro5.com
Wisconsin Women's Volleyball Team Leaked Pictures
Studentvue Columbia Heights
Nail Salon Goodman Plaza
Ruben van Bommel: diepgang en doelgerichtheid als wapens, maar (nog) te weinig rendement
Metro Pcs.near Me
MLB power rankings: Red-hot Chicago Cubs power into September, NL wild-card race
Noaa Duluth Mn
Best Nail Salons Open Near Me
Marion City Wide Garage Sale 2023
11 Ways to Sell a Car on Craigslist - wikiHow
Bòlèt Florida Midi 30
Getmnapp
eugene bicycles - craigslist
12657 Uline Way Kenosha Wi
Wbap Iheart
Skepticalpickle Leak
Does Royal Honey Work For Erectile Dysfunction - SCOBES-AR
Ixl Lausd Northwest
Mckinley rugzak - Mode accessoires kopen? Ruime keuze
Tirage Rapid Georgia
Trap Candy Strain Leafly
St Anthony Hospital Crown Point Visiting Hours
Lake Kingdom Moon 31
The Realreal Temporary Closure
Unitedhealthcare Community Plan Eye Doctors
Arnesons Webcam
Advance Auto.parts Near Me
Television Archive News Search Service
Cch Staffnet
Wolf Of Wallstreet 123 Movies
Wisconsin Volleyball titt*es
Haunted Mansion Showtimes Near Millstone 14
Www.homedepot .Com
El Patron Menu Bardstown Ky
Brutus Bites Back Answer Key
Morbid Ash And Annie Drew
Where To Find Mega Ring In Pokemon Radical Red
How To Find Reliable Health Information Online
Philasd Zimbra
Latest Posts
Article information

Author: Jonah Leffler

Last Updated:

Views: 5994

Rating: 4.4 / 5 (45 voted)

Reviews: 84% of readers found this page helpful

Author information

Name: Jonah Leffler

Birthday: 1997-10-27

Address: 8987 Kieth Ports, Luettgenland, CT 54657-9808

Phone: +2611128251586

Job: Mining Supervisor

Hobby: Worldbuilding, Electronics, Amateur radio, Skiing, Cycling, Jogging, Taxidermy

Introduction: My name is Jonah Leffler, I am a determined, faithful, outstanding, inexpensive, cheerful, determined, smiling person who loves writing and wants to share my knowledge and understanding with you.