Close Menu
Peter Klapwijk – In The Cloud 24-7Peter Klapwijk – In The Cloud 24-7
    Facebook X (Twitter) Instagram
    Peter Klapwijk – In The Cloud 24-7Peter Klapwijk – In The Cloud 24-7
    • Home
    • Intune
    • Windows
      • Modern Workplace
    • macOS
    • Android
    • iOS
    • Automation
      • Logic Apps
      • Intune Monitoring
      • GitHub
    • Security
      • Passwordless
      • Security
    • Speaking
    • About me
    Peter Klapwijk – In The Cloud 24-7Peter Klapwijk – In The Cloud 24-7
    Home»Security»Azure Active Directory Domain Services
    Security

    Azure Active Directory Domain Services

    Peter KlapwijkBy Peter KlapwijkSeptember 26, 2016Updated:December 3, 20193 Mins Read

    Almost a year ago Microsoft announced Azure Active Directory Domain Services in preview (and it is still in preview). Before releasing this service you needed to deploy domain controllers in Azure or have a site-to-site VPN (from on-premises to Azure) contacting on-premises domain controllers to use services in the cloud relying on active directory and related servics. With the release of Azure AD Domain Services you now have a cloud-based identity solution which allows you to manage users and groups without deploying domain controllers.

    When you enable this service, two domain controllers are automatically setup in you environment for high-availability, but you don`t have to pay for these two domain controllers (VM`s), you pay for the service per hour (see this site for the pricing). As you can not login directly to these domain controllers, you don`t have to worry about managing these domain controllers like you have to do with on-premises domain controllers or domain controllers deployed by yourself in Azure, Microsoft does it for you. It is really Active Directory as a service.

    azure-ad-domain-services-aducWhen the two domain controllers are up-and-running you can manage Active Directory by joining a Windows Server Virtual Machine hosted on Azure to the domain you setup AD Domain Services for. Just add the required management features to the server and you are able to manage the environment via Active Directory Users and Computers or Group Policy Management. All your users and groups which are available in Azure AD/ Office 365, from now can also be found in ADUC.
    Note that managing the AD and policies are very basic at this moment. You are not a Domain Admin and you have limited rights on the AD. You are allowed to manage the existing Group Policies, but at this moment, you are not allowed to create your own GPO`s unfortunately.

    You are now able to deploy VM`s (Windows or Linux) running an application which rely on Active Directory to the cloud  without deploying domain controllers to the cloud. Access control can be done by Azure AD Domain Services. You don`t have to use different user accounts from another cloud provider which hosts your application, you just use the same user accounts already present in Azure/ Office 365. Another example is running an FTP server on IIS deployed on an Azure VM. Setup the required user rights on the FTP folder based on the AD groups/ users and your users only have to remember just one set of credentials.

    Some functionalities Azure AD Domain Services provides:

    • Join servers to a domain (Windows and Linux)
    • Use (basic) Group Policies
    • Create custom organizational units (OU`s)
    • Use Kerberos/ NTLM
    • Support for secure LDAP
    • Administer DNS on the managed domain

    For now Azure AD Domain Services is still in preview and some functionalities, like managing Group Policies, are very basic. But I expect the functionalities will be increased in the future.

    For further information and pricing you can visit this website of Microsoft.

    Azure AD Identity Management Security
    Share. Facebook Twitter LinkedIn Email WhatsApp
    Peter Klapwijk
    • Website
    • X (Twitter)
    • LinkedIn

    Peter is a Security (Intune) MVP since 2020 and is working as Modern Workplace Engineer at Wortell in The Netherlands. He has more than 15 years of experience in IT, with a strong focus on Microsoft technologies like Microsoft Intune, Windows, and (low-code) automation.

    Related Posts

    Azure AD shows all devices

    August 28, 2017

    Intune MAM Conditional Access update

    September 30, 2016

    Intune Mobile Application Management

    September 13, 2016
    Add A Comment
    Leave A Reply Cancel Reply

    Peter Klapwijk

    Hi! Welcome to my blog post.
    I hope you enjoy reading my articles.

    Hit the About Me button to get in contact with me or leave a comment.

    Awards
    Sponsor
    Latest Posts

    Hide the “Turn on an ad privacy feature” pop-up in Chrome with Microsoft Intune

    April 19, 2025

    How to set Google as default search provider with Microsoft Intune

    April 18, 2025

    Using Windows Autopilot device preparation with Windows 365 Frontline shared cloud PCs

    April 13, 2025

    Using Visual Studio with Microsoft Endpoint Privilege Management, some notes

    April 8, 2025
    follow me
    • Twitter 4.8K
    • LinkedIn 6.1K
    • YouTube
    Tags
    Administrative Templates Android Automation Autopilot Azure Azure AD Browser Conditional Access Edge EMS Exchange Online Feitian FIDO2 Flow Google Chrome Graph Graph API Identity Management Intune Intune Monitoring iOS KIOSK Logic Apps macOS MEM MEMMonitoring Microsoft 365 Microsoft Edge Microsoft Endpoint Manager Modern Workplace Office 365 OneDrive for Business Outlook Passwordless PowerApps Power Automate Security SharePoint Online Teams Windows Windows 10 Windows10 Windows 11 Windows Autopilot Windows Update
    Copy right

    This information is provided “AS IS” with no warranties, confers no rights and is not supported by the authors, or In The Cloud 24-7.

     

    Copyright © 2025 by In The Cloud 24-7/ Peter Klapwijk. All rights reserved, No part of the information on this web site may be reproduced or posted in any form or by any means without the prior written permission of the publisher.

    Shorthand; Don’t pass off my work as yours, it’s not nice.

    Recent Comments
    • Nathalie on How to update win32 applications with Microsoft Intune
    • Peter Klapwijk on Using Windows Autopilot device preparation with Windows 365 Frontline shared cloud PCs
    • John M on Using Windows Autopilot device preparation with Windows 365 Frontline shared cloud PCs
    • Christoffer Jakobsen on Connect to Azure file shares with Microsoft Entra Private Access
    • Ludo on How to block Bluetooth file transfer with Microsoft Intune
    most popular

    Application installation issues; Download pending

    October 1, 2024

    Restrict which users can logon into a Windows 10 device with Microsoft Intune

    April 11, 2020

    How to change the Windows 11 language with Intune

    November 11, 2022

    Update Microsoft Edge during Windows Autopilot enrollments

    July 9, 2024
    Peter Klapwijk – In The Cloud 24-7
    X (Twitter) LinkedIn YouTube RSS
    © 2025 ThemeSphere. Designed by ThemeSphere.

    Type above and press Enter to search. Press Esc to cancel.

    Manage Cookie Consent
    To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
    Functional Always active
    The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
    Preferences
    The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
    Statistics
    The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
    Marketing
    The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
    Manage options Manage services Manage {vendor_count} vendors Read more about these purposes
    View preferences
    {title} {title} {title}