Cloud based Domain

Soldato
Joined
9 Nov 2008
Posts
7,122
Hello all,

Just wanted to see if anybody else has come across a situation I'm being asked to look into.

A very small company (currently 10-15 staff using a wide range of standalone devices) have asked me to setup a Domain for them (which I have no problem doing) but they've absolutely insisted it must be 100% 'in the Cloud'. They have a bit of IT experience within the company so this is driving it, if I can't 'Cloud' the solution they'll go elsewhere.

They want a hosted DC (with all the benefits of an on prem solution - so network shares etc...). This would likely be an Azure based VM running Server 2016.

To complicate things slightly these resources (mainly network shares, but eventually AD accounts and other bits and pieces) need to be shared with 7 other sites (different physical locations and LANs). Each site has it's own different on prem DC and domain with varying setups. The company has agreements with these sites to allow me whatever access I require so with my 'on prem' hat on I had considered setting up trusts between each site and the Azure based DC (over newly created VPN links).

I've already gone through the list of reasons why I don't feel they should put everything into the Cloud but they are dead set on it so with this in mind have any of you done similar? Do you have any advice or can see anything that jumps out as being difficult / impossible?

I've been using the below Microsoft link to base my plan on;

https://blogs.technet.microsoft.com...1-days-of-servers-in-the-cloud-part-20-of-31/

Edit: the company are based at one of the 7 sites so currently the server from that site (which I setup) is providing DNS and DHCP (and can continue to do so).

Any potential tie ins to Office365 would also be welcomed as they'll be eventually moving all sites over to this for email.
 
Can you not just move the lot of it over to Office 365 and AzureAD? That may remove a lot of the over complication if it meets their needs.

From my (limited) understanding of AzureAD it's not going to give me what is required. I need to be able to use group policy to manage the users and PCs. They want traditional Windows Server features as there won't be anyone from IT Support on site to help the users (who are very basic, office admin type people).

It's also going to have to link in with the existing 7 domains to allow users on those systems access to resources.

Finally for legal reasons the solution must be hosted within the UK (due to GDPR and the data they will be working on) and AzureAD cannot currently be run out of UK South or UK West. Although I guess Azure AD could be hosted in another DC providing all the data is hosted within the UK.
 
Back
Top Bottom