Azure AD connect download

Azure AD connect download

In this Azure tutorial, we will discuss Azure AD connect download. Apart from this, we will also discuss below topics

  • Azure Active Directory Connect Download
  • Where to get Azure AD Connect
  • Azure ad connect requirements
  • AAD connect upgrade
  • Check Azure AD Connect version
  • Azure AD Connect Download Previous Version

Azure AD connect download

Azure AD Connect is one of the  Microsoft tools that helps with multiple features like Password hash synchronization – This is a sign-in method that synchronizes a hash of the on-premises Active Directory password of the user with Azure AD.

Where to get Azure AD Connect

Now, the question is where you can download Azure Ad Connect. To download this, you need to open the below link

https://www.microsoft.com/en-us/download/details.aspx?id=47594

Once you open the above link, you need to click on the Download button

Azure Active Directory Connect Download

Once you click on the Download button, AzureADConnect.msi file gets downloaded.

How to download Azure ad connect

Note: One important thing to note here is that AzureADConnect installation only supports the below-operating systems

Windows Server 2012, Windows Server 2012 R2, Windows Server 2016, Windows Server 2019

If you try installing it in any other operating system, you will get a warning “AADConnect is only supported on Windows Server operating systems”.

download azure ad connect

You can also download the Azure Active Directory Connect from the Azure Portal using the below steps

  1. Login to Azure Portal (https://portal.azure.com/).
  2. Click on the Azure Active Directory link from the left of the Azure Portal Menu.
Azure Active Directory Connect Download

Or, for the same option, you can search for the Azure Active Directory and click on the search result Azure Active Directory as shown below.

azure ad connect download server 2012 r2

3. On the Azure Active Directory pane, click on the Azure AD Connect option as highlighted below from the right side.

Where to download Azure AD Connect

4. Click the Download Azure AD Connect link under the Provision from Active Directory section as highlighted below.

azure ad connect step by step

This is how you can download the Azure Active Directory using Azure Portal.

How to install and configure Azure AD Connect

As we have discussed, you can download the .msi file from the Microsoft link or the Azure Portal using the above steps. Once you will download the .msi file using the above steps. Follow the below instructions to learn how to install Azure Ad Connect.

Install Azure AD Connect

  1. The first step is to double-click on the AzureADConnect.msi file to launch it that you have downloaded in the above step.
  2. Now, you can see the Microsoft Azure Active Directory Connect wizard welcome screen. Click on the Continue button to navigate to the next screen.
  3. Now you will see two buttons that are customized and Use express settings. Click on the Use Express settings button.
  4. The Connect to Azure AD screen will ask you to enter your Azure AD global administrator credentials. Enter your credentials and click the Next button to navigate to the next screen. An important point to remember is that this account is only needed to configure the AAD connect.
  5. Enter your Active Directory Domain Services enterprise administrator credentials on the Connect to AD DS screen and click Next.
  6. You might see the Azure AD Sign-in configuration page. Review if you can see any domains not listed as verified, and you need to verify it in the Azure AD before moving to the next step.
  7. After verifying your domain, click on the Refresh icon. You should see the status as verified by now.
  8. Otherwise, for the same stuff, you can tick the check box for Continue without matching all UPN suffixes to verified domains. This will allow you to continue the Azure AD Connect wizard.
  9. Click on the Next button as the next step.
  10. After verifying the domain in the last step, check the box for starting the synchronization process when the configuration completes. Otherwise, you can uncheck the check box and click the Install button. One important point is that if you uncheck the box, sync will be configured, but the problem is that it won’t run until you re-run the AAD Connect wizard. It won’t run.
  11. Now, the installation will start. If there are any errors, it will be listed on the Configuration Complete page. You can click on the Exit button to complete the setup.

This is How to install and configure Azure AD Connect by following the above steps.

Azure ad connect requirements

Before installing Azure Ad Connect, consider the below points as prerequisites.

Azure AD

You should have an Azure AD tenant. You can get one by creating a free Azure account. If you don’t have an account yet, follow my article How to Create Azure Free Account (Step by Step tutorial) to create an Azure free account.

Active Directory

You can use the Microsoft 365 IdFix tool to identify errors such as duplicates and formatting problems in your directory before synchronizing to Azure Active Directory and Office 365.

The Active Directory schema version must be Windows Server 2003 or later version, and The domain controller used by Azure Active Directory must be writable.

It is recommended to enable the Azure Active Directory recycle bin before proceeding further. This will help you to keep the accidentally deleted Azure AD user object in a soft-deleted state for 30 days. You can restore it based on your needs.

It is not recommended if you want to install Azure AD Connect on a Domain Controller due to security practices that can create problems during Azure AD Connect installation.

Operating system Requirements

Azure AD Connect must be installed on Windows Server 2012 or later version (Windows Server 2012, Windows Server 2012 R2, Windows Server 2016, Windows Server 2019), or else you will get a warning message, and it will not allow you to do the installation. 

If you want to deploy Active Directory Federation Services, then in that case, you need TLS/SSL Certificates, and you need to configure name resolution.

It is recommended to harden your Azure AD Connect server. This will reduce the security attack.

If you want to integrate an Azure AD Global Administrator account for the Azure AD tenant. This account must be a school or organization account.

PowerShell and .NET Framework

You need to install Microsoft PowerShell and .NET Framework 4.5.1 version or a later version installed on your server, as  Azure AD Connect depends on those.

Enable TLS 1.2

Ensure that TLS 1.2 is enabled for Azure AD Connect, and do not forget to install .NET 4.5.1 hotfix.

Hardware requirements for Azure AD Connect

When the number of objects in the Active directory is less than 10,000, the CPU is 1.6 GHz, and the Memory required is 4 GB with a hard disk size of 70 GB.

If the number of objects in the Active directory is between 10,000 and 50,000, then the CPU is 1.6 GHz, and the Memory required is 4 GB with a hard disk size of 70 GB.

If the no of objects in the Active directory is between 150,000–100,000, then the CPU required is 1.6 GHz, Memory required is 16 GB with a hard disk size of 100 GB.

But, when the no of objects in the Active directory is between 100,000–300,000, then the CPU required is 1.6 GHz, and the Memory required is 32 GB with a hard disk size of 300 GB.

While the no of objects in the Active directory is between 300,000–600,000, the CPU required is 1.6 GHz, Memory required is 32 GB with a hard disk size of 450 GB.

If the no of the object in Active Directory is more than 600,000, then the CPU required is 1.6 GHz, and the Memory required is 32 GB with a hard disk size of 500 GB.

Azure ad connect upgrade

Here, we will discuss the methods to upgrade the current version of Azure ad connect to the latest version. It is always suggested to keep the updated version.

Update Azure AD connect

There are three ways to upgrade the Azure ad Connect version

  • Automatic upgrade
  • In-place upgrade
  • Swing Migration

Automatic upgrade

It is always a better option to enable the Automatic upgrade option, which will always upgrade to the current version automatically. It is enabled by default for express installations and DirSync upgrades.

The below PowerShell cmdlet can check the current status of the Automatic upgrade

PS C:\windows\system32> Get-ADSyncAutoUpgrade
download aad connect

It has four states i.e., Enabled (Automatic upgrade feature is already enabled), Suspended (The system is not eligible to enable Automatic upgrade), and Disabled (Automatic upgrade feature is disabled on the system).

With the help of the Set-ADSyncAutoUpgrade PowerShell command, you can change the status between Enabled and Disabled.

In-place upgrade

You can use this method when you have a single server to upgrade the installation on the same server. It works for moving from Azure AD Sync or Azure AD Connect.

It is a choice when you only have a server containing less than 100,000 objects.

This process ensures that the new configuration is applied to all existing objects and might take a few hours, depending on the number of objects.

So it is suggested to perform the in-place upgrade during a weekend.

It will check if there are no changes to the OOB configuration with the new Azure AD Connect release, and then it will start a normal import/sync. But if you have made any changes to the OOB sync rules in the out-of-box, these rules are set back to the default configuration after the upgrade.

Swing Migration

You can choose the swing migration when there are many objects in the system, or you have a complex deployment.

We can also use swing migration when you are planning to make substantial changes to your configuration, and we want to test them before we publish them to the cloud.

For this method, there is a need for two servers

  • Active serve
  • Staging server

Active production load will be there on the Active server, and the new release or configuration will be stored on the staging server. When it’s fully ready, this server is converted to the active and previous active server, where the old version or configuration installed is converted to the staging server and is upgraded.

Ensure that both your active server and staging server use the same version. If you use Azure AD Connect on both servers and planning, make only a configuration change. If you upgrade from Azure AD Sync, these servers have different versions.

This is how to update Azure ad connect whenever you require it.

Check Azure ad connect version

Multiple ways are available to check the version of the Azure Active Directory Connect.

Approach-1

  • From the start menu, search for the Control panel
  • Now click on the Programs link
  • Then click on the Uninstall a Program link
  • The complete path will be (Control Panel\Programs\Programs and Features). Here, you can search for Azure AD Connect and check for the version number in the last column.

Approach-2

Using the PowerShell cmdlet also, you can check the version number of your Azure Connect AD installed on your machine. Below is the Powershell cmdlet

(Get-ADSyncGlobalSettings).Parameters | select Name,Value
how to check version of azure ad connect
ad connect is only supported on windows server operating systems

Azure AD Connect Two-way Sync

The synchronization process of Azure AD Connect is one-way or unidirectional. The synchronization process is automatic, and there is no need to configure anything as part of the synchronization process.

Azure AD Connect Download Previous Version

You can check out the Azure AD connect previous versions now. You will get detailed information on the Azure AD Connect version.

FAQs

Is Azure AD connect free?

Yes, It helps you to sync up to 500,000 directory objects.

Where should I install Azure AD Connect?

You must install the Azure AD Connect on Windows Server 2008 or later versions.

How often does Azure AD connect sync?

Azure AD Connect performs a sync by default every 30 minutes.

Is Azure AD connect bidirectional?

The behavior of the Azure AD Connect is unidirectional as of now. That means the users can be synced from on-premises AD to Azure AD only but won’t work vice versa.

How do I reset my Azure AD Connect?

  • Navigate to Windows Service Control Manager –> Then Start –> Services.
  • Then, select Microsoft Azure AD Sync –> Click on the Restart button.

What are the best practices for using Azure ADConnect?

Below is the list of Azure Ad Connect best practices that need to be followed while using Azure Ad Connect.

  • You should always install and upgrade to the latest Azure AD Connect version. Please configure the auto-upgrade.
  • Ensure to encrypt the disks wherever possible.
  • Minimize the number of admin access or admin accounts with access to Azure AD Connect.
  • Make sure to update the latest security updates each month.
  • The account password must be changed to a complex password.

How do I get rid of Azure AD Connect?

If you don’t want Azure AD Connect, you can easily uninstall Azure AD Connect by following the below steps.

  1. Navigate to Control Panel.
  2. Click on Uninstall a Program.
  3. Select the Azure AD Connect application.
  4. Click on the Yes button to confirm the installation.
  5. Once the installation completes, click on the Exit button.

You may like the following Azure tutorials:

Conclusion

In this tutorial, we learned the following things:

  • Azure Active Directory Connect Download
  • Where to get Azure AD Connect
  • Azure ad connect requirements
  • AAD connect upgrade
  • Check Azure AD Connect version
  • Azure AD Connect Download Previous Version

Hope you have enjoyed this article !!!