How To Setup Azure AD

How To Setup Azure AD

In this Azure tutorial, we will discuss How To set up Azure AD. Along with this, we will also discuss the below topics.

  • Configure Azure Active Directory to perform Single Sign-On
  • Setup Azure Active Directory Domain Services

How To Setup Azure AD

Well, before discussing about Azure AD setup, We should have a little idea of What is Azure Active Directory?

Follow the below steps to set up Azure Active Directory using the Azure Portal.

Step-1: Login to Azure Portal (https://portal.azure.com/)

Step-2: Once you logged in, click on the + Create a resource from the left navigation menu.

How To Setup Azure AD

Step-3: On the New page, search for the Azure Active Directory and click on the search result.

azure active directory configuration step by step

Step-4: Click on the Create button on the Azure Active Directory page.

how to set up azure active directory

Step-5: On the Create tenant page, enter the Organization name, Initial domain name, and the Country or Region, and then click on the Create Button.

azure active directory setup

Navigate to the Azure Active Directory you have created, from the left navigation, select App registrations

setup azure active directory free

Provide the name of the application and choose the other options like below and then click on the Register button.

setup azure active directory

If you want to see all the registered applications under that Azure Active Directory then click on the App registrations and then click on the All application options.

setup azure AD

You can click on the registered application and then can set the Redirect URLs and Application ID URL by clicking on the Add a Redirect URL and Add an Application ID URL links respectively.

How do i setup azure AD

Now you can click on the Endpoints to see all the endpoints including the Microsoft GraphAPI. You can copy these endpoints if you need to use those externally.

How do I create Azure Active Directory

Click on the API permission from the left side menu then click on the + Add permission then You can click on the Microsoft Graph from the list of APIs.

how to setup azure active directory

Now from the Request API permissions, you can choose the Delegated permissions and then select the needed permission under the Permission section based on your business needs and click on the Add permissions button.

You can also choose the Application permissions based on your business needs.

how to configure azure AD

In the same way, you can choose the other API like Azure DevOps, Azure Key Vault, Azure Rights Management Services, Azure Service Management, Azure Storage, etc based on your business need.

Configure Azure Active Directory to perform Single Sign-On

Navigate to the Azure Active Directory, click on the App registrations and then you can click New application registration to add a new application

Configure Azure Active Directory to perform Single Sign-On

On the Register, an application page, Provide a name, Choose an option for Who can use these applications, or access this API? and then choose the Redirect URI as a Public client/native (mobile/desktop) option and provide the required URI then click on the Register button.

How To configure Azure Active Directory

Click on the API permissions and then + Add a permission —> Select an API based on your requirement.

Steps to set up Azure AD

Setup Azure Active Directory Domain Services

Azure Active Directory Domain Services provides domain join, group policy, etc that are compatible with Windows Server Active Directory. It is one of the managed domain services from Microsoft in the Cloud.

Before going to start with the setup of the Azure Active Directory Domain Services, We need a few things as Prerequisites.

  • The first thing is, you should have a valid Azure Account/Subscription. If you don’t have then create an Azure free account now.
  • The next thing you need is, An Azure Active Directory tenant that belongs to your Azure Subscription
  • You must have global administrator privileges in your Azure Active Directory tenant.

So now, let’s start the Setup of Azure Active Directory Domain Services

The first step is to log in to the Microsoft Azure portal (https://portal.azure.com/)

How to create a managed domain

Follow the below steps to enable the Azure AD Domain Services wizard

Once you logged in to the Azure Portal, click on the + Create a resource from the left navigation menu.

Setup Azure Active Directory Domain Services

On the New page, Search for Domain Services and click on the search result Azure AD Domain Services.

How to Setup Azure Active Directory Domain Services

On the Azure AD Domain Services window, click on the Create button.

Settings up azure active directory domain services

On the Create Azure AD Domain Services, Select the Subscription, Choose an existing Resource group or you can also create a new resource group by clicking the Create new link to create a new resource group.

Provide a DNS Domain name. While Providing a DNS domain name, you can choose either the default domain name which will be auto-populated or you can also choose a custom domain name if you want. This is the most common approach to choosing a custom domain.

Note: A recommendation here is, always to use a separate domain name that is different than any existing Azure or on-premises DNS name. For example, if your existing DNS name is xyz.com then don’t use the same one. you may use AADxyz.com.

There are also a few restrictions while choosing your domain mane. These are as below

  • The prefix for your domain name should contain within 15 characters.
  • The domain name shouldn’t already exist in the virtual network.

Now the next thing is to choose the location in which the domain should be created.

The work of the SKU is to determine the backup frequency, performance, and the maximum number of forest trusts you can create. Choose the SKU as Standard. You can also choose other options based on your business needs.

The next option to choose is the forest type. Basically, this is a logical construct that is used by the Active Directory Domain Services to group more than one domain. The user option is the default option for the Forest Type. You can use the default option in this case.

how to configure azure active directory domain services

For all other tabs, you can keep the default option as it is. Now the next option is to click on the Review + Create button.

Create Azure AD Domain Services

Now the final step is to click on the Create button to create Azure Active Directory Domain Services.

FAQs

How do I manually sync my Azure AD?

We can manually sync the Azure Active Directory using the PowerShell cmdlet. Follow the below steps to sync your Azure AD.

Step-1: Open the Windows PowerShell or PowerShell ISE in administrator mode.

azure ad setup

Step-2: Run the below cmdlet, to import the ADSync module

Import-Module ADSync
azure ad sync powershell commands

Step-3: You can use the below PowerShell cmdlet

PS C:\WINDOWS\system32> Start-ADSyncSyncCycle -PolicyType Delta
azure ad connect sync

Or, you can also use the below PowerShell cmdlet to force AD sync

PS C:\WINDOWS\system32> Start-ADSyncSyncCycle -PolicyType Initial
how do i manually sync my azure ad connect

Does Azure replace Active Directory?

The answer to this question is no. Azure Active Directory is not meant to be exactly the same as Active Directory.

The Azure Active Directory is not a replacement of Active Directory. Azure Active Directory has a different set of activities compared to the Active Directory. Azure Active Directory has more features compared to AD.

Azure Active Directory is designed to support different types of Web-based services but the Active Directory is not designed to support the same.

What are the Differences Between Windows Active Directory and Azure AD

As discussed above, Windows Active Directory and Azure AD are not designed for the same. So there are many differences between them. Let’s discuss a few key differences between them.

Windows Active DirectoryAzure Active Directory
Windows Active Directory is mainly designed to provide the opportunity to get control over their on-premises devices and different applications by organizing users and computers, etc. It helps users with authorization and authentication functionality.It also is popularly known as Azure AD, which is the single and universal cloud-based identity and access management platform.
Active Directory doesn’t support different types of Web-based servicesAzure Active Directory is designed to support different types of Web-based services
Security is the Key for the on-premises environment.Security is the Key for the cloud environment

These are few differences between Windows Active Directory and Azure AD.

Is LDAP Active Directory?

No, LDAP is not the Active directory. LDAP is Lightweight Directory Access Protocol is protocol that helps to communicate to the Active directory.

In other words, LDAP helps you to provide the communication language that helps the applications to communicate with the different other directory services servers.

LDAP (Lightweight Directory Access Protocol) is the open-access protocol that different directory services like Active Directory, Red Hat Directory Service, Apache Directory Server, etc can understand.

When should an organization consider using Microsoft Azure active directory?

First of all, an organization considers using Microsoft Azure Active Directory if the organization already has Microsoft Office 365 services.

Azure AD is the identity platform to manage your internal and external users securely. Organizations use Azure AD to store user information like Name, ID, Email, Address, etc.

It really helps the Organizations interns of Security. Authentication and authorization functionalities.

You may also like following the below tutorials

Conclusion

Well, in this tutorial, we discussed How To Setup Azure AD, Steps to set up Azure Active Directory, Configure Azure Active Directory to perform Single Sign-On, Setup Azure Active Directory Domain Services and along with this, we also discussed a few FAQs.