Active Directory Domain Services on Windows Azure Virtual Machines Samuel Devasahayam Active Directory Product Group Microsoft SIA205
Objectives Why are we even discussing Active Directory? IMPLICATION: “there’s something specific to its deployment in Azure” Vernacular … terminology specific to Windows Azure that will get us all on the same page Considerations for a cloud-deployment … optimal configuration knobs and deployment topologies
Objectives Why are we even discussing Active Directory? IMPLICATION: “there’s something specific to its deployment in Azure” Vernacular … terminology specific to Windows Azure that will get us all on the same page Considerations for a cloud-deployment … optimal configuration knobs and deployment topologies
Objectives Why are we even discussing Active Directory? IMPLICATION: “there’s something specific to its deployment in Azure” Vernacular … terminology specific to Windows Azure that will get us all on the same page Considerations for a cloud-deployment … optimal configuration knobs and deployment topologies
Deploy DC in Separate Cloud Service Cloud Service for AD Clients Location: North Central US Name: app-cloudservice.cloudapp.net Affinity Group: ADAG Deployment Virtual Network: MyVNET DNS Ips: Virtual Machine Role Name: advm1 Subnet: AppSubnet IP Address: Cloud Service for AD Domains Location: North Central US Name: ad-cloudservice.cloudapp.net Affinity Group: ADAG Deployment Virtual Network: ADVNET DNS Ips: (On-Premise AD IP) Virtual Machine Role Name: ad-dc Subnet: ADSubnet IP Address: DIP ADVNET
Site to Site VPN Tunnel AD Authentication + On-Premises Resources Contoso.com Active Directory Load Balancer Public IP
Site to Site VPN Tunnel AD Authentication + On-Premises Resources Contoso.com Active Directory AD Auth Load Balancer Public IP
Timeline of events TIME: T2TIME: T3TIME: T4 Create Snapshot T1 Snapshot Applied! USN: 100 ID: A RID Pool: USN: 100 ID: A RID Pool: USN: 250 ID: A RID Pool: more users created = 200 DC2 receives updates: USNs >200 = 250 USN: 200 ID: A RID Pool: users added DC2 receives updates: USNs >100 DC1 DC2 TIME: T1 USN rollback NOT detected: only 50 users converge across the two DCs All others are either on one or the other DC 100 security principals (users in this example) with RIDs have conflicting SIDs
Asia US HQ Windows Azure CORP Windows Azure Virtual Networks
Questions? Thank you
DOWNLOAD Windows Server 2012 Release Candidate microsoft.com/windowsserver #TESIA205 DOWNLOAD Microsoft System Center 2012 Evaluation microsoft.com/systemcenter Hands-On Labs Talk to our Experts at the TLC
Connect. Share. Discuss. Learning Microsoft Certification & Training Resources TechNet Resources for IT Professionals Resources for Developers
Evaluations Submit your evals online