Common scenarios for virtual machines
In the following part of the chapter, you will learn a view common scenarios to start with Azure virtual machines.
Optimization of Azure related communication traffic
As you already learned in Chapter 3, Deploying and Synchronizing Azure Active Directory, replication traffic for your hybrid identities normally goes through the Internet. It's only encrypted by using SSL on port 443.
There is an option to optimize security for that traffic by placing the virtual machines in Azure. They will still communicate against the Azure public IP from Azure Active Directory but the traffic is handled on the internal switches and router from Microsoft and the traffic isn't leaving the Azure data center.
To get the Active Directory account from your on-premises, you build up a VPN tunnel or use ExpressRoute to build a secure connection. Afterwards you place an Active Directory domain controller in Azure and replicate from a bridgehead domain controller in your on-premises...