Choosing the best directory synchronization scenario for cloud identities
To integrate or extend the local Active Directory to the cloud, we need a rich set of capabilities to address all the different requirements of our customers. In the following figure, we see the three most common synchronization and two extension scenarios we can use.
Synchronization scenarios:
Directory and password synchronization
Federation and directory synchronization
Federation, directory, and password synchronization
Extension scenarios:
Stretching your local Active Directory to Azure IaaS
Using Azure Active Directory Domain Services to bring legacy authentication LOBs to the cloud
Synchronization scenarios
With the creation of a new Azure Active Directory tenant, directory information is managed independently from the On-Premises Active Directory forest by default. A new on-board user must be created in both the Azure Active Directory and the local Active Directory. Unless you drive a cloud-only company, you always...