Active Directory in the Cloud
Many customers will use the Azure IaaS services, which are fundamentally virtual machines. The reasons for having a domain on premises (central authentication, policy, directory services) likely still apply to the operating systems deployed in Azure IaaS, which means often the AD services from on premises need to be extended to Azure.
As mentioned at the start of this chapter, two things are required for Active Directory to be leveraged by computers, users, and services:
- The ability to locate a domain controller or specific service, which for Active Directory means DNS name resolution for DNS servers hosting the domain DNS partitions
- The ability to communicate with the located domain controller using a variety of protocols, such as Lightweight Directory Access Protocol (LDAP), Kerberos, RPC, or Netlogon
A complete list of protocols is available here:
http://technet.microsoft.com/en-us/library/dd772723(v=ws.10).aspx
The key point is that communication is...