QuestionQ45

Deploy and manage AD DS

Your network includes an on-premises Active Directory Domain Services (AD DS) domain called contoso.com.

You have an Azure virtual network named VNet1 that connects to the on-premises network by using a Site-to-Site (S2S) VPN. VNet1 contains a domain-joined virtual machine named VM1, which hosts an application called App1.

App1 uses Kerberos authentication and modifies objects in AD DS. An Azure Firewall filters traffic from VM1 to the contoso.com domain controllers.

You need to deploy domain controllers in VNet1. The solution must support VM1's requirements and provide domain-controller redundancy in Azure.

What should you deploy?

Explanation

Because App1 updates AD DS objects, it requires writable domain controllers; an RODC cannot accept changes to the AD DS database it stores. Deploying two writable domain-controller VMs in separate availability zones provides replicated, write-capable AD DS services and resilience against an Azure zone failure within the region hosting VNet1.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!