How to integrate Office 365 to your LDAP with Azure AD Connect

Couple weeks ago, Someone are discuss how to integrate the local LDAP to Office 365 in our wechat group. Well, it has been for a long while for us to deploy to tools to integrate the local LDAP to Office 365 and let me also spend sometime to explain how we setup the integration for last couple years.

First of all, I remember that at 13-14 school year when we start to using office 365. We use the tool call ADFS to integrate local LDAP to office 365.

This is not a good tool in my mind, because one you deploy ADFS, when you login to your tenant and it will jump to another page which host on your local server to finish to authentication produce. If the server which install ADFS has any hardware issue or the network is down for your server room. That means no one can login to your tenant anymore because the authentication page won’t show up. As I know, this is the only solution workable for O365 that moment, so we don’t have any option to choose.

Then start from 14-15 school year on, Microsoft have a new tool to do the integration business. The tools calld Microsoft DirSyn.

This is the real integrate tools in my mind. End user don’t need to jump to another page to login to owa and even there is any problems with your server, we still can access to the owa because Dirsync make a clone copy on Azure. But this service is retired in 2017.

At the end of 15-16 school year (Maybe, I really forget it now). We switch the integrate server to Azure AD Connect which is more security and stability compare with DirSyn. Well I am not sure how security and stability for Azure AD Connect work for. But my Boss will keep pushing me to using the latest solution. OK, Then Let me play with it and this the official way to integrate Office 365 to Local LDAP server until now.

So today let’s see how to deploy Azure AD connect service.

  1. Download Azure AD Connect installation package from the link below:

http://www.microsoft.com/en-us/download/details.aspx?id=47594

2.Install this package to one of your local server.

3.Check the box “I agree to the license terms and privacy notice” and click continue.

计算机生成了可选文字: Microsoft Azure Active Directory Connect Welcome Express Settlngs Welcome to Azure AD Connect Run this installation t001 on the server where the synchronization service component will be installed. Azure Active Directory Connect integrates your on-premises and online directories This installation to will: Guide you in select-ng 3 solution (for example, password synchronization or federation with AD FS 〕 Install identity synchronization and other Microsoft software components required for deployment Verify the Integration Of your on-premises and online 0 000s5 Learn n10 re 《 《 《 agree to the license terms and privacy notice. Conünue 4.Click “User express setting”

计算机生成了可选文字: 本 Microsoft Azure Active Directory Connect Express Settlngs Express Settings If you have 彐 single Windows Server Active 訓 00 forest we will do the following Configure synchronization Of identities in the current AD forest Of AISG Configure password synchronization from on-premises AD to Azure 0 Start 引 1 initial synchronization Synchronize attributes Enable Auto upgrade Learn mo re about express settings If you would like different settings, click Customize. CUStOmlZe Use express settlngs 5.Login with your Office 365 admin account and click “Next”.

6.Login with your local LDAP admin account and click Next.

7.Leave all the setting as default and click Next.

8.Don’t select anything first and we can do the configuration later. Click Install.

计算机生成了可选文字: 本 Microsoft Azure Active Directory Connect Welcome apress Settings Connect to Azure AD Connect to AD DS Azure AD Slgn-ln Configure Ready to configure Onceyou click 的 st 《 we “ do the following: 的 st 《 the synchronization engine Configure Azure AD Connector Configure alsg.edu/cn Connector Enable Password synchronization Enable Auto upgrade Configure synchronization servlces on this computer 囗 Start the synchronization process when configuration completes 囗 Exchange hybrid deploymen Synchronization will be disabled. Your Active Directory forest(s) will not be synchronized with Azure until synchronization is enabled. Learn m 0 re preVlOUS Install 9.Then you will finish the installation part.

10.Now let’s start to setup the Azure AD Connect, you should double click this icon from your desktop.

计算机生成了可选文字: № u 代 D Connect 11.Click “Configure”.

计算机生成了可选文字: Microsoft Azure Active Directory Connect Welcome Tasks Welcome to Azure AD Connect The synchronization service scheduler is suspended until this setup wizard is closed. Learn Configure EXIt 12.Choose “Customize synchronization options” and click next.

计算机生成了可选文字: 4 . Microsoft Azure Active Directory Connect Tasks Connect to Azure AD Staging Mode Configure Additional tasks The required tasks for the scenario ha been completed. Ch005 巳 from the list below to perform additional tasks. VIEW current configuration Customize 野 n [ h ℃ niz n options Refresh directory schema Configure staging mode (current state: disabled) Change user slgn-in preVlOUS Next 13.Login with your Office 365 admin account and click Next.

14.Click Next

15.Select the OU which you want to syn to O365. You should ask your LDAP administrator to double check it very carefully, if you forget to select some OU, some user may have problems. Normally, we will just select the OU contain all user and groups in your LDAP. After all, click Next.

16.Check the box “Password synchronization” and click Next.

计算机生成了可选文字: Microsoft Azure Active Directory Connect Welcome Tasks Connect to Azure AD Connect Dlrectones Domain/OCl Filtering Optlonal Features Configure Optional features Select enhanced functionality if required by your organization. 囗 Exchange hybrid deployment 囗 Exchange Mail Public Folders (Preview) 姬 u AD app 引 记 attribute filtering 囗 “ 0 忆 synchronization 囗 “ 0 忆 writeback 囗 Group writeback (Preview) Device writeback 囗 [ 囗 Directory extenslon attribute sync Learn more about optional features. PreVlOus Next 17.Check the box ”Start the synchronization process when configuration completes” and click configure.

计算机生成了可选文字: 本 Microsoft Azure Active Directory Connect Welcome Tasks Connect to Azure AD Connect Dlrectones Domain/OCl Filtering Optional Features Configure Ready to configure Once you click Configure, we will do the following: update aisgz.edu/cn 〔 onn 巳 亡 or Configure synchronization servlces on this computer 动 Start the synchronization process when configuration completes PreVlOus Configure 18.After the configuration complete, click Exit.

计算机生成了可选文字: Microsoft Azure Active Directory Connect Welcome Tasks Connect to Azure AD Connect Dlrectones Domain/OCl Filtering Optional Features Configure Configuration complete Azure AD Connect configuration succeeded. The synchronization process has been initiated. The configuration is complete. You ca n no 训 《 og in to the Azure or Office 365 po 引 to verify that user accounts from you oc 引 directory have 巧 n created Then do a test sign-on 0 the Azure l. Learn more EXIt 19.Go to office 365 owa page and click the Admin icon in the waffle then you can check your state for the AAD Connect