In my blog here(Setup Azure Active Directory (AD) Domain Services – AADDS – HayDrive), I documented the process of creating an Azure AD Domain service managed domain for my environment – in this blog, I will document the process of joining a management Virtual Machine to the domain and using the virtual machine to manage/administer my managed domain.
To access the management console for my AADDS domain we need to
- Connect a VM to the Domain
- Install Active Directory Management services to the VM
If the virtual machine is in Azure we need to ensure that it is in a VNET with connectivity to the AADDS’ VNET. I documented the process for connecting my VM’s VNET with the VNET linked to my AADDS Managed Domain here ( https://haydrive.com/azure-vnet-pairing/)
Joining a Virtual Machine to the Domain
- Navigate to system info on the Server/VM (Control Panel\System and Security\System)
data:image/s3,"s3://crabby-images/e80da/e80da6143886f852de9c2ce5beec16c52d895e0b" alt=""
- Click the change settings option
- In the Computer Name Tab click Change
data:image/s3,"s3://crabby-images/0b3e8/0b3e8f88647097d30799649748e7b9f1dd2478b7" alt=""
- Then select the Domain toggle ( instead of WorkGroup) and enter the URL for your Managed domain
- Enter an Admin credential for the Managed Domain ( this is anyone that’s a member of the security Group ” AAD DC Administrators” ) or with the Domain Services Contributor Permission in Azure
- Remember the Admin needs to be one of the users that have been synced to the AADDS – this can be done by resetting the user’s password.
data:image/s3,"s3://crabby-images/5ce93/5ce93cc9d4401be6afbd84909edd1b111198c5a9" alt=""
data:image/s3,"s3://crabby-images/14f49/14f498c19a2a2a2b95e4d4efa597dbb3b6bf4b49" alt=""
Install Active Directory Management services to the VM
To install Active Directory Management services to the management VM follow the instructions below:
- On the VM, Open Server Manager
data:image/s3,"s3://crabby-images/9748f/9748f9e25957029dfc76f752f9188927a2a31c9e" alt=""
- Select Add roles and features
- On the before you begin page, in the Add roles and features wizard, click next
data:image/s3,"s3://crabby-images/11ad8/11ad82ee622c9824ac3ac7e85609930c9be89899" alt=""
- Select Role-based or feature-based installation, then click next
data:image/s3,"s3://crabby-images/5b064/5b06460e7525e4b8c23949e6fad6a46dc3dc9e03" alt=""
- Select the server from the list of servers and click next
data:image/s3,"s3://crabby-images/e9d3b/e9d3b34633bd68b5364695ff83b5f0904dd7cfef" alt=""
- Click next on the Select Server roles page
- In the features, page expand the RemoteServer Admin Tools option, then expand the Role Admin tools, then select AD DS and LDS Tools
data:image/s3,"s3://crabby-images/b7d62/b7d62788178dfd5d4c16087f268056884e64f5cf" alt=""
- Click next, and install the selection
data:image/s3,"s3://crabby-images/e6fca/e6fca5bd8ded72fcbdf3598fd3b6c38650a04843" alt=""
Install will take a few minutes, once complete you should now be able to use the Management Server to Manage AADDS as normal – meaning you should be able to access Active Directory Users and Computers, Group Policy Management, etc.
data:image/s3,"s3://crabby-images/7e0b5/7e0b59be971ff959cd490ee0ecfc905e7cc1d111" alt=""
Screenshot of ADUC:
data:image/s3,"s3://crabby-images/41dc3/41dc3753f3308ec26d34e739a992af5bb9040ff6" alt=""