what if I don't place #domain_controllers in #Azure ?

what if I don't place #domain_controllers in #Azure ?

when the client asks you, why it's mandatory to place my #domain_controllers in #Azure? 

you have to Ask this question "what if I don't place #domain_controllers in #Azure??

Consider if I'm hosting important services in #Azure that are integrated with my #Active_Directory. 

-If my ExpressRoute link goes down, if my site-to-site VPN goes down, those services can no longer contact Active Directory. 

-So what would happen? Some services may carry on working for a short duration and have a certain amount of cached information. Others will just stop functioning, and at that point, you have to make a decision. You have to try and get past this trust issue because that's all this really is. This is just a trust issue. There are a few cost elements.

- If I don't place domain controllers in Azure, then any authentication, any traffic will be going over my link so there will be a certain amount of egress. 

-I pay for egress. So data from Azure to my On-premises domain controllers, I will pay for that. If I put #domain_controllers in #Azure, I won't have that cost of traffic flowing to On-premises for normal authentication, etc.,

- but I will pay for replication traffic. So originating changes in #Azure will have to be sent to On-premises so they can replicate out. So there'll be different types of costs.

- How do I really make the decision? If the services in Azure were hosted in an on-premises location, would you place a domain controller there? If the answer is yes because of the criticality of the service, if the links went down, just for performance, then you should be placing a domain controller in Azure.

要查看或添加评论,请登录

Mo . ????的更多文章

  • Tips for azure Monitor

    Tips for azure Monitor

    In the ever-evolving landscape of cloud computing, efficient monitoring is the key to maintaining optimal performance…

    2 条评论
  • Monitoring in Azure

    Monitoring in Azure

    If your organization asked you to design a monitoring strategy to cover all of its teIf your organization asked you to…

  • Sustainability and IT

    Sustainability and IT

    Over the past several years, organizations have had to adjust quickly to unprecedented, unpredictable pressures…

  • EU-U.S. data agreement an important milestone for data protection, Microsoft is committed to doing our part

    EU-U.S. data agreement an important milestone for data protection, Microsoft is committed to doing our part

    The newly announced Trans-Atlantic Data Privacy Framework between the EU and U.S.

  • Scrum : the Basics - Part 1

    Scrum : the Basics - Part 1

    the Agile Method Allow teams to self -Organize they will do a much better job working on the design and tests from the…

  • Azure Infra

    Azure Infra

    1-Azure Monitor collects two types of data: metrics and logs. Metrics are numerical values that describe some aspect of…

  • tips on hardening security with Azure security

    tips on hardening security with Azure security

    1-Classifying data that should be encrypted is commonly based on the impact it can have on customers if it is exposed…

    1 条评论
  • Connecting a local FortiGate to an Azure VNet VPN

    Connecting a local FortiGate to an Azure VNet VPN

    This recipe provides a sample configuration of a site-to-site VPN connection from a local FortiGate to an Azure VNet…

  • What is Azure AD Identity Protection?

    What is Azure AD Identity Protection?

    Microsoft claims that 60% of all successful attacks rely on compromised credentials, so extra care needs to be taken to…

  • History of the deployment models (Azure)

    History of the deployment models (Azure)

    #Azure originally provided only the classic deployment model. In this model, each resource existed independently; there…

社区洞察

其他会员也浏览了