Presentation is loading. Please wait.

Presentation is loading. Please wait.

Active Directory Domain Services on Windows Azure Virtual Machines Samuel Devasahayam Active Directory Product Group Microsoft SIA205.

Similar presentations


Presentation on theme: "Active Directory Domain Services on Windows Azure Virtual Machines Samuel Devasahayam Active Directory Product Group Microsoft SIA205."— Presentation transcript:

1 Active Directory Domain Services on Windows Azure Virtual Machines Samuel Devasahayam Active Directory Product Group Microsoft SIA205

2

3

4

5 Objectives Why are we even discussing Active Directory? IMPLICATION: “there’s something specific to its deployment in Azure” Vernacular … terminology specific to Windows Azure that will get us all on the same page Considerations for a cloud-deployment … optimal configuration knobs and deployment topologies

6

7 Objectives Why are we even discussing Active Directory? IMPLICATION: “there’s something specific to its deployment in Azure” Vernacular … terminology specific to Windows Azure that will get us all on the same page Considerations for a cloud-deployment … optimal configuration knobs and deployment topologies

8

9

10

11

12 Objectives Why are we even discussing Active Directory? IMPLICATION: “there’s something specific to its deployment in Azure” Vernacular … terminology specific to Windows Azure that will get us all on the same page Considerations for a cloud-deployment … optimal configuration knobs and deployment topologies

13

14 Deploy DC in Separate Cloud Service Cloud Service for AD Clients Location: North Central US Name: app-cloudservice.cloudapp.net Affinity Group: ADAG Deployment Virtual Network: MyVNET DNS Ips: 192.168.1.4 Virtual Machine Role Name: advm1 Subnet: AppSubnet IP Address: 192.168.2.4 Cloud Service for AD Domains Location: North Central US Name: ad-cloudservice.cloudapp.net Affinity Group: ADAG Deployment Virtual Network: ADVNET DNS Ips: (On-Premise AD IP) Virtual Machine Role Name: ad-dc Subnet: ADSubnet IP Address: 192.168.1.4 DIP ADVNET

15 Site to Site VPN Tunnel AD Authentication + On-Premises Resources Contoso.com Active Directory Load Balancer Public IP

16 Site to Site VPN Tunnel AD Authentication + On-Premises Resources Contoso.com Active Directory AD Auth Load Balancer Public IP

17

18

19 Timeline of events TIME: T2TIME: T3TIME: T4 Create Snapshot T1 Snapshot Applied! USN: 100 ID: A RID Pool: 500 - 1000 USN: 100 ID: A RID Pool: 500 - 1000 USN: 250 ID: A RID Pool: 650 - 1000 +150 more users created DC1(A) @USN = 200 DC2 receives updates: USNs >200 DC1(A) @USN = 250 USN: 200 ID: A RID Pool: 600- 1000 +100 users added DC2 receives updates: USNs >100 DC1 DC2 TIME: T1 USN rollback NOT detected: only 50 users converge across the two DCs All others are either on one or the other DC 100 security principals (users in this example) with RIDs 500-599 have conflicting SIDs

20

21

22

23

24

25

26

27

28

29

30 Asia US HQ Windows Azure CORP Windows Azure Virtual Networks

31

32

33 Questions? Thank you samueld@microsoft.com

34 DOWNLOAD Windows Server 2012 Release Candidate microsoft.com/windowsserver #TESIA205 DOWNLOAD Microsoft System Center 2012 Evaluation microsoft.com/systemcenter Hands-On Labs Talk to our Experts at the TLC

35 Connect. Share. Discuss. http://europe.msteched.com Learning Microsoft Certification & Training Resources www.microsoft.com/learning TechNet Resources for IT Professionals http://microsoft.com/technet Resources for Developers http://microsoft.com/msdn

36 Evaluations http://europe.msteched.com/sessions Submit your evals online

37

38


Download ppt "Active Directory Domain Services on Windows Azure Virtual Machines Samuel Devasahayam Active Directory Product Group Microsoft SIA205."

Similar presentations


Ads by Google