Updated: February 7, 2024 (June 15, 2015)
Charts & IllustrationsAD and AAD Integration
There are a variety of ways to integrate on-premises Active Directory (AD) deployments with Azure Active Directory (AAD). This chart shows three typical integration levels. Higher levels of integration reduce account management effort and simplify sign-on by users but have higher technical requirements to enable the integration. Each column in this chart shows a degree of integration between AD and AAD, ranging from no integration (“None”), to synchronization of objects and attributes between the two directories, to directory synchronization and federation.
None | Objects and Attributes Synchronized | Directories Synchronized and Federated | |
User identities, passwords, and requests to sign on | Multiple. | Multiple (identity must be authenticated by both AAD and AD). | One. |
Provision of directory objects occurs at | Azure or subscription service portal. | On-premises AD, or both if two-way synchronization is configured. | On-premises AD, |
Atlas Members have full access
Get access to this and thousands of other unbiased analyses, roadmaps, decision kits, infographics, reference guides, and more, all included with membership. Comprehensive access to the most in-depth and unbiased expertise for Microsoft enterprise decision-making is waiting.
Membership OptionsAlready have an account? Login Now