[Samba] Azure AD Connect but domain functional level 2012_R2 not yet supported?

Dr. Hansjörg Maurer hansjoerg.maurer at itsd.de
Thu Jul 8 10:45:19 UTC 2021



Am 29.06.21 um 19:14 schrieb ralph strebbing via samba:
>> Thanks; it's clear to me that Azure AD Connect (the "old" tool) doesn't require
>> a DC, but can the new Azure AD Connect Cloud Sync tool be run on a Domain
>> Member also or does it require running on a DC too (or only if you want to do
>> two-way password sync)?
> I did have the new tool working, but couldn't get password-hash syncs
> to work or rather update after the initial sync. And this was
> following the Samba wiki without deviation.
I can confirm, that a password changed on the samba-ad was synched to 
azure (azure logs below)

We created the wiki page you mention and we retested it right now again.

AD Provisioning 
Directory","0d0e9d06-b33f-42d6-9885-51851a1c9d79","Azure Active 
AD Provisioning 
Directory","b922fd42-0800-414d-aead-3ab7b001523d","Azure Active 

The Azure AD Connect Cloud Syncs runs on a member server (no DC)
We did an

samba-tool domain functionalprep --function-level=2012_R2
and the User who performs the sync is member of the Enterprise Admins Group

If a password is changed in azure , the sync back does not work and the 
passwords differ.

If you change it again in samba-ad, it is synched again to azure

Best Regards


>> Did you set up the "old" tool on 3 different Domain Members as the docs
>> recommend for redundancy? If so, was the setup process easier on the subsequent
>> two ( all of the settings had already been configured on the first instance)?
> I did not, I'm just running this on one Windows Server 2019 VM in our cluster.
> Regards,
> Ralph

Dr. Hansjörg Maurer
itsystems Deutschland AG
Erzgießereistr. 22
80335 München
Tel:   +49-89-52 04 68-41
Fax:   +49-89-52 04 68-59
E-Mail: hansjoerg.maurer at itsd.de
Web:    http://www.itsd.de

Amtsgericht München HRB 132146
USt-IdNr. DE 812991301
Steuer-Nr. 143/100/81575

Stefan Adam
Dr. Michael Krocka
Dr. Hansjörg Maurer

More information about the samba mailing list