MicrosoftDocs / azure-docs

Open source documentation of Microsoft Azure
https://docs.microsoft.com/azure
Creative Commons Attribution 4.0 International
10.24k stars 21.41k forks source link

Pg needs more info how Azure AD Connect and Azure AD Password protection agents and proxies co-exist in an environment. #90583

Open gbms311 opened 2 years ago

gbms311 commented 2 years ago

This section is confusing, as the page is dedicated to "Azure AD Password Protection" , and is talking about "Azure AD Password Protection DC Agent" and "Azure AD Password Protection Proxy Service" , but then this section 'Microsoft Azure AD Connect Agent Updater prerequisites' states .... (categorically... ie does not start the sentence with IF)

"The Microsoft Azure AD Connect Agent Updater service is installed side by side with the Azure AD Password Protection Proxy service"

Nowhere in the article does it refer to how 'Azure AD Connect' password sync, (incl PHS) is related to, or works with Azure AD Password Protection, so this reference seems out of place and incomplete.

The article goes on to say ... Warning: Azure AD Password Protection proxy and Azure AD Application Proxy install different versions of the Microsoft Azure AD Connect Agent Updater service, which is why the instructions refer to Application Proxy content.

This page needs more information how these agents and proxies co-exist in an environment.

After reading this, I do not understand the separation needed between Azure AD Connect (password sync solution) and Azure AD Password Protection DC agent + Proxy service.

On separate servers ? Are both needed for Hybrid AD DS <-> Azure AD password sync ? (Where a company wants password protection both in Cloud and On-prem, by taking advantage of 'Azure AD Password Protection' )


Document Details

Do not edit this section. It is required for docs.microsoft.com ➟ GitHub issue linking.

shashishailaj commented 2 years ago

@gbms311 Thank you for your feedback . We will investigate and update the thread.