Azure AD Connect must be installed on a server in your on-premises environment. It's recommended that you use a server without a domain controller role but with access to a domain controller. A server with Azure AD Connect must have access to the internet as it will need the internet to sync information between on-premises AD and AAD. All traffic going over Azure AD Connect is encrypted and secure.
The installation wizard is very intuitive and explains every step of the process; you just need to follow the guidelines (and understand the local AD structure). A screenshot of the first screen in the installation process, explaining what the tool will do, is shown here:
The first choice you need to make is whether ...