Multi-forest integration

Larger organizations or distributed organizations have environments with multiple on-premises ADs. They're typically used in account/resource forests or provided through mergers and acquisitions. These rules need to be followed:

  • Users have only one enabled account across all on-premises Active Directory Forests
  • UserPrincipalName and Source anchor will be provided from the forest
  • Users have only one mailbox
  • Users that have a linked mailbox also have an account in a different forest
  • There's no need to use Azure AD Connect on a domain-joined server

The following diagram shows the account/resource forest scenario:

Get Mastering Identity and Access Management with Microsoft Azure - Second Edition now with O’Reilly online learning.

O’Reilly members experience live online training, plus books, videos, and digital content from 200+ publishers.