All about Information Technology infrastructure and system. Helpdesk & support issue, deployment guide, and daily activity in managing an information technology operation.
Search This Blog
Saturday, April 10, 2021
ExpressRoute Direct VS FastPath VS Global Reach
ExpressRoute Private Peering VS Microsoft Peering in Azure
Availability Sets VS Availability Zones in Azure
Availability Sets
Availability Sets is for virtual machine only. When you configure virtual machine with availability sets, it will make a copy of your virtual machine in isolated separate physical server, compute rack, storage units and network switches within a single datacentre within an Azure Region.
Availability Zones
Availability Zones can be use by many Azure Services including virtual machine. With Availably Zones, your workload will be spread out across the different zones that make up an Azure region. An Azure region is made up of multiple datacentres and each zone is made up of one or more datacentres. Each datacentre is equipped with independent power, cooling and networking.
Availability Zone has better SLA compare to Availability Sets
Sunday, March 28, 2021
Azure AD Connect account usage
Azure AD Connect uses 3 accounts in order to synchronize information from on-premises or Windows Server Active Directory to Azure Active Directory. These accounts are:
AD DS Connector account: used to read/write information to Windows Server Active Directory
ADSync service account: used to run the synchronization service and access the SQL database
Azure AD Connector account: used to write information to Azure AD
In addition to these three accounts used to run Azure AD Connect, you will also need the following additional accounts to install Azure AD Connect. These are:
Local Administrator account: The administrator who is installing Azure AD Connect and who has local Administrator permissions on the machine.
AD DS Enterprise Administrator account: Optionally used to create the “AD DS Connector account” above.
Azure AD Global Administrator account: used to create the Azure AD Connector account and configure Azure AD.
SQL SA account (optional): used to create the ADSync database when using the full version of SQL Server. This SQL Server may be local or remote to the Azure AD Connect installation. This account may be the same account as the Enterprise Administrator. Provisioning the database can now be performed out of band by the SQL administrator and then installed by the Azure AD Connect administrator with database owner rights.
Cannot Start Azure ATP or Defender for Identity Services when using gMSA
Description:
Make sure you have Restarted the Domain Controllers that you put inside the new universal or domain local group. After the Domain Controller restart, try to login and notice that Azure ATP Sensor Services will be able to start properly. Delayed start is expected for Azure ATP services.