Coming soon - Get a detailed view of why an account is flagged as spam!
view details

This post has been de-listed

It is no longer included in search results and normal feeds (front page, hot posts, subreddit posts, etc). It remains visible only via the author's post history.

1
365 - single domain, multiple 365 tenants - has anyone does this? What about SSO?
Author Summary
Hakkensha is age 36
Post Body

We have a client that has a single on-prem AD domain with 2 companies in it used to be one company - now its one big and one small one. Users from both companies need to access the same file server. Only the CEO has mailboxes in both companies.

Each company has their own 365 tenant. They currently have Microsoft Standard licensing and we want to migrate them to Premium to provide Intune and MDE.

I aware that single AD to multiple AAD tenants is a supported configuration, but it has a lot of caveats and complexity. The main one is loosing Seamless SSO. If I understood correctly, that means that users will need to authenticated again if they want to access 365 resources from their hybrid-joined AAD PCs.

  1. Has anyone implemented single AD to multiple forests before and can share their experience?
  2. Is there a better solution then single AD to multiple AAD tenants sync here? Something like upgrading the main company's licensing and using the AD as a base tenant. Then downgrading changing the smaller companies' licensing to EOP1 Defender for Office. Now only the smaller companies' employees will loose SSO.

EDIT:

Will probably just tell them they need a new DC and file server for the smaller company. Then we can treat them as a separate company all together relative to Entra Connect sync and licensing.

Author
Account Strength
100%
Account Age
10 years
Verified Email
Yes
Verified Flair
No
Total Karma
11,760
Link Karma
4,890
Comment Karma
6,529
Profile updated: 2 minutes ago
Posts updated: 8 months ago

Subreddit

Post Details

Age
36
We try to extract some basic information from the post title. This is not always successful or accurate, please use your best judgement and compare these values to the post title and body for confirmation.
Posted
9 months ago