Azure Active Directory Connect Upgrade In-place or Swing Migration

In this article we are going to discuss different methods that you can use to upgrade your Azure Active Directory (Azure AD) Connect installation to the latest release.

I have been reading lot of queries and question mark over the type of upgrade process or approach should be taken by the Architects or an Engineer managing the AAD Connect software.

First of all, it is very important that the environment and specially the servers  are in line with the current and the latest releases of Azure AD Connect. Microsoft is constantly making upgrades to AADConnect, and these upgrades include fixes to security issues and bugs, as well as serviceability, performance, and scalability improvements.

As been on the field working for different clients the issues and confusion is whether to do in place upgrade or do a swing migration, Microsoft states with small environment and not many complex settings usually in-place upragde should be carried out. But in my opinion I do not like to disturb the existing setup and configuration by doing a in-place upgrade as not always the process is smooth and you can hit some hiccups, in turn that could cause the working server some issues.

So always follow the swing migration to safeguard the environment and follow the Microsoft's AAD Connect Swing Migration process over here

High Level points are:

  • Backup the existing AAD Connect Server
  • Discovery and Analysis of the existing AAD Connect Server configuration
  • Export of the Configuration Settings from the AAD Connect
  • Network Connectivity from the New Server to all the domains,Azure 
  • Global Administrator or Hybrid Account Access
  • Setup the AAD Connect in a Staging Mode on the new server
  • Import the Configuration File on the new server
  • Compare the Configuration File from the old server and the new server (Link here for the config tool)
  • Monitor the Full Import and Sync Process on the new server
  • Once all confirmed and verified that Sync Process is without any errors, carry out the swing migration
  • Again monitor the Full Import and Sync Process on the new server
  • If all is well and working as expected, the old server can be decomissioned and AAD Connect can be uninstalled and removed from the old server
Also the new AAD Connect Server specification should be well spec as the initial full import, syncs takes up lot of processing power and you will need to have more power for the services to complete the setup.

Reboot periodically, monitor the services via SCOM or other monitoring tools, keep upto date with Microsoft bulletin news and if you have any issues do not forget to gather all the logs and events from the server before you raise a support call with Microsoft or you can ask Microsoft Q&A Forums,

Hope this helps and don't forget to provide any feedback or comments.


Comments

Popular posts from this blog

Windows 11 22H2 RDP disconnects and freezes randomly

Certification - 70-533

Windows 2019 Server Change TimeZone error "Unable to continue" You Do not have permissions to perform this task.