Azure Active Directory Connect Upgrade In-place or Swing Migration
In this article we are going to
discuss different methods that you can use to upgrade your Azure Active
Directory (Azure AD) Connect installation to the latest release.
I have been reading lot of
queries and question mark over the type of upgrade process or approach should
be taken by the Architects or an Engineer managing the AAD Connect software.
First of all, it is very
important that the environment and specially the servers are in line with the current and the latest
releases of Azure AD Connect. Microsoft is constantly making upgrades to
AADConnect, and these upgrades include fixes to security issues and bugs, as
well as serviceability, performance, and scalability improvements.
As been on the field working for different clients the issues and confusion is whether to do in place upgrade or do a swing migration, Microsoft states with small environment and not many complex settings usually in-place upragde should be carried out. But in my opinion I do not like to disturb the existing setup and configuration by doing a in-place upgrade as not always the process is smooth and you can hit some hiccups, in turn that could cause the working server some issues.
So always follow the swing migration to safeguard the environment and follow the Microsoft's AAD Connect Swing Migration process over here
High Level points are:
- Backup the existing AAD Connect Server
- Discovery and Analysis of the existing AAD Connect Server configuration
- Export of the Configuration Settings from the AAD Connect
- Network Connectivity from the New Server to all the domains,Azure
- Global Administrator or Hybrid Account Access
- Setup the AAD Connect in a Staging Mode on the new server
- Import the Configuration File on the new server
- Compare the Configuration File from the old server and the new server (Link here for the config tool)
- Monitor the Full Import and Sync Process on the new server
- Once all confirmed and verified that Sync Process is without any errors, carry out the swing migration
- Again monitor the Full Import and Sync Process on the new server
- If all is well and working as expected, the old server can be decomissioned and AAD Connect can be uninstalled and removed from the old server
Comments
Post a Comment