Synchronize with Entra Connect through ExpressRoute

yulei0917 95 Reputation points
2024-08-13T07:06:10.8333333+00:00

Hello,
Hope you are doing well!

I think it is the prerequisite to deploy the hybrid AVD environment,
so I need to use Entra Connect to synchronize the on-premise AD and Entra ID in a locked hybrid network which connected by ExpressRoute between local office and Azure which means there should be no public traffic from or out of the on-premise network, is it possible?

Though the 2nd link below mentioned that Entra ID could be routed by Microsoft Peering, but regarding the 1st link, it seems that the Entra Connect require public traffic to internet as the No.59 shows that it cannnot be routed by ER.
M365 Required URL
https://video2.skills-academy.com/en-us/azure/expressroute/expressroute-faqs#microsoft-peering

Why I mentioned the No.59 URL is because the following link shows that "*microsoftonline.com" might be the Entra Connect synchronization required URL other than those used for authentication.
Connectivity issues in the installation wizard

Any advice will be highly appreciated!

Azure Virtual Network
Azure Virtual Network
An Azure networking service that is used to provision private networks and optionally to connect to on-premises datacenters.
2,400 questions
Azure Virtual Desktop
Azure Virtual Desktop
A Microsoft desktop and app virtualization service that runs on Azure. Previously known as Windows Virtual Desktop.
1,516 questions
Azure ExpressRoute
Azure ExpressRoute
An Azure service that provides private connections between Azure datacenters and infrastructure, either on premises or in a colocation environment.
365 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
21,371 questions
0 comments No comments
{count} votes

Accepted answer
  1. akinbade abiola 15,225 Reputation points
    2024-08-13T07:21:20.3266667+00:00

    "so I need to use Entra Connect to synchronize the on-premise AD and Entra ID in a locked hybrid network which connected by ExpressRoute between local office and Azure which means there should be no public traffic from or out of the on-premise network, is it possible?"

    Simply put, No. You will need allowances for specific URLS and ports for functionality.

    Entra connect needs access to specific ports and URLS. It is a prerequisite. https://video2.skills-academy.com/en-us/entra/identity/hybrid/connect/how-to-connect-install-prerequisites. I am listing the prerequisites from the above doc below per networking:

    The URL you mentioned is"*.msappproxy.net", which is used for Azure AD Application Proxy. It needs internet access and cannot be routed through ExpressRoute.

    If you have a locked environment, I will recommend:

    • Review the full list of URLs and IP address ranges required by Entra Connect.
    • Work with your network team to ensure that only the necessary traffic is allowed through your firewall.
    • Consider using Azure Firewall or a similar solution to manage outbound traffic from your Azure environment.

    You can mark it 'Accept Answer' and 'Upvote' if this helped you

    Regards,

    Abiola


0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.