Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

alz checklist updates #569

Merged
merged 3 commits into from
Dec 14, 2023
Merged

alz checklist updates #569

merged 3 commits into from
Dec 14, 2023

Conversation

igorjnzl
Copy link
Contributor

@igorjnzl igorjnzl commented Dec 7, 2023

small updates around product naming and consolidation of couple checks

@igorjnzl igorjnzl requested review from a team as code owners December 7, 2023 21:20
@@ -530,7 +531,7 @@
{
"category": "Resource Organization",
"subcategory": "Subscriptions",
"text": "If AD on Windows Server, establish a dedicated identity subscription in the Indentity management group, to host Windows Server Active Directory domain controllers",
"text": "If Entra Domain Services on Windows server, establish a dedicated identity subscription in the Identity management group, to host the domain controllers",
Copy link
Collaborator

@brsteph brsteph Dec 8, 2023

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Question on this and a few other sections - I am not aware that Windows Server Active Directory is being changed to Entra Domain Services. The product documentation still refers to it as AD. I thought Entra Domain Services was a replacement name for the Azure AD Domain Services.

Some of these recommendations are agnostic to which approach, and some are dependent, so I think we would want to be clear here.

Copy link
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

For this section, could we change this to:

If servers will be used for Identity services, like domain controllers, establish a dedicated identity subscription in the Identity management group to host the services.

Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Good spotting here, I'll update based on recent comment

@@ -916,17 +917,6 @@
"training": "https://learn.microsoft.com/learn/modules/design-implement-azure-expressroute/",
"link": "https://learn.microsoft.com/azure/expressroute/designing-for-disaster-recovery-with-expressroute-privatepeering#challenges-of-using-multiple-expressroute-circuits"
},
{
Copy link
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I'm not sure why we would remove this. Is there a reason we would not want the domain controllers to be in the more fault-tolerant configuration?

Copy link
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think this is being consolidated into B03.11

Copy link
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I was reading B03.11 as being just for Entra Domain Services - I think this might be tied to my other comment thread then.

I am thinking the sheet should be agnostic to the provider used, and we can treat Active Directory Domain Services and Entra Domain Services with the same recommendations - the same HA for DCs applies to both. Although I may be missing some roadmap items here.

Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Correct, consolidating under the identity design area

@@ -321,7 +322,7 @@
{
"category": "Identity and Access Management",
"subcategory": "Identity",
"text": "If AD on Windows server in use, are the resources in Azure using the correct domain controller?",
"text": "If Microsoft Entra Domain Services on Windows server is in use, are the resources in Azure using the correct domain controller?",
Copy link
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Could we change this to:

If domain controllers are being used, ensure that resources are set to use the correct domain controller.

@igorjnzl igorjnzl requested review from brsteph and erjosito December 12, 2023 01:25
@erjosito erjosito merged commit 16d9649 into Azure:main Dec 14, 2023
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants