#ad1.tacos-telco.cloud or ad1.tacos-telco.local ?

74 messages · Page 1 of 1 (latest)

signal fogBOT
#

CliptokInformation @restive lintel, if you want to play around with lots of emoji, please use #offtopic-and-memes to avoid punishment.

steady spire
#

.cloud is reserved

#

Its a actual TLD

restive lintel
#

and if I use .com ?

steady spire
#

What were the question

#

but .com is a real TLD too

restive lintel
#

I have a domain tacos-telco.cloud linked with my website on Godaddy Can I configure my AD with tacos-telco.cloud without impact my website ?

steady spire
#

Nobody owns it

trim moat
#

inb4 someone random here buys it for ransom

steady spire
#

Well I wont

trim moat
#

haha me neither xd

steady spire
#

i have nyasaki.cloud and nyasaki.dev already

restive lintel
#

yes , I use antoher domain name . it's for my example

trim moat
#

but you should use .local or a domain you actually own

steady spire
#

Else our dns tries to resolve them publicly

#

which it cant

#

you could tell it that .cloud is local which would cause issues with actual .cloud domains

trim moat
#

if you use your DC as DNS server you are going to have to do some extra stuff too though

#

either employ what is called split-brain dns

#

or set up your own public dns zone

#

split brain dns is easier to setup and understand, but requires constant maintenance

#

setting up your own public dns to host your domain is difficult, but more hands off afterwards

#

alternatively, you can use the same primary domain name, but put your AD as a subdomain which does not exist on the public zone

#

those are your 4 options

#
  1. use .local
  2. use split-brain dns
  3. use self-hosted public dns
  4. use subdomain for AD
#

I personally recommend options 1 or 4

#

there are even more options though, but that would go into schizo admin tier

restive lintel
trim moat
#

yes, syncing to 365 works with all options

#

you just need to do an extra step for option 1, which is to add an alternative upn suffix

#

for option 4 too tbh

restive lintel
#

the option 1 it's most easier ?

trim moat
#

yeah

#

it is

#

or well, option 1 and 4 are more or less identical

#

just with option 4 you are locking yourself to paying for a public domain name for all eternity

#

I prefer option 1 overall

restive lintel
#

it's true ?

trim moat
#

well not all eternity, but for as long as you wanna keep that AD secure

#

you figure out how to add upn suffix?

#

I think there's a simple ms doc for it in relation to the guide for setting up adsync

steady spire
#

Choose 1

#

for 4 you would have to buy a domain

trim moat
#

yeah 1 is best, at least until you learn the difference

steady spire
#

and forward into your network

trim moat
#

once you know the pros and cons of all the options you can consider something else

#

there are scenarios where other options than 1 is preferable

restive lintel
#

I'll choose 1

trim moat
#

usually when you have self-hosted systems that have integrated AD authentication and you want to access them publicly

#

then you may need options 2-4

#

unless you do it via azure ad app integrations then it doesn't matter really

steady spire
#

Dont confuse them now xD

trim moat
#

xd

restive lintel
#

I have only my website now

steady spire
#

Your website

#

ist it hosted at home too?

#

ummm

restive lintel
#

on Godaddy

steady spire
#

with what domain?

#

u could use .test too

#

Browsers have issues with .local

restive lintel
#

I can't say it unfortunately

steady spire
#

not sure if edge supports .test too

restive lintel
#

but my website use .cloud

trim moat
#

wut

steady spire
#

.local is not a domain

restive lintel
#

sorry .cloud not .local xd

steady spire
#

kk

#

domain names are no secret btw

restive lintel
#

thank you guys , I was thinking about this but now I'm good to continue. Thank you everyone !

trim moat
#

np :)

trim moat