
Is it possible for Dynamics CRM on-premise to setup single sign on with Azure AD and bypass the local AD authentication? Thanks.
Hey Kevin
I wouldn't say "bypass" but instead, authenticate on AzureAD and through federation, provide access. When we have Dynamics 365 Onprem and need to expose it externally (outside the network) it's mandatory to use a federation service (STS/ADFS for sample). So Azure AD could be an additional identity provider which will be integrated with local ADFS, but it can’t act as a Federation Service.
You can refer to this article:
docs.microsoft.com/.../active-directory-compare-azure-ad-to-ad
Additionally, Azure Active Directory is not designed to be the cloud version of Active Directory. It is not a domain controller or a directory in the cloud that will provide the exact same capabilities with AD. It actually provides many more capabilities in a different way.
Here you can find how to Extend Active Directory Federation Services (AD FS) to Azure: docs.microsoft.com/.../adfs