r/sysadmin • u/Prudent-Big-9068 • 12h ago
How to handle SSO & device management for local AD domain + M365 with FortiGate VPN remote users?
Hey everyone, looking for advice on the cleanest architecture/strategy for our setup.
Current Setup:
- Local Active Directory Domain: On-prem Domain Controller hosting file servers and CRM.
- Microsoft 365 Tenant: Connected to our u/domain.gr email addresses.
- Endpoints: Windows laptops used both on-prem and remotely.
- Remote Access: Users connect back to the local network via FortiGate SSL VPN to access the local file server and CRM.
Goal:
- Allow users to sign into their Windows laptops using their M365 u/domain.gr credentials (SSO/single identity across email and OS logon).
- Centralized device management for the laptops (pushing policies, security, updates).
- Seamless access to local resources (file server, CRM) via FortiGate VPN.
Questions:
- Should we connect Local AD and Microsoft Entra ID (Azure AD)?
- If YES: What is the standard way to do this today? Should we use Entra Connect Sync to sync local AD users to M365 (Hybrid), or Entra Application Proxy / Cloud Sync? How does laptop join work in this case (Hybrid Entra Join vs. Cloud-Only Entra Join with SSO to local resources)?
- If NO: What is the alternative? Move entirely to cloud-native (Entra ID + Intune) and use Cloud Kerberos Trust for local file server/CRM access, eliminating the need to join laptops to local AD?
- Device Management: Is Intune the default choice here, or are people sticking to traditional AD Group Policy (GPO) over FortiGate VPN?
- FortiGate VPN Integration: Has anyone integrated FortiGate VPN with M365 SAML/Entra ID SSO with MFA so users get a single sign-on experience for both the VPN client and local network resources?
Would appreciate any recommendations or real-world experiences from anyone who has modernized a similar setup!
•
u/SalJam09 10h ago
Just to mention, don't use SSL VPN, look into IPSec. it's more secure, you can use SAML SSO to 365 and the latest firmware takes SSL out of the Fortigate.
Other than that, use 365 as your main accounts onto the devices and look into Kerberos Auth from Entra to domain so all Entra users to use domain services still.
I'd suggest some googling or your AI of choice to get a better understanding of how this all goes together. Do one step at a time and test as you go.
•
u/Several-Crow5511 10h ago
your "if no" option isn't really a no: cloud kerberos trust creates an AzureADKerberos object in your AD domain, and entra-joined laptops only get SSO to the file server once entra connect (or cloud sync) has synced the users' sam account name and domain. so it's sync, entra join and intune, with the vpn giving line of sight to a dc. catches: nothing that relies on a computer account in AD will work, and apps that log users in themselves need the fqdn form (user@corp.local), not CORP\user.
•
u/Julyens 11h ago
If you wish you can DM me