Loading...

Secure, scalable, and simple onboarding to Azure Arc-enabled servers using Group Policy

Secure, scalable, and simple onboarding to Azure Arc-enabled servers using Group Policy

Whether its Microsoft Defender for Cloud’s Security Posture Management capabilities or Azure Automanage Machine Configuration’s Guest-OS level governance capabilities or Update Management Center’s patching capabilities, Azure Arc-enabled servers helps customers achieve consistent security and compliance across their hybrid infrastructure. With thousands of servers spread across subsidiaries and environments, it can be challenging to have the asset inventory needed to onboard to Azure Arc. Yet one solution, a favorite among our customers, most often traverses across disparate environments. You guessed it, that solution is Active Directory. Using Active Directory’s Group Policy engine, IT admins can point and click to onboard hundreds or even thousands of servers to Azure Arc.  

 

aurnovcy_0-1675184639582.png

 

Onboarding at scale is simpler than you think. First, set up a service principal, a limited identity restricted to the Azure Connected Machine Onboarding role. Next, prepare a remote share to host the Azure Connected Machine agent installer and configuration file. Finally, identify and develop a landing zone in Azure (region, subscription, etc.) for where the Azure Arc-enabled servers will be onboarded.

 

aurnovcy_1-1675184639588.png

Once you’ve completed the pre-requisites, you can go to Azure portal and under the option to onboard multiple machines, you’ll be provided with the ability to onboarding using Group Policy. Here you’ll be provided with access to a replicable Group Policy Object (GPO) project structure and a pre-populated command that will fill generate a scheduled task with your Azure information. The command handles encryption of the service principal secret, generating a GPO that can be readily applied.

 

aurnovcy_2-1675184639594.png

 

Now that you’ve successfully created the GPO, simply link it to the desired Organizational Units from the Group Policy Management Console (GPMC). Within 10 to 20 minutes, the Group Policy Object will be replicated to the respective domain controllers and the GPO will trigger the scheduled task to onboard servers to Azure Arc. Once onboard to Azure Arc, start deploying Azure services like VM Insights, Windows Admin Center, or Change Tracking for modernized management of your Arc-enabled servers. If you don’t know where to get started, consider using Azure Automanage Machine Best Practices, a service that eliminates the need to discover or configure the right Azure services to secure, monitor, and govern your Arc-enabled servers.

 

aurnovcy_3-1675184639599.png

 

Helping IT administrators see the forest from the trees, Azure Arc’s single pane of glass affords unprecedented visibility. Your seat at the world’s computer is now just a Group Policy away.

Published on:

Learn more
Azure Arc Blog articles
Azure Arc Blog articles

Azure Arc Blog articles

Share post:

Related posts

Azure Adaptive Cloud Pre-Days at Microsoft Ignite 2024

As the excitement builds for Microsoft Ignite 2024, tech enthusiasts and professionals worldwide are eagerly anticipating the Azure Adaptive C...

1 year ago

Launching the Arc Jumpstart Newsletter: October 2024 Edition

👋 Welcome! We are excited to kick off this monthly newsletter, where you can get the latest updates on everything happening in the Arc Jumpst...

1 year ago

Announcing Public Preview of Windows Server Hotpatch enabled by Azure Arc

We’re excited to announce the Public Preview of Hotpatch enabled by Azure Arc for Windows Sever 2025 Datacenter and Standard editions!   ...

1 year ago

Public Preview of Azure Container Storage enabled by Azure Arc Edge Volumes

Release Summary  We are thrilled to announce the Public Preview of Azure Container Storage enabled by Azure Arc Edge Volumes, a groundbre...

1 year ago

Introducing ArcBox 3.0 General Availability

Today, the Arc Jumpstart team is excited to announce the general availability of ArcBox 3.0!   Since it was first introduced in 2021, Ar...

2 years ago

CloudCasa for Azure Arc

Azure Arc is a platform that helps users build and develop their applications by extending Azure to their datacenters, edge, or even to multic...

2 years ago

Generally Available: Transition to WS2012 / R2 ESUs enabled by Azure Arc from Volume Licensing

Customers that have enrolled in WS2012/ R2 ESUs through Volume Licensing for Year 1 can transition to Azure Arc for Year 2 of the program. Ext...

2 years ago

Comparing feature sets for AKS enabled by Azure Arc deployment options

This article shows a comparison of features available for the different deployment options under AKS enabled by Azure Arc.    ...

2 years ago

Increasing Security for SQL Server Enabled by Azure Arc

Back in November 2023, the least privileges deployment model was introduced as a public preview. After thorough testing, we are excited to ann...

2 years ago

Five Key Updates on WS2012 ESUs enabled by Azure Arc

We have a myriad of key updates for customers enrolled in WS2012/R2 ESUs enabled by Azure Arc! As we continue to refine and expand the offer, ...

2 years ago

Newsletter

Get the latest Dynamics 365 and Power Platform content in your inbox

A curated digest of community blogs, product news, videos, and podcasts — delivered without the noise.

Weekly updates Unsubscribe anytime Fresh community picks
We use your email only for the newsletter and you can unsubscribe at any time.
By subscribing, you agree to the privacy policy.