有关 Azure Active Directory (AD) 域服务的常见问题 (FAQ)Frequently asked questions (FAQs) about Azure Active Directory (AD) Domain Services

本页面解答了有关 Azure Active Directory 域服务的常见问题。This page answers frequently asked questions about Azure Active Directory Domain Services.

配置Configuration

是否可为单个 Azure AD 目录创建多个托管域?Can I create multiple managed domains for a single Azure AD directory?

否。No. 对于单个 Azure AD 目录,只能创建一个由 Azure AD 域服务提供服务的托管域。You can only create a single managed domain serviced by Azure AD Domain Services for a single Azure AD directory.

是否可在经典虚拟网络中启用 Azure AD 域服务?Can I enable Azure AD Domain Services in a Classic virtual network?

新部署不支持经典虚拟网络。Classic virtual networks aren't supported for new deployments. 经典虚拟网络中部署的现有托管域将继续受支持,直到 2023 年 3 月 1 日停用。Existing managed domains deployed in Classic virtual networks continue to be supported until they're retired on March 1, 2023. 对于现有部署,你可以将 Azure AD 域服务从经典虚拟网络模型迁移到资源管理器For existing deployments, you can migrate Azure AD Domain Services from the Classic virtual network model to Resource Manager.

有关详细信息,请查看正式的弃用通知For more information, see the official deprecation notice.

是否可以在 Azure 资源管理器虚拟网络中启用 Azure AD 域服务?Can I enable Azure AD Domain Services in an Azure Resource Manager virtual network?

是的。Yes. 可以在 Azure 资源管理器虚拟网络中启用 Azure AD 域服务。Azure AD Domain Services can be enabled in an Azure Resource Manager virtual network. 创建托管域时,经典 Azure 虚拟网络不再可用。Classic Azure virtual networks are no longer available when you create a managed domain.

是否可将现有托管域从经典虚拟网络迁移到资源管理器虚拟网络?Can I migrate my existing managed domain from a Classic virtual network to a Resource Manager virtual network?

是的。Yes. 有关详细信息,请参阅将 Azure AD 域服务从经典虚拟网络模型迁移到资源管理器For more information, see Migrate Azure AD Domain Services from the Classic virtual network model to Resource Manager.

是否可以在 Azure CSP(云解决方案提供商)订阅中启用 Azure AD 域服务?Can I enable Azure AD Domain Services in an Azure CSP (Cloud Solution Provider) subscription?

是的。Yes. 有关详细信息,请参阅如何在 Azure CSP 订阅中启用 Azure AD 域服务For more information, see how to enable Azure AD Domain Services in Azure CSP subscriptions.

能否启用联合 Azure AD 目录中的 Azure AD 域服务?Can I enable Azure AD Domain Services in a federated Azure AD directory? 我不会将密码哈希同步到 Azure AD。I do not synchronize password hashes to Azure AD. 能否为此目录启用 Azure AD 域服务?Can I enable Azure AD Domain Services for this directory?

否。No. 若要通过 NTLM 或 Kerberos 对用户进行身份验证,Azure AD 域服务需要访问用户帐户的密码哈希。To authenticate users via NTLM or Kerberos, Azure AD Domain Services needs access to the password hashes of user accounts. 在联合目录中,密码哈希未存储于 Azure AD 目录中。In a federated directory, password hashes aren't stored in the Azure AD directory. 因此,Azure AD 域服务不适用于此类 Azure AD 目录。Therefore, Azure AD Domain Services doesn't work with such Azure AD directories.

但是,如果使用 Azure AD Connect 进行密码哈希同步,则可以使用 Azure AD 域服务,因为密码哈希值存储在 Azure AD 中。However, if you're using Azure AD Connect for password hash synchronization, you can use Azure AD Domain Services because the password hash values are stored in Azure AD.

是否可以在订阅中的多个虚拟网络内使用 Azure AD 域服务?Can I make Azure AD Domain Services available in multiple virtual networks within my subscription?

域服务本身无法直接支持这种方案。The service itself doesn't directly support this scenario. 托管域每次只能在一个虚拟网络中使用。Your managed domain is available in only one virtual network at a time. 但是,可以在多个虚拟网络之间配置连接,将 Azure AD 域服务公开到其他虚拟网络。However, you can configure connectivity between multiple virtual networks to expose Azure AD Domain Services to other virtual networks. 有关详细信息,请参阅如何使用 VPN 网关虚拟网络对等互连连接 Azure 中的虚拟网络。For more information, see how to connect virtual networks in Azure using VPN gateways or virtual network peering.

是否可以使用 PowerShell 来启用 Azure AD 域服务?Can I enable Azure AD Domain Services using PowerShell?

是的。Yes. 有关详细信息,请参阅如何使用 PowerShell 启用 Azure AD 域服务For more information, see how to enable Azure AD Domain Services using PowerShell.

是否可以使用资源管理器模板来启用 Azure AD 域服务?Can I enable Azure AD Domain Services using a Resource Manager Template?

是的,可以使用资源管理器模板创建 Azure AD 域服务托管域。Yes, you can create an Azure AD Domain Services managed domain using a Resource Manager template. 在部署模板之前,必须使用 Azure 门户或 Azure PowerShell 创建用于管理的服务主体和 Azure AD 组。A service principal and Azure AD group for administration must be created using the Azure portal or Azure PowerShell before the template is deployed. 有关详细信息,请参阅使用 Azure 资源管理器模板创建 Azure AD DS 托管域For more information, see Create an Azure AD DS managed domain using an Azure Resource Manager template. 在 Azure 门户中创建 Azure AD 域服务托管域时,还可以导出模板以用于其他部署。When you create an Azure AD Domain Services managed domain in the Azure portal, there's also an option to export the template for use with additional deployments.

是否可将域控制器添加到 Azure AD 域服务托管域?Can I add domain controllers to an Azure AD Domain Services managed domain?

否。No. Azure AD 域服务提供的域是托管域。The domain provided by Azure AD Domain Services is a managed domain. 你不需要预配、配置或以其他方式管理此域的域控制器。You don't need to provision, configure, or otherwise manage domain controllers for this domain. 这些管理活动由 Microsoft 以服务形式提供。These management activities are provided as a service by Microsoft. 因此,你无法为托管域添加其他域控制器(读写或只读)。Therefore, you can't add additional domain controllers (read-write or read-only) for the managed domain.

邀请到我的目录中的来宾用户能否使用 Azure AD 域服务?Can guest users be invited to my directory use Azure AD Domain Services?

否。No. 使用 Azure AD B2B 邀请进程邀请到 Azure AD 目录的来宾用户会同步到 Azure Active Directory 域服务托管域。Guest users invited to your Azure AD directory using the Azure AD B2B invite process are synchronized into your Azure AD Domain Services managed domain. 但这些用户的密码不会存储在 Azure AD 目录中。However, passwords for these users aren't stored in your Azure AD directory. 因此,Azure AD 域服务无法将这些用户的 NTLM 和 Kerberos 哈希同步到托管域。Therefore, Azure AD Domain Services has no way to synchronize NTLM and Kerberos hashes for these users into your managed domain. 这类用户可以登录到或者将计算机加入到托管域。Such users can't sign in or join computers to the managed domain.

是否可将现有 Azure AD 域服务托管域移动到不同的订阅、资源组、区域或虚拟网络?Can I move an existing Azure AD Domain Services managed domain to a different subscription, resource group, region, or virtual network?

否。No. 创建 Azure AD 域服务托管域后,无法将托管域移到其他资源组、虚拟网络、订阅等位置。部署托管域时,请注意选择最合适的订阅、资源组、区域和虚拟网络。After you create an Azure AD Domain Services managed domain, you can't then move the managed domain to a different resource group, virtual network, subscription, etc. Take care to select the most appropriate subscription, resource group, region, and virtual network when you deploy the managed domain.

Azure AD 域服务是否包含高可用性选项?Does Azure AD Domain Services include high availability options?

是的。Yes. 每个 Azure AD 域服务托管域都包括两个域控制器。Each Azure AD Domain Services managed domain includes two domain controllers. 你不需要管理或连接到这些域控制器,它们是托管服务的一部分。You don't manage or connect to these domain controllers, they're part of the managed service. 如果将 Azure AD 域服务部署到支持可用性局部区域的区域中,则域控制器将分布到各个局部区域中。If you deploy Azure AD Domain Services into a region that supports Availability Zones, the domain controllers are distributed across zones. 在不支持可用性局部区域的区域中,域控制器将分布在多个可用性集中。In regions that don't support Availability Zones, the domain controllers are distributed across Availability Sets. 对于此分布,你无法通过选项进行配置,也无法进行管理控制。You have no configuration options or management control over this distribution. 有关详细信息,请参阅 Azure 中虚拟机的可用性选项For more information, see Availability options for virtual machines in Azure.

管理和操作Administration and operations

是否可以使用远程桌面连接到托管域的域控制器?Can I connect to the domain controller for my managed domain using Remote Desktop?

否。No. 你没有权限使用远程桌面连接到托管域的域控制器。You don't have permissions to connect to domain controllers for the managed domain using Remote Desktop. “AAD DC 管理员”组的成员可以使用 AD 管理工具(例如 Active Directory 管理中心 (ADAC) 或 AD PowerShell)来管理托管域。Members of the AAD DC Administrators group can administer the managed domain using AD administration tools such as the Active Directory Administration Center (ADAC) or AD PowerShell. 可使用“远程服务器管理工具”功能在加入托管域的 Windows 服务器上安装这些工具。These tools are installed using the Remote Server Administration Tools feature on a Windows server joined to the managed domain. 有关详细信息,请参阅创建一个管理 VM 来配置和管理 Azure AD 域服务托管域For more information, see Create a management VM to configure and administer an Azure AD Domain Services managed domain.

我已启用了 Azure AD 域服务。I've enabled Azure AD Domain Services. 应使用哪个用户帐户将计算机加入此域?What user account do I use to domain join machines to this domain?

属于该托管域的任何用户帐户都可以将 VM 加入域。Any user account that's part of the managed domain can join a VM. “AAD DC 管理员”组的成员有权通过远程桌面访问已加入托管域的计算机。Members of the AAD DC Administrators group are granted remote desktop access to machines that have been joined to the managed domain.

我是否具有 Azure AD 域服务提供的托管域的域管理员特权?Do I have domain administrator privileges for the managed domain provided by Azure AD Domain Services?

否。No. 你在托管域上没有管理权限。You aren't granted administrative privileges on the managed domain. 你不可以在该域中使用“域管理员”和“企业管理员”权限。 Domain Administrator and Enterprise Administrator privileges aren't available for you to use within the domain. 本地 Active Directory 中的域管理员或企业管理员组成员在该托管域上也没有域/企业管理员权限。Members of the domain administrator or enterprise administrator groups in your on-premises Active Directory are also not granted domain / enterprise administrator privileges on the managed domain.

能否在托管域上使用 LDAP 或其他 AD 管理工具修改组成员身份?Can I modify group memberships using LDAP or other AD administrative tools on managed domains?

无法修改从 Azure Active Directory 同步到 Azure AD 域服务的用户和组,因为其来源是 Azure Active Directory。Users and groups that are synchronized from Azure Active Directory to Azure AD Domain Services cannot be modified because their source of origin is Azure Active Directory. 这包括将用户或组从 AADDC 用户管理的组织单位移至自定义组织单位。This includes moving users or groups from the AADDC Users managed organizational unit to a custom organizational unit. 可以修改源自托管域的任何用户或组。Any user or group originating in the managed domain may be modified.

对 Azure AD 目录的更改需要多长时间才可在托管域中显示?How long does it take for changes I make to my Azure AD directory to be visible in my managed domain?

在 Azure AD 目录中使用 Azure AD UI 或 PowerShell 所做的更改将自动同步到托管域中。Changes made in your Azure AD directory using either the Azure AD UI or PowerShell are automatically synchronized to your managed domain. 此同步过程在后台运行。This synchronization process runs in the background. 没有规定此同步完成所有对象更改的时间段。There's no defined time period for this synchronization to complete all the object changes.

能否扩展 Azure AD 域服务提供的托管域的架构?Can I extend the schema of the managed domain provided by Azure AD Domain Services?

否。No. 托管域的架构由 Microsoft 管理。The schema is administered by Microsoft for the managed domain. Azure AD 域服务不支持架构扩展。Schema extensions aren't supported by Azure AD Domain Services.

是否可以在托管域中修改或添加 DNS 记录?Can I modify or add DNS records in my managed domain?

是的。Yes. “AAD DC 管理员”组的成员具有“DNS 管理员”权限,可在托管域中修改 DNS 记录。 Members of the AAD DC Administrators group are granted DNS Administrator privileges to modify DNS records in the managed domain. 这些用户可以在运行已加入托管域的 Windows Server 的计算机上使用 DNS 管理器控制台来管理 DNS。Those users can use the DNS Manager console on a machine running Windows Server joined to the managed domain to manage DNS. 若要使用 DNS 管理器控制台,请在服务器上安装“远程服务器管理工具”可选功能中包含的“DNS 服务器工具” 。To use the DNS Manager console, install DNS Server Tools, which are part of the Remote Server Administration Tools optional feature on the server. 有关详细信息,请参阅管理 Azure AD 域服务托管域中的 DNSFor more information, see Administer DNS in an Azure AD Domain Services managed domain.

什么是托管域上的密码生存期策略?What is the password lifetime policy on a managed domain?

Azure AD 域服务托管域上的默认密码生存期为 90 天。The default password lifetime on an Azure AD Domain Services managed domain is 90 days. 此密码生存期与在 Azure AD 中配置的密码生存期不同步。This password lifetime is not synchronized with the password lifetime configured in Azure AD. 因此,可能会出现用户密码在托管域中已过期,但在 Azure AD 中仍然有效的情况。Therefore, you may have a situation where users' passwords expire in your managed domain, but are still valid in Azure AD. 在这种情况下,用户需要更改 Azure AD 中的密码,并且将新密码同步到托管域。In such scenarios, users need to change their password in Azure AD and the new password will synchronize to your managed domain. 如果要更改托管域中的默认密码生存期,可以创建并配置自定义密码策略If you want to change the default password lifetime in a managed domain, you can create and configure custom password policies..

此外,DisablePasswordExpiration 的 Azure AD 密码策略将同步到托管域。Additionally, the Azure AD password policy for DisablePasswordExpiration is synchronized to a managed domain. 当将 DisablePasswordExpiration 应用于 Azure AD 中的用户时,托管域中已同步用户的 UserAccountControl 值已应用 DONT_EXPIRE_PASSWORD 。When DisablePasswordExpiration is applied to a user in Azure AD, the UserAccountControl value for the synchronized user in the managed domain has DONT_EXPIRE_PASSWORD applied.

当用户在 Azure AD 中重置密码时,将应用 forceChangePasswordNextSignIn=True 属性。When users reset their password in Azure AD, the forceChangePasswordNextSignIn=True attribute is applied. 托管域从 Azure AD 同步此属性。A managed domain synchronizes this attribute from Azure AD. 当托管域检测到为来自 Azure AD 的同步用户设置了 forceChangePasswordNextSignIn 时,托管域中的 pwdLastSet 属性设置为 0,这将使当前设置的密码无效 。When the managed domain detects forceChangePasswordNextSignIn is set for a synchronized user from Azure AD, the pwdLastSet attribute in the managed domain is set to 0, which invalidates the currently set password.

Azure AD 域服务是否提供 AD 帐户锁定保护?Does Azure AD Domain Services provide AD account lockout protection?

是的。Yes. 在托管域上于 2 分钟内尝试五个无效密码将导致用户帐户锁定 30 分钟。Five invalid password attempts within 2 minutes on the managed domain cause a user account to be locked out for 30 minutes. 30 分钟后用户帐户将自动解锁。After 30 minutes, the user account is automatically unlocked. 在 Azure AD 中,在托管域上尝试无效密码不会锁定用户帐户。Invalid password attempts on the managed domain don't lock out the user account in Azure AD. 仅在 Azure AD 域服务托管域中锁定用户帐户。The user account is locked out only within your Azure AD Domain Services managed domain. 有关详细信息,请参阅托管域中的密码和帐户锁定策略For more information, see Password and account lockout policies on managed domains.

是否可在 Azure AD 域服务中配置分布式文件系统和复制?Can I configure Distributed File System and replication within Azure AD Domain Services?

否。No. 使用 Azure AD 域服务时,分布式文件系统 (DFS) 和复制不可用。Distributed File System (DFS) and replication aren't available when using Azure AD Domain Services.

如何在 Azure AD 域服务中应用 Windows 更新?How are Windows Updates applied in Azure AD Domain Services?

托管域中的域控制器会自动应用必需的 Windows 更新。Domain controllers in a managed domain automatically apply required Windows updates. 无需在此处进行任何配置或管理。There's nothing for you to configure or administer here. 请确保你没有创建阻止到 Windows 更新的出站流量的网络安全组规则。Make sure you don't create network security group rules that block outbound traffic to Windows Updates. 对于加入托管域的你自己的 VM,你负责配置和应用任何必需的操作系统和应用程序更新。For your own VMs joined to the managed domain, you are responsible for configuring and applying any required OS and application updates.

计费和可用性Billing and availability

Azure AD 域服务是付费服务吗?Is Azure AD Domain Services a paid service?

是的。Yes. 有关详细信息,请参阅定价页For more information, see the pricing page.

该服务是否有试用版?Is there a trial for the service?

Azure 的试用版中包含 Azure AD 域服务。Azure AD Domain Services is included in the trial for Azure. 可以注册 Azure 试用版You can sign up for a trial of Azure.

我能否暂停 Azure AD 域服务托管域?Can I pause an Azure AD Domain Services managed domain?

否。No. 一旦启用 Azure AD 域服务托管域,即可在选定的虚拟网络中使用该服务,直到删除托管域为止。Once you've enabled an Azure AD Domain Services managed domain, the service is available within your selected virtual network until you delete the managed domain. 无法暂停该服务。There's no way to pause the service. 删除托管域前,会按小时对服务计费。Billing continues on an hourly basis until you delete the managed domain.

对于 DR 事件,是否可以将 Azure AD 域服务故障转移到另一个区域?Can I fail over Azure AD Domain Services to another region for a DR event?

是的,要为托管域提供异地复原能力,可以在支持 Azure AD DS 的任何 Azure 区域中为对等的虚拟网络创建一个额外的副本集Yes, to provide geographical resiliency for a managed domain, you can create an additional replica set to a peered virtual network in any Azure region that supports Azure AD DS. 副本集与托管域共享相同的命名空间和配置。Replica sets share the same namespace and configuration with the managed domain.

是否可以从企业移动性套件 (EMS) 获取 Azure AD 域服务?Can I get Azure AD Domain Services as part of Enterprise Mobility Suite (EMS)? 是否需要 Azure AD Premium 才能使用 Azure AD 域服务?Do I need Azure AD Premium to use Azure AD Domain Services?

否。No. Azure AD 域服务是即用即付的 Azure 服务,未包含在 EMS 中。Azure AD Domain Services is a pay-as-you-go Azure service and isn't part of EMS. Azure AD 域服务可用于所有版本的 Azure AD(免费版和高级版)。Azure AD Domain Services can be used with all editions of Azure AD (Free and Premium). 它按小时计费,具体取决于使用量。You're billed on an hourly basis, depending on usage.

哪些 Azure 区域提供此服务?What Azure regions is the service available in?

请参阅按区域列出的 Azure 服务页,获取提供 Azure AD 域服务的 Azure 区域列表。Refer to the Azure Services by region page to see a list of the Azure regions where Azure AD Domain Services is available.

故障排除Troubleshooting

有关配置或管理 Azure AD 域服务的常见问题的解决方法,请参阅疑难解答指南Refer to the Troubleshooting guide for solutions to common issues with configuring or administering Azure AD Domain Services.

后续步骤Next steps

若要详细了解 Azure AD 域服务,请参阅什么是 Azure Active Directory 域服务?To learn more about Azure AD Domain Services, see What is Azure Active Directory Domain Services?.

若要开始使用,请参阅创建并配置 Azure Active Directory 域服务托管域To get started, see Create and configure an Azure Active Directory Domain Services managed domain.