Question: What is HC AD Sync Secondary setup and when is it mandatory to deploy Secondary setup of HC AD Sync Tool?
Answer: This article explains why AD Connect Sync Secondary setup is required ? How it is deployed ? and how to configure it properly?
Why ADSync Secondary Setup deployment is required ?
If you host an additional Domain Controller in your infrastructure and want to keep track of the password change event performed on the additional Domain Controller towards Cloud DC then a Primary setup alone will not be enough to hook the password and sync it. In order to handle the situation, HC ADSync Tool also needs to be installed on the additional Domain Controller.
How ADSync Secondary Setup is installed ?
There is no separate installer for Secondary Setup of ADSync tool on additional DCs. As you run the same installer, you are provided with 2 options:
- Primary Domain Controller
- Additional Domain Controller
If ADSync installer is to be deployed on Additional Domain Controller, then select the option Secondary Domain Controller.
How ADSync Secondary Setup is configured ?
HCDirSync Secondary Tool can be configured on Additional Domain Controller by following the steps given below :
- Run HCDirSync tool by selecting option Run as administrator
- Provide Local AD credentials
- Click on Save Settings button. ( See below screenshot for clarity)
Upon successful configuration, password change now triggered from the Additional Domain Controller is synced to the Cloud DC.