If customer has multiple AD Domains without trust, can we move these devices directly to AAD?

    You can only create a single managed domain serviced by Azure AD Domain Services for a single Azure AD directory.

  1. It’s all depends on application authetication. If there are a lot of apps that needs kerberos or NTLM authetication with Active Directories then that would be a challenge.

    But there is no relation or trust concept between on prem active directory and Azure AD. These two things to be connected via Azure AD connect.

    Azure AD join is possible for many scenarios like this but I don’t think an online forum would be the right place to discuss the business scenarios and define a architecture and solution.

