About This Architecture
Multi-forest Active Directory topology synchronized to Azure Entra ID across Forest A and Forest B, with headquarters domain controllers in separate VLANs and branch site replication via WAN links. Entra ID sync agents connect to designated domain controllers in each forest, while Azure VM domain controllers extend Forest A into the cloud and VPN gateways establish secure connectivity between on-premises sites. This architecture demonstrates hybrid identity management at scale, enabling organizations to maintain separate AD forests while presenting a unified identity plane to Microsoft 365. Fork this diagram on Diagrams.so to customize forest names, IP ranges, or add additional branch sites and cloud regions. The design balances security through firewall-protected perimeters, redundancy via multiple domain controllers per forest, and cloud integration through Azure VM-hosted DCs and VPN tunneling.