Wanted to share a personal project writeup in case it's useful to anyone working through similar AD/Azure hybrid identity stuff. (Posted this in r/sysadmin first, but the mods correctly pointed out it's blog content and belongs here instead – fair enough.)
Built from scratch: a single Windows Server VM on EC2 -> promoted to a domain controller -> hardened (static IP/DNS, time sync, OU structure, Recycle Bin) -> right-sized twice as real workloads (AD DS, then Entra Connect Sync's SQL LocalDB) demanded more RAM -> populated with 25 users across proper security-group-scoped access tiers -> connected to Microsoft Entra ID via Entra Connect Sync for hybrid identity.
The interesting part isn't the happy path – it's the actual bugs hit and diagnosed along the way:
Install-Module -Name Az reporting "success" while silently leaving Az.Accounts missing (turned out to be a missing NuGet provider, not a resource problem – confirmed by upsizing RAM 4x and hitting the exact same failure)
An Azure AD Connect Health Agent install that silently overwrote PSModulePath, wiping the personal modules folder out of the search path
AADSTS50020 hell signing into Entra Connect Sync with a personal Microsoft account that held Global Admin – personal accounts get rejected outright regardless of role
A tenant that existed for weeks with zero attached Azure subscriptions, causing New-AzResourceGroup to fail on a null SubscriptionId
Full writeup with every command and actual error messages: https://github.com/bcole84/windows-dc-on-aws
Happy to answer questions if anyone's fighting similar issues.
Source: r/SysAdminBlogs · by /u/Eastern_Outcome