Identities and Azure AD Premium Presented By : Micah Linehan Cloud Sherpa
Topics Covered Azure AD Connect Sourcing Identities Write Back to Active Directory Azure RMS Multi-Factor Authentication Third Party SAAS Applications
Windows Azure Active Directory Azure AD Connect IT Academy, Other service Windows Azure Active Directory CRM & Project Online STS on premises Trust Active Directory Federation Server 3.0 Admin Portal/ PowerShell IdP Office 365 Directory Store IdP AD AAD Connect Provisioning platform Windows Intune Directory Graph REST API 3rd Party Apps
Azure AD Connect Cloud Identity Pairing Immutable ID UserPrincipalName Soft Pair vs Hard Pair Immutable ID Base 64 Hex Conversion of ObjectGuid UserPrincipalName Basis for soft cloud pairing Exchange Hybrid Deployment
Identities Users, groups, objects, identities mastered in the cloud Cloud Identity Cloud Identity With On-Premises AD Federated Identity with On-Premises AD Cloud Identity Cloud Identity Federated Identity AAD Connect AAD Connect User User User Federation On-Premises Identity On-Premises Identity On-Premises Identity Users, groups, objects, identities mastered in the cloud Users, groups, objects mastered On-Premises and identities mastered in the cloud, *optional password hash sync to the cloud Users, groups, objects, identities mastered On-Premises
Sourcing Identities Identities and Groups are the way we manage access Incorrectly configured or misappropriated accounts are a huge vulnerability Control what accounts go into the cloud Filtering Object From Active Directory OU based Filtering Object based filtering based on attributes
Write Back to AD Active Directory on Server 2016 supports Azure AD Join write back Password Write Back Self Service Password Reset Group Membership Write Back Delegated administration of group members in the cloud
Azure RMS Instant revocation of access Securely share documents and files No certificate management required Hybrid management integrate with your on premise RMS server
Multi-Factor Authentication Azure Administrators do not require AD Premium for this feature Real Time Alerts and Monitoring for Access Azure Access Third Party Application Access Location Access Use in cloud or Hybrid with on premise servers White List your on premise IPs Azure Administrators do not require AD Premium for this feature Real Time Alerts and Monitoring for Access Azure Access Third Party Application Access Location Access Use in cloud or Hybrid with on premise servers White List your on premise IPs
Third Party SAAS Applications Publish Access to Third Party Apps Manage Shared Access and Security by automating password changes through Azure 3rd Party SSO Twitter Facebook WordPress Office 365 can be the Central Application Hub
Q & A