One Foot in the Cloud, Another On-Premises Ross Adams 2016 Redmond Summit | Identity Without Boundaries May 25 th 2016 Azure AD
IT superhero
How can I leverage the cloud to… Lower costs Improve scalability Increase flexibility Enhance Productivity Enable collaboration Embrace Mobility IT HERO Improve Security
I know what my CEO and users want… Any DeviceAny PlaceAny timeTo all their apps Using their corporate identity
The Current Reality…
Azure Active Directory: Our Focus A modern identity management system spanning cloud and on-premises, providing a common control plane to manage your identities, credentials, devices, applications and accesses to them.
Changing the center of gravity to the cloud AAD
Components of our strategy Common access plane for all apps Devices and Infra shift to cloud Credentials and Identities managed from cloud Reduce friction to cloud “On-prem sees Cloud as authority” “On-prem transitions key infra to cloud” “On-prem begins to ‘trust’ Cloud” “Cloud ‘trusts’ on-prem” Increasing security, monitoring and IT governance value
Hybrid Value Faster
Hybrid Value Faster. Leverage AAD to…
Increase flexibility Enhance Productivity Enable collaboration Embrace Mobility
The first step
Azure AD Connect
Easy onboarding—closing thoughts
Lower costs Enhance Productivity Embrace Mobility Improve Security
Great O365/SaaS experience!
Azure AD Application Proxy Connector Connector
What can I publish
Publishing SharePoint on-prem through Azure AD Demo
Anywhere/Any device access to on-prem apps—closing thoughts
Lower costsEnhance Productivity
Those support calls are costly!!
Self Service Password Reset
Group management
Self-service extends on-prem: Closing thoughts
Lower costs Improve scalability Increase flexibility
Reducing footprint on-prem Traditional approaches are cumbersome
Azure AD Domain Services Azure Active Directory Domain Services Azure Active Directory Windows Server Active Directory Your virtual network Your Azure IaaS workloads/apps Azure
Moving legacy apps to cloud: Closing thoughts
Lower costs Increase flexibility Enhance Productivity Enable collaboration Embrace MobilityImprove Security
Conditional Access Control On-Premises applications Application Per-service Managed client app Other Inside corp. network Outside corp. network Devices Authenticated MDM Managed (Intune) Compliant with policies Not lost/stolen User attributes User identity Group memberships Auth strength (MFA) Risk score Conditional access control
AAD Control plane extends on- prem
Cloud analytics for on- premises
Secure control plane for on-prem apps: Closing thoughts
Thank you! Questions? m