Enabling the Modern Workstyle with Windows 10 & Azure Active Directory Venkatesh Gopalakrishnan 2016 Redmond Summit | Identity Without Boundaries May 25, 2016 Principal PM Manager
1. What is the modern workstyle? 2. How Windows 10 and Azure AD help end users and IT embrace the modern workstyle 3. Security, Access Control and Data Protection in the modern IT environment Topics
The Modern Workstyle
What is the modern workstyle?
Current IT reality …is also an opportunity to enable the modern workstyle
Windows 10 & Azure AD enable the modern workstyle
Azure Active Directory Join Register Windows 10 devices directly to your company’s Azure Active Directory in the cloud Azure AD Joined Devices Windows Server Domain Joined Devices Easy set up Self-service setup by end users via OOBE, Settings or within apps Automatic enrollment into management – no extra steps required SSO to org apps and resources SSO to Office 365 and 1,000’s of enterprise apps, websites and resources. Install apps from the Windows Store for Business Familiar Enterprise Services Roaming Settings, Windows Backup/Restore, Store access, etc. Compliant, enterprise-class data storage and backend services Support for hybrid environments Domain-joined and Azure AD-joined devices coexist seamlessly when on- premises AD is connected with Azure AD Security Supports Windows Hello – passwords are never used
A typical use case 1.Employees set up devices by themselves 2.MDM deploys apps, certificates and policies to the devices 3.Employees use Windows Hello to unlock 4.Seamlessly access company mail, documents and LOB apps from anywhere
Demo
Azure AD Joined Devices Domain Joined Devices Personal Devices (BYOD) Device configurations
Security, Access Control and Protection
Windows Hello A more personal, more secure way to unlock your Windows 10 devices. Active Directory Azure Active Directory Microsoft Account Other IDP’s User 1 Create Account or Proves Identity Create and trust my unique key or Authenticate me by validating this signed request 2 Windows 10 3 Intranet Resource 4 4 Here is your authentication token I trust tokens from IDP So do I Intranet Resource User Unlocks Windows identity container w/ PIN or Bio IDP
Conditional Access Control User attributes User identity Group memberships Auth strength (MFA) Application Authorized application Type (web, native) Business sensitivity Other Location (network) Risk profile Conditional access control in Active Directory Devices Known to organization MDM Managed (Intune) Compliant with policies Not lost/stolen
Bitlocker RMS Enterprise Data Protection Device Protection
Summary: Enabling the modern workstyle
Move productivity to the cloud Enhance security Critical elements Enable protection
2016 Redmond Summit Sponsors
Thank you! Venkatesh Gopalakrishnan