EMS in action Hugh Simpson-Wells and Mark Riley 2016 Redmond Summit | Identity Without Boundaries
Traditionally at this point Active Directory HR SAP Another Dir
Active Directory HR Another Directory AAD Connect SSO
Active Directory HR AAD Connect SSO
What’s driving adoption of EMS?
AD Connect AADP Azure RMS Conditional access Mobile Device Management Agenda
AD is designed for on- premises Active Directory LDAP Kerberos
AAD is designed for the cloud Windows Azure Active Directory SAML-P RESTful Graph API OAUTH and OpenIDConnect WS-Federation Portal
AAD is designed for the cloud
APIs
Active Directory HR SSO Demo environment
Demo AD Connect
AADP
Demo AADP
Azure RMS
Conditional Access
Randomization
Demo Conditional Access Denied/Device Enrollment
Conditional Access On-premises
Overview
Demo Conditional Access
Active Directory Federation Services (ADFS) On-premises
Integration overview User attributes are synchronized including the password hash, Authentication can be completed against either Azure or Windows Server Active Directory User attributes are synchronized, Authentication is passed back through federation and completed against Windows Server Active Directory Synchronization Federation AD FS provides true SSO, conditional access to resources, Work Place Join for device registration and integrated Multi- Factor Authentication Microsoft Azure
AAD Connect with Single Sign-on O365 / Azure STS redirects authentication requests to AD FS STS User authentication is completed against AD Optionally passwords can be sync’d too, for quick fall-back AD
Active Directory Federation Services
Multi-Factor Configuration
Demo Active Directory Federation Services (ADFS)
Multi-Factor Authentication On-premises
AD DS or LDAP On-Premises Apps MFA Server Cloud MFA Cloud Apps 2 Azure Active Directory 1 How it works
MFA for Office 365 (included in Office 365 SKUs) MFA for Azure Administrators (included with Azure Subscription) Azure MFA (Included in AADP/EMS) Administrators can protect accounts with MFA●Administrator accounts only● Mobile app as a second factor●●● Phone call as second factor●●● SMS as second factor●●● App passwords for clients that don’t support MFA●●● Admin control over authentication methods● PIN mode● Fraud alert● MFA Reports● One-Time Bypass● Custom greetings for phone calls● Customizable caller ID for phone calls● Event Confirmation● Trusted IPs● Suspend MFA for remembered devices (Public Preview)●● MFA SDK● MFA for on-premises applications using MFA Server● MFA Versions – Feature Comparison
Authentication Methods Phone CallSMS (2-way) SMS (1-way) Authentication Code App Notification
Demo Multi-Factor Authentication
Mobile Device Management (MDM) Windows Intune
Mobile Device Management (MDM)
Demo Mobile Device Management
Mobile Application Management (MAM) Windows Intune
Mobile Application Management
MAM ‘enlightened’ apps
Demo Mobile Application Management
What is driving EMS adoption?