61% of workers mix personal and work tasks in their devices* * Forrester Research: “BT Futures Report: Info workers will erase boundary between enterprise.

Slides:



Advertisements
Similar presentations
Office 365 Identity June 2013 Microsoft Office365 4/2/2017
Advertisements

Agenda AD to Windows Azure AD Sync Options Federation Architecture
Azure AD & Office Logon with Username / Password 2. MFA challenge 3. Reply to MFA challenge -1-way or 2-way SMS -Phone call -Mobile Application.
Users expect to be able to work in any location and have access to all their work resources. The explosion of devices has eradicated the standards-
Microsoft Ignite /16/2017 3:28 PM
SharePoint Server Exchange Server CORPORATE NETWORK Mobile devices PCs Browsers INTERNET DMZ Active Directory Policies Filter EAS Filter web access.
Peter Ginnegar Technical Solution Professional Microsoft Corporation
Federated sign-in WS-Federation WS-Trust SAML 2.0 Metadata Shibboleth Graph API Synchronize accounts Authentication.
Microsoft Ignite /16/2017 4:55 PM
4/17/2017 © 2014 Microsoft Corporation. All rights reserved. Microsoft, Windows, and other product names are or may be registered trademarks and/or trademarks.
What is Azure Multi-Factor Authentication? An Azure Identity and Access management service that prevents unauthorized access to both on- premises.
Today’s challenges Deliver applications to mobile platforms (BYOD) Respond to dynamic business requirements for IT: Seasonal/temporary workers Vendors.
4/17/2017 © 2014 Microsoft Corporation. All rights reserved. Microsoft, Windows, and other product names are or may be registered trademarks and/or trademarks.
4/17/2017 © 2014 Microsoft Corporation. All rights reserved. Microsoft, Windows, and other product names are or may be registered trademarks and/or trademarks.
Empower Enterprise Mobility. of employees use personal devices for work purposes.* of employees that typically work on employer premises, also frequently.
Mobility is the new normal 52% of information workers across 17 countries report using three or more devices for work* 52% 90% of enterprises will have.
Active Directory Integration with Microsoft Office 365
User Microsoft Account Ex: User Organizational Account Ex: Microsoft Account Windows Azure Active Directory.
Demi Albuz SENIOR PRODUCT MARKETING MANAGER Samim Erdogan PRINCIPAL ENGINEERING MANAGER Thomas Willingham TECHNICAL PRODUCT MANAGER.
Empower Enterprise Mobility Jasbir Gill Azure Mobility.
Single Sign-On with Microsoft Azure
User Microsoft Account Ex: User Organizational Account Ex: Microsoft Account Microsoft Azure Active Directory.
Microsoft ® Official Course Module 13 Implementing Windows Azure Active Directory.
PCIT313. Today’s challenges Deliver applications to mobile platforms (BYOD) Respond to dynamic business requirements for IT: Seasonal/temporary workers.
Empowering people-centric IT Unified device management Access and information protection Desktop Virtualization Hybrid Identity.
Paul Andrew. Recently Announced… Identity Integration Options 2 3 Identity Management Overview 1.
Alessandro Cardoso Microsoft MVP | Readify National Manager |
Access and Information Protection Product Overview Andrew McMurray Technical Evangelist – Windows
Bronze Sky customer premises AD MS Online Directory Sync Provisioning platform Provisioning platform Lync Online Lync Online SharePoint Online SharePoint.
Get identities to the cloud Mix on-premises and cloud identity for improved PC, mobile, and web productivity Cloud identities help you run your business.
FND2851. Mobile First | Cloud First Sixty-one percent of workers mix personal and work tasks on their devices* >Seventy-five percent of network intrusions.
Access resources in a federation partner organization.
Configuration Manager and InTune Gemeinsam oder einsam?
Manage and secure identities in a cloud and mobile world
Pat Fetty – Principal PM Manager Securing your mobile assets with Microsoft Intune WIN33 1.
Craig Pringle & Derek Moir
Identities and Azure AD Premium
Why EMS? What benefit does EMS provide O365 customers Manage Mobile Productivity Increase IT ProductivitySimplify app delivery and deployment LOB Apps.
Enterprise Mobility Suite: Simplify security, stay productive Protect data and empower workers Unsecured company data can cost millions in lost research,
Agenda  Microsoft Directory Synchronization Tool  Active Directory Federation Server  ADFS Proxy  Hybrid Features – LAB.
Go mobile. Stay in control. Craig Morris EMPOWER ENTERPRISE MOBILITY.
Enabling the Modern Workstyle with Windows 10 & Azure Active Directory Venkatesh Gopalakrishnan 2016 Redmond Summit | Identity Without Boundaries May 25,
EMS in action Hugh Simpson-Wells and Mark Riley 2016 Redmond Summit | Identity Without Boundaries
SaaS apps.
Azure Active Directory Uday Hegde 2016 Redmond Summit | Identity Without Boundaries May 26, 2016 Group Program Manager, Azure AD
Gregor Šuster, Microsoft Azure Active Directory. Kaj je in kaj ni Azure Active Directory (AAD)? Različice storitve Azure Active Directory Predstavitev.
of employees use personal devices for work purposes.* of employees that typically work on employer premises, also frequently work away from their desks.***
Managing Devices in the Enterprise: From EMS zero to Hero in only 60 minutes Ken Goossens Herman Arnedo Mahr.
Protect your data Enable your users Desktop Virtualization Information protection Mobile device & application management Identity and Access Management.
Recording Brief EMS Partner Bootcamp Variables Values Module Title
Active Directory Modernization Technical data deck
Active Directory Modernization Technical competitive comparison
Implementing and Managing Azure Multi-factor Authentication
Microsoft Ignite /27/2018 9:00 AM THR2016
Identity and access management
SaaS Application Deep Dive
Mobile Device Management options in Office 365 and beyond
The power of common identity across any cloud
Examine common architectures for hybrid identity
Secure Remote Access to on-premises Web Apps using Azure AD
9/13/2018 4:54 PM BRK How to get Office 365 to the next level with Azure Active Directory Premium Brjann Brekkan Program Manager Lead – Customer.
Microsoft Virtual Academy
Office 365 Identity Management
11/15/2018 3:42 AM © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN.
Access and Information Protection Product Overview October 2013
Microsoft Ignite NZ October 2016 SKYCITY, Auckland.
Matthew Levy Azure AD B2B vs B2C Matthew Levy
4/9/2019 5:05 AM © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS.
Microsoft 365 Business Technical Fundamentals Series
Azure AD Simon May Technical Evangelist.
Presentation transcript:

61% of workers mix personal and work tasks in their devices* * Forrester Research: “BT Futures Report: Info workers will erase boundary between enterprise & consumer technologies,” Feb. 21, 2013 ** *** Verizon 2013 data breach investigation report >70% percent of network intrusions exploited weak or stolen credentials * ** >80% of employees admit to using non-approved software-as-a-service (SaaS) applications in their jobs** Mobile & Cloud- challenging security paradigms

IT EmployeesCustomersBusiness Partners What's driving change? Devices DataUsers Apps

Access from many devices Manage and secure productivity Preserve existing investments Support iOS, Android, Windows Why Microsoft’s Enterprise Mobility Solution? It’s integrated on common identity It protects Office better It just worksIt’s comprehensive

The current reality…

Self-service Single sign on Username Identity as the control plane Simple connection Cloud SaaS Azure Office 365 Public cloud Other Directories Windows Server Active Directory On-premises Microsoft Azure Active Directory

What is Azure Active Directory? A comprehensive identity and access management cloud solution for your employees, partners and customers. It combines directory services, advanced identity governance, application access management and a rich standards-based platform for developers.

Azure Active Directory Connect and Connect Health * Microsoft Azure Active Directory Other Directories PowerShell LDAP v3 SQL (ODBC) Web Services ( SOAP, JAVA, REST) MIM *

DirSync Azure Active Directory Sync FIM+Azure Active Directory Connector Sync Engine

Microsoft Azure

SaaS apps Microsoft Azure Active Directory Other Directories

Microsoft Azure 1000s of Applications, 1 Password Web Apps (Azure Active Directory Application Proxy) SaaS appsIntegrated custom apps Other Directories

Microsoft Azure Active Directory Corporate Network DMZ contoso.msappproxy.net/

IT professional

B2B collaboration “I need to let my partners access my company’s apps using their own credentials.”

B2B collaboration – verified provisioning Partner

Partners use their own creds to access your org. Users lose access when they leave the partner org. No external directories. No per partner federation. Partners manage their own credentials You control partner access in your directory: app assignment group membership custom attributes Organizations manage access Thousands of bulk invites at a time. Partners with Azure AD sign in to accept invite. Other partners simply sign up to accept invite. Partners of all sizes

Azure AD Join makes it possible to connect work-owned Windows 10 devices to your company’s Azure Active Directory. Users can sign into Windows with their cloud-hosted work credentials and enjoy modern Windows experiences.  Enterprise-compliant services  SSO from the desktop to cloud and on- premises applications with no VPN  MDM auto enrollment  Support for hybrid environments Azure AD Join for Windows 10 Windows 10 Azure AD Joined Devices MDM Auto-enrolment

A stand-alone Azure Identity and Access management service also included in Azure Active Directory Premium Prevents unauthorized access to both on-premises and cloud applications by providing an additional level of authentication Trusted by thousands of enterprises to authenticate employee, customer, and partner access. What is Azure Multi-Factor Authentication?

How it works

Users sign in from any device using their existing username/password. 1 On-Premises Apps Windows Server Active Directory or Other LDAP Users must also authenticate using their phone or mobile device before access is granted. 2 Microsoft Azure Active Directory Multi-Factor Authentication Server Multi-Factor Authentication Server User

Azure MFA vs MFA for Office 365 MFA for Office 365/Azure Administrators Azure Multi-Factor Authentication Administrators can Enable/Enforce MFA to end-usersYes Use Mobile app (online and OTP) as second authentication factorYes Use Phone call as second authentication factorYes Use SMS as second authentication factorYes Application passwords for non-browser clients (e.g. Outlook, Lync)Yes Default Microsoft greetings during authentication phone callsYes Suspend MFA from known devicesYes Custom greetings during authentication phone callsYes Fraud alertYes MFA SDKYes Security ReportsYes MFA for on-premises applications/ MFA Server.Yes One-Time BypassYes Block/Unblock UsersYes Customizable caller ID for authentication phone callsYes Event ConfirmationYes Trusted IPsYes

Allow Access Block Access Cloud Apps On-premises Application Access policies Enforce MFA per user/per app Location (IP Range) Device State User Group

Microsoft Azure Active Directory Cloud App Discovery 10 x Source: Help Net Security 2014 as many Cloud apps are in use than IT estimates SaaS app category Number of users Utilization volume Comprehensive reporting Reveal shadow IT : Discover all SaaS apps in use within your organization

Rich standards-based platform for developers

No Object Limit No Limit Advanced Security Reports Yes Premium+ Basic Features Group-based access management/provisioningYes Self-Service Password Reset for cloud usersYes Company Branding (Logon Pages/Access Panel customization)Yes Application ProxyYes SLAYes

Consumer identity and access management in the cloud Azure Active Directory B2C A highly available, global, cost-effective identity management service for consumer-facing applications Improve connection with your consumers Pay only for what you use Scale to hundreds of millions of consumers Help protect your consumers’ identities Let consumers use their social media accounts Customizable workflows for consumer interactions

Self-service Single sign on Username Identity as the control plane Simple connection Cloud SaaS Azure Office 365 Public cloud Other Directories Windows Server Active Directory On-premises Microsoft Azure Active Directory