Using AAD B2C for WordPress & Secure Deployment Scenario

Slides:



Advertisements
Similar presentations
A lap around Azure Active Directory Business to Consumer (B2C)
Advertisements

Azure Active Directory - Business 2 Consumer
Microsoft Teams Behind the Scenes – Q&A
Successfully migrate existing databases to Azure SQL Database
From IT Pros to IT Heroes - with Azure DevTest Labs
5/21/2018 9:40 PM BRK3021 Learn about modern infrastructure roles in RDS: Next generation Windows desktop & app virtualization Clark Nicholson - Principal.
5/22/2018 1:39 AM BRK2156 Power BI Report Server: Self-service BI and enterprise reporting on-premises Christopher Finlan Senior Program Manager © Microsoft.
Azure on Steroids: Full Automation with PowerShell
5/29/2018 1:51 AM THR2071 Managing enterprise applications, permissions, and consent in Azure Active Directory Adam Steenwyk & Jeff Sakowicz Program Managers.
6/10/2018 5:07 PM THR2218 Deploying Windows Defender AV and more with Intune and Configuration Manager Amitai Senior Program Manager,
Azure Cloud Shell Magic of Modern Command-line Management
Developing Hybrid Apps on Microsoft Azure Stack
Windows 10 and the cloud: Why the future needs hybrid solutions
Modernizing your Remote Access
Do more with Microsoft Word and Office 365
Decoding audit events in Microsoft Office 365
Optimizing Microsoft OneDrive for the enterprise
What a Real, Functioning DevOps Team Looks Like
The power of common identity across any cloud
Protect sensitive information with Office 365 DLP
Microsoft Ignite /31/ :08 AM
8/1/ :13 PM BRK2276 Azure Active Directory B2C: Modernize your customer identity management Saeed Akhter Senior Program Manager © Microsoft Corporation.
Microsoft 365 Business: Under the Hood
Understanding Windows Analytics Update Compliance
Excel and Power BI Better Together Democratization of data
Workflow Orchestration with Adobe I/O
How we got a traditional bank collaborating across boundaries
Windows 10 Subscription Activation
Find, try and get line-of-business apps on Microsoft AppSource
Azure Security in four steps
Automate all things! Microsoft Azure continuous deployment
Agile Planning with Visual Studio Team Services (VSTS)
9/22/2018 3:49 AM BRK2247 Learn from MVPs: Panel discussion on all things SharePoint and OneDrive © Microsoft Corporation. All rights reserved. MICROSOFT.
Azure PowerShell Aaron Roney Senior Program Manager Cormac McCarthy
11/15/ :59 AM THR2294 Building great looking experiences with Microsoft Graph and Office UI Fabric Ben Summers Office Marketing David Lavenda Harmon.ie.
Continuous Delivery with Visual Studio Team Services
Azure Advisor: Optimization in the best way
Bring existing desktop apps to UWP with the Desktop Bridge
12/5/2018 2:50 AM How to secure your front door with real-time risk assessments of your logons Jan Ketil Skanke COO and Principal Cloud Architect CloudWay.
Accelerate Office 365 Adoption Through Microsoft FastTrack Services
Microsoft products for non-profits
Learn how to use and customize the Dynamics AX interactive help system
Automating security for better, continuous compliance in the cloud
Introduction to ASP.NET Core 1.0
Five cool things you can do with Windows PowerShell on Office 365
Microsoft To-Do Preview
MDM Migration Analysis Tool (MMAT)
Overview: Dynamics 365 for Project Service Automation
Keep up with Office 365 evolution in the real world
Understand your Azure cloud assets dependencies with BMC Discovery
Surviving identity management in a hybrid world
Learn how to leverage the Microsoft Store for Education in your school
Sami Laiho AMA - Ask Me Anything
Breaking Down the Value of A Yammer Post: 20 Things to Do
Cool Microsoft Edge Tips and Tricks
Getting the most out of Azure resources with Azure Advisor
Manage your App Service resources using Command line tools
“Hey Mom, I’ll Fix Your Computer”
4/21/2019 7:09 AM THR2098 Unlock New Opportunities with Nintex Hawkeye Process Intelligence and Workflow Analytics Sr. Product.
Business Continuity and the Microsoft Cloud
4/28/2019 3:30 AM THR1061 Learn how Dynamics 365, Office 365 and related applications work together to transform the workplace Donna Edwards Solution Architect.
Consolidate, manage, backup, and secure your cloud content
Designing Bots that Fit Your Organization
Ask the Experts: Windows 10 deployment and servicing
Passwordless Service Accounts
Digital Transformation: Putting the Jigsaw Together
WCF and .NET Framework Microservices in Containers
Diagnostics and troubleshooting in Azure App Service Support Center
Optimizing your content for search and discovery
Microsoft Virtual Academy
Presentation transcript:

Using AAD B2C for WordPress & Secure Deployment Scenario 9/14/2018 5:31 AM Using AAD B2C for WordPress & Secure Deployment Scenario Bill Hughes @_billhughes Technical Architect – Concurrency © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

Powers 28% of all websites 59% market share of all sites using CMS More than 50,000 plugins available Enables Forums, Blogs, eCommerce, etc…

Azure Active Directory B2C Social IDs Business & Government IDs contoso Customers Apps Analytics CRM and Marketing Automation Business Provide branded (white-label) registration and login experiences Securely authenticate your customers using their preferred identity provider Capture login, preference, and conversion data for customers

WordPress Plugin https://github.com/AzureAD/active-directory-b2c-wordpress-plugin-openidconnect

What we are using https://github.com/AzureAD/active-directory-b2c-wordpress-plugin-openidconnect/pull/14

Demo Using the plugin 9/14/2018 5:31 AM © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

Installation & Configuration 1) Create B2C items & Graph API 2) Download plugin from GitHub 3) Unzip, rename & rezip plugin 4) Upload plugin to WordPress 5) Configure plugin settings for: B2C tenant, policy, Graph API, etc…

Demo Plugin Installation & Configuration 9/14/2018 5:31 AM © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

Secure and reliable Protect your customers’ identities 9/14/2018 5:31 AM Secure and reliable Users can only view their own accounts and profiles Additional security layers (MFA) Standards-based authentication Security reports and auditing Protect your customers’ identities © 2013 Microsoft Corporation. All rights reserved. Microsoft, Windows, and other product names are or may be registered trademarks and/or trademarks in the U.S. and/or other countries. The information herein is for informational purposes only and represents the current view of Microsoft Corporation as of the date of this presentation. Because Microsoft must respond to changing market conditions, it should not be interpreted to be a commitment on the part of Microsoft, and Microsoft cannot guarantee the accuracy of any information provided after the date of this presentation. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

Intelligent protection with Azure Active Directory For MSA 9.8M users marked as compromised monthly 115.5M blocked login attempts or 15.8M credentials daily 1.7M users protected by real-time detection and challenges each day For Azure AD 1M users marked as Med/High risk monthly across 50K tenants 2.4M users marked as at risk monthly over 100K tenants 10K users confirmed to be compromised each month

Build your solution your way for Identity Experts Step-by- step user journeys Open standards Connect to a store or migrate its users Conditional branching Enrich user journeys Connect with existing systems Identity Experts Integrate with any SAML, OIDC, WsFed, or WsTrust-based identity provider Connect to your existing user stores or migrate from those systems seamlessly Connect with existing CRM systems, marketing tools, and databases Use REST APIs to enrich claims and empower user journeys Customize your user journeys with conditional branching Define user journeys between claims providers step-by-step

What does a secure deployment mean?

How to enhance our security 1 Installation = 1 App in B2C Policy Isolation Should my deployment have SSO between installations? Do we need MFA? Secure my configuration Who are my admins? Do I need to consider any compliance scenarios? Who has access to my WordPress DB? Where is my environment hosted?

Resources Docs & samples: https://aka.ms/aadb2c Service blog: https://blogs.msdn.microsoft.com/azureadb2c/ Pricing: https://azure.microsoft.com/en-us/pricing/details/active-directory-b2c/ Feedback: aaddev@microsoft.com UserVoice: https://feedback.azure.com/forums/169401-azure-active-directory/category/160596-b2c © 2014 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

Free IT Pro resources To advance your career in cloud technology Microsoft Ignite 2016 9/14/2018 5:31 AM Free IT Pro resources To advance your career in cloud technology Plan your career path IT Pro Career Center http://www.microsoft.com/itprocareercenter Get started with Azure IT Pro Cloud Essentials https://www.microsoft.com/itprocloudessentials Demos and how-to videos Microsoft Mechanics https://www.microsoft.com/mechanics Connect with peers and experts Ask questions, get answers, exchange ideas https://techcommunity.microsoft.com Azure Solutions Get started with Azure Solutions today http://azure.com/solutions Azure monthly webinar series Join live or watch on-demand http://aka.ms/AzureMonthlyWebinar © 2016 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

Q&A

Please evaluate this session Tech Ready 15 9/14/2018 Please evaluate this session From your Please expand notes window at bottom of slide and read. Then Delete this text box. PC or tablet: visit MyIgnite https://myignite.microsoft.com/evaluations Phone: download and use the Microsoft Ignite mobile app https://aka.ms/ignite.mobileapp Your input is important! © 2012 Microsoft Corporation. All rights reserved. Microsoft, Windows, Windows Vista and other product names are or may be registered trademarks and/or trademarks in the U.S. and/or other countries. The information herein is for informational purposes only and represents the current view of Microsoft Corporation as of the date of this presentation. Because Microsoft must respond to changing market conditions, it should not be interpreted to be a commitment on the part of Microsoft, and Microsoft cannot guarantee the accuracy of any information provided after the date of this presentation. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

9/14/2018 5:31 AM © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

Azure AD B2B Collaboration 9/14/2018 5:31 AM To B2C or To B2B ? Azure AD B2B Collaboration Azure AD B2C What is it for? IT Pros providing access to their organization’s data and apps to a partner organization & collaborators Developers working on consumer- & citizen-facing mobile & web apps Who is it for? Partner users acting *on behalf of*, i.e., as representatives or employees of their organizations Consumers and citizens acting as themselves Manageability Access reviews, email verification, allowlist/denylist, etc. govern access to host application and resources Self-service: Users manage their own profiles. Discoverability Partner users are discoverable and can see other users from their own organization (subject to policy) Consumers and citizens are invisible to other consumers and citizens. Privacy and consent are paramount. © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.