11/15/2018 3:42 AM © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN.

Slides:



Advertisements
Similar presentations
Federated sign-in WS-Federation WS-Trust SAML 2.0 Metadata Shibboleth Graph API Synchronize accounts Authentication.
Advertisements

Empower Enterprise Mobility Jasbir Gill Azure Mobility.
Empowering people-centric IT Unified device management Access and information protection Desktop Virtualization Hybrid Identity.
Access and Information Protection Product Overview Andrew McMurray Technical Evangelist – Windows
Get identities to the cloud Mix on-premises and cloud identity for improved PC, mobile, and web productivity Cloud identities help you run your business.
Access resources in a federation partner organization.
Agenda  Microsoft Directory Synchronization Tool  Active Directory Federation Server  ADFS Proxy  Hybrid Features – LAB.
Hybrid Identity Deep dive Ross Adams 2016 Redmond Summit | Identity Without Boundaries May 25 th 2016 Azure AD
Recording Brief EMS Partner Bootcamp Variables Values Module Title
Identity; What you need to know to be in the Microsoft Cloud
Active Directory Modernization Technical competitive comparison
Implementing and Managing Azure Multi-factor Authentication
Deployment Planning Services
Microsoft Ignite /27/2018 9:00 AM THR2016
Deploy and get started with Microsoft Advanced Threat Analytics
Enterprise Security in Practice
5/31/2018 3:40 PM BRK3113 How Microsoft IT builds Privileged Access Workstation using Windows 10 and Windows Server 2016 Jian (Jane) Yan Sr. Program Manager.
Identity & Access Management for a cloud-first, mobile-first world
Four common problems to avoid with your AD FS environment
Journey to Microsoft Secure Cloud
Cloud-First, Modern Windows Management and Security
O365 & AZURE ADDS Mladen Baranek, Miadria
Developing Hybrid Apps on Microsoft Azure Stack
Azure AD for the client management guy (or gal!)
6/19/2018 2:57 AM THR3092 Monitor and investigate actions on your user and data with alerts, insights and reports Binyan Chen Program Manager II, Office.
Microsoft /20/2018 9:26 AM BRK1037 Win the IT security battle: automate password changes, privileged access & Minimize Cyber Losses Christopher.
6/25/ :13 PM BRK1076 Make Windows devices more secure by taking them out of your existing infrastructure Chris Rhodes & Andrew Bettany MCTs & MVPs.
Microsoft Virtual Academy
The power of common identity across any cloud
Directory Synchronization in Office 365
Examine common architectures for hybrid identity
Microsoft Ignite /31/ :08 AM
Wait, Microsoft is in the Security Game?
9/13/2018 4:54 PM BRK How to get Office 365 to the next level with Azure Active Directory Premium Brjann Brekkan Program Manager Lead – Customer.
11/8/2018 5:23 PM © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN.
Company Overview & Strategy
Office 365 Identity Management
11/17/2018 9:32 PM © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN.
05 | AD to Windows Azure AD IT Professionals
Microsoft Ignite /20/2018 2:21 PM
Ensure users have the right access with Azure Active Directory
Access and Information Protection Product Overview October 2013
11/27/ :16 AM © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN.
Microsoft Ignite NZ October 2016 SKYCITY, Auckland.
11/29/ :53 AM © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN.
11/29/2018 2:19 PM © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN.
12/1/ :04 AM © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN.
Microsoft Virtual Academy
M7: New Features for Office 365 Identity Management
Five mistakes to avoid when deploying Enterprise Mobility + Security
Office 365 Identity Management
12/28/2018 3:03 PM © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN.
Microsoft Virtual Academy
1/3/2019 1:47 PM © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS.
1/16/2019 4:44 PM © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN.
M3: Guidance for choosing the right integration option
Enabling the hybrid cloud with remote access appliances
Choosing the right authentication method for Azure AD
Surviving identity management in a hybrid world
4/3/2019 3:20 PM © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS.
Protecting your data with Azure AD
4/9/2019 5:05 AM © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS.
4/9/ :42 PM © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN.
System Center Marketing
Empower your users with Azure Active Directory Premium
Choosing the right authentication method for Azure Active Directory
7/18/2019 7:04 PM Pregled scenarijev uporabe storitve Azure Active Directory pri integraciji in nadzoru identitete uporabnika Gregor Šuster Microsoft Slovenija.
Azure AD Simon May Technical Evangelist.
Azure Active Directory Identity Protection
Microsoft Virtual Academy
Presentation transcript:

11/15/2018 3:42 AM © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

11/15/2018 3:42 AM Secure access to Office 365/Azure Active Directory with new features in AD FS in Windows Server 2019 and Azure AD password protection BRK3226 Anand Yadav © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

Choosing the right sign-in

Choosing the right sign-in Password hash synchronization (PHS) Pass- through Authentication (PTA) Active Directory Federation Service (AD FS) Authentication in cloud Password hash is synced to Azure Username + Password WIA with Seamless SSO Authentication in cloud + on-premises agent Username + Password WIA with Seamless SSO On-premises authentication Username + Password, WIA, samAccountName, Certificate, Smart-Card

Users actively use AD FS to sign-in to Azure 71+million Users actively use AD FS to sign-in to Azure

High availability hybrid auth in Azure

On-premises only AD FS On-premises AD FS + WAP User On-premises AD FS Infrastructure

On-premises only AD FS On-premises AD FS + WAP User On-premises AD FS Infrastructure

AD FS in Azure On-premises Azure https://aka.ms/AdfsInAzure 11/15/2018 3:42 AM AD FS in Azure VPN / Express Route On-premises Azure AD FS + WAP AD FS + WAP AD FS + WAP On-premises AD FS Infrastructure Azure Traffic Manager AD FS Infrastructure https://aka.ms/AdfsInAzure © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

Securing organizational resources

Securing organizational resources Operations Admin access Users MFA Privileged Access Workstations Privileged Identity Management Extranet lockout / Extranet Smart lockout MFA for external access Stronger passwords Connect Health Audit logs Lock-down network

Demo: Extranet Smart Lockout – More secure more productive

Stay ahead with Connect Health for AD FS

360º view of your sign-ins on-premises Continuous infrastructure health monitoring Critical alerts email notifications Application usage analytics Performance trend analysis Bad password attempts report Risky-IP report

Risky IP Report

Strong passwords with Azure AD password protection

The threats are real, global, and target all of us 1.29 Billion Authentications blocked in August 2018

81% of data breaches involved weak, default, or stolen passwords 11/15/2018 3:42 AM 81% of data breaches involved weak, default, or stolen passwords © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

Common Passwords Attempted in Password Spray Attacks Spring 2018 Summer September 1234 Winter Football Your Company Name

Azure AD Password Protection Power of Azure – in cloud and on-premises Powered by Azure Intelligence from monitoring billions of authentication attempts every day Custom list Define custom list of weak strings for your organization Protect users on-premises Simple deployment on-premises to leverage the Azure logic and ensure stronger passwords

52% As high as weak passwords were found and blocked by Azure AD Password Protection

Under the hood Password change Normalization Strength check Allowed / Blocked All password change or reset events are processed by Azure AD Password Protection Normalize the passwords for general transformations, like ‘0’ for ‘O’ and ‘!’ for an ‘i’ Password strings are checked to ensure they have enough score to be considered as a strong password Based on the normalization and strength check, password is allowed / blocked

Locked down network access Audit Mode No internet Internet connectivity DC + DC Agent Server + Proxy Agent Azure DC + DC Agent

Locked down network access Enforced No internet Internet connectivity DC + DC Agent Server + Proxy Agent Azure DC + DC Agent

Demo Stronger passwords with Azure AD password protection

Azure AD Password Protection Cloud intelligence to ensure strong passwords Dynamic banning of passwords based on known bad patterns and those you define. Built for hybrid environments. Built for secure no-internet zone domain controllers Unified admin experience for on-premises and cloud. Support for multi-forest environment High availability architecture

Please evaluate this session Your feedback is important to us! 11/15/2018 3:42 AM Please evaluate this session Your feedback is important to us! Please evaluate this session through MyEvaluations on the mobile app or website. Download the app: https://aka.ms/ignite.mobileApp Go to the website: https://myignite.techcommunity.microsoft.com/evaluations © 2014 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

11/15/2018 3:42 AM © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.