Introduction Please answer the survey questions posted at the end of this meeting. Let us know what sessions you want! Josh Topal at

Slides:



Advertisements
Similar presentations
Office 365 Identity June 2013 Microsoft Office365 4/2/2017
Advertisements

Agenda AD to Windows Azure AD Sync Options Federation Architecture
Core identity scenarios Federation and synchronization 2 3 Identity management overview 1 Additional features 4.
 This session details common scenarios for deploying Office 365 services. Office 365 provides a breadth of capability, but often there is a key scenario.
Configuring SharePoint 2013 and Office 365 Hybrid – Part 1
Implementing and Administering AD FS
Hybrid Search with SharePoint 2013 and Office 365 Brendan Griffin.
Identity management integration options for Office 365
Federated sign-in WS-Federation WS-Trust SAML 2.0 Metadata Shibboleth Graph API Synchronize accounts Authentication.
Sessions about to start – Get your rig on!. Notes from the field – Implement Hybrid Search and OneDrive for Business Chris Zhong - Microsoft Aaron Dinnage.
Active Directory Integration with Microsoft Office 365
Active Directory Integration with Microsoft Office 365 Ross Adams & Jono Luk Program Managers Microsoft Corporation OSP321.
TechEd /20/2017 2:02 AM © 2013 Microsoft Corporation. All rights reserved. Microsoft, Windows, and other product names are or may be registered trademarks.
Managing Client Access
Module 4 Managing Client Access. Module Overview Configuring the Client Access Server Role Configuring Client Access Services for Outlook Clients Configuring.
Scenario covered in this presentation Separate credential from on- premises credential Authentication occurs via cloud directory service Does not.
Module 10: Designing an AD RMS Infrastructure in Windows Server 2008.
OUC204. Recently Announced… Identity Integration Options 2 3 Identity Management Overview 1.
Timothy Heeney| Microsoft Corporation. Discuss the purpose of Identity Federation Explain how to implement Identity Federation Explain how Identity Federation.
Module 4: Add Client Computers and Devices to the Network.
MCSE Guide to Microsoft Exchange Server 2003 Administration Chapter Four Configuring Outlook and Outlook Web Access.
©Kwan Sai Kit, All Rights Reserved Windows Small Business Server 2003 Features.
5 | Microsoft Confidential 6 | Microsoft Confidential.
Configuring and Troubleshooting Identity and Access Solutions with Windows Server® 2008 Active Directory®
Single Sign-On with Microsoft Azure
Module 5: Designing a Terminal Services Infrastructure.
…. PrePlanPrepareMigratePost Pre- Deployment PlanPrepareMigrate Post- Deployment First Mailbox.
Cloud Identity Windows Azure Active Directory Cloud Identity & Directory SyncFederated Identity Appropriate for Smaller orgs without.
Microsoft NDA Confidential Enabling users to be productive, responsibly Finding the right balance Devices & Experiences Users Want Applications and.
Microsoft ® Official Course Module 13 Implementing Windows Azure Active Directory.
Empowering people-centric IT Unified device management Access and information protection Desktop Virtualization Hybrid Identity.
Paul Andrew. Recently Announced… Identity Integration Options 2 3 Identity Management Overview 1.
Office 365 deployment choices Cutover, Staged, Hybrid What is AD FS (Active Directory Federation Services) Attribute Stores, ADFS Configuration Database.
Module 12 Upgrading from Exchange Server 2003 or Exchange Server 2007 to Exchange Server 2010.
Office 365: Identity and Access Solutions Suresh Menon Technology Specialist – Office 365 Microsoft Corporation India.
Version 2.0 for Office 365. Day 1 Administering Office 365 Day 2 Administering Office 365 Office 365 Overview & InfrastructureAdministering Lync Online.
Office 365 Directory Synchronization Update: Deploying Password Sync.
Access and Information Protection Product Overview Andrew McMurray Technical Evangelist – Windows
Bronze Sky customer premises AD MS Online Directory Sync Provisioning platform Provisioning platform Lync Online Lync Online SharePoint Online SharePoint.
Get identities to the cloud Mix on-premises and cloud identity for improved PC, mobile, and web productivity Cloud identities help you run your business.
Configuring and Troubleshooting Identity and Access Solutions with Windows Server® 2008 Active Directory®
Implementing Microsoft Exchange Online with Microsoft Office 365
Configuration Manager and InTune Gemeinsam oder einsam?
Microsoft Virtual Academy Preparing for the Windows 8.1 MCSA Module 5: Managing Devices & Resource Access.
Module 10: Identity and Access Services in Windows Server 2008 Active Directory.
DNS DNS changes required to validate domains in Office 365 UPN – User Principal Name Every user must have a UPN UPN suffixes must match a validated.
BE-com.eu Brussel, 26 april 2016 EXCHANGE 2010 HYBRID (IN THE EXCHANGE 2016 WORLD)
Agenda  Microsoft Directory Synchronization Tool  Active Directory Federation Server  ADFS Proxy  Hybrid Features – LAB.
Managing Office 365 Identities and Requirements Question Answer
Managing Office 365 Identities and Requirements.
 Step 2 Deployment Overview  What is DirSync?  Purpose – What does it do?  Understanding Synchronization  Understanding Coexistence  Understanding.
 What is DirSync?  Purpose – What does it do?  Understanding Synchronization  Understanding Coexistence  Demo.
ADFS - Does it Still have a Place? Fitting into the EMS puzzle Frank C. Drewes III 2016 Redmond Summit | Identity.
Office 365 Migration Challenges Drew St. John 2016 Redmond Summit | Identity Without Boundaries May 24, 2016 Consultant
MCSA Windows Server 2012 Pass Upgrading Your Skills to MCSA Windows Server 2012 Exam By The Help Of Exams4Sure Get Complete File From
Protect your data Enable your users Desktop Virtualization Information protection Mobile device & application management Identity and Access Management.
Identity; What you need to know to be in the Microsoft Cloud
Microsoft - Managing Office 365 Identities and Requirements
6/17/2018 5:54 AM OSP322 Getting the best of both worlds, making the most of SharePoint hybrid search solutions Shyam Narayan Microsoft © 2013 Microsoft.
Microsoft Online Services Partner Deployment Training for Office 365
Cloud Connect Seamlessly
Hybrid Search Planning Implementation.
05 | AD to Windows Azure AD IT Professionals
Microsoft Ignite NZ October 2016 SKYCITY, Auckland.
SharePoint Online Hybrid – Configure Outbound Search
Office 365 Identity Management
Office 365 Identity Management
M3: Guidance for choosing the right integration option
Microsoft 365 Business Technical Fundamentals Series
10 | Implementing Directory Synchronization
Presentation transcript:

Introduction

Please answer the survey questions posted at the end of this meeting. Let us know what sessions you want! Josh Topal at Feel free to give feedback too.

Module 1: Understanding Identities Module 2: Environment Preparation for Single Sign-On & Directory Synchronization (DirSync) Module 3: Deploying SSO and ADFS 2.0 Module 4: Deploying Directory Synchronization (DirSync)

Server Technologies Active Directory Active Directory Federation Services (AD FS) Windows PowerShell™ 2.0 Network Technologies AD sites, trusts, & topology DNS & related technologies Wide area connectivity: networks, equipment, bandwidth, & latency Firewall technologies SSL certificates

Module 1 Understanding Identities

Understanding Identities Understanding Single Sign-On Understanding DirSync

Cloud Identity Separate credential from corporate credential Authentication occurs via cloud directory service Password policy stored in Office 365 Federated Identity Same credential as corporate credential Authentication occurs via on- premises Active Directory service Password policy is stored on- premises Requires Directory Synchronization

Cloud IdentityCloud Identity + DirSyncFederated Identity* Scenario  Smaller organizations without on-premises Active Directory  Medium to Large organizations with Active Directory on-premises  Large enterprise organizations with Active Directory on-premises Pros  Does not require on-premises server deployment  “Source of Authority” is on- premises  Enables coexistence  Password Synchronization (Optional)  Single Sign-On experience  “Source of Authority” is on- premises  2-Factor Authentication options  Enables coexistence Cons  No Single Sign-On  No 2-Factor Authentication options  2 sets of credentials to manage with, potentially, different password policies  No Single Sign-On  No 2-Factor Authentication options  2 sets of credentials to manage with, potentially, different password policies  Requires on-premises server deployment  Requires on-premises server deployment in high availability scenario * Requires DirSync

Understanding Single Sign- On (Federated Identity)

Cloud IdentityCloud Identity + DirSyncFederated Identity* Scenario Smaller organizations without on-premises Active Directory Medium to Large organizations with on-premises Active Directory Large enterprise organizations with on-premises Active Directory Pros Does not require on- premises server deployment “Source of Authority” is on- premises Enables coexistence Password Synchronization (Optional) Single Sign-On experience “Source of Authority” is on- premises 2-Factor Authentication options Enables coexistence Cons No Single Sign-On No 2-Factor Authentication options 2 sets of credentials to manage with, potentially, different password policies No Single Sign-On No 2-Factor Authentication options 2 sets of credentials to manage with, potentially, different password policies Requires on-premises server deployment Requires on-premises server deployment in high-availability scenario * Requires DirSync

Policy Control Access Control Reduced Support Calls Security

Understanding DirSync

Cloud Identity Cloud Identity + DirSync Federated Identity* Scenario Smaller organizations without on-premises Active Directory Medium to Large organizations with Active Directory on-premises Large enterprise organizations with Active Directory on- premises Pros Does not require on- premises server deployment “Source of Authority” is on-premises Enables coexistence Password Synchronization (Optional) Single Sign-On experience “Source of Authority” is on- premises 2-Factor Authentication options Enables coexistence Cons No Single Sign-On No 2-Factor Authentication options 2 sets of credentials to manage with, potentially, different password policies No Single Sign-On No 2-Factor Authentication options 2 sets of credentials to manage with, potentially, different password policies Requires on-premises server deployment Requires on-premises server deployment in high-availability scenario * Requires DirSync

FeatureDirsync +Password Sync SSO with AD FS Use same username + password Control password policy on-premises No password re-entry if on-premises Client access filtering Authentication occurs on-premises (no credentials on cloud) Support for multi-forest configurations (FIM)

Module 1 Environment Preparation

DNS Preparation Active Directory Preparation Office 365 OnRamp

DNS Preparation

Active Directory(AD) Preparation

Office 365 OnRamp

OnRamp for Office 365 is an automated assistance tool that helps you gather configuration requirements and perform deployment readiness checks against your on-premises environment. OnRamp can accelerate the deployment timeline, especially for organizations with requirements such as identity federation or hybrid deployment. Tool is available at:

Module 3: Deploying SSO & ADFS 2.0

Deploying Active Directory Federation Server Deploying Active Directory Federation Server Proxy

AD FS 2.x Server Default topology for Office 365 is an AD FS 2.x federation server farm that consists of multiple servers hosting your organization’s Federation Service Recommend using at least two federation servers in a load-balanced configuration AD FS 2.x Proxy Server Federation server proxies are used to redirect client authentication requests coming from outside your corporate network to the federation server farm Federation server proxies should be deployed in the DMZ

Windows Server 2008/2008R2 or Windows Server 2012PowerShellWeb Server (IIS).NET 3.5 SP1Windows Identity FoundationPublicly registered domain nameSSL Trusted Public CertificatesWindows Azure Active Directory Module for Windows PowerShellMicrosoft Online Sign In AssistantHigh availability design

Internet Explorer 8.0 or laterFirefox 10.0Chrome 17.0 or laterSafari 5.0 or laterMicrosoft Office 2010/2007 (Latest Service Pack)Microsoft Office for Mac 2011 (Latest Service Pack)Microsoft Office 2008 for Mac version Office 365 Desktop Setup (Suggested)Microsoft Online Sign In Assistant

1) Single server configuration 2) AD FS 2.x Server Farm and load-balancer 3) AD FS 2.x Proxy Server or UAG/TMG (External Users, Active Sync, Down-level Clients with Outlook) Enterprise Perimeter AD FS 2.x Server Proxy External User Internal user Active Directory AD FS 2.x Server Proxy

Active Directory running in Windows Server 2003, Windows Server 2008, or Windows Server 2008 R2 with a functional level of mixed or native mode AD FS 2.x deployed on Windows Server 2008/R2 or Windows Server 2012 AD FS 2.x Proxy deployed, if some users are connecting from outside the company’s network Windows Azure Active Directory Module for Windows PowerShell to establish a trust with Office 365 Required updates installed for Office 365 A unique third-party certificate when installing and configuring federation servers and federation server proxies

Deploying Active Directory Federation Server

AD FS 2.x Server The default topology for Office 365 is an AD FS 2.x federation server farm that consists of multiple servers hosting your organization’s Federation Service We recommend the use of at least two federation servers in a load-balanced configuration

Buy and request a certificate from a Third- Party SSL Certificate Provider

Select the newly imported and generated certificate

Buy and request a certificate from a Third- Party SSL Certificate Provider

CommandDescription $cred=Get-Credential Prompt for Office 365 credentials and store them in a variable Connect-MsolService – Credential $cred Connect to Office 365 using stored credentials Set-MSOLAdfscontext -Computer Specify the local AD FS 2.x Server Convert-MSOLDomainToFederated –Domainname Convert the standard local domain to an Identity Federated Domain Get-MSOLFederationProperty Show Identity Federation Proprieties

Deploying Active Directory Federation Server Proxy

AD FS 2.x Proxy Server Federation server proxies are used to redirect client authentication requests coming from outside your corporate network to the federation server farm Federation server proxies should be deployed in the DMZ

External-facing federation server proxies are required if: An organization will use Outlook clients Users will access Office 365 for enterprise from home or public locations Users will access Office 365 for enterprise via mobile devices Prerequisites to deploy federation server proxies are: Federation server proxies deployed in the edge/DMZ network Federation servers & federation server proxies able to communicate over TCP 443 AD FS 2.x deployed on a Windows Server 2008/R2 or Windows Server 2012 Internet Information Services (IIS) 7 or 7.5 installed + Imported Certificate.NET Framework 3.5 SP1 installed

AD FS 2.x and SSO are now in place, but there are no users inside the Office 365 subscription We will need to replicate our users from the local AD to Office 365 We will deploy and use DirSync for that purpose (see Module 4)

Deployment Considerations

Number of usersMinimum number of servers Fewer than 1,000 users 0 dedicated federation servers 0 dedicated federation server proxies 1 dedicated NLB server 1,000 to 15,000 users 2 dedicated federation servers 2 dedicated federation server proxies 15,000 to 60,000 users Between 3 and 5 dedicated federation servers At least 2 dedicated federation server proxies

Use the following method only if this condition is true: The problem is caused by an on premise service outage that requires immediately restoring user access or the Active Directory Federation Services (AD FS) 2.0 server is available. Additional Info: kb/ /en-us kb/ /en-us

$cred = Get-Credential When you are prompted, enter Office 365 administrator credentials that are not SSO-enabled Connect-MsolService –credential $cred Set-MsolADFSContext –Computer Note In this command, the placeholder represents the name of the primary AD FS 2.x server Convert-MSOLDomainToStandard –DomainName - SkipUserConversion $false -PasswordFile c:\userpasswords.txt The userpasswords.txt file will contain the Cloud Identity passwords for all users.

The AD FS 2.x federation service can support access policies for allowing or denying access based upon the combination of the user requesting access and the IP address of his devices. ScenarioDescription Block all external access to Office 365 Office 365 access is allowed from all clients on the internal corporate network, but requests from external clients are denied based on the IP address of the external client. Block all external access to Office 365, except Exchange ActiveSync Office 365 access is allowed from all clients on the internal corporate network, as well as from any external client devices, such as smart phones, that make use of Exchange ActiveSync. All other external clients, such as those using Outlook, are blocked. Block all external access to Office 365, except for browser-based applications Blocks external access to Office 365, except for passive (browser-based) applications such as Outlook Web Access or SharePoint Online. Block all external access to Office 365 for members of designated Active Directory groups This scenario is used for testing and validating client access policy deployment. It blocks external access to Office 365 only for members of one or more Active Directory group. It can also be used to provide external access only to members of a group.

Module 4: Deploying Directory Synchronization (DirSync)

DirSync Requirements Overview

Windows Installer 4.5 or later Windows PowerShell version 2.0 Microsoft.NET Framework version 3.5 or later Windows Server 2008 R2 x64 with the latest service pack installed

Number of objects in Active Directory CPUMemoryHard disk size Fewer than 10, GHz4 GB70 GB 10,000–50, GHz4 GB70 GB 50,000–100, GHz16 GB100 GB 100,000–300, GHz32 GB300 GB 300,000–600, GHz32 GB450 GB More than 600, GHz32 GB500 GB

DirSync Synchronization

DirSync activation could require up to 48 hours, plan this activity in advance!

Troubleshooting

Reference Number will be always different

Q&A and Feedback