Download presentation
Presentation is loading. Please wait.
Published byMadlyn Flowers Modified over 6 years ago
1
5/17/2018 Productivity and protection for your employees, partners, and customers with Azure Active Directory Alex Simons Partner Director Program Mgmt Microsoft Identity Division Nasos Kladakis Senior Product Marketing Mgr Microsoft Identity Division © 2012 Microsoft Corporation. All rights reserved. Microsoft, Windows, and other product names are or may be registered trademarks and/or trademarks in the U.S. and/or other countries. The information herein is for informational purposes only and represents the current view of Microsoft Corporation as of the date of this presentation. Because Microsoft must respond to changing market conditions, it should not be interpreted to be a commitment on the part of Microsoft, and Microsoft cannot guarantee the accuracy of any information provided after the date of this presentation. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.
2
Is the new control plane
5/17/ :50 AM Identity Is the new control plane On-premises / Private cloud © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION. 2
3
Identity as the Control Plane
Build 2012 5/17/2018 Identity as the Control Plane Partners Customers Commercial IdPs Consumer IdPs Azure Public cloud Microsoft Azure Active Directory Cloud Windows Server Active Directory On- premises Azure AD Connect BYO
4
Azure Active Directory in the Marketplace Every Office 365 and Microsoft Azure customer uses Azure Active Directory organizations 12.8M users 950M 3rd party apps in Azure AD 272K paid Azure AD / EMS customers 56K of Fortune 500 companies use Azure AD 90% Governance Security Reporting Access Reviews HR App Integration Microsoft Authenticator - Password-less Access Self-Service capabilities SSO to SaaS Azure AD B2C B2B collaboration MDM-auto enrollment / Enterprise State Roaming Privileged Identity Management Azure AD Join Remote Access to on-premises apps Addition of custom cloud apps Conditional Access Multi-Factor Authentication Identity Protection Dynamic Groups Azure AD DS Provisioning-Deprovisioning Azure AD Connect Connect Health Office 365 App Launcher Group-Based Licensing Access Panel/MyApps +30% YoY +45% YoY +200% YoY +74% YoY © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.
5
Azure Active Directory
Azure AD Connect B2B collaboration Provisioning-Deprovisioning Conditional Access SSO to SaaS Self-Service capabilities Connect Health Multi-Factor Authentication Addition of custom cloud apps Access Panel/MyApps Dynamic Groups Identity Protection Remote Access to on-premises apps Azure AD B2C Group-Based Licensing Privileged Identity Management Azure Active Directory I want to quickly deploy applications to devices, do more with less and automate Join/Move/Leave processes I need my customers, partners, and users to access the apps they need from everywhere and collaborate seamlessly [dev use case] I want to provide my employees secure and easy access to every application from any location and any device I need to comply with industry regulation and national data protection laws I want to protect access to my resources from advanced threats Microsoft Authenticator - Password-less Access Azure AD Join MDM-auto enrollment / Enterprise State Roaming Security Reporting Azure AD DS Office 365 App Launcher HR App Integration Access Reviews
6
Identity and Access Management Use Cases
Azure AD Connect B2B collaboration Provisioning-Deprovisioning Conditional Access SSO to SaaS Self-Service capabilities Connect Health Multi-Factor Authentication 1 I want to provide my employees secure and easy access to every application from any location and any device Addition of custom cloud apps Access Panel/MyApps Dynamic Groups Identity Protection 2 I want to quickly deploy applications to devices, do more with less and automate Join/Move/Leave processes Remote Access to on-premises apps Azure AD B2C Group-Based Licensing Privileged Identity Management 3 I need my customers and partners to access the apps they need from everywhere and collaborate seamlessly Microsoft Authenticator - Password-less Access Azure AD Join MDM-auto enrollment / Enterprise State Roaming Security Reporting 4 I want to protect access to my resources from advanced threats 5 I need to comply with industry regulation and national data protection laws Azure AD DS Office 365 App Launcher HR App Integration Access Reviews 6 I want to write applications that work with my corporate identities in Azure Active Directory
7
Identity and Access Management Use Cases
1 I want to provide my employees secure and easy access to every application from any location and any device Microsoft Azure Active Directory Remote Access to on-premises apps Azure AD Connect SSO to SaaS Access Panel/MyApps Self-Service capabilities Azure AD DS Microsoft Authenticator - Password-less Access Office 365 App Launcher Conditional Access Multi-Factor Authentication On- premises Azure AD Connect
8
Pass-through authentication is Generally Available Identity synchronization + Pass-through authentication with Seamless SSO Microsoft Azure Active Directory Office 365, SaaS, and LoB apps Identity synchronization using Azure AD Connect Pass-through authentication On- premises Password validation requests are sent to Windows Server Active Directory via Pass-through authentication Pass-through authentication agent
9
3rd party apps and Azure AD
5/17/ :50 AM 3rd party apps and Azure AD Google Apps Workday ServiceNow Cornerstone OnDemand SuccessFactors 272,000 Salesforce Clever Workplace by Facebook Active applications Canvas Zscaler Two © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.
10
https://appX-contoso.msappproxy.net/
5/17/ :50 AM Azure Active Directory Application Proxy Single Sign-on to on premises applications Microsoft Azure Active Directory Azure or 3rd Party IaaS connector Application Proxy DMZ connector connector connector app app app app © 2013 Microsoft Corporation. All rights reserved. Microsoft, Windows, and other product names are or may be registered trademarks and/or trademarks in the U.S. and/or other countries. The information herein is for informational purposes only and represents the current view of Microsoft Corporation as of the date of this presentation. Because Microsoft must respond to changing market conditions, it should not be interpreted to be a commitment on the part of Microsoft, and Microsoft cannot guarantee the accuracy of any information provided after the date of this presentation. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.
11
PingAccess for Azure Active Directory
12
https://appX-contoso.msappproxy.net/
5/17/ :50 AM Azure Active Directory Application Proxy + PingAccess Access even more on premises web applications Microsoft Azure Active Directory Azure or 3rd Party IaaS connector Application Proxy DMZ connector connector connector app app app app Custom app © 2013 Microsoft Corporation. All rights reserved. Microsoft, Windows, and other product names are or may be registered trademarks and/or trademarks in the U.S. and/or other countries. The information herein is for informational purposes only and represents the current view of Microsoft Corporation as of the date of this presentation. Because Microsoft must respond to changing market conditions, it should not be interpreted to be a commitment on the part of Microsoft, and Microsoft cannot guarantee the accuracy of any information provided after the date of this presentation. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.
13
Identity and Access Management Use Cases
Azure AD Connect B2B collaboration Provisioning-Deprovisioning Conditional Access SSO to SaaS Self-Service capabilities Connect Health Multi-Factor Authentication I want to provide my employees secure and easy access to every application from any location and any device Addition of custom cloud apps Access Panel/MyApps Dynamic Groups Identity Protection 2 I want to quickly deploy applications to devices, do more with less and automate Join/Move/Leave processes Remote Access to on-premises apps Azure AD B2C Group-Based Licensing Privileged Identity Management 3 I need my customers and partners to access the apps they need from everywhere and collaborate seamlessly Microsoft Authenticator - Password-less Access Azure AD Join MDM-auto enrollment / Enterprise State Roaming Security Reporting 4 I want to protect access to my resources from advanced threats 5 I need to comply with industry regulation and national data protection laws Azure AD DS Office 365 App Launcher HR App Integration Access Reviews 6 I want to write applications that work with my corporate identities in Azure Active Directory
14
Identity and Access Management Use Cases
2 I want to quickly deploy applications to devices, do more with less and automate Join/Move/Leave processes HR app Microsoft Azure Active Directory Azure AD Connect Provisioning-Deprovisioning Dynamic groups SSO to SaaS Self-Service capabilities Microsoft Authenticator - Password-less Access Remote Access to on-premises apps Access Panel/MyApps Group-Based Licensing On- premises Dynamic Groups Conditional Access Access Reviews MDM-auto enrollment / Enterprise State Roaming Multi-Factor Authentication HR App Integration
15
Microsoft Azure Active Directory
Office 365 SharePoint Online Kronos Box Workplace by Facebook Access panel HR app Microsoft Azure Active Directory Dynamic groups On- premises
16
Identity and Access Management Use Cases
Azure AD Connect B2B collaboration Provisioning-Deprovisioning Conditional Access SSO to SaaS Self-Service capabilities Connect Health Multi-Factor Authentication I want to provide my employees secure and easy access to every application from any location and any device Addition of custom cloud apps Access Panel/MyApps Dynamic Groups Identity Protection I want to quickly deploy applications to devices, do more with less and automate Join/Move/Leave processes Remote Access to on-premises apps Azure AD B2C Group-Based Licensing Privileged Identity Management 3 I need my customers and partners to access the apps they need from everywhere and collaborate seamlessly Microsoft Authenticator - Password-less Access Azure AD Join MDM-auto enrollment / Enterprise State Roaming Security Reporting 4 I want to protect access to my resources from advanced threats 5 I need to comply with industry regulation and national data protection laws Azure AD DS Office 365 App Launcher HR App Integration Access Reviews 6 I want to write applications that work with my corporate identities in Azure Active Directory
17
Identity and Access Management Use Cases
3 I need my customers and partners to access the apps they need from everywhere and collaborate seamlessly Assign B2B users access to any app or service your organization owns Other organizations SharePoint Online & Office 365 apps Remote Access to on-premises apps Azure AD Connect SSO to SaaS Access Panel/MyApps Self-Service capabilities B2B collaboration Dynamic Groups Office 365 App Launcher Conditional Access Multi-Factor Authentication Microsoft Azure Active Directory Add B2B users with accounts in other Azure AD organizations On- premises Other Identity Providers* Google ID* Microsoft Account Add B2B users with MSA, Google, or other Identity Provider accounts
18
Azure Active Directory B2C
Social IDs Analytics Microsoft Azure Active Directory Any SAML provider Apps Business & Government IDs contoso Customers Business Securely authenticate your customers using their preferred identity provider Capture login, preference, and conversion data for customers Provide branded (white-label) registration and login experiences
19
Customer-centric and flexible
5/17/ :50 AM Customer-centric and flexible Friction-free customer experience Sign in with Google Sign in with Facebook Sign in with Twitter Sign in with Match your identity experience to your application branding User-friendly self-service sign-in and sign-up experience “Bring-your-own-identity” using social ID or create a new, local account set of credentials Enhance account records with media and detailed metadata Self-service profile management/password reset © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.
20
Demo Nasos Kladakis Senior Product Marketing Mgr
Microsoft Identity Division
21
Identity and Access management use cases
Azure AD Connect B2B collaboration Provisioning-Deprovisioning Conditional Access SSO to SaaS Self-Service capabilities Connect Health Multi-Factor Authentication I want to provide my employees secure and easy access to every application from any location and any device Addition of custom cloud apps Access Panel/MyApps Dynamic Groups Identity Protection I want to quickly deploy applications to devices, do more with less and automate Join/Move/Leave processes Remote Access to on-premises apps Azure AD B2C Group-Based Licensing Privileged Identity Management I need my customers and partners to access the apps they need from everywhere and collaborate seamlessly Microsoft Authenticator - Password-less Access Azure AD Join MDM-auto enrollment / Enterprise State Roaming Security Reporting 4 I want to protect access to my resources from advanced threats 5 I need to comply with industry regulation and national data protection laws Azure AD DS Office 365 App Launcher HR App Integration Access Reviews 6 I want to write applications that work with my corporate identities in Azure Active Directory
22
Identity and Access management use cases
Cloud apps 4 I want to protect access to my resources from advanced threats Multi-Factor Authentication Conditional Access Privileged Identity Management Identity Protection Remote Access to on-premises apps SSO to SaaS Security Reporting Conditions Allow access Location (IP range) Device state Risk User group Enforce MFA On-premises applications Block access Wipe device On- premises MFA
23
Microsoft Intelligent Security Graph
Xbox Live Azure Active Directory Microsoft Accounts Azure Skype Enterprise Mobility + Security Office365 Bing OneDrive Microsoft Intelligent Security Graph Microsoft Digital Crimes Unit Microsoft Cyber Defense Operations Center
24
Conditions Controls 10TB On-premises apps Web apps 3 Allow access
Users Machine learning Session Risk 3 Require MFA Devices On-premises apps Real time Evaluation Engine ****** Force password reset Policies Location Deny access Effective policy Web apps Apps Limit access
25
Azure Active Directory New MFA partners
26
Conditions Controls 10TB 3 Azure AD MFA Allow access Users Require MFA
Machine learning Session Risk 3 Require MFA Devices Real time Evaluation Engine ****** Force password reset Policies Location Deny access Effective policy Apps Limit access
27
Privileged Identity Management
Discover, restrict, and monitor privileged identities User Administrator Administrator privileges expire after a specified interval User Enforce on-demand, just-in-time administrative access when needed Ensure policies are met with alerts, audit reports and access reviews Manage admins access in Azure AD and also in Azure RBAC
28
Identity and Access Management Use Cases
Azure AD Connect B2B collaboration Provisioning-Deprovisioning Conditional Access SSO to SaaS Self-Service capabilities Connect Health Multi-Factor Authentication I want to provide my employees secure and easy access to every application from any location and any device Addition of custom cloud apps Access Panel/MyApps Dynamic Groups Identity Protection I want to quickly deploy applications to devices, do more with less and automate Join/Move/Leave processes Remote Access to on-premises apps Azure AD B2C Group-Based Licensing Privileged Identity Management I need my customers and partners to access the apps they need from everywhere and collaborate seamlessly Microsoft Authenticator - Password-less Access Azure AD Join MDM-auto enrollment / Enterprise State Roaming Security Reporting I want to protect access to my resources from advanced threats 5 I need to comply with industry regulation and national data protection laws Azure AD DS Office 365 App Launcher HR App Integration Access Reviews 6 I want to write applications that work with my corporate identities in Azure Active Directory
29
Identity and Access Management Use Cases
Apps Now in public preview! Access Reviews 5 I need to comply with industry regulation and national data protection laws Conditional Access Privileged Identity Management Identity Protection Group-Based Licensing Access Panel/MyApps Provisioning-Deprovisioning Access Reviews HR App Integration Groups Microsoft Azure Active Directory Resources
30
Azure Active Directory Governance partners
31
Password reset extension
Fine-grained lifecycle provisioning Access request Access certification Policy-based workflow and approval Compliance and audit reporting
32
Demo Nasos Kladakis Senior Product Marketing Mgr
Microsoft Identity Division
33
Identity and Access Management Use Cases
Azure AD Connect B2B collaboration Provisioning-Deprovisioning Conditional Access SSO to SaaS Self-Service capabilities Connect Health Multi-Factor Authentication I want to provide my employees secure and easy access to every application from any location and any device Addition of custom cloud apps Access Panel/MyApps Dynamic Groups Identity Protection I want to quickly deploy applications to devices, do more with less and automate Join/Move/Leave processes Remote Access to on-premises apps Azure AD B2C Group-Based Licensing Privileged Identity Management I need my customers and partners to access the apps they need from everywhere and collaborate seamlessly Microsoft Authenticator - Password-less Access Azure AD Join MDM-auto enrollment / Enterprise State Roaming Security Reporting I want to protect access to my resources from advanced threats I need to comply with industry regulation and national data protection laws Azure AD DS Office 365 App Launcher HR App Integration Access Reviews 6 I want to write applications that work with my corporate identities in Azure Active Directory
34
Identity and Access Management Use Cases
6 I want to write applications that work with my corporate identities in Azure Active Directory Identity Experience Framework Access Libraries MSAL OAuth ADAL Microsoft Azure Active Directory OpenID-Connect Microsoft SDKs on Github Microsoft Graph SAML SCIM Microsoft Graph
35
Microsoft Graph HTTPS://GRAPH.MICROSOFT.COM
Microsoft Build 2017 5/17/ :50 AM Microsoft Graph Azure AD Excel Intune Outlook OneDrive OneNote SharePoint Planner Single API that proxies multiple Microsoft services Allows for easy traversal of objects and relationships Eliminates the need to discovery endpoints Only one OAuth access token needed For both personal and work and school accounts Exposing User data, Group data and Organizational data © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.
36
With Microsoft Graph Get the user profile Yina Tristan Groups Dmitry
Microsoft Build 2017 5/17/ :50 AM GET: /users/yina { "displayName": "Yina", "jobTitle": "PRINCIPAL PM MANAGER" } GET: /users/yina/photo/$value Stream image/jpeg GET: /users/yina/manager {"displayName": "Tristan", …} GET: /users/yina/directReports "value" : [ {"displayName": "Matt", …}, {"displayName": "Dmitry", …}, ] GET: /users/yina/memberOf {"displayName": "Office engineering", …}, {"displayName": "Women in tech", …} With Microsoft Graph Get the user profile Tristan manager Groups memberOf Yina Dmitry Matt Sudhi directReports © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.
37
Identity and Access Management Use Cases
Azure AD Connect B2B collaboration Provisioning-Deprovisioning Conditional Access SSO to SaaS Self-Service capabilities Connect Health Multi-Factor Authentication I want to provide my employees secure and easy access to every application from any location and any device Addition of custom cloud apps Access Panel/MyApps Dynamic Groups Identity Protection I want to quickly deploy applications to devices, do more with less and automate Join/Move/Leave processes Remote Access to on-premises apps Azure AD B2C Group-Based Licensing Privileged Identity Management I need my customers and partners to access the apps they need from everywhere and collaborate seamlessly Microsoft Authenticator - Password-less Access Azure AD Join MDM-auto enrollment / Enterprise State Roaming Security Reporting I want to protect access to my resources from advanced threats I need to comply with industry regulation and national data protection laws Azure AD DS Office 365 App Launcher HR App Integration Access Reviews I want to write applications that work with my corporate identities in Azure Active Directory
38
Customer stories Transportation, Logistics, Oil-Gas
Retail, Hospitality and Travel Government, Banking, Insurance Construction, Professional Services Education, Nonprofit Health
39
Methodology & resources
Next steps Get to production team Fast Track Engineers Methodology & resources Tools & insights Expert partners and Microsoft Engineering remote assistance to accelerate your Azure AD deployment Microsoft Engineers engage directly to get you up and running with Azure Active Directory Try Azure Active Directory today for free Microsoft Azure Active Directory Let our team help with your implementation
40
Identity @ Ignite | Monday
5/17/ :50 AM Ignite | Monday BRK3020 What's new and upcoming in AD FS to securely sign-in your users to Office 365 and other applications OCCC Valencia W415 CD Monday 4:00–5:15 Sam Devasahayam Ignite | Tuesday BRK2019 Productivity and protection for your employees, partners, and customers with Azure Active Directory OCCC West Hall F2 Tue 9:00–10:15 Alex Simons Nasos Kladakis THR2072 Migrate your apps from legacy APIs to Microsoft Graph OCCC South – Expo Theater #6 Tue 11:35-11:55 Jeff Sakowicz, Dan Kershaw BRK2017 Saying goodbye to passwords OCCC West Hall F3-4 Tue 12:45-1:30 Manini Roy THR2071 Managing enterprise applications, permissions, and consent in Azure Active Directory OCCC West Building Theater - Level 2 Tue 2:10–2:30 Jeff Sakowicz BRK1051 Locking down access to the Azure Cloud using SSO, Roles Based Access Control, and Conditional Access OCCC W308 Tue 2:15–3:30 Stuart Kwan © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.
41
Identity @ Ignite | Wednesday
5/17/ :50 AM Ignite | Wednesday BRK3388 Build applications to secure and manage your enterprise using Microsoft Graph OCCC S210 Wed 09:00-09:45 Jeff Sakowicz, Dan Kershaw BRK3225 Office development: Authentication demystified OCCC W315 Wed 10:45–12:00 Vittorio Bertocci BRK3146 The power of common identity across any cloud OCCC W240 Wed 12:45-1:30 Sam Devasahayam THR2126 Azure Active Directory: Your options explained from AD sync to pass through authentication & more OCCC West – Microsoft Ignite Studio Wed 1:35-1:55 Alex Simons Simon May BRK3352 Windows devices in Azure Active Directory: Why should I care? OCCC Valencia W415 AB Wed 2:15–3:30 Jairo Cadena THR2007 How to get Office 365 to the next level with Azure Active Directory Premium OCCC South – Expo Theater Wed 3:15-4:00 Brjann Brekkan BRK3295 What’s new in Azure Active Directory Domain Services Hyatt Regency Windermere Z Wed 4:00–5:15 Mahesh Unnikrishnan BRK3016 Shut the door to cybercrime with Azure Active Directory risk-based identity protection OCCC Valencia W415 CD Alex Weinert Nitika Gupta © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.
42
Identity @ Ignite | Thursday
5/17/ :50 AM Ignite | Thursday BRK2018 Share corporate resources with your partners using Azure Active Directory B2B collaboration OCCC W230 Thu 9:00–10:15 Mary Lynch Sarat Subramaniam Laith Al Shamri BRK3207 The keys to the cloud: Use Microsoft identities to sign in and access API from your mobile+web apps OCCC S310 Thu 10:45-12:00 Vittorio Bertocci BRK3012 Secure access to Office 365, SaaS and on-premises apps with Microsoft Enterprise Mobility + Security OCCC W311 Caleb Baker Chris Green BRK3013 Ensure users have the right access with Azure Active Directory OCCC Valencia W415 AB Thu 12:30–1:45 Joseph Dadzie Mark Wahl BRK3015 Deep-dive: Azure Active Directory Authentication and Single-Sign-On OCCC West Hall E1 Thu 2:15-3:30 John Craddock BRK3014 Azure Active Directory best practices from around the world Thu 4:00–5:15 Tarek Dawoud Mark Morowczynski Ignite | Friday BRK2276 Modernize your customer identity management with Azure Active Directory B2C OCCC W314 Friday 9:00-9:45 Saeed Akhter © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.
43
Thank you @alex_a_simons For more information microsoft.com/identity
5/17/ :50 AM Thank you @alex_a_simons For more information microsoft.com/identity @akladakis © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.
Similar presentations
© 2025 SlidePlayer.com. Inc.
All rights reserved.