Presentation is loading. Please wait.

Presentation is loading. Please wait.

5/17/2018 Productivity and protection for your employees, partners, and customers with Azure Active Directory Alex Simons Partner Director Program Mgmt.

Similar presentations


Presentation on theme: "5/17/2018 Productivity and protection for your employees, partners, and customers with Azure Active Directory Alex Simons Partner Director Program Mgmt."— Presentation transcript:

1 5/17/2018 Productivity and protection for your employees, partners, and customers with Azure Active Directory Alex Simons Partner Director Program Mgmt Microsoft Identity Division Nasos Kladakis Senior Product Marketing Mgr Microsoft Identity Division © 2012 Microsoft Corporation. All rights reserved. Microsoft, Windows, and other product names are or may be registered trademarks and/or trademarks in the U.S. and/or other countries. The information herein is for informational purposes only and represents the current view of Microsoft Corporation as of the date of this presentation. Because Microsoft must respond to changing market conditions, it should not be interpreted to be a commitment on the part of Microsoft, and Microsoft cannot guarantee the accuracy of any information provided after the date of this presentation. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

2 Is the new control plane
5/17/ :50 AM Identity Is the new control plane On-premises / Private cloud © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION. 2

3 Identity as the Control Plane
Build 2012 5/17/2018 Identity as the Control Plane Partners Customers Commercial IdPs Consumer IdPs Azure Public cloud Microsoft Azure Active Directory Cloud Windows Server Active Directory On- premises Azure AD Connect BYO

4 Azure Active Directory in the Marketplace Every Office 365 and Microsoft Azure customer uses Azure Active Directory organizations 12.8M users 950M 3rd party apps in Azure AD 272K paid Azure AD / EMS customers 56K of Fortune 500 companies use Azure AD 90% Governance Security Reporting Access Reviews HR App Integration Microsoft Authenticator - Password-less Access Self-Service capabilities SSO to SaaS Azure AD B2C B2B collaboration MDM-auto enrollment / Enterprise State Roaming Privileged Identity Management Azure AD Join Remote Access to on-premises apps Addition of custom cloud apps Conditional Access Multi-Factor Authentication Identity Protection Dynamic Groups Azure AD DS Provisioning-Deprovisioning Azure AD Connect Connect Health Office 365 App Launcher Group-Based Licensing Access Panel/MyApps +30% YoY +45% YoY +200% YoY +74% YoY © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

5 Azure Active Directory
Azure AD Connect B2B collaboration Provisioning-Deprovisioning Conditional Access SSO to SaaS Self-Service capabilities Connect Health Multi-Factor Authentication Addition of custom cloud apps Access Panel/MyApps Dynamic Groups Identity Protection Remote Access to on-premises apps Azure AD B2C Group-Based Licensing Privileged Identity Management Azure Active Directory I want to quickly deploy applications to devices, do more with less and automate Join/Move/Leave processes I need my customers, partners, and users to access the apps they need from everywhere and collaborate seamlessly [dev use case] I want to provide my employees secure and easy access to every application from any location and any device I need to comply with industry regulation and national data protection laws I want to protect access to my resources from advanced threats Microsoft Authenticator - Password-less Access Azure AD Join MDM-auto enrollment / Enterprise State Roaming Security Reporting Azure AD DS Office 365 App Launcher HR App Integration Access Reviews

6 Identity and Access Management Use Cases
Azure AD Connect B2B collaboration Provisioning-Deprovisioning Conditional Access SSO to SaaS Self-Service capabilities Connect Health Multi-Factor Authentication 1 I want to provide my employees secure and easy access to every application from any location and any device Addition of custom cloud apps Access Panel/MyApps Dynamic Groups Identity Protection 2 I want to quickly deploy applications to devices, do more with less and automate Join/Move/Leave processes Remote Access to on-premises apps Azure AD B2C Group-Based Licensing Privileged Identity Management 3 I need my customers and partners to access the apps they need from everywhere and collaborate seamlessly Microsoft Authenticator - Password-less Access Azure AD Join MDM-auto enrollment / Enterprise State Roaming Security Reporting 4 I want to protect access to my resources from advanced threats 5 I need to comply with industry regulation and national data protection laws Azure AD DS Office 365 App Launcher HR App Integration Access Reviews 6 I want to write applications that work with my corporate identities in Azure Active Directory

7 Identity and Access Management Use Cases
1 I want to provide my employees secure and easy access to every application from any location and any device Microsoft Azure Active Directory Remote Access to on-premises apps Azure AD Connect SSO to SaaS Access Panel/MyApps Self-Service capabilities Azure AD DS Microsoft Authenticator - Password-less Access Office 365 App Launcher Conditional Access Multi-Factor Authentication On- premises Azure AD Connect

8 Pass-through authentication is Generally Available Identity synchronization + Pass-through authentication with Seamless SSO Microsoft Azure Active Directory Office 365, SaaS, and LoB apps Identity synchronization using Azure AD Connect Pass-through authentication On- premises Password validation requests are sent to Windows Server Active Directory via Pass-through authentication Pass-through authentication agent

9 3rd party apps and Azure AD
5/17/ :50 AM 3rd party apps and Azure AD Google Apps Workday ServiceNow Cornerstone OnDemand SuccessFactors 272,000 Salesforce Clever Workplace by Facebook Active applications Canvas Zscaler Two © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

10 https://appX-contoso.msappproxy.net/
5/17/ :50 AM Azure Active Directory Application Proxy Single Sign-on to on premises applications Microsoft Azure Active Directory Azure or 3rd Party IaaS connector Application Proxy DMZ connector connector connector app app app app © 2013 Microsoft Corporation. All rights reserved. Microsoft, Windows, and other product names are or may be registered trademarks and/or trademarks in the U.S. and/or other countries. The information herein is for informational purposes only and represents the current view of Microsoft Corporation as of the date of this presentation. Because Microsoft must respond to changing market conditions, it should not be interpreted to be a commitment on the part of Microsoft, and Microsoft cannot guarantee the accuracy of any information provided after the date of this presentation. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

11 PingAccess for Azure Active Directory

12 https://appX-contoso.msappproxy.net/
5/17/ :50 AM Azure Active Directory Application Proxy + PingAccess Access even more on premises web applications Microsoft Azure Active Directory Azure or 3rd Party IaaS connector Application Proxy DMZ connector connector connector app app app app Custom app © 2013 Microsoft Corporation. All rights reserved. Microsoft, Windows, and other product names are or may be registered trademarks and/or trademarks in the U.S. and/or other countries. The information herein is for informational purposes only and represents the current view of Microsoft Corporation as of the date of this presentation. Because Microsoft must respond to changing market conditions, it should not be interpreted to be a commitment on the part of Microsoft, and Microsoft cannot guarantee the accuracy of any information provided after the date of this presentation. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

13 Identity and Access Management Use Cases
Azure AD Connect B2B collaboration Provisioning-Deprovisioning Conditional Access SSO to SaaS Self-Service capabilities Connect Health Multi-Factor Authentication I want to provide my employees secure and easy access to every application from any location and any device Addition of custom cloud apps Access Panel/MyApps Dynamic Groups Identity Protection 2 I want to quickly deploy applications to devices, do more with less and automate Join/Move/Leave processes Remote Access to on-premises apps Azure AD B2C Group-Based Licensing Privileged Identity Management 3 I need my customers and partners to access the apps they need from everywhere and collaborate seamlessly Microsoft Authenticator - Password-less Access Azure AD Join MDM-auto enrollment / Enterprise State Roaming Security Reporting 4 I want to protect access to my resources from advanced threats 5 I need to comply with industry regulation and national data protection laws Azure AD DS Office 365 App Launcher HR App Integration Access Reviews 6 I want to write applications that work with my corporate identities in Azure Active Directory

14 Identity and Access Management Use Cases
2 I want to quickly deploy applications to devices, do more with less and automate Join/Move/Leave processes HR app Microsoft Azure Active Directory Azure AD Connect Provisioning-Deprovisioning Dynamic groups SSO to SaaS Self-Service capabilities Microsoft Authenticator - Password-less Access Remote Access to on-premises apps Access Panel/MyApps Group-Based Licensing On- premises Dynamic Groups Conditional Access Access Reviews MDM-auto enrollment / Enterprise State Roaming Multi-Factor Authentication HR App Integration

15 Microsoft Azure Active Directory
Office 365 SharePoint Online Kronos Box Workplace by Facebook Access panel HR app Microsoft Azure Active Directory Dynamic groups On- premises

16 Identity and Access Management Use Cases
Azure AD Connect B2B collaboration Provisioning-Deprovisioning Conditional Access SSO to SaaS Self-Service capabilities Connect Health Multi-Factor Authentication I want to provide my employees secure and easy access to every application from any location and any device Addition of custom cloud apps Access Panel/MyApps Dynamic Groups Identity Protection I want to quickly deploy applications to devices, do more with less and automate Join/Move/Leave processes Remote Access to on-premises apps Azure AD B2C Group-Based Licensing Privileged Identity Management 3 I need my customers and partners to access the apps they need from everywhere and collaborate seamlessly Microsoft Authenticator - Password-less Access Azure AD Join MDM-auto enrollment / Enterprise State Roaming Security Reporting 4 I want to protect access to my resources from advanced threats 5 I need to comply with industry regulation and national data protection laws Azure AD DS Office 365 App Launcher HR App Integration Access Reviews 6 I want to write applications that work with my corporate identities in Azure Active Directory

17 Identity and Access Management Use Cases
3 I need my customers and partners to access the apps they need from everywhere and collaborate seamlessly Assign B2B users access to any app or service your organization owns Other organizations SharePoint Online & Office 365 apps Remote Access to on-premises apps Azure AD Connect SSO to SaaS Access Panel/MyApps Self-Service capabilities B2B collaboration Dynamic Groups Office 365 App Launcher Conditional Access Multi-Factor Authentication Microsoft Azure Active Directory Add B2B users with accounts in other Azure AD organizations On- premises Other Identity Providers* Google ID* Microsoft Account Add B2B users with MSA, Google, or other Identity Provider accounts

18 Azure Active Directory B2C
Social IDs Analytics Microsoft Azure Active Directory Any SAML provider Apps Business & Government IDs contoso Customers Business Securely authenticate your customers using their preferred identity provider Capture login, preference, and conversion data for customers Provide branded (white-label) registration and login experiences

19 Customer-centric and flexible
5/17/ :50 AM Customer-centric and flexible Friction-free customer experience Sign in with Google Sign in with Facebook Sign in with Twitter Sign in with Match your identity experience to your application branding User-friendly self-service sign-in and sign-up experience “Bring-your-own-identity” using social ID or create a new, local account set of credentials Enhance account records with media and detailed metadata Self-service profile management/password reset © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

20 Demo Nasos Kladakis Senior Product Marketing Mgr
Microsoft Identity Division

21 Identity and Access management use cases
Azure AD Connect B2B collaboration Provisioning-Deprovisioning Conditional Access SSO to SaaS Self-Service capabilities Connect Health Multi-Factor Authentication I want to provide my employees secure and easy access to every application from any location and any device Addition of custom cloud apps Access Panel/MyApps Dynamic Groups Identity Protection I want to quickly deploy applications to devices, do more with less and automate Join/Move/Leave processes Remote Access to on-premises apps Azure AD B2C Group-Based Licensing Privileged Identity Management I need my customers and partners to access the apps they need from everywhere and collaborate seamlessly Microsoft Authenticator - Password-less Access Azure AD Join MDM-auto enrollment / Enterprise State Roaming Security Reporting 4 I want to protect access to my resources from advanced threats 5 I need to comply with industry regulation and national data protection laws Azure AD DS Office 365 App Launcher HR App Integration Access Reviews 6 I want to write applications that work with my corporate identities in Azure Active Directory

22 Identity and Access management use cases
Cloud apps 4 I want to protect access to my resources from advanced threats Multi-Factor Authentication Conditional Access Privileged Identity Management Identity Protection Remote Access to on-premises apps SSO to SaaS Security Reporting Conditions Allow access Location (IP range) Device state Risk User group Enforce MFA On-premises applications Block access Wipe device On- premises MFA

23 Microsoft Intelligent Security Graph
Xbox Live Azure Active Directory Microsoft Accounts Azure Skype Enterprise Mobility + Security Office365 Bing OneDrive Microsoft Intelligent Security Graph Microsoft Digital Crimes Unit Microsoft Cyber Defense Operations Center

24 Conditions Controls 10TB On-premises apps Web apps 3 Allow access
Users Machine learning Session Risk 3 Require MFA Devices On-premises apps Real time Evaluation Engine ****** Force password reset Policies Location Deny access Effective policy Web apps Apps Limit access

25 Azure Active Directory New MFA partners

26 Conditions Controls 10TB 3 Azure AD MFA Allow access Users Require MFA
Machine learning Session Risk 3 Require MFA Devices Real time Evaluation Engine ****** Force password reset Policies Location Deny access Effective policy Apps Limit access

27 Privileged Identity Management
Discover, restrict, and monitor privileged identities User Administrator Administrator privileges expire after a specified interval User Enforce on-demand, just-in-time administrative access when needed Ensure policies are met with alerts, audit reports and access reviews Manage admins access in Azure AD and also in Azure RBAC

28 Identity and Access Management Use Cases
Azure AD Connect B2B collaboration Provisioning-Deprovisioning Conditional Access SSO to SaaS Self-Service capabilities Connect Health Multi-Factor Authentication I want to provide my employees secure and easy access to every application from any location and any device Addition of custom cloud apps Access Panel/MyApps Dynamic Groups Identity Protection I want to quickly deploy applications to devices, do more with less and automate Join/Move/Leave processes Remote Access to on-premises apps Azure AD B2C Group-Based Licensing Privileged Identity Management I need my customers and partners to access the apps they need from everywhere and collaborate seamlessly Microsoft Authenticator - Password-less Access Azure AD Join MDM-auto enrollment / Enterprise State Roaming Security Reporting I want to protect access to my resources from advanced threats 5 I need to comply with industry regulation and national data protection laws Azure AD DS Office 365 App Launcher HR App Integration Access Reviews 6 I want to write applications that work with my corporate identities in Azure Active Directory

29 Identity and Access Management Use Cases
Apps Now in public preview! Access Reviews 5 I need to comply with industry regulation and national data protection laws Conditional Access Privileged Identity Management Identity Protection Group-Based Licensing Access Panel/MyApps Provisioning-Deprovisioning Access Reviews HR App Integration Groups Microsoft Azure Active Directory Resources

30 Azure Active Directory Governance partners

31 Password reset extension
Fine-grained lifecycle provisioning Access request Access certification Policy-based workflow and approval Compliance and audit reporting

32 Demo Nasos Kladakis Senior Product Marketing Mgr
Microsoft Identity Division

33 Identity and Access Management Use Cases
Azure AD Connect B2B collaboration Provisioning-Deprovisioning Conditional Access SSO to SaaS Self-Service capabilities Connect Health Multi-Factor Authentication I want to provide my employees secure and easy access to every application from any location and any device Addition of custom cloud apps Access Panel/MyApps Dynamic Groups Identity Protection I want to quickly deploy applications to devices, do more with less and automate Join/Move/Leave processes Remote Access to on-premises apps Azure AD B2C Group-Based Licensing Privileged Identity Management I need my customers and partners to access the apps they need from everywhere and collaborate seamlessly Microsoft Authenticator - Password-less Access Azure AD Join MDM-auto enrollment / Enterprise State Roaming Security Reporting I want to protect access to my resources from advanced threats I need to comply with industry regulation and national data protection laws Azure AD DS Office 365 App Launcher HR App Integration Access Reviews 6 I want to write applications that work with my corporate identities in Azure Active Directory

34 Identity and Access Management Use Cases
6 I want to write applications that work with my corporate identities in Azure Active Directory Identity Experience Framework Access Libraries MSAL OAuth ADAL Microsoft Azure Active Directory OpenID-Connect Microsoft SDKs on Github Microsoft Graph SAML SCIM Microsoft Graph

35 Microsoft Graph HTTPS://GRAPH.MICROSOFT.COM
Microsoft Build 2017 5/17/ :50 AM Microsoft Graph Azure AD Excel Intune Outlook OneDrive OneNote SharePoint Planner Single API that proxies multiple Microsoft services Allows for easy traversal of objects and relationships Eliminates the need to discovery endpoints Only one OAuth access token needed For both personal and work and school accounts Exposing User data, Group data and Organizational data © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

36 With Microsoft Graph Get the user profile Yina Tristan Groups Dmitry
Microsoft Build 2017 5/17/ :50 AM GET: /users/yina { "displayName": "Yina", "jobTitle": "PRINCIPAL PM MANAGER" } GET: /users/yina/photo/$value Stream image/jpeg GET: /users/yina/manager {"displayName": "Tristan", …} GET: /users/yina/directReports "value" : [ {"displayName": "Matt", …}, {"displayName": "Dmitry", …}, ] GET: /users/yina/memberOf {"displayName": "Office engineering", …}, {"displayName": "Women in tech", …} With Microsoft Graph Get the user profile Tristan manager Groups memberOf Yina Dmitry Matt Sudhi directReports © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

37 Identity and Access Management Use Cases
Azure AD Connect B2B collaboration Provisioning-Deprovisioning Conditional Access SSO to SaaS Self-Service capabilities Connect Health Multi-Factor Authentication I want to provide my employees secure and easy access to every application from any location and any device Addition of custom cloud apps Access Panel/MyApps Dynamic Groups Identity Protection I want to quickly deploy applications to devices, do more with less and automate Join/Move/Leave processes Remote Access to on-premises apps Azure AD B2C Group-Based Licensing Privileged Identity Management I need my customers and partners to access the apps they need from everywhere and collaborate seamlessly Microsoft Authenticator - Password-less Access Azure AD Join MDM-auto enrollment / Enterprise State Roaming Security Reporting I want to protect access to my resources from advanced threats I need to comply with industry regulation and national data protection laws Azure AD DS Office 365 App Launcher HR App Integration Access Reviews I want to write applications that work with my corporate identities in Azure Active Directory

38 Customer stories Transportation, Logistics, Oil-Gas
Retail, Hospitality and Travel Government, Banking, Insurance Construction, Professional Services Education, Nonprofit Health

39 Methodology & resources
Next steps Get to production team Fast Track Engineers Methodology & resources Tools & insights Expert partners and Microsoft Engineering remote assistance to accelerate your Azure AD deployment Microsoft Engineers engage directly to get you up and running with Azure Active Directory Try Azure Active Directory today for free Microsoft Azure Active Directory Let our team help with your implementation

40 Identity @ Ignite | Monday
5/17/ :50 AM Ignite | Monday BRK3020 What's new and upcoming in AD FS to securely sign-in your users to Office 365 and other applications OCCC Valencia W415 CD Monday 4:00–5:15 Sam Devasahayam Ignite | Tuesday BRK2019 Productivity and protection for your employees, partners, and customers with Azure Active Directory OCCC West Hall F2 Tue 9:00–10:15 Alex Simons Nasos Kladakis THR2072 Migrate your apps from legacy APIs to Microsoft Graph OCCC South – Expo Theater #6 Tue 11:35-11:55 Jeff Sakowicz, Dan Kershaw BRK2017 Saying goodbye to passwords OCCC West Hall F3-4 Tue 12:45-1:30 Manini Roy THR2071 Managing enterprise applications, permissions, and consent in Azure Active Directory OCCC West Building Theater - Level 2 Tue 2:10–2:30 Jeff Sakowicz BRK1051 Locking down access to the Azure Cloud using SSO, Roles Based Access Control, and Conditional Access OCCC W308 Tue 2:15–3:30 Stuart Kwan © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

41 Identity @ Ignite | Wednesday
5/17/ :50 AM Ignite | Wednesday BRK3388 Build applications to secure and manage your enterprise using Microsoft Graph OCCC S210 Wed 09:00-09:45 Jeff Sakowicz, Dan Kershaw BRK3225 Office development: Authentication demystified OCCC W315 Wed 10:45–12:00 Vittorio Bertocci BRK3146 The power of common identity across any cloud OCCC W240 Wed 12:45-1:30 Sam Devasahayam THR2126 Azure Active Directory: Your options explained from AD sync to pass through authentication & more OCCC West – Microsoft Ignite Studio Wed 1:35-1:55 Alex Simons Simon May   BRK3352 Windows devices in Azure Active Directory: Why should I care? OCCC Valencia W415 AB Wed 2:15–3:30 Jairo Cadena THR2007 How to get Office 365 to the next level with Azure Active Directory Premium OCCC South – Expo Theater Wed 3:15-4:00 Brjann Brekkan BRK3295 What’s new in Azure Active Directory Domain Services Hyatt Regency Windermere Z Wed 4:00–5:15 Mahesh Unnikrishnan BRK3016 Shut the door to cybercrime with Azure Active Directory risk-based identity protection OCCC Valencia W415 CD Alex Weinert Nitika Gupta © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

42 Identity @ Ignite | Thursday
5/17/ :50 AM Ignite | Thursday BRK2018 Share corporate resources with your partners using Azure Active Directory B2B collaboration OCCC W230 Thu 9:00–10:15 Mary Lynch Sarat Subramaniam Laith Al Shamri BRK3207 The keys to the cloud: Use Microsoft identities to sign in and access API from your mobile+web apps OCCC S310 Thu 10:45-12:00 Vittorio Bertocci BRK3012 Secure access to Office 365, SaaS and on-premises apps with Microsoft Enterprise Mobility + Security OCCC W311 Caleb Baker Chris Green BRK3013 Ensure users have the right access with Azure Active Directory OCCC Valencia W415 AB Thu 12:30–1:45 Joseph Dadzie Mark Wahl BRK3015 Deep-dive: Azure Active Directory Authentication and Single-Sign-On OCCC West Hall E1 Thu 2:15-3:30 John Craddock BRK3014 Azure Active Directory best practices from around the world Thu 4:00–5:15 Tarek Dawoud Mark Morowczynski Ignite | Friday BRK2276 Modernize your customer identity management with Azure Active Directory B2C OCCC W314 Friday 9:00-9:45 Saeed Akhter © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

43 Thank you @alex_a_simons For more information microsoft.com/identity
5/17/ :50 AM Thank you @alex_a_simons For more information microsoft.com/identity @akladakis © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.


Download ppt "5/17/2018 Productivity and protection for your employees, partners, and customers with Azure Active Directory Alex Simons Partner Director Program Mgmt."

Similar presentations


Ads by Google