Download presentation
Presentation is loading. Please wait.
Published byKatherine Fowler Modified over 6 years ago
1
Azure AD for the client management guy (or gal!)
Andre Della Monica Senior Content Developer Microsoft, SCCM & Intune @andredm7 Jeff Gilbert Senior Content Developer Microsoft, Azure AD @jeffgilb
2
Session overview General understanding of how Azure AD fits into the client management world. How to integrate on-premises AD with Azure AD. Find out what Azure AD admins are up to and when you might need their help.
3
Azure AD Microsoft’s cloud based directory and identity management service. Core directory services, identity governance, and application access management. Synchronize on-premises resource information and seamless integration with other services.
4
Connecting directories
Common identity for Office 365, Azure, and SaaS apps Azure AD Connect Azure AD Connect Health
5
Managing management Configuration Manager Intune Both?
Domain joined or you need fine grain control of settings management. Intune Non-domain joined, mobile devices (Azure AD join or add work or school account). Both? Handle some workloads with each.
6
Devices & Azure AD OOBE Experience
Azure AD Join or set up a work or school account Device registration
7
Enable Auto-MDM Auto-mobile device management (MDM) enrollment with Azure AD & Intune Enroll devices via Group Policy AD-joined PC running Windows 10, version 1709 Enterprise has MDM service already configured Enterprise AD must be registered with Azure AD
8
Demo
9
MFA Two-step authentication verification MFA in the cloud
Something you know (typically a password) Something you have (a trusted device that is not easily duplicated, like a phone) Something you are (biometrics) MFA in the cloud MFA on-premises
10
Conditional Access Azure AD & Intune Compliance policies
Access policies
11
Conditional access from Intune managed devices
6/19/2018 1:26 AM Conditional access from Intune managed devices SharePoint Online 7 Client signs in; Azure AD performs a redirect to Intune Client is directed to join the device to Azure AD or to add a work or school account Device begins enrollment Device enrolls in Intune and is registered in AAD Device management and compliance status is set in AAD AAD issues direct access token Client accesses service with direct access token Data is delivered to client 8 Company Portal Step 1: Enroll device 6 2 Intune Azure Active Directory 1 3 Device object device id isManaged MDMStatus Unified Enrollment 5 4 Microsoft Cloud © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.
12
Demo
13
Questions ?
Similar presentations
© 2025 SlidePlayer.com. Inc.
All rights reserved.