Download presentation
Presentation is loading. Please wait.
Published byΣωφρονία Ρόκας Modified over 5 years ago
1
4/9/2019 5:05 AM © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.
2
4/9/2019 5:05 AM Secure access to Office 365/Azure Active Directory with new features in AD FS in Windows Server 2019 and Azure AD password protection BRK3226 Anand Yadav © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.
3
Choosing the right sign-in
4
Choosing the right sign-in
Password hash synchronization (PHS) Pass- through Authentication (PTA) Active Directory Federation Service (AD FS) Authentication in cloud Password hash is synced to Azure Username + Password WIA with Seamless SSO Authentication in cloud + on-premises agent Username + Password WIA with Seamless SSO On-premises authentication Username + Password, WIA, samAccountName, Certificate, Smart-Card
5
Users actively use AD FS to sign-in to Azure
71+million Users actively use AD FS to sign-in to Azure
6
High availability hybrid auth in Azure
7
On-premises only AD FS On-premises AD FS + WAP User On-premises
AD FS Infrastructure
8
On-premises only AD FS On-premises AD FS + WAP User On-premises
AD FS Infrastructure
9
AD FS in Azure On-premises Azure https://aka.ms/AdfsInAzure
4/9/2019 5:05 AM AD FS in Azure VPN / Express Route On-premises Azure AD FS + WAP AD FS + WAP AD FS + WAP On-premises AD FS Infrastructure Azure Traffic Manager AD FS Infrastructure © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.
10
Securing organizational resources
11
Securing organizational resources
Operations Admin access Users MFA Privileged Access Workstations Privileged Identity Management Extranet lockout / Extranet Smart lockout MFA for external access Stronger passwords Connect Health Audit logs Lock-down network
12
Demo: Extranet Smart Lockout – More secure more productive
13
Stay ahead with Connect Health for AD FS
14
360º view of your sign-ins on-premises
Continuous infrastructure health monitoring Critical alerts notifications Application usage analytics Performance trend analysis Bad password attempts report Risky-IP report
15
Risky IP Report
16
Strong passwords with Azure AD password protection
17
The threats are real, global, and target all of us
1.29 Billion Authentications blocked in August 2018
18
81% of data breaches involved weak, default, or stolen passwords
4/9/2019 5:05 AM 81% of data breaches involved weak, default, or stolen passwords © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.
19
Common Passwords Attempted in Password Spray Attacks
Spring 2018 Summer September 1234 Winter Football Your Company Name
20
Azure AD Password Protection
Power of Azure – in cloud and on-premises Powered by Azure Intelligence from monitoring billions of authentication attempts every day Custom list Define custom list of weak strings for your organization Protect users on-premises Simple deployment on-premises to leverage the Azure logic and ensure stronger passwords
21
52% As high as weak passwords were found and blocked by
Azure AD Password Protection
22
Under the hood Password change Normalization Strength check
Allowed / Blocked All password change or reset events are processed by Azure AD Password Protection Normalize the passwords for general transformations, like ‘0’ for ‘O’ and ‘!’ for an ‘i’ Password strings are checked to ensure they have enough score to be considered as a strong password Based on the normalization and strength check, password is allowed / blocked
23
Locked down network access
Audit Mode No internet Internet connectivity DC + DC Agent Server + Proxy Agent Azure DC + DC Agent
24
Locked down network access
Enforced No internet Internet connectivity DC + DC Agent Server + Proxy Agent Azure DC + DC Agent
25
Demo Stronger passwords with Azure AD password protection
26
Azure AD Password Protection
Cloud intelligence to ensure strong passwords Dynamic banning of passwords based on known bad patterns and those you define. Built for hybrid environments. Built for secure no-internet zone domain controllers Unified admin experience for on-premises and cloud. Support for multi-forest environment High availability architecture
27
Please evaluate this session Your feedback is important to us!
4/9/2019 5:05 AM Please evaluate this session Your feedback is important to us! Please evaluate this session through MyEvaluations on the mobile app or website. Download the app: Go to the website: © 2014 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.
28
4/9/2019 5:05 AM © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.
Similar presentations
© 2025 SlidePlayer.com. Inc.
All rights reserved.