azure active directory, practical guide

32
Azure Active Directory The Practical Guide Sasha Rosenbaum @DivineOps September 2015

Upload: sasha-rosenbaum

Post on 07-Jan-2017

1.405 views

Category:

Technology


6 download

TRANSCRIPT

Page 1: Azure Active Directory, Practical Guide

Azure Active DirectoryThe Practical Guide

Sasha Rosenbaum@DivineOpsSeptember 2015

Page 2: Azure Active Directory, Practical Guide

The “What”

Page 3: Azure Active Directory, Practical Guide

Where did it all start?

Page 4: Azure Active Directory, Practical Guide

Windows Active Directory•Centralized storage of information about all network objects (users, computers, etc.)•Authentication •Access control providing permission levels•Audit trail for monitoring network activity

@DivineOps

Page 5: Azure Active Directory, Practical Guide

@DivineOps

Active Directory

Page 6: Azure Active Directory, Practical Guide

Azure Active Directory

Page 7: Azure Active Directory, Practical Guide

@DivineOps

Azure Active DirectoryIdentity as a Service• Identity Management•Directory Services•Application Access Management

Page 8: Azure Active Directory, Practical Guide

@DivineOps

New Features

Page 9: Azure Active Directory, Practical Guide

The “Why”

Page 10: Azure Active Directory, Practical Guide

When should you choose

Identity as a Service

Page 11: Azure Active Directory, Practical Guide

@DivineOps

You already have!

Every Azure, Office365, Microsoft Intune and Dynamics CRM tenant is an AAD tenant

Page 12: Azure Active Directory, Practical Guide

@DivineOps

Dynamics CRM

Page 13: Azure Active Directory, Practical Guide

@DivineOps

Office 365

Page 14: Azure Active Directory, Practical Guide

@DivineOps

Microsoft Intune

Page 15: Azure Active Directory, Practical Guide

@DivineOps

Integration

Page 16: Azure Active Directory, Practical Guide

@DivineOps

ProtocolsOpenID ConnectOAuth 2.0WS-FederationSAML-P

Page 17: Azure Active Directory, Practical Guide

@DivineOps

TiersTIER FREE BASIC PREMIUM

Directory as a Service Yes Yes YesUser and Group Management Yes Yes YesDevice registration Yes Yes YesDirectory Objects 1 500 K Unlimited UnlimitedEnd User Access Panel Yes Yes YesSSO for SaaS Apps 10 Apps /

User 210 Apps /

User 2Unlimited

Directory Synchronization Yes Yes YesUser-based Access Management and Provisioning

Yes Yes Yes

Basic Security Reports Yes Yes Yes

Page 18: Azure Active Directory, Practical Guide

@DivineOps

TiersTIER FREE BASIC PREMIUM

Logon/Access Panel Branding Customization

-- Yes Yes

Group-based Access Management and Provisioning

-- Yes Yes

Self-Service Password Reset for Cloud Users

-- Yes Yes

Secure Remote Access and SSO to on-premises web applications

-- Yes Yes

Self-Service Password Reset for Users w/ writeback to on-premises directories

-- -- Yes

Self-service group management for cloud users

-- -- Yes

Page 19: Azure Active Directory, Practical Guide

@DivineOps

TiersTIER FREE BASIC PREMIUM

Multi-Factor Authentication (for cloud and on-premises applications)

-- -- Yes

Advanced Usage and Security Reports

-- -- Yes

Connect Health -- -- Yes

Cloud App Discovery -- -- Yes

Microsoft Identity Manager User CAL

-- -- Yes

Service Level Agreement -- 99.9% 99.9%

Page 20: Azure Active Directory, Practical Guide

@DivineOps

Scenarios•Green field applications•Web•Mobile

Page 21: Azure Active Directory, Practical Guide

@DivineOps

ADAL•Web Browser to Web Application (.Net)• Single Page Application (JavaScript, .Net) •Native Application to Web API (.Net, ObjC, Java) •Web Application to Web API (.Net, Nodejs)•Calling Azure AD Graph API (.Net, Java, PHP)

Page 22: Azure Active Directory, Practical Guide

@DivineOps

Scenarios•SaaS Applications•Over 2500 apps, including

Page 23: Azure Active Directory, Practical Guide

@DivineOps

Scenarios•On-Premise Applications• Integration with Local AD

Page 24: Azure Active Directory, Practical Guide

The “How”

Page 25: Azure Active Directory, Practical Guide

How do you get started?

Page 26: Azure Active Directory, Practical Guide

Demo Active Directory Sync

Azure AD Connect Demo Slides

Page 27: Azure Active Directory, Practical Guide

@DivineOps

Azure AD Connect

Page 28: Azure Active Directory, Practical Guide

@DivineOps

Azure AD Connect•Azure AD Global Administrator account•Enterprise Administrator account for your local Active Directory•SQL Server database to store identity data•Meet server version and hardware requirements

Page 29: Azure Active Directory, Practical Guide

Demo Greenfield Application Development

AAD with new MVC app Demo Slides

Page 30: Azure Active Directory, Practical Guide

The “Where”are we headed?

Page 31: Azure Active Directory, Practical Guide

@DivineOps

What’s New•Azure AD Connect with Connect Health is GA•Multi-Factor Authentication per app•Dynamic groups for applications and licenses•Out-of-the-box dedicated user group “All Users”•Azure Active Directory Application Proxy updates•Password write-back from AAD to AD is GA

Page 32: Azure Active Directory, Practical Guide

@DivineOps

B2C AADAs of September 2015 Business to Consumer AAD is in public preview!•Self-registration•Registration with social accounts•Customer defined UX•Security and scalability of Azure Cloud B2C AAD Overview