SlideShare a Scribd company logo
PRESENTS
Microsoft, DLF Cyber City August 20, 2017
MICROSOFT AZURE DAY
Subhendu Bhattacharyya
Microsoft Certified Trainer , MCP ,MCSA , MCSE , MS – Azure
Corporate Trainer @ Koenig Solutions Pvt Ltd , Blogger
Blog/Website : www.SubhenduMCT.com
Azure AD – Identity As A Service
Public Cloud Offering From Microsoft
42 Datacenter Across The Globe
62 Compliance Offering
90% of Fortune 500 company use Azure
72 product available in portal
One Stop Support from Microsoft
Great compatibility with your on prem env
www.SubhenduMCT.co
Azure AD – Identity As A Service
Azure AD – Provide Authentication and Authorization to
Cloud App (Office365 , SharePoint online Etc) and Azure .
www.SubhenduMCT.com
Starting from Facebook ,
Gmail , Hotmail
Even this Gate Pass of
this seminar says –
Who you are ?
&
What you can Do ?
www.SubhenduMCT.co
In organization - Employee prove there Identity by their domain username and password.
To set up this , we install ADDS role in Server.
www.SubhenduMCT.co
ADDS is a Role in windows server – Provide 3A Factor
Authentication – Authorization - Accounting
in our Domain Environment
www.SubhenduMCT.com
Azure AD – Provide
Authentication and
Authorization to cloud app
(Office365 , SP online etc)
and Azure .
www.SubhenduMCT.com
• Microsoft-managed
• A platform as a service offering
• Multitenant by design
• Employs Internet-friendly protocols
• Supports users, groups, applications, and devices
• No organizational units or computer objects
• Does not support Group Policy settings
• No support for forests, relies on federations to extend scope of
authentication and authorization
• Delegation model based on Role-Based Access Control
• Easily extensible, includes multi-factor authentication support
• Provides authentication and authorization:
• Cloud identity
• Synchronized identity
• Federated identity
www.SubhenduMCT.com
ADDS Azure AD
First introduced with Windows
2000 Server
Introduced with Azure
It has a hierarchical structure
based on X.500. It uses DNS
for locating objects, can be
interacted with using LDAP,
and
it primarily uses Kerberos for
authentication.
Azure AD is a multi-customer public
directory service for your cloud servers
and apps such as O365. Users and
groups are created in a flat structure
without
OUs or GPOs. Authentication is
performed through protocols such as
SAML, WS-Federation, and OAuth. It's
possible to query Azure AD, but instead
of using LDAP you must use a REST
API called AD Graph API. These all
work over HTTP and HTTPS.
www.SubhenduMCT.co
Managing multiple Azure AD tenants
Uses for multiple directories:
• Live directory
• Test directory
• Sync directory
Multiple cloud services can use Azure AD for authentication and
authorization:
• Azure
• Office 365
• Intune
You can add users from one directory to another directory
www.SubhenduMCT.com
Implementing Azure AD B2B and Azure AD
B2C
Azure AD Business to Business (B2B):
• Provides simple and secure sharing of data and applications
• Works with partners that have their own Azure AD tenant and with
partners that do not have an Azure AD tenant
• Requires a company to federate only once with Azure AD
Azure AD Business to Consumer (B2C):
• Provides Identity as a Service for applications
• Supports standard protocols, such as OpenID Connect and OAuth 2.0
• Supports identity management by using social accounts such as
Facebook, Google, and LinkedIn
www.SubhenduMCT.com
Overview of managing Cloud Applications
• Enable SSO for apps
• Use centralized application access management
• Grant access to users and groups from Azure AD or from
AD DS
• Use unified reporting and monitoring
• Use the Application Access Panel
http://myapps.microsoft.com
www.SubhenduMCT.com
Integrating applications with Azure AD
• Add an application from the Azure AD application gallery
• http://azure.microsoft.com/en-us/gallery/active-directory/
• Add a custom LOB application in Azure AD:
• Register the web app in the Azure AD tenant
• Add logic or code to the web app:
• Block and redirect unauthenticated request
• Grant access to authenticated requests
• Add a SaaS application that is not listed in the Azure AD
application gallery:
• Register the web app in the Azure AD tenant
• Configure SSO with Azure AD
• Assign users and groups to the application
www.SubhenduMCT.com
Introducing Azure AD Premium
Features of Azure AD Premium:
•Self-service group management
•Advanced security reports and alerts
•Multi-Factor Authentication
•Enterprise SLA of 99.9 percent
•Self-service password reset with writeback
•Cloud App Discovery
•Azure AD Connect Health
www.SubhenduMCT.com
Azure Multi-Factor Authentication
• Azure Multi-Factor Authentication requires
additional form of authentication:
• Mobile app authentication
• Phone call
• Text message
• Email message
• Third party OAuth token
• Multi-factor security solution:
• For cloud-only apps
• For on-premises applications
www.SubhenduMCT.com
Deploy Active Directory domain controllers in
Azure
• Reasons for placing domain controllers in Azure:
• Providing resilience to the on-premises directory
• Keeping authentication requests for Azure-based services within Azure
• Extending access to on-premises Active Directory to worldwide sites
• Enabling additional directory synchronization options
• Deployment scenarios:
• Deploy domain controllers only in Azure
• Deploy AD DS only in an on-premises infrastructure with cross-premises
connectivity
• Deploy AD DS in an on-premises infrastructure and on an Azure virtual
machine
• Planning considerations:
• Inter-site connectivity
• Active Directory sites
• Read-only domain controllers
• FSMO roles and global catalog placement
• Backup and restore www.SubhenduMCT.com
Installing and configuring Azure AD
Connect
• Use express settings for:
• A single Active Directory forest
• Signing in with the same password by using password
synchronization
• Installing Azure AD Connect with express settings:
• Installs the synchronization engine
• Configures Azure AD Connector
• Configures the on-premises AD DS connector
• Enables password synchronization
• Configures synchronization services
• Configures synchronization services for Exchange hybrid
deployment (optional)
www.SubhenduMCT.com
Overview of AD DS and Azure AD integration
options
• Extend on-premises Active Directory to Azure
• Synchronize AD DS with Azure AD:
• Optional password synchronization
• Implement trust relationship and single sign-on
(SSO):
• Active Directory Federation Service (AD FS)
• Web Application Proxy
www.SubhenduMCT.com
Hum Hain Rahi Cloud Ke - Phir Milenge Chalte
Chalte…. - $ubhendu

More Related Content

PPTX
Azure Identity and access management
PPTX
Azure active directory
PPTX
Azure WAF
PDF
Understanding Azure AD
PPTX
Azure Active Directory - An Introduction
PDF
Demystifying SAML 2.0,Oauth 2.0, OpenID Connect
PDF
Microsoft Azure Overview | Cloud Computing Tutorial with Azure | Azure Traini...
PDF
Azure Active Directory | Microsoft Azure Tutorial for Beginners | Azure 70-53...
Azure Identity and access management
Azure active directory
Azure WAF
Understanding Azure AD
Azure Active Directory - An Introduction
Demystifying SAML 2.0,Oauth 2.0, OpenID Connect
Microsoft Azure Overview | Cloud Computing Tutorial with Azure | Azure Traini...
Azure Active Directory | Microsoft Azure Tutorial for Beginners | Azure 70-53...

What's hot (20)

PPTX
Azure Tutorial For Beginners | Microsoft Azure Tutorial For Beginners | Azure...
PPTX
Azure AD connect- Deep Dive Webinar PPT
PPTX
Azure-AD.pptx
PDF
Identity and Access Management from Microsoft and Razor Technology
PDF
Microsoft Azure Active Directory
PDF
Identity Security - Azure Identity Protection
PPTX
Azure AD Connect
PDF
Microsoft Azure Fundamentals
PPTX
48. Azure Active Directory - Part 1
PPTX
Microsoft azure
PDF
Az 104 session 5: Azure networking
PDF
Azure security architecture
PDF
Az 104 session 4: azure storage
PPTX
Azure role based access control (rbac)
PPTX
Azure governance
PDF
Azure DDoS Protection Standard
PPTX
Azure Network Security Groups (NSG)
PDF
Az 104 session 3 azure compute
PPTX
Windows Azure Virtual Machines
PPTX
Introduction to Microsoft Azure
Azure Tutorial For Beginners | Microsoft Azure Tutorial For Beginners | Azure...
Azure AD connect- Deep Dive Webinar PPT
Azure-AD.pptx
Identity and Access Management from Microsoft and Razor Technology
Microsoft Azure Active Directory
Identity Security - Azure Identity Protection
Azure AD Connect
Microsoft Azure Fundamentals
48. Azure Active Directory - Part 1
Microsoft azure
Az 104 session 5: Azure networking
Azure security architecture
Az 104 session 4: azure storage
Azure role based access control (rbac)
Azure governance
Azure DDoS Protection Standard
Azure Network Security Groups (NSG)
Az 104 session 3 azure compute
Windows Azure Virtual Machines
Introduction to Microsoft Azure
Ad

Similar to Azure - Identity as a service (20)

PPTX
JoTechies - Cloud identity
PPTX
Análisis de riesgos en Azure y protección de la información
PPTX
Microsoft Azure AD architecture and features
PPTX
What's new in Azure Active Directory and what's coming new ?
PPTX
Azure Community Tour 2019 - AZUGDK
PPTX
Windows Azure Active Directory: Identity Management in the Cloud
PDF
Premier Webcast - Identity Management with Windows Azure AD
PPTX
2018 November - AZUGDK - Azure AD
PPTX
Microsoft Azure Active Directory
PPTX
20150924 Xylos Technology Day - Stay in control of your identity with Azure A...
PDF
AZ-104 Course Training Presentation_KoFi.pdf
PPTX
Azure Global Bootcamp 2017 Azure AD Deployment
PPTX
Azure AD Presentation - @ BITPro - Ajay
PPTX
Azure Day 1.pptx
PDF
Protect your business with identity and access management in the cloud
PDF
O365Con18 - Red Team vs Blue Team - Sasha Kranjac & Mustafa Toroman
PDF
Understanding Azure AD Webinar Presentation
PDF
MS Cloud Identity and Access Infographic 2015 (1)
PDF
Ms cloud identity and access infographic 2015
PPTX
Azure AD and Office 365 - Deja Vu All Over Again
JoTechies - Cloud identity
Análisis de riesgos en Azure y protección de la información
Microsoft Azure AD architecture and features
What's new in Azure Active Directory and what's coming new ?
Azure Community Tour 2019 - AZUGDK
Windows Azure Active Directory: Identity Management in the Cloud
Premier Webcast - Identity Management with Windows Azure AD
2018 November - AZUGDK - Azure AD
Microsoft Azure Active Directory
20150924 Xylos Technology Day - Stay in control of your identity with Azure A...
AZ-104 Course Training Presentation_KoFi.pdf
Azure Global Bootcamp 2017 Azure AD Deployment
Azure AD Presentation - @ BITPro - Ajay
Azure Day 1.pptx
Protect your business with identity and access management in the cloud
O365Con18 - Red Team vs Blue Team - Sasha Kranjac & Mustafa Toroman
Understanding Azure AD Webinar Presentation
MS Cloud Identity and Access Infographic 2015 (1)
Ms cloud identity and access infographic 2015
Azure AD and Office 365 - Deja Vu All Over Again
Ad

More from BizTalk360 (20)

PPTX
Optimise Business Activity Tracking – Insights from Smurfit Kappa
PPTX
Optimise Business Activity Tracking – Insights from Smurfit Kappa
PPTX
What's inside "migrating to biz talk server 2020" Book (BizTalk360 Webinar)
PPTX
Integration Monday - Logic Apps: Development Experiences
PPTX
Integration Monday - BizTalk Migrator Deep Dive
PPTX
Testing for Logic App Solutions | Integration Monday
PPTX
No-Slides
PPTX
System Integration using Reactive Programming | Integration Monday
PPTX
Building workflow solution with Microsoft Azure and Cloud | Integration Monday
PPTX
Serverless Minimalism: How to architect your apps to save 98% on your Azure b...
PPTX
Migrating BizTalk Solutions to Azure: Mapping Messages | Integration Monday
PPTX
Integration-Monday-Infrastructure-As-Code-With-Terraform
PDF
Integration-Monday-Stateful-Programming-Models-Serverless-Functions
PPTX
Integration-Monday-Serverless-Slackbots-with-Azure-Durable-Functions
PPTX
Integration-Monday-Building-Stateful-Workloads-Kubernetes
PPTX
Integration-Monday-Logic-Apps-Tips-Tricks
PPTX
Integration-Monday-Terraform-Serverless
PPTX
Integration-Monday-Microsoft-Power-Platform
PDF
One name unify them all
PPTX
Securely Publishing Azure Services
Optimise Business Activity Tracking – Insights from Smurfit Kappa
Optimise Business Activity Tracking – Insights from Smurfit Kappa
What's inside "migrating to biz talk server 2020" Book (BizTalk360 Webinar)
Integration Monday - Logic Apps: Development Experiences
Integration Monday - BizTalk Migrator Deep Dive
Testing for Logic App Solutions | Integration Monday
No-Slides
System Integration using Reactive Programming | Integration Monday
Building workflow solution with Microsoft Azure and Cloud | Integration Monday
Serverless Minimalism: How to architect your apps to save 98% on your Azure b...
Migrating BizTalk Solutions to Azure: Mapping Messages | Integration Monday
Integration-Monday-Infrastructure-As-Code-With-Terraform
Integration-Monday-Stateful-Programming-Models-Serverless-Functions
Integration-Monday-Serverless-Slackbots-with-Azure-Durable-Functions
Integration-Monday-Building-Stateful-Workloads-Kubernetes
Integration-Monday-Logic-Apps-Tips-Tricks
Integration-Monday-Terraform-Serverless
Integration-Monday-Microsoft-Power-Platform
One name unify them all
Securely Publishing Azure Services

Recently uploaded (20)

PPTX
PA Analog/Digital System: The Backbone of Modern Surveillance and Communication
PPTX
Cloud computing and distributed systems.
PPT
“AI and Expert System Decision Support & Business Intelligence Systems”
PPTX
VMware vSphere Foundation How to Sell Presentation-Ver1.4-2-14-2024.pptx
PDF
cuic standard and advanced reporting.pdf
PDF
Building Integrated photovoltaic BIPV_UPV.pdf
PDF
Electronic commerce courselecture one. Pdf
PDF
Machine learning based COVID-19 study performance prediction
PDF
Review of recent advances in non-invasive hemoglobin estimation
PDF
Empathic Computing: Creating Shared Understanding
PDF
Modernizing your data center with Dell and AMD
PDF
Dropbox Q2 2025 Financial Results & Investor Presentation
PPTX
KOM of Painting work and Equipment Insulation REV00 update 25-dec.pptx
PDF
Blue Purple Modern Animated Computer Science Presentation.pdf.pdf
PDF
7 ChatGPT Prompts to Help You Define Your Ideal Customer Profile.pdf
PDF
Bridging biosciences and deep learning for revolutionary discoveries: a compr...
PDF
Spectral efficient network and resource selection model in 5G networks
PDF
KodekX | Application Modernization Development
PDF
TokAI - TikTok AI Agent : The First AI Application That Analyzes 10,000+ Vira...
PDF
Approach and Philosophy of On baking technology
PA Analog/Digital System: The Backbone of Modern Surveillance and Communication
Cloud computing and distributed systems.
“AI and Expert System Decision Support & Business Intelligence Systems”
VMware vSphere Foundation How to Sell Presentation-Ver1.4-2-14-2024.pptx
cuic standard and advanced reporting.pdf
Building Integrated photovoltaic BIPV_UPV.pdf
Electronic commerce courselecture one. Pdf
Machine learning based COVID-19 study performance prediction
Review of recent advances in non-invasive hemoglobin estimation
Empathic Computing: Creating Shared Understanding
Modernizing your data center with Dell and AMD
Dropbox Q2 2025 Financial Results & Investor Presentation
KOM of Painting work and Equipment Insulation REV00 update 25-dec.pptx
Blue Purple Modern Animated Computer Science Presentation.pdf.pdf
7 ChatGPT Prompts to Help You Define Your Ideal Customer Profile.pdf
Bridging biosciences and deep learning for revolutionary discoveries: a compr...
Spectral efficient network and resource selection model in 5G networks
KodekX | Application Modernization Development
TokAI - TikTok AI Agent : The First AI Application That Analyzes 10,000+ Vira...
Approach and Philosophy of On baking technology

Azure - Identity as a service

  • 1. PRESENTS Microsoft, DLF Cyber City August 20, 2017 MICROSOFT AZURE DAY Subhendu Bhattacharyya Microsoft Certified Trainer , MCP ,MCSA , MCSE , MS – Azure Corporate Trainer @ Koenig Solutions Pvt Ltd , Blogger Blog/Website : www.SubhenduMCT.com Azure AD – Identity As A Service
  • 2. Public Cloud Offering From Microsoft 42 Datacenter Across The Globe 62 Compliance Offering 90% of Fortune 500 company use Azure 72 product available in portal One Stop Support from Microsoft Great compatibility with your on prem env www.SubhenduMCT.co
  • 3. Azure AD – Identity As A Service Azure AD – Provide Authentication and Authorization to Cloud App (Office365 , SharePoint online Etc) and Azure . www.SubhenduMCT.com
  • 4. Starting from Facebook , Gmail , Hotmail Even this Gate Pass of this seminar says – Who you are ? & What you can Do ? www.SubhenduMCT.co
  • 5. In organization - Employee prove there Identity by their domain username and password. To set up this , we install ADDS role in Server. www.SubhenduMCT.co
  • 6. ADDS is a Role in windows server – Provide 3A Factor Authentication – Authorization - Accounting in our Domain Environment www.SubhenduMCT.com
  • 7. Azure AD – Provide Authentication and Authorization to cloud app (Office365 , SP online etc) and Azure . www.SubhenduMCT.com
  • 8. • Microsoft-managed • A platform as a service offering • Multitenant by design • Employs Internet-friendly protocols • Supports users, groups, applications, and devices • No organizational units or computer objects • Does not support Group Policy settings • No support for forests, relies on federations to extend scope of authentication and authorization • Delegation model based on Role-Based Access Control • Easily extensible, includes multi-factor authentication support • Provides authentication and authorization: • Cloud identity • Synchronized identity • Federated identity www.SubhenduMCT.com
  • 9. ADDS Azure AD First introduced with Windows 2000 Server Introduced with Azure It has a hierarchical structure based on X.500. It uses DNS for locating objects, can be interacted with using LDAP, and it primarily uses Kerberos for authentication. Azure AD is a multi-customer public directory service for your cloud servers and apps such as O365. Users and groups are created in a flat structure without OUs or GPOs. Authentication is performed through protocols such as SAML, WS-Federation, and OAuth. It's possible to query Azure AD, but instead of using LDAP you must use a REST API called AD Graph API. These all work over HTTP and HTTPS. www.SubhenduMCT.co
  • 10. Managing multiple Azure AD tenants Uses for multiple directories: • Live directory • Test directory • Sync directory Multiple cloud services can use Azure AD for authentication and authorization: • Azure • Office 365 • Intune You can add users from one directory to another directory www.SubhenduMCT.com
  • 11. Implementing Azure AD B2B and Azure AD B2C Azure AD Business to Business (B2B): • Provides simple and secure sharing of data and applications • Works with partners that have their own Azure AD tenant and with partners that do not have an Azure AD tenant • Requires a company to federate only once with Azure AD Azure AD Business to Consumer (B2C): • Provides Identity as a Service for applications • Supports standard protocols, such as OpenID Connect and OAuth 2.0 • Supports identity management by using social accounts such as Facebook, Google, and LinkedIn www.SubhenduMCT.com
  • 12. Overview of managing Cloud Applications • Enable SSO for apps • Use centralized application access management • Grant access to users and groups from Azure AD or from AD DS • Use unified reporting and monitoring • Use the Application Access Panel http://myapps.microsoft.com www.SubhenduMCT.com
  • 13. Integrating applications with Azure AD • Add an application from the Azure AD application gallery • http://azure.microsoft.com/en-us/gallery/active-directory/ • Add a custom LOB application in Azure AD: • Register the web app in the Azure AD tenant • Add logic or code to the web app: • Block and redirect unauthenticated request • Grant access to authenticated requests • Add a SaaS application that is not listed in the Azure AD application gallery: • Register the web app in the Azure AD tenant • Configure SSO with Azure AD • Assign users and groups to the application www.SubhenduMCT.com
  • 14. Introducing Azure AD Premium Features of Azure AD Premium: •Self-service group management •Advanced security reports and alerts •Multi-Factor Authentication •Enterprise SLA of 99.9 percent •Self-service password reset with writeback •Cloud App Discovery •Azure AD Connect Health www.SubhenduMCT.com
  • 15. Azure Multi-Factor Authentication • Azure Multi-Factor Authentication requires additional form of authentication: • Mobile app authentication • Phone call • Text message • Email message • Third party OAuth token • Multi-factor security solution: • For cloud-only apps • For on-premises applications www.SubhenduMCT.com
  • 16. Deploy Active Directory domain controllers in Azure • Reasons for placing domain controllers in Azure: • Providing resilience to the on-premises directory • Keeping authentication requests for Azure-based services within Azure • Extending access to on-premises Active Directory to worldwide sites • Enabling additional directory synchronization options • Deployment scenarios: • Deploy domain controllers only in Azure • Deploy AD DS only in an on-premises infrastructure with cross-premises connectivity • Deploy AD DS in an on-premises infrastructure and on an Azure virtual machine • Planning considerations: • Inter-site connectivity • Active Directory sites • Read-only domain controllers • FSMO roles and global catalog placement • Backup and restore www.SubhenduMCT.com
  • 17. Installing and configuring Azure AD Connect • Use express settings for: • A single Active Directory forest • Signing in with the same password by using password synchronization • Installing Azure AD Connect with express settings: • Installs the synchronization engine • Configures Azure AD Connector • Configures the on-premises AD DS connector • Enables password synchronization • Configures synchronization services • Configures synchronization services for Exchange hybrid deployment (optional) www.SubhenduMCT.com
  • 18. Overview of AD DS and Azure AD integration options • Extend on-premises Active Directory to Azure • Synchronize AD DS with Azure AD: • Optional password synchronization • Implement trust relationship and single sign-on (SSO): • Active Directory Federation Service (AD FS) • Web Application Proxy www.SubhenduMCT.com
  • 19. Hum Hain Rahi Cloud Ke - Phir Milenge Chalte Chalte…. - $ubhendu