SlideShare a Scribd company logo
Protiviti
Antonio Maio
Senior SharePoint Architect & Senior Manager
Microsoft SharePoint Server MVP
Identity Management Challenges
Moving SharePoint to the Cloud
Email: Antonio.maio@protiviti.com
Blog: www.trustsharepoint.com
Slide share: http://www.slideshare.net/AntonioMaio2
Twitter: @AntonioMaio2
© 2014 Protiviti Consulting Private Ltd. An Equal Opportunity Employer.
CONFIDENTIAL: This document is for internal use only and may not be copied nor distributed to another third party.
About Protiviti
INDIA (3)
Protiviti (www.protiviti.com) is a global consulting firm that helps companies solve problems in finance,
technology, operations, governance, risk and internal audit. Through our network of more than 70 offices in
over 20 countries, we have served more than 35 percent of FORTUNE® 1000 and Global 500 companies. We
also work with smaller, growing companies, including those looking to go public, as well as with government
agencies.
Protiviti is a wholly owned subsidiary of Robert Half International Inc. (NYSE: RHI). Founded in 1948, Robert
Half International is a member of the S&P 500 index.
• 2,500+
professionals
• 1,000+ clients
• 70+ offices
• Over 20
countries in
the Americas,
Europe and
Asia-Pacific
Protiviti is one of
the fastest
growing
consulting firms
worldwide. Our
revenues have
increased from
US $15 million in
2002, to US
$423.8 million in
2011.
© 2014 Protiviti Consulting Private Ltd. An Equal Opportunity Employer.
CONFIDENTIAL: This document is for internal use only and may not be copied nor distributed to another third party.
• Sensitive data
• Access systems and data
• Log/track access
• Malicious access to systems/data
• Business Identity Theft
© 2014 Protiviti Consulting Private Ltd. An Equal Opportunity Employer.
CONFIDENTIAL: This document is for internal use only and may not be copied nor distributed to another third party.
…moving to the Cloud
© 2014 Protiviti Consulting Private Ltd. An Equal Opportunity Employer.
CONFIDENTIAL: This document is for internal use only and may not be copied nor distributed to another third party.
Why Hybrid?
• Get started slowly | Take small steps | Explore cloud services
• Access to collaboration features for extranet & remote users
• Employees connect to Corp. resources/content from almost anywhere
• 3rd party solutions or custom code – continue to use & extend to cloud
• Retain corporate control & storage of sensitive data
Hybrid Deployments
© 2014 Protiviti Consulting Private Ltd. An Equal Opportunity Employer.
CONFIDENTIAL: This document is for internal use only and may not be copied nor distributed to another third party.
Identity Models for Office 365
© 2014 Protiviti Consulting Private Ltd. An Equal Opportunity Employer.
CONFIDENTIAL: This document is for internal use only and may not be copied nor distributed to another third party.
Cloud Identity Model
© 2014 Protiviti Consulting Private Ltd. An Equal Opportunity Employer.
CONFIDENTIAL: This document is for internal use only and may not be copied nor distributed to another third party.
Synchronized Identity Model
© 2014 Protiviti Consulting Private Ltd. An Equal Opportunity Employer.
CONFIDENTIAL: This document is for internal use only and may not be copied nor distributed to another third party.
Federated Identity Model
© 2014 Protiviti Consulting Private Ltd. An Equal Opportunity Employer.
CONFIDENTIAL: This document is for internal use only and may not be copied nor distributed to another third party.
Select the Simplest Model
© 2014 Protiviti Consulting Private Ltd. An Equal Opportunity Employer.
CONFIDENTIAL: This document is for internal use only and may not be copied nor distributed to another third party.
Selecting an Identity Model
I need to…
Directory Sync
Scenario
Directory Sync with
Password Sync
Directory Sync with
Single Sign-On
Sync new user, contact, & groups created in on-premises Active
Directory to cloud automatically
Sync incremental updates made to existing accounts in on-premises
Active Directory to cloud automatically
Set up my tenant for Office 365 hybrid scenarios
Enable users to sign in to cloud services using on-premises password
Reduce password administration costs
Control password policies from on-premises Active Directory
Enable cloud-based multi-factor authentication solutions
Enable on-premises multi-factor authentication solutions
Ensure user authentications occur in on-premises Active Directory
Implement single sign-on using corporate credentials
Customize the user Sign-In page
Limit access to cloud services based on the location, client type or
Exchange endpoint of the client
© 2014 Protiviti Consulting Private Ltd. An Equal Opportunity Employer.
CONFIDENTIAL: This document is for internal use only and may not be copied nor distributed to another third party.
Configuring Directory Sync
Multi-steps process
1. Prepare for Directory Synchronization
• Prerequisites, Permissions, Understand Limits
• Alternate UPN Suffix for .local Domain
• Clean Up Active Directory
2. Activate Directory Synchronization
• Register your Domain with Office 365 & Validate Ownership
• Use “Microsoft Deployment Readiness Tool”
3. Setup Directory Synchronization Server
• Option: Hybrid Deployment
• Option: Enable Password Synchronization
4. Synchronize Directories
5. Activate Users & Assign Office 365 Licenses
6. Manage Directory Synchronization
© 2014 Protiviti Consulting Private Ltd. An Equal Opportunity Employer.
CONFIDENTIAL: This document is for internal use only and may not be copied nor distributed to another third party.
DEMONSTRATION
© 2014 Protiviti Consulting Private Ltd. An Equal Opportunity Employer.
CONFIDENTIAL: This document is for internal use only and may not be copied nor distributed to another third party.
Configuring Directory Sync
Multi-steps process
1. Prepare for Directory Synchronization
• Prerequisites, Permissions, Understand Limits
• Alternate UPN Suffix for .local Domain
• Clean Up Active Directory
2. Activate Directory Synchronization
• Register your Domain with Office 365 & Validate Ownership
• Use “Microsoft Deployment Readiness Tool”
3. Setup Directory Synchronization Server
• Option: Hybrid Deployment
• Option: Enable Password Synchronization
4. Synchronize Directories
5. Activate Users & Assign Office 365 Licenses
6. Manage Directory Synchronization
© 2014 Protiviti Consulting Private Ltd. An Equal Opportunity Employer.
CONFIDENTIAL: This document is for internal use only and may not be copied nor distributed to another third party.
Configuring Directory Sync
• Alternate UPN Suffix for .local Domain
© 2014 Protiviti Consulting Private Ltd. An Equal Opportunity Employer.
CONFIDENTIAL: This document is for internal use only and may not be copied nor distributed to another third party.
Configuring Directory Sync
• Alternate UPN Suffix for .local Domain
© 2014 Protiviti Consulting Private Ltd. An Equal Opportunity Employer.
CONFIDENTIAL: This document is for internal use only and may not be copied nor distributed to another third party.
Configuring Directory Sync
• Clean up Active Directory – set UPN for each user identity
© 2014 Protiviti Consulting Private Ltd. An Equal Opportunity Employer.
CONFIDENTIAL: This document is for internal use only and may not be copied nor distributed to another third party.
Configuring Directory Sync
• Clean up Active Directory – set proxyAddresses each user identity
© 2014 Protiviti Consulting Private Ltd. An Equal Opportunity Employer.
CONFIDENTIAL: This document is for internal use only and may not be copied nor distributed to another third party.
Configuring Directory Sync
• Clean up Active Directory – set proxyAddresses each user identity
© 2014 Protiviti Consulting Private Ltd. An Equal Opportunity Employer.
CONFIDENTIAL: This document is for internal use only and may not be copied nor distributed to another third party.
Configuring Directory Sync
Multi-steps process
1. Prepare for Directory Synchronization
• Prerequisites, Permissions, Understand Limits
• Alternate UPN Suffix for .local Domain
• Clean Up Active Directory
2. Activate Directory Synchronization
• Register your Domain with Office 365 & Validate Ownership
• Use “Microsoft Deployment Readiness Tool”
3. Setup Directory Synchronization Server
• Option: Hybrid Deployment
• Option: Enable Password Synchronization
4. Synchronize Directories
5. Activate Users & Assign Office 365 Licenses
6. Manage Directory Synchronization
© 2014 Protiviti Consulting Private Ltd. An Equal Opportunity Employer.
CONFIDENTIAL: This document is for internal use only and may not be copied nor distributed to another third party.
Configuring Directory Sync
• Register Domain with Office 365 & Validate Ownership
© 2014 Protiviti Consulting Private Ltd. An Equal Opportunity Employer.
CONFIDENTIAL: This document is for internal use only and may not be copied nor distributed to another third party.
Configuring Directory Sync
• Register Domain with Office 365 & Validate Ownership
© 2014 Protiviti Consulting Private Ltd. An Equal Opportunity Employer.
CONFIDENTIAL: This document is for internal use only and may not be copied nor distributed to another third party.
Configuring Directory Sync
• Register Domain with Office 365 & Validate Ownership
© 2014 Protiviti Consulting Private Ltd. An Equal Opportunity Employer.
CONFIDENTIAL: This document is for internal use only and may not be copied nor distributed to another third party.
Configuring Directory Sync
• Register Domain with Office 365 & Validate Ownership
© 2014 Protiviti Consulting Private Ltd. An Equal Opportunity Employer.
CONFIDENTIAL: This document is for internal use only and may not be copied nor distributed to another third party.
Configuring Directory Sync
• Register Domain with Office 365 & Validate Ownership
© 2014 Protiviti Consulting Private Ltd. An Equal Opportunity Employer.
CONFIDENTIAL: This document is for internal use only and may not be copied nor distributed to another third party.
Configuring Directory Sync
• Activate Directory Synchronization
© 2014 Protiviti Consulting Private Ltd. An Equal Opportunity Employer.
CONFIDENTIAL: This document is for internal use only and may not be copied nor distributed to another third party.
Configuring Directory Sync
• Activate Directory Synchronization
© 2014 Protiviti Consulting Private Ltd. An Equal Opportunity Employer.
CONFIDENTIAL: This document is for internal use only and may not be copied nor distributed to another third party.
Configuring Directory Sync
Multi-steps process
1. Prepare for Directory Synchronization
• Prerequisites, Permissions, Understand Limits
• Alternate UPN Suffix for .local Domain
• Clean Up Active Directory
2. Activate Directory Synchronization
• Register your Domain with Office 365 & Validate Ownership
• Use “Microsoft Deployment Readiness Tool”
3. Setup Directory Synchronization Server
• Option: Hybrid Deployment
• Option: Enable Password Sync
4. Synchronize Directories
5. Activate Users & Assign Office 365 Licenses
6. Manage Directory Synchronization
• Requires: AD Enterprise Domain Admin Acct
• Requires: O365 Service Admin Acct
© 2014 Protiviti Consulting Private Ltd. An Equal Opportunity Employer.
CONFIDENTIAL: This document is for internal use only and may not be copied nor distributed to another third party.
Configuring Directory Sync
Multi-steps process
1. Prepare for Directory Synchronization
• Prerequisites, Permissions, Understand Limits
• Alternate UPN Suffix for .local Domain
• Clean Up Active Directory
2. Activate Directory Synchronization
• Register your Domain with Office 365 & Validate Ownership
• Use “Microsoft Deployment Readiness Tool”
3. Setup Directory Synchronization Server
• Option: Hybrid Deployment
• Option: Enable Password Synchronization
4. Synchronize Directories
5. Activate Users & Assign Office 365 Licenses
6. Manage Directory Synchronization
© 2014 Protiviti Consulting Private Ltd. An Equal Opportunity Employer.
CONFIDENTIAL: This document is for internal use only and may not be copied nor distributed to another third party.
Configuring Directory Sync
• After users & groups are synchronized
© 2014 Protiviti Consulting Private Ltd. An Equal Opportunity Employer.
CONFIDENTIAL: This document is for internal use only and may not be copied nor distributed to another third party.
Configuring Directory Sync
Multi-steps process
1. Prepare for Directory Synchronization
• Prerequisites, Permissions, Understand Limits
• Alternate UPN Suffix for .local Domain
• Clean Up Active Directory
2. Activate Directory Synchronization
• Register your Domain with Office 365 & Validate Ownership
• Use “Microsoft Deployment Readiness Tool”
3. Setup Directory Synchronization Server
• Option: Hybrid Deployment
• Option: Enable Password Synchronization
4. Synchronize Directories
5. Activate Users & Assign Office 365 Licenses
6. Manage Directory Synchronization
© 2014 Protiviti Consulting Private Ltd. An Equal Opportunity Employer.
CONFIDENTIAL: This document is for internal use only and may not be copied nor distributed to another third party.
Configuring Identity Federation
Multi-steps process:
1. Prepare for Single Sign On
• Prerequisites, Prepare Active Directory
• Prepare Network infrastructure for Federation servers
2. Setup the On Premise Security Token Service (STS) - Active
Directory Federation Services (ADFS)
• Set up Windows PowerShell for SSO with AD FS
• Set up trust between AD FS and Azure AD
3. Setup Directory Synchronization
4. Verify & Manage Single Sign On
© 2014 Protiviti Consulting Private Ltd. An Equal Opportunity Employer.
CONFIDENTIAL: This document is for internal use only and may not be copied nor distributed to another third party.
Configuring Identity Federation
Multi-steps process:
1. Prepare for Single Sign On
• Prerequisites, Prepare Active Directory
• Prepare Network infrastructure for Federation servers
2. Setup the On Premise Security Token Service (STS) - Active
Directory Federation Services (ADFS)
• Set up Windows PowerShell for SSO with AD FS
• Set up trust between AD FS and Azure AD
3. Setup Directory Synchronization
4. Verify & Manage Single Sign On
© 2014 Protiviti Consulting Private Ltd. An Equal Opportunity Employer.
CONFIDENTIAL: This document is for internal use only and may not be copied nor distributed to another third party.
Configuring Identity Federation
Multi-steps process:
1. Prepare for Single Sign On
• Prerequisites, Prepare Active Directory
• Prepare Network infrastructure for Federation servers
2. Setup the On Premise Security Token Service (STS) - Active
Directory Federation Services (ADFS)
• Set up Windows PowerShell for SSO with AD FS
• Set up trust between AD FS and Azure AD
3. Setup Directory Synchronization
4. Verify & Manage Single Sign On
© 2014 Protiviti Consulting Private Ltd. An Equal Opportunity Employer.
CONFIDENTIAL: This document is for internal use only and may not be copied nor distributed to another third party.
Configuring Identity Federation
Multi-steps process:
1. Prepare for Single Sign On
• Prerequisites, Prepare Active Directory
• Prepare Network infrastructure for Federation servers
2. Setup the On Premise Security Token Service (STS) - Active
Directory Federation Services (ADFS)
• Set up Windows PowerShell for SSO with AD FS
• Set up trust between AD FS and Azure AD
3. Setup Directory Synchronization
4. Verify & Manage Single Sign On
© 2014 Protiviti Consulting Private Ltd. An Equal Opportunity Employer.
CONFIDENTIAL: This document is for internal use only and may not be copied nor distributed to another third party.
Overall Benefits
• Reduced administration costs
• Leveraging your already existing on-premises user and group
accounts
• Improved productivity
• Significantly reduce the amount of time it takes to make cloud based
services accessible
• Increased security
• Ensures that only those appropriate users have access to your
corporate assets
© 2014 Protiviti Consulting Private Ltd. An Equal Opportunity Employer.
CONFIDENTIAL: This document is for internal use only and may not be copied nor distributed to another third party.
Step by Step Procedures
Please see 2 blog posts:
• Part 1: http://sharepoint.protiviti.com/blog/Lists/Posts/Post.aspx?ID=142
• Part 2: http://sharepoint.protiviti.com/blog/Lists/Posts/Post.aspx?ID=165
This deck will be posted to my blog: www.trustsharepoint.com
Email: Antonio.maio@protiviti.com
Blog: www.trustsharepoint.com
Slide share: http://www.slideshare.net/AntonioMaio2
Twitter: @AntonioMaio2
Identity Management Challenges when moving SharePoint to the Cloud
Antonio Maio
Senior SharePoint Architect & Senior Manager
Microsoft SharePoint Server MVP
Thank You – Question and Answer

More Related Content

PDF
Overcoming Security Threats and Vulnerabilities in SharePoint
PPTX
SharePoint In The Cloud: Evaluating Impact, Pros, and Cons - SPLive360
PPTX
Governing and managing hybrid SharePoint environments
PDF
Topic-oriented information architecture for very large websites
PDF
Cross-format content with Lightweight DITA
PPTX
Managing SharePoint On-Premises vs. Online -- Compare and Contrast
PPTX
Ondernemen naast je huidige baan.
PDF
Kuopion alueen menestys 2000 luvulla
Overcoming Security Threats and Vulnerabilities in SharePoint
SharePoint In The Cloud: Evaluating Impact, Pros, and Cons - SPLive360
Governing and managing hybrid SharePoint environments
Topic-oriented information architecture for very large websites
Cross-format content with Lightweight DITA
Managing SharePoint On-Premises vs. Online -- Compare and Contrast
Ondernemen naast je huidige baan.
Kuopion alueen menestys 2000 luvulla

Viewers also liked (17)

PDF
Time Planner
PDF
SDP aluekehitysseminaari 26.11.2013
PDF
LIIKENNE JA KAUPUNKISEUTUJEN KEHITYS
DOCX
Time planner
PPS
Cantos
PDF
Triangeli-projektin loppuarvioinnin keskeiset nostot
PDF
3Q14
PPTX
Shop cctv camera in dallas
PDF
Financial presentation 07 vfinal
PPTX
Chapter 04 storage csc & tts
DOCX
Women and personal finance
PDF
Mullistaako muuttoliike Suomen?
PDF
Muuttoliike ja asuntomarkkinoiden ostovoima
PDF
KAUPUNKIEN JA KAUPUNKISEUTUJEN MERKITYS IH-ALUEITA MUODOSTETTAESSA
PDF
L'App store per applicazioni Enterprise: La mobilità porta a porta
PDF
Satakunnan asema alueiden välisessä kilpailussa 2000-luvulla
PDF
373 arezzo investor_day_-_expansion_presentation_vrev
Time Planner
SDP aluekehitysseminaari 26.11.2013
LIIKENNE JA KAUPUNKISEUTUJEN KEHITYS
Time planner
Cantos
Triangeli-projektin loppuarvioinnin keskeiset nostot
3Q14
Shop cctv camera in dallas
Financial presentation 07 vfinal
Chapter 04 storage csc & tts
Women and personal finance
Mullistaako muuttoliike Suomen?
Muuttoliike ja asuntomarkkinoiden ostovoima
KAUPUNKIEN JA KAUPUNKISEUTUJEN MERKITYS IH-ALUEITA MUODOSTETTAESSA
L'App store per applicazioni Enterprise: La mobilità porta a porta
Satakunnan asema alueiden välisessä kilpailussa 2000-luvulla
373 arezzo investor_day_-_expansion_presentation_vrev
Ad

Similar to Identity management challenges when moving share point to the cloud antonio maio (20)

PPTX
Hybrid Identity Management with SharePoint and Office 365 - Antonio Maio
PPTX
Best practices for Security and Governance in SharePoint 2013
PPTX
Best Practices for Security and Governance in SharePoint 2013
PDF
A Practical Guide Information Governance with Microsoft SharePoint 2013
PDF
What can IBM Connections Cloud do for my business?
PDF
How Claims is Changing the Way We Authenticate and Authorize in SharePoint
PDF
Proven Practices for Office 365 Deployment, Security and Management
PDF
Oracle Document Cloud Service
PDF
Creating a Collaborative Workplace Culture Webinar Series: “How does workplac...
PDF
Rescue.org Intranet
PDF
Relationship Management for Property Investment Management webinar 2.5.13
PPTX
Data Visualization in SharePoint and Office 365
PDF
Is Teams Turned on But Not Rolled Out_Hannemann
PPTX
Intranet Case Studies
PPTX
Intranet Case Studies
PPTX
Gain Control of Microsoft Teams Chaos
PPTX
Oracle BI Big Data and Bics
PDF
Consistent flexibility - Creating and Managing your Desktop Workflows
PDF
DevOps: Retooling the End-to-End IT Model
PDF
bip-overview-and-best-practices.pdf
Hybrid Identity Management with SharePoint and Office 365 - Antonio Maio
Best practices for Security and Governance in SharePoint 2013
Best Practices for Security and Governance in SharePoint 2013
A Practical Guide Information Governance with Microsoft SharePoint 2013
What can IBM Connections Cloud do for my business?
How Claims is Changing the Way We Authenticate and Authorize in SharePoint
Proven Practices for Office 365 Deployment, Security and Management
Oracle Document Cloud Service
Creating a Collaborative Workplace Culture Webinar Series: “How does workplac...
Rescue.org Intranet
Relationship Management for Property Investment Management webinar 2.5.13
Data Visualization in SharePoint and Office 365
Is Teams Turned on But Not Rolled Out_Hannemann
Intranet Case Studies
Intranet Case Studies
Gain Control of Microsoft Teams Chaos
Oracle BI Big Data and Bics
Consistent flexibility - Creating and Managing your Desktop Workflows
DevOps: Retooling the End-to-End IT Model
bip-overview-and-best-practices.pdf
Ad

More from AntonioMaio2 (19)

PDF
Introduction to Microsoft Enterprise Mobility + Security
PDF
Learn how to protect against and recover from data breaches in Office 365
PDF
A beginners guide to administering office 365 with power shell antonio maio
PDF
Office 365 Security - MacGyver, Ninja or Swat team
PDF
Information security in office 365 a shared responsibility - antonio maio
PDF
SharePoint Saturday Ottawa - How secure is my data in office 365?
PPTX
Office 365 security new innovations from microsoft ignite - antonio maio
PPTX
Real world SharePoint information governance a case study - published
PPTX
What’s new in SharePoint 2016!
PDF
Developing custom claim providers to enable authorization in share point an...
PPTX
Best practices for security and governance in share point 2013 published
PDF
Keeping SharePoint Always On
PPTX
SPTechCon Boston 2013 - Introduction to Security in Microsoft Sharepoint 2013...
PPTX
Best Practices for Security in Microsoft SharePoint 2013
PPTX
Intro to Develop and Deploy Apps for Microsoft SharePoint and Office 2013
PPTX
SharePoint Governance: Impacts of Moving to the Cloud
PPTX
Share point security 101 sps-ottawa 2012 - antonio maio
PPTX
Webinar: Take Control of SharePoint Security
PPTX
SharePoint Saturday Toronto July 2012 - Antonio Maio
Introduction to Microsoft Enterprise Mobility + Security
Learn how to protect against and recover from data breaches in Office 365
A beginners guide to administering office 365 with power shell antonio maio
Office 365 Security - MacGyver, Ninja or Swat team
Information security in office 365 a shared responsibility - antonio maio
SharePoint Saturday Ottawa - How secure is my data in office 365?
Office 365 security new innovations from microsoft ignite - antonio maio
Real world SharePoint information governance a case study - published
What’s new in SharePoint 2016!
Developing custom claim providers to enable authorization in share point an...
Best practices for security and governance in share point 2013 published
Keeping SharePoint Always On
SPTechCon Boston 2013 - Introduction to Security in Microsoft Sharepoint 2013...
Best Practices for Security in Microsoft SharePoint 2013
Intro to Develop and Deploy Apps for Microsoft SharePoint and Office 2013
SharePoint Governance: Impacts of Moving to the Cloud
Share point security 101 sps-ottawa 2012 - antonio maio
Webinar: Take Control of SharePoint Security
SharePoint Saturday Toronto July 2012 - Antonio Maio

Recently uploaded (20)

PDF
Empathic Computing: Creating Shared Understanding
PDF
Diabetes mellitus diagnosis method based random forest with bat algorithm
PDF
Modernizing your data center with Dell and AMD
PDF
Network Security Unit 5.pdf for BCA BBA.
PPTX
KOM of Painting work and Equipment Insulation REV00 update 25-dec.pptx
PPT
Teaching material agriculture food technology
PPTX
MYSQL Presentation for SQL database connectivity
PDF
Peak of Data & AI Encore- AI for Metadata and Smarter Workflows
PDF
Mobile App Security Testing_ A Comprehensive Guide.pdf
PDF
The Rise and Fall of 3GPP – Time for a Sabbatical?
PPTX
Big Data Technologies - Introduction.pptx
PPTX
PA Analog/Digital System: The Backbone of Modern Surveillance and Communication
PDF
CIFDAQ's Market Insight: SEC Turns Pro Crypto
PDF
cuic standard and advanced reporting.pdf
PDF
Reach Out and Touch Someone: Haptics and Empathic Computing
PDF
Dropbox Q2 2025 Financial Results & Investor Presentation
PDF
KodekX | Application Modernization Development
PPTX
A Presentation on Artificial Intelligence
PPTX
Digital-Transformation-Roadmap-for-Companies.pptx
PPTX
Effective Security Operations Center (SOC) A Modern, Strategic, and Threat-In...
Empathic Computing: Creating Shared Understanding
Diabetes mellitus diagnosis method based random forest with bat algorithm
Modernizing your data center with Dell and AMD
Network Security Unit 5.pdf for BCA BBA.
KOM of Painting work and Equipment Insulation REV00 update 25-dec.pptx
Teaching material agriculture food technology
MYSQL Presentation for SQL database connectivity
Peak of Data & AI Encore- AI for Metadata and Smarter Workflows
Mobile App Security Testing_ A Comprehensive Guide.pdf
The Rise and Fall of 3GPP – Time for a Sabbatical?
Big Data Technologies - Introduction.pptx
PA Analog/Digital System: The Backbone of Modern Surveillance and Communication
CIFDAQ's Market Insight: SEC Turns Pro Crypto
cuic standard and advanced reporting.pdf
Reach Out and Touch Someone: Haptics and Empathic Computing
Dropbox Q2 2025 Financial Results & Investor Presentation
KodekX | Application Modernization Development
A Presentation on Artificial Intelligence
Digital-Transformation-Roadmap-for-Companies.pptx
Effective Security Operations Center (SOC) A Modern, Strategic, and Threat-In...

Identity management challenges when moving share point to the cloud antonio maio

  • 1. Protiviti Antonio Maio Senior SharePoint Architect & Senior Manager Microsoft SharePoint Server MVP Identity Management Challenges Moving SharePoint to the Cloud Email: Antonio.maio@protiviti.com Blog: www.trustsharepoint.com Slide share: http://www.slideshare.net/AntonioMaio2 Twitter: @AntonioMaio2
  • 2. © 2014 Protiviti Consulting Private Ltd. An Equal Opportunity Employer. CONFIDENTIAL: This document is for internal use only and may not be copied nor distributed to another third party. About Protiviti INDIA (3) Protiviti (www.protiviti.com) is a global consulting firm that helps companies solve problems in finance, technology, operations, governance, risk and internal audit. Through our network of more than 70 offices in over 20 countries, we have served more than 35 percent of FORTUNE® 1000 and Global 500 companies. We also work with smaller, growing companies, including those looking to go public, as well as with government agencies. Protiviti is a wholly owned subsidiary of Robert Half International Inc. (NYSE: RHI). Founded in 1948, Robert Half International is a member of the S&P 500 index. • 2,500+ professionals • 1,000+ clients • 70+ offices • Over 20 countries in the Americas, Europe and Asia-Pacific Protiviti is one of the fastest growing consulting firms worldwide. Our revenues have increased from US $15 million in 2002, to US $423.8 million in 2011.
  • 3. © 2014 Protiviti Consulting Private Ltd. An Equal Opportunity Employer. CONFIDENTIAL: This document is for internal use only and may not be copied nor distributed to another third party. • Sensitive data • Access systems and data • Log/track access • Malicious access to systems/data • Business Identity Theft
  • 4. © 2014 Protiviti Consulting Private Ltd. An Equal Opportunity Employer. CONFIDENTIAL: This document is for internal use only and may not be copied nor distributed to another third party. …moving to the Cloud
  • 5. © 2014 Protiviti Consulting Private Ltd. An Equal Opportunity Employer. CONFIDENTIAL: This document is for internal use only and may not be copied nor distributed to another third party. Why Hybrid? • Get started slowly | Take small steps | Explore cloud services • Access to collaboration features for extranet & remote users • Employees connect to Corp. resources/content from almost anywhere • 3rd party solutions or custom code – continue to use & extend to cloud • Retain corporate control & storage of sensitive data Hybrid Deployments
  • 6. © 2014 Protiviti Consulting Private Ltd. An Equal Opportunity Employer. CONFIDENTIAL: This document is for internal use only and may not be copied nor distributed to another third party. Identity Models for Office 365
  • 7. © 2014 Protiviti Consulting Private Ltd. An Equal Opportunity Employer. CONFIDENTIAL: This document is for internal use only and may not be copied nor distributed to another third party. Cloud Identity Model
  • 8. © 2014 Protiviti Consulting Private Ltd. An Equal Opportunity Employer. CONFIDENTIAL: This document is for internal use only and may not be copied nor distributed to another third party. Synchronized Identity Model
  • 9. © 2014 Protiviti Consulting Private Ltd. An Equal Opportunity Employer. CONFIDENTIAL: This document is for internal use only and may not be copied nor distributed to another third party. Federated Identity Model
  • 10. © 2014 Protiviti Consulting Private Ltd. An Equal Opportunity Employer. CONFIDENTIAL: This document is for internal use only and may not be copied nor distributed to another third party. Select the Simplest Model
  • 11. © 2014 Protiviti Consulting Private Ltd. An Equal Opportunity Employer. CONFIDENTIAL: This document is for internal use only and may not be copied nor distributed to another third party. Selecting an Identity Model I need to… Directory Sync Scenario Directory Sync with Password Sync Directory Sync with Single Sign-On Sync new user, contact, & groups created in on-premises Active Directory to cloud automatically Sync incremental updates made to existing accounts in on-premises Active Directory to cloud automatically Set up my tenant for Office 365 hybrid scenarios Enable users to sign in to cloud services using on-premises password Reduce password administration costs Control password policies from on-premises Active Directory Enable cloud-based multi-factor authentication solutions Enable on-premises multi-factor authentication solutions Ensure user authentications occur in on-premises Active Directory Implement single sign-on using corporate credentials Customize the user Sign-In page Limit access to cloud services based on the location, client type or Exchange endpoint of the client
  • 12. © 2014 Protiviti Consulting Private Ltd. An Equal Opportunity Employer. CONFIDENTIAL: This document is for internal use only and may not be copied nor distributed to another third party. Configuring Directory Sync Multi-steps process 1. Prepare for Directory Synchronization • Prerequisites, Permissions, Understand Limits • Alternate UPN Suffix for .local Domain • Clean Up Active Directory 2. Activate Directory Synchronization • Register your Domain with Office 365 & Validate Ownership • Use “Microsoft Deployment Readiness Tool” 3. Setup Directory Synchronization Server • Option: Hybrid Deployment • Option: Enable Password Synchronization 4. Synchronize Directories 5. Activate Users & Assign Office 365 Licenses 6. Manage Directory Synchronization
  • 13. © 2014 Protiviti Consulting Private Ltd. An Equal Opportunity Employer. CONFIDENTIAL: This document is for internal use only and may not be copied nor distributed to another third party. DEMONSTRATION
  • 14. © 2014 Protiviti Consulting Private Ltd. An Equal Opportunity Employer. CONFIDENTIAL: This document is for internal use only and may not be copied nor distributed to another third party. Configuring Directory Sync Multi-steps process 1. Prepare for Directory Synchronization • Prerequisites, Permissions, Understand Limits • Alternate UPN Suffix for .local Domain • Clean Up Active Directory 2. Activate Directory Synchronization • Register your Domain with Office 365 & Validate Ownership • Use “Microsoft Deployment Readiness Tool” 3. Setup Directory Synchronization Server • Option: Hybrid Deployment • Option: Enable Password Synchronization 4. Synchronize Directories 5. Activate Users & Assign Office 365 Licenses 6. Manage Directory Synchronization
  • 15. © 2014 Protiviti Consulting Private Ltd. An Equal Opportunity Employer. CONFIDENTIAL: This document is for internal use only and may not be copied nor distributed to another third party. Configuring Directory Sync • Alternate UPN Suffix for .local Domain
  • 16. © 2014 Protiviti Consulting Private Ltd. An Equal Opportunity Employer. CONFIDENTIAL: This document is for internal use only and may not be copied nor distributed to another third party. Configuring Directory Sync • Alternate UPN Suffix for .local Domain
  • 17. © 2014 Protiviti Consulting Private Ltd. An Equal Opportunity Employer. CONFIDENTIAL: This document is for internal use only and may not be copied nor distributed to another third party. Configuring Directory Sync • Clean up Active Directory – set UPN for each user identity
  • 18. © 2014 Protiviti Consulting Private Ltd. An Equal Opportunity Employer. CONFIDENTIAL: This document is for internal use only and may not be copied nor distributed to another third party. Configuring Directory Sync • Clean up Active Directory – set proxyAddresses each user identity
  • 19. © 2014 Protiviti Consulting Private Ltd. An Equal Opportunity Employer. CONFIDENTIAL: This document is for internal use only and may not be copied nor distributed to another third party. Configuring Directory Sync • Clean up Active Directory – set proxyAddresses each user identity
  • 20. © 2014 Protiviti Consulting Private Ltd. An Equal Opportunity Employer. CONFIDENTIAL: This document is for internal use only and may not be copied nor distributed to another third party. Configuring Directory Sync Multi-steps process 1. Prepare for Directory Synchronization • Prerequisites, Permissions, Understand Limits • Alternate UPN Suffix for .local Domain • Clean Up Active Directory 2. Activate Directory Synchronization • Register your Domain with Office 365 & Validate Ownership • Use “Microsoft Deployment Readiness Tool” 3. Setup Directory Synchronization Server • Option: Hybrid Deployment • Option: Enable Password Synchronization 4. Synchronize Directories 5. Activate Users & Assign Office 365 Licenses 6. Manage Directory Synchronization
  • 21. © 2014 Protiviti Consulting Private Ltd. An Equal Opportunity Employer. CONFIDENTIAL: This document is for internal use only and may not be copied nor distributed to another third party. Configuring Directory Sync • Register Domain with Office 365 & Validate Ownership
  • 22. © 2014 Protiviti Consulting Private Ltd. An Equal Opportunity Employer. CONFIDENTIAL: This document is for internal use only and may not be copied nor distributed to another third party. Configuring Directory Sync • Register Domain with Office 365 & Validate Ownership
  • 23. © 2014 Protiviti Consulting Private Ltd. An Equal Opportunity Employer. CONFIDENTIAL: This document is for internal use only and may not be copied nor distributed to another third party. Configuring Directory Sync • Register Domain with Office 365 & Validate Ownership
  • 24. © 2014 Protiviti Consulting Private Ltd. An Equal Opportunity Employer. CONFIDENTIAL: This document is for internal use only and may not be copied nor distributed to another third party. Configuring Directory Sync • Register Domain with Office 365 & Validate Ownership
  • 25. © 2014 Protiviti Consulting Private Ltd. An Equal Opportunity Employer. CONFIDENTIAL: This document is for internal use only and may not be copied nor distributed to another third party. Configuring Directory Sync • Register Domain with Office 365 & Validate Ownership
  • 26. © 2014 Protiviti Consulting Private Ltd. An Equal Opportunity Employer. CONFIDENTIAL: This document is for internal use only and may not be copied nor distributed to another third party. Configuring Directory Sync • Activate Directory Synchronization
  • 27. © 2014 Protiviti Consulting Private Ltd. An Equal Opportunity Employer. CONFIDENTIAL: This document is for internal use only and may not be copied nor distributed to another third party. Configuring Directory Sync • Activate Directory Synchronization
  • 28. © 2014 Protiviti Consulting Private Ltd. An Equal Opportunity Employer. CONFIDENTIAL: This document is for internal use only and may not be copied nor distributed to another third party. Configuring Directory Sync Multi-steps process 1. Prepare for Directory Synchronization • Prerequisites, Permissions, Understand Limits • Alternate UPN Suffix for .local Domain • Clean Up Active Directory 2. Activate Directory Synchronization • Register your Domain with Office 365 & Validate Ownership • Use “Microsoft Deployment Readiness Tool” 3. Setup Directory Synchronization Server • Option: Hybrid Deployment • Option: Enable Password Sync 4. Synchronize Directories 5. Activate Users & Assign Office 365 Licenses 6. Manage Directory Synchronization • Requires: AD Enterprise Domain Admin Acct • Requires: O365 Service Admin Acct
  • 29. © 2014 Protiviti Consulting Private Ltd. An Equal Opportunity Employer. CONFIDENTIAL: This document is for internal use only and may not be copied nor distributed to another third party. Configuring Directory Sync Multi-steps process 1. Prepare for Directory Synchronization • Prerequisites, Permissions, Understand Limits • Alternate UPN Suffix for .local Domain • Clean Up Active Directory 2. Activate Directory Synchronization • Register your Domain with Office 365 & Validate Ownership • Use “Microsoft Deployment Readiness Tool” 3. Setup Directory Synchronization Server • Option: Hybrid Deployment • Option: Enable Password Synchronization 4. Synchronize Directories 5. Activate Users & Assign Office 365 Licenses 6. Manage Directory Synchronization
  • 30. © 2014 Protiviti Consulting Private Ltd. An Equal Opportunity Employer. CONFIDENTIAL: This document is for internal use only and may not be copied nor distributed to another third party. Configuring Directory Sync • After users & groups are synchronized
  • 31. © 2014 Protiviti Consulting Private Ltd. An Equal Opportunity Employer. CONFIDENTIAL: This document is for internal use only and may not be copied nor distributed to another third party. Configuring Directory Sync Multi-steps process 1. Prepare for Directory Synchronization • Prerequisites, Permissions, Understand Limits • Alternate UPN Suffix for .local Domain • Clean Up Active Directory 2. Activate Directory Synchronization • Register your Domain with Office 365 & Validate Ownership • Use “Microsoft Deployment Readiness Tool” 3. Setup Directory Synchronization Server • Option: Hybrid Deployment • Option: Enable Password Synchronization 4. Synchronize Directories 5. Activate Users & Assign Office 365 Licenses 6. Manage Directory Synchronization
  • 32. © 2014 Protiviti Consulting Private Ltd. An Equal Opportunity Employer. CONFIDENTIAL: This document is for internal use only and may not be copied nor distributed to another third party. Configuring Identity Federation Multi-steps process: 1. Prepare for Single Sign On • Prerequisites, Prepare Active Directory • Prepare Network infrastructure for Federation servers 2. Setup the On Premise Security Token Service (STS) - Active Directory Federation Services (ADFS) • Set up Windows PowerShell for SSO with AD FS • Set up trust between AD FS and Azure AD 3. Setup Directory Synchronization 4. Verify & Manage Single Sign On
  • 33. © 2014 Protiviti Consulting Private Ltd. An Equal Opportunity Employer. CONFIDENTIAL: This document is for internal use only and may not be copied nor distributed to another third party. Configuring Identity Federation Multi-steps process: 1. Prepare for Single Sign On • Prerequisites, Prepare Active Directory • Prepare Network infrastructure for Federation servers 2. Setup the On Premise Security Token Service (STS) - Active Directory Federation Services (ADFS) • Set up Windows PowerShell for SSO with AD FS • Set up trust between AD FS and Azure AD 3. Setup Directory Synchronization 4. Verify & Manage Single Sign On
  • 34. © 2014 Protiviti Consulting Private Ltd. An Equal Opportunity Employer. CONFIDENTIAL: This document is for internal use only and may not be copied nor distributed to another third party. Configuring Identity Federation Multi-steps process: 1. Prepare for Single Sign On • Prerequisites, Prepare Active Directory • Prepare Network infrastructure for Federation servers 2. Setup the On Premise Security Token Service (STS) - Active Directory Federation Services (ADFS) • Set up Windows PowerShell for SSO with AD FS • Set up trust between AD FS and Azure AD 3. Setup Directory Synchronization 4. Verify & Manage Single Sign On
  • 35. © 2014 Protiviti Consulting Private Ltd. An Equal Opportunity Employer. CONFIDENTIAL: This document is for internal use only and may not be copied nor distributed to another third party. Configuring Identity Federation Multi-steps process: 1. Prepare for Single Sign On • Prerequisites, Prepare Active Directory • Prepare Network infrastructure for Federation servers 2. Setup the On Premise Security Token Service (STS) - Active Directory Federation Services (ADFS) • Set up Windows PowerShell for SSO with AD FS • Set up trust between AD FS and Azure AD 3. Setup Directory Synchronization 4. Verify & Manage Single Sign On
  • 36. © 2014 Protiviti Consulting Private Ltd. An Equal Opportunity Employer. CONFIDENTIAL: This document is for internal use only and may not be copied nor distributed to another third party. Overall Benefits • Reduced administration costs • Leveraging your already existing on-premises user and group accounts • Improved productivity • Significantly reduce the amount of time it takes to make cloud based services accessible • Increased security • Ensures that only those appropriate users have access to your corporate assets
  • 37. © 2014 Protiviti Consulting Private Ltd. An Equal Opportunity Employer. CONFIDENTIAL: This document is for internal use only and may not be copied nor distributed to another third party. Step by Step Procedures Please see 2 blog posts: • Part 1: http://sharepoint.protiviti.com/blog/Lists/Posts/Post.aspx?ID=142 • Part 2: http://sharepoint.protiviti.com/blog/Lists/Posts/Post.aspx?ID=165 This deck will be posted to my blog: www.trustsharepoint.com
  • 38. Email: Antonio.maio@protiviti.com Blog: www.trustsharepoint.com Slide share: http://www.slideshare.net/AntonioMaio2 Twitter: @AntonioMaio2 Identity Management Challenges when moving SharePoint to the Cloud Antonio Maio Senior SharePoint Architect & Senior Manager Microsoft SharePoint Server MVP Thank You – Question and Answer

Editor's Notes

  • #2: Most sensitive information: employees, partners, clients With many online services available & constant reports of identity thefts org’s are becoming concerned with protecting id’s and info they contain How – when moving a collab platform like SP to cloud provider like O365 – presents challenges …intro Abstract: Identity Management Challenges when moving SharePoint to the Cloud Some of the most sensitive information in our organizations are our identities - the identities of our employees, our partners and of our clients. With the many online services available to us and the constant public reports about massive identity thefts, businesses are becoming increasingly concerned with protecting those identities and the information they contain. But - how do you effectively protect identity information when moving a collaboration platform like SharePoint to a cloud provider like Office 365? This can present interesting challenges. My name is Antonio Maio and identity is something that I’m passionate about. I’m here to talk to you today about how we manage those identities in a secure way and overcome some of those challenges - challenges like single sign on, storing sensitive identity information and identity synchronization. In this session we'll explore those challenges and provide a short walk-through of the capabilities that Microsoft has built to effectively solve these challenges. Bio Antonio Maio is an information security professional with over 20 years of experience in cyber security practices and systems. Based in the Dallas/Fort Worth area, Antonio is a senior manager and senior SharePoint architect with Protiviti. His varied background includes in-depth knowledge of public key infrastructure, identity management and access control systems, as well as information security best practices. His broad knowledge and experience with Microsoft SharePoint extends over the last 8 years and focusses on solving security challenges for enterprise customers, military organizations and governments. Antonio is passionate about helping customers be productive with software and he has received a Microsoft MVP Award (Most Valuable Professional) for the last 3 consecutive years specializing in Microsoft SharePoint Server. When he’s not working with customers to help them get the most out of SharePoint, he can be found contributing to the SharePoint community either through sessions at user group meetings and conferences or through his blog at www.trustsharepoint.com.
  • #3: Protiviti is a global consulting firm with over 70 offices and 2500 professionals worldwide We’ve served over 40% of the world’s fortune 1000 enterprises Our organization includes leading consulting practices in the areas of internal audit, health care, risk, governance and IT security We also have an award-winning SharePoint consulting practice - where we’ve helped over 1000 organizations with all aspects of their SharePoint implementation these clients also look to us to guide them in establishing appropriate SharePoint security controls and planning their governance strategy for SharePoint …and that’s what we’re here today to talk about
  • #4: Identities are primarily digital. Most sensitive information: employees, partners, clients With many online services available & constant reports of identity thefts org’s are becoming concerned with protecting id’s and info they contain How – when moving a collab platform like SP to cloud provider like O365 – presents challenges …intro Abstract: Identity Management Challenges when moving SharePoint to the Cloud Some of the most sensitive information in our organizations are our identities - the identities of our employees, our partners and of our clients. With the many online services available to us and the constant public reports about massive identity thefts, businesses are becoming increasingly concerned with protecting those identities and the information they contain. But - how do you effectively protect identity information when moving a collaboration platform like SharePoint to a cloud provider like Office 365? This can present interesting challenges. My name is Antonio Maio and identity is something that I’m passionate about. I’m here to talk to you today about how we manage those identities in a secure way and overcome some of those challenges - challenges like single sign on, storing sensitive identity information and identity synchronization. In this session we'll explore those challenges and provide a short walk-through of the capabilities that Microsoft has built to effectively solve these challenges. Why we secure identities: Contain sensitive data Used to access systems and data Used to log/track access Lead to malicious access to systems/data Lead to Business Identity Theft
  • #6: Why Hybrid? Get started slowly in the cloud; Take small steps & explore cloud services as needed Provide access to collaboration features for extranet users & remote divisions Enterprise users can connect to corporate resources & content from almost anywhere Continue using 3rd party solutions or custom code & extend them to the cloud when needed Retain corporate control & storage of sensitive data Common SharePoint Scenarios Search content in both SharePoint 2013 on prem & SharePoint Online Seamlessly access files/data in SharePoint Server 2013 on prem & SharePoint Online Access corporate line of business systems (ex. SAP) from SharePoint 2013 on prem & SharePoint Online Extend SharePoint 2013 on prem solutions using business connectivity services (BCS) to SharePoint Online Keep sensitive corporate data within SharePoint 2013 on prem, with non-sensitive data in SharePoint Online
  • #37: Overall Benefits: Reduced administration costs - Leveraging your already existing on-premises user and group accounts, eliminates the need to manually manage them in your Azure AD, which removes a costly manual operation from your budget. Improved productivity - By automating the process of synchronizing user and group accounts, you can significantly reduce the amount of time it takes to make cloud based services accessible for your employees. Increased security - Automated provisioning and de-provisioning of user and group accounts ensures that only those physical entities have access to your corporate assets that really require it as long as they need it.