SlideShare a Scribd company logo
S H A R E P O I N T
CONFERENCES
2 0 1 4
Scott Hoag
bit.ly/
STP1413
#auspc #nzspc
#spt1413
#auspc #nzspc
#spt1413
Identity Management in Office 365
Identity Scenarios
Synchronisation Demo
Add-ons and More to Think About
1
2
3
4
#auspc #nzspc
#spt1413
#auspc #nzspc
#spt1413
What is Identity Management?
“Identity management (IdM) describes the
management of individual principals, their
authentication, authorisation, and privileges within or
across system and enterprise boundaries with the goal
of increasing security and productivity while decreasing
cost, downtime and repetitive tasks.”
https://en.wikipedia.org/wiki/Identity_management
#auspc #nzspc
#spt1413
Authentication and Authorization
Verifying that a user, device, or
service such as an application
provided on a network server is
the entity that it claims to be.
Determining which actions an
authenticated entity is authorized
to perform on the network
Authentication Authorization
#auspc #nzspc
#spt1413
 Single Sign On (SSO) is the ability for two disjoint Identity
Providers (IDP) to trust each other such that a user logged in to
one does not need to log in again for the second
 Relying Party (RP) is the system that relies on the IDP to
authenticate a user
Security Assertion Markup
Language (SAML)
SAML is a public standard managed by OASIS.
SAML is the identity token and also the
protocol.
WSFED is used for web browser-based
authentication with an IDP. WS-Trust is used by
Office client apps to authenticate.*
WS-Federation (WSFED) / WS-Trust
#auspc #nzspc
#spt1413
WS-Federation
WS-Trust
SAML 2.0
Metadata
Shibboleth
Graph API
#auspc #nzspc
#spt1413User
Microsoft Account
Ex: alice@outlook.com
User
Organizational Account
Ex: alice@contoso.com
Microsoft Account Azure Active Directory
#auspc #nzspc
#spt1413
What is AAD?
“Azure Active Directory is a comprehensive identity and
access management cloud solution that provides a
robust set of capabilities to manage users and groups
and help secure access to applications including
Microsoft online services like Office 365 and a world of
non-Microsoft SaaS applications.”
#auspc #nzspc
#spt1413
#auspc #nzspc
#spt1413
#auspc #nzspc
#spt1413
Cloud Identity
Zero on-premises servers
On-premises directory restructuring
Pilots and Proof of Concept
#auspc #nzspc
#spt1413
Synchronized Identity
Federation is not
required
Simple Sign On is
acceptable
#auspc #nzspc
#spt1413
Federated Identity
 Already have ADFS or
a 3rd party IDP
 Require immediate
disable or Sign-in
Audit
 SSO is required
 Multiple Forests
 CAC or on-premises
MFA
 Business requires it
#auspc #nzspc
#spt1413
On your terms
#auspc #nzspc
#spt1413
#auspc #nzspc
#spt1413
What are we going to do?
Office 365 E3 Tenant
Configure DirSync
 Users in targeted OU
 One way password sync
 Alternate Login ID
#auspc #nzspc
#spt1413
 Logon to the Portal
 Select Users and groups and
then activate DirSync
 Select Users and Groups and
click Set up Active Directory
synchronization
 Activate Directory
Synchronization
 Wait for DirSync to enable
 Review all documentation,
follow the implementation
steps, and download DirSync
Form DirSync server
Download DirSync
#auspc #nzspc
#spt1413
 Logon to DirSync server and
run setup
 Follow setup wizard
 When finished, option to start
the configuration wizard
#auspc #nzspc
#spt1413
Run configuration wizard
Provide O365admin creds
Provide AD admin creds
If Exchange hybrid, configure
“write-back”
Password sync option
Create configuration
When finished, option to run
synchronization
#auspc #nzspc
#spt1413
#auspc #nzspc
#spt1413
 When your on-premises UPN is non-routable on the public
internet and you can’t easily update UPN suffixes
 Requires Windows Server 2012 R2 for AD FS*
 Requires comfort with FIM and editing Management Agents
#auspc #nzspc
#spt1413
 DirSync for LDAPv3
 Supports multiple forests
 Doesn’t include password hash sync
 Includes write back capability with Azure AD Premium subscription
 Availability
 Preview now available at: http://go.microsoft.com/?linkid=9845645
 Release later in 2014
 Target Identity Providers
 Same as FIM 2010 R2 connector
 FIM connector details at http://go.microsoft.com/fwlink/?LinkID=270179
#auspc #nzspc
#spt1413
 SSO with passive authentication
 Works with WSFED and SAML 2.0
 Planned for later in 2014
 Will require Office Client
updates
 Move to Active Directory
Authentication Library (ADAL)
 OAUTH for passive authentication
 Support for MFA with AAD
 CAC/PIV support
SAML 2.0
#auspc #nzspc
#spt1413
 What is it?
 Qualification of third party identity
providers for federation with Office 365.
Microsoft supports Office 365 only when
qualified third party identity providers are
used.
 Program Requirements
 Published Qualification Requirements
 Published Technical Integration Docs
 Automated Testing Tool
 Self Testing work by Partner
 Predictable and Shorter Qualification
 http://aka.ms/ssoproviders
*For representative purposes
only.
WS-Trust & WS-
Federation
SAML (passive
auth)
Active Directory with ADFS
• Flexibility to reuse
existing identity
provider investments
• Confidence that the
solution is qualified by
Microsoft
• Coordinated support
between the partner
and Microsoft
Customer
Benefits
#auspc #nzspc
#spt1413
Suitable for medium,
large enterprises including
educational organizations
Suitable for medium,
large enterprises including
educational organizations
Suitable for educational
organizations
For organizations that
need to use SAML 2.0
#auspc #nzspc
#spt1413
#auspc #nzspc
#spt1413
WS-Federation
WS-Trust
#auspc #nzspc
#spt1413
Identity Management in Office 365
Identity Scenarios
Synchronisation Demo
Add-ons and More to Think About




#auspc #nzspc
#spt1413
#auspc #nzspc
#spt1413
 Use third-party identity
providers to implement
single sign-on
 Deployment scenarios for
Office 365 with single sign-
on and Azure
 Choosing a sign-in model
for Office 365
 Password hash sync
simplifies user management
for Office 365
 Using Alternate Login IDs
with Azure Active Directory
 Office 365 SAML 2.0
Federation Implementer’s
Guide
 Simplified login to Yammer
from Office 365
 Multi-Factor Authentication
for Office 365
 Office 365 User Account
Management
#auspc #nzspc
#spt1413
Thank you to our sponsors

More Related Content

PPTX
Webinar: Extend The Power of The ForgeRock Identity Platform Through Scripting
PDF
Enterprise Single Sign On
PPTX
OpenID Connect and Single Sign-On for Beginners
PDF
Azure AD B2C – integration in a bank
PPTX
Azure B2C
PPT
Open Identity Stack Roadmap
PDF
Shoot Me a Token: OpenAM as an OAuth2 Provider
PPTX
The bits and pieces of Azure AD B2C
Webinar: Extend The Power of The ForgeRock Identity Platform Through Scripting
Enterprise Single Sign On
OpenID Connect and Single Sign-On for Beginners
Azure AD B2C – integration in a bank
Azure B2C
Open Identity Stack Roadmap
Shoot Me a Token: OpenAM as an OAuth2 Provider
The bits and pieces of Azure AD B2C

What's hot (20)

PDF
Enterprise Security Requirements
PPTX
APIdays London 2020: Toward certifying Financial-grade API security profile w...
PDF
OpenID Connect Federation
PPT
Incredible Edible Identity
PDF
Federation in Practice
PDF
Technical Case Study: McKesson - Employing the Open Identity Stack
PPTX
Webinar: ForgeRock Identity Platform Preview (Dec 2015)
PDF
Introduction to the Salesforce.com Mobile SDK for iOS
PDF
OIDF Workshop at Verizon Media -- 9/30/2019 -- OpenID Connect Federation Update
PDF
apidays LIVE London 2021 - Authorization is on the rise. by Damian Schenkelma...
PPTX
OpenID Connect - a simple[sic] single sign-on & identity layer on top of OAut...
PPTX
A Developer's Introduction to Azure Active Directory B2C
PPTX
What API Specifications and Tools Help Engineers to Construct a High-Security...
PPTX
OIDF Workshop at Verizon Media -- 9/30/2019 -- FastFed Working Group Update
PDF
Authlete: API Authorization Enabler for API Economy
PPTX
IAM/IRM CONSIDERATIONS FOR SAAS PROVIDER SELECTION
PPTX
Building secure applications with keycloak
PDF
Saby-Oracle Business Intelligence Cloud Service Specialist-07-June-2015
PDF
OpenID Foundation RISC WG Update - 2017-10-16
Enterprise Security Requirements
APIdays London 2020: Toward certifying Financial-grade API security profile w...
OpenID Connect Federation
Incredible Edible Identity
Federation in Practice
Technical Case Study: McKesson - Employing the Open Identity Stack
Webinar: ForgeRock Identity Platform Preview (Dec 2015)
Introduction to the Salesforce.com Mobile SDK for iOS
OIDF Workshop at Verizon Media -- 9/30/2019 -- OpenID Connect Federation Update
apidays LIVE London 2021 - Authorization is on the rise. by Damian Schenkelma...
OpenID Connect - a simple[sic] single sign-on & identity layer on top of OAut...
A Developer's Introduction to Azure Active Directory B2C
What API Specifications and Tools Help Engineers to Construct a High-Security...
OIDF Workshop at Verizon Media -- 9/30/2019 -- FastFed Working Group Update
Authlete: API Authorization Enabler for API Economy
IAM/IRM CONSIDERATIONS FOR SAAS PROVIDER SELECTION
Building secure applications with keycloak
Saby-Oracle Business Intelligence Cloud Service Specialist-07-June-2015
OpenID Foundation RISC WG Update - 2017-10-16
Ad

Similar to Office 365 and Cloud Identity – What Does It Mean For Me? (20)

PPTX
SPSVB - Office 365 and Cloud Identity - What Does It Mean for Me?
PPTX
SPS Sydney - Office 365 and Cloud Identity – What does it mean for me?
PDF
WSO2 ITALIA SMART TALK #3 WSO2 IS NEW FEATURE
PPTX
SYDSP - Office 365 and Cloud Identity - What does it mean for me?
PDF
JAXSPUG January 2016 - Microsoft Cloud Identities in Azure and Office 365
PPT
Fédération d’identité : des concepts Théoriques aux études de cas d’implément...
PDF
2015-06-10 Ceus by IberianSPC - new options for SharePoint 2016 and Office 36...
PPTX
SPIntersection 2016 - MICROSOFT CLOUD IDENTITIES IN AZURE AND OFFICE 365
PDF
O365con14 - moving from on-premises to online, the road to follow
PPTX
TugaIT 2017 Office 365 Multi-factor authentication with Microsoft Azure Activ...
PPTX
SPSLisbon 2017 Office 365 Multi-factor Authentication with Microsoft Azure Ac...
PDF
O365Con19 - A Life Without Passwords Dream or Reality - Sander Berkouwer
PDF
CIS14: Creating a Federated Identity Service for Better SSO
PDF
The Future is Now: What’s New in ForgeRock Identity Management
PPTX
#SPSToronto The SharePoint Framework and the Microsoft Graph on steroids with...
PPTX
#SPSottawa The SharePoint Framework and The Microsoft Graph on steroids with ...
PDF
Making your Cloud Initiatives Successful
PPTX
AvePoint Cloud Series - When do you decide to go to Office 365?
PPTX
Spunite exploring identity management options in office 365
PPTX
SPSVB - Office 365 and Cloud Identity - What Does It Mean for Me?
SPS Sydney - Office 365 and Cloud Identity – What does it mean for me?
WSO2 ITALIA SMART TALK #3 WSO2 IS NEW FEATURE
SYDSP - Office 365 and Cloud Identity - What does it mean for me?
JAXSPUG January 2016 - Microsoft Cloud Identities in Azure and Office 365
Fédération d’identité : des concepts Théoriques aux études de cas d’implément...
2015-06-10 Ceus by IberianSPC - new options for SharePoint 2016 and Office 36...
SPIntersection 2016 - MICROSOFT CLOUD IDENTITIES IN AZURE AND OFFICE 365
O365con14 - moving from on-premises to online, the road to follow
TugaIT 2017 Office 365 Multi-factor authentication with Microsoft Azure Activ...
SPSLisbon 2017 Office 365 Multi-factor Authentication with Microsoft Azure Ac...
O365Con19 - A Life Without Passwords Dream or Reality - Sander Berkouwer
CIS14: Creating a Federated Identity Service for Better SSO
The Future is Now: What’s New in ForgeRock Identity Management
#SPSToronto The SharePoint Framework and the Microsoft Graph on steroids with...
#SPSottawa The SharePoint Framework and The Microsoft Graph on steroids with ...
Making your Cloud Initiatives Successful
AvePoint Cloud Series - When do you decide to go to Office 365?
Spunite exploring identity management options in office 365
Ad

More from Scott Hoag (20)

PPTX
SharePoint Conference 2018 - Understanding Office 365 Usage Reporting
PPTX
SharePoint Conference 2018 - Securing Office 365 and SharePoint Online with A...
PDF
Global Azure Bootcamp 2018 - Azure Security Center
PDF
Global Azure Bootcamp 2018 - Azure Network Security
PPTX
SPIntersection 2016 - TO THE CLOUD! USING IAAS AS A HOSTING PROVIDER FOR SHAR...
PPTX
JAXSPUG April 2016 - Staying in the Know with Office 365
PPTX
SPSDC - To the Cloud! Using IaaS as a Hosting Provider for SharePoint
PPTX
SPSNYC SharePoint Worst Practices
PPTX
March Sydney Office 365 Meetup - Office 365 and Hybrid Solutions... what work...
PPTX
SPSVB - Office 365 and Hybrid Solutions... what works for my organization?
PPTX
SPSVB - To the Cloud! Using IaaS as a Hosting Provider for SharePoint
PPTX
SPS Sydney - To the Cloud! Utilising Azure as a Cloud Hosting Provider for Sh...
PPTX
SPSCBR - Pitfalls of Migrating to SharePoint 2013
PPTX
Canberra SPUG - February 2014 - Pitfalls of Migrating to SharePoint 2013
PPTX
Sydney SPUG - February 2014 - Pitfalls of Migrating to SharePoint 2013
PPTX
SPSNYC - Authentication, Authorization, and Identity – More than meets the eye…
PPTX
SPT15 To the Cloud! Utilizing AWS and Azure as Cloud Hosting Providers for Sh...
PPTX
Getting Started with Office 365
PPTX
Authentication, Authorization, and Identity – More than meets the eye…
PPTX
FEDSPUG - SharePoint 2013 - A Brief Capability Overview
SharePoint Conference 2018 - Understanding Office 365 Usage Reporting
SharePoint Conference 2018 - Securing Office 365 and SharePoint Online with A...
Global Azure Bootcamp 2018 - Azure Security Center
Global Azure Bootcamp 2018 - Azure Network Security
SPIntersection 2016 - TO THE CLOUD! USING IAAS AS A HOSTING PROVIDER FOR SHAR...
JAXSPUG April 2016 - Staying in the Know with Office 365
SPSDC - To the Cloud! Using IaaS as a Hosting Provider for SharePoint
SPSNYC SharePoint Worst Practices
March Sydney Office 365 Meetup - Office 365 and Hybrid Solutions... what work...
SPSVB - Office 365 and Hybrid Solutions... what works for my organization?
SPSVB - To the Cloud! Using IaaS as a Hosting Provider for SharePoint
SPS Sydney - To the Cloud! Utilising Azure as a Cloud Hosting Provider for Sh...
SPSCBR - Pitfalls of Migrating to SharePoint 2013
Canberra SPUG - February 2014 - Pitfalls of Migrating to SharePoint 2013
Sydney SPUG - February 2014 - Pitfalls of Migrating to SharePoint 2013
SPSNYC - Authentication, Authorization, and Identity – More than meets the eye…
SPT15 To the Cloud! Utilizing AWS and Azure as Cloud Hosting Providers for Sh...
Getting Started with Office 365
Authentication, Authorization, and Identity – More than meets the eye…
FEDSPUG - SharePoint 2013 - A Brief Capability Overview

Recently uploaded (20)

PDF
Building Integrated photovoltaic BIPV_UPV.pdf
DOCX
The AUB Centre for AI in Media Proposal.docx
PDF
Mobile App Security Testing_ A Comprehensive Guide.pdf
PDF
Diabetes mellitus diagnosis method based random forest with bat algorithm
PPTX
MYSQL Presentation for SQL database connectivity
PPTX
Big Data Technologies - Introduction.pptx
PDF
Chapter 3 Spatial Domain Image Processing.pdf
PDF
Machine learning based COVID-19 study performance prediction
PPT
Teaching material agriculture food technology
PPTX
VMware vSphere Foundation How to Sell Presentation-Ver1.4-2-14-2024.pptx
PDF
CIFDAQ's Market Insight: SEC Turns Pro Crypto
PDF
7 ChatGPT Prompts to Help You Define Your Ideal Customer Profile.pdf
PPTX
Detection-First SIEM: Rule Types, Dashboards, and Threat-Informed Strategy
PPT
“AI and Expert System Decision Support & Business Intelligence Systems”
PDF
Peak of Data & AI Encore- AI for Metadata and Smarter Workflows
PDF
Dropbox Q2 2025 Financial Results & Investor Presentation
PPTX
Effective Security Operations Center (SOC) A Modern, Strategic, and Threat-In...
PDF
NewMind AI Weekly Chronicles - August'25 Week I
PDF
Agricultural_Statistics_at_a_Glance_2022_0.pdf
PDF
The Rise and Fall of 3GPP – Time for a Sabbatical?
Building Integrated photovoltaic BIPV_UPV.pdf
The AUB Centre for AI in Media Proposal.docx
Mobile App Security Testing_ A Comprehensive Guide.pdf
Diabetes mellitus diagnosis method based random forest with bat algorithm
MYSQL Presentation for SQL database connectivity
Big Data Technologies - Introduction.pptx
Chapter 3 Spatial Domain Image Processing.pdf
Machine learning based COVID-19 study performance prediction
Teaching material agriculture food technology
VMware vSphere Foundation How to Sell Presentation-Ver1.4-2-14-2024.pptx
CIFDAQ's Market Insight: SEC Turns Pro Crypto
7 ChatGPT Prompts to Help You Define Your Ideal Customer Profile.pdf
Detection-First SIEM: Rule Types, Dashboards, and Threat-Informed Strategy
“AI and Expert System Decision Support & Business Intelligence Systems”
Peak of Data & AI Encore- AI for Metadata and Smarter Workflows
Dropbox Q2 2025 Financial Results & Investor Presentation
Effective Security Operations Center (SOC) A Modern, Strategic, and Threat-In...
NewMind AI Weekly Chronicles - August'25 Week I
Agricultural_Statistics_at_a_Glance_2022_0.pdf
The Rise and Fall of 3GPP – Time for a Sabbatical?

Office 365 and Cloud Identity – What Does It Mean For Me?

  • 1. S H A R E P O I N T CONFERENCES 2 0 1 4 Scott Hoag bit.ly/ STP1413
  • 3. #auspc #nzspc #spt1413 Identity Management in Office 365 Identity Scenarios Synchronisation Demo Add-ons and More to Think About 1 2 3 4
  • 5. #auspc #nzspc #spt1413 What is Identity Management? “Identity management (IdM) describes the management of individual principals, their authentication, authorisation, and privileges within or across system and enterprise boundaries with the goal of increasing security and productivity while decreasing cost, downtime and repetitive tasks.” https://en.wikipedia.org/wiki/Identity_management
  • 6. #auspc #nzspc #spt1413 Authentication and Authorization Verifying that a user, device, or service such as an application provided on a network server is the entity that it claims to be. Determining which actions an authenticated entity is authorized to perform on the network Authentication Authorization
  • 7. #auspc #nzspc #spt1413  Single Sign On (SSO) is the ability for two disjoint Identity Providers (IDP) to trust each other such that a user logged in to one does not need to log in again for the second  Relying Party (RP) is the system that relies on the IDP to authenticate a user Security Assertion Markup Language (SAML) SAML is a public standard managed by OASIS. SAML is the identity token and also the protocol. WSFED is used for web browser-based authentication with an IDP. WS-Trust is used by Office client apps to authenticate.* WS-Federation (WSFED) / WS-Trust
  • 9. #auspc #nzspc #spt1413User Microsoft Account Ex: alice@outlook.com User Organizational Account Ex: alice@contoso.com Microsoft Account Azure Active Directory
  • 10. #auspc #nzspc #spt1413 What is AAD? “Azure Active Directory is a comprehensive identity and access management cloud solution that provides a robust set of capabilities to manage users and groups and help secure access to applications including Microsoft online services like Office 365 and a world of non-Microsoft SaaS applications.”
  • 13. #auspc #nzspc #spt1413 Cloud Identity Zero on-premises servers On-premises directory restructuring Pilots and Proof of Concept
  • 14. #auspc #nzspc #spt1413 Synchronized Identity Federation is not required Simple Sign On is acceptable
  • 15. #auspc #nzspc #spt1413 Federated Identity  Already have ADFS or a 3rd party IDP  Require immediate disable or Sign-in Audit  SSO is required  Multiple Forests  CAC or on-premises MFA  Business requires it
  • 18. #auspc #nzspc #spt1413 What are we going to do? Office 365 E3 Tenant Configure DirSync  Users in targeted OU  One way password sync  Alternate Login ID
  • 19. #auspc #nzspc #spt1413  Logon to the Portal  Select Users and groups and then activate DirSync  Select Users and Groups and click Set up Active Directory synchronization  Activate Directory Synchronization  Wait for DirSync to enable  Review all documentation, follow the implementation steps, and download DirSync Form DirSync server Download DirSync
  • 20. #auspc #nzspc #spt1413  Logon to DirSync server and run setup  Follow setup wizard  When finished, option to start the configuration wizard
  • 21. #auspc #nzspc #spt1413 Run configuration wizard Provide O365admin creds Provide AD admin creds If Exchange hybrid, configure “write-back” Password sync option Create configuration When finished, option to run synchronization
  • 23. #auspc #nzspc #spt1413  When your on-premises UPN is non-routable on the public internet and you can’t easily update UPN suffixes  Requires Windows Server 2012 R2 for AD FS*  Requires comfort with FIM and editing Management Agents
  • 24. #auspc #nzspc #spt1413  DirSync for LDAPv3  Supports multiple forests  Doesn’t include password hash sync  Includes write back capability with Azure AD Premium subscription  Availability  Preview now available at: http://go.microsoft.com/?linkid=9845645  Release later in 2014  Target Identity Providers  Same as FIM 2010 R2 connector  FIM connector details at http://go.microsoft.com/fwlink/?LinkID=270179
  • 25. #auspc #nzspc #spt1413  SSO with passive authentication  Works with WSFED and SAML 2.0  Planned for later in 2014  Will require Office Client updates  Move to Active Directory Authentication Library (ADAL)  OAUTH for passive authentication  Support for MFA with AAD  CAC/PIV support SAML 2.0
  • 26. #auspc #nzspc #spt1413  What is it?  Qualification of third party identity providers for federation with Office 365. Microsoft supports Office 365 only when qualified third party identity providers are used.  Program Requirements  Published Qualification Requirements  Published Technical Integration Docs  Automated Testing Tool  Self Testing work by Partner  Predictable and Shorter Qualification  http://aka.ms/ssoproviders *For representative purposes only. WS-Trust & WS- Federation SAML (passive auth) Active Directory with ADFS • Flexibility to reuse existing identity provider investments • Confidence that the solution is qualified by Microsoft • Coordinated support between the partner and Microsoft Customer Benefits
  • 27. #auspc #nzspc #spt1413 Suitable for medium, large enterprises including educational organizations Suitable for medium, large enterprises including educational organizations Suitable for educational organizations For organizations that need to use SAML 2.0
  • 30. #auspc #nzspc #spt1413 Identity Management in Office 365 Identity Scenarios Synchronisation Demo Add-ons and More to Think About    
  • 32. #auspc #nzspc #spt1413  Use third-party identity providers to implement single sign-on  Deployment scenarios for Office 365 with single sign- on and Azure  Choosing a sign-in model for Office 365  Password hash sync simplifies user management for Office 365  Using Alternate Login IDs with Azure Active Directory  Office 365 SAML 2.0 Federation Implementer’s Guide  Simplified login to Yammer from Office 365  Multi-Factor Authentication for Office 365  Office 365 User Account Management