SlideShare a Scribd company logo
Office 365 and Cloud Identity
What does it mean for me?
Scott Hoag
Applied Information Sciences
SYDSP  - Office 365 and Cloud Identity - What does it mean for me?
Agenda
Identity Management in Office 365
Identity Scenarios
Synchronisation Demo
Add-ons and More to Think About
1
2
3
4
Identity Management Overview
Terminology
What is Identity Management?
“Identity management (IdM) describes the
management of individual principals, their
authentication, authorisation, and privileges within
or across system and enterprise boundaries with
the goal of increasing security and productivity
while decreasing cost, downtime and repetitive
tasks.”
https://en.wikipedia.org/wiki/Identity_management
Determining which actions an
authenticated entity is authorized
to perform on the network
Terminology
Verifying that a user, device, or
service such as an application
provided on a network server is
the entity that it claims to be.
Authentication Authorization
Terminology
 Single Sign On (SSO) is the ability for two disjointed Identity
Providers (IDP) to trust each other such that a user logged in to one
does not need to log in again for the second
 Relying Party (RP) is the system that relies on the IDP to
authenticate a user
Security Assertion Markup
Language (SAML)
SAML is a public standard managed by OASIS.
SAML is the identity token and also the
protocol.
WSFED is used for web browser-based
authentication with an IDP. WS-Trust is used by
Office client apps to authenticate.*
WS-Federation (WSFED) / WS-Trust
Identity Synchronisation and Federation
WS-Federation
WS-Trust
SAML 2.0
Metadata
Shibboleth
Graph API
Microsoft Identity Services
User
Microsoft Account
Ex: alice@outlook.com
User
Organizational Account
Ex: alice@contoso.com
Microsoft Account Azure Active Directory
Azure Active Directory
What is AAD?
“Azure Active Directory is a comprehensive identity
and access management cloud solution that
provides a robust set of capabilities to manage
users and groups and help secure access to
applications including Microsoft online services like
Office 365 and a world of non-Microsoft SaaS
applications.”
Identity Scenarios
SYDSP  - Office 365 and Cloud Identity - What does it mean for me?
13
Password Synchronisation
Choosing a Model
Cloud Identity
Zero on-premises servers
On-premises directory restructuring
Pilots and Proof of Concept
Choosing a Model
Synchronized Identity
Federation is not
required
Simple Sign On is
acceptable
Choosing a Model
Federated Identity
Already have ADFS or a
3rd party IDP
Require immediate
disable or Sign-in Audit
SSO is required
Multiple Forests
CAC or on-premises
MFA
Business requires it
Choosing a Model
On your terms
18
Synchronisation Landscape
Feature Azure Active Directory
Synchronization Tool
(DirSync)
Azure Active Directory
Synchronization Services
(AAD Sync)
Azure Active Directory
Connect
Forefront Identity
Manager 2010 R2 (FIM)
Connect to single on-
premises AD forest
X X PP X
Connect to multiple on-
premises AD forests
X PP X
Connect to single on-
premises LDAP directory
CS X
Connect to multiple on-
premises LDAP directories
CS X
Connect to on-premises
AD and on-premises LDAP
directories
CS X
Connect to custom
systems (i.e. SQL, Oracle,
MySQL, etc.)
X
Synchronize customer
defined attributes
(directory extensions)
CS
Directory Sync Demonstration
The Setup
What are we going to do?
• Office 365 E3 Tenant
• Configure Sync
‐ Users in targeted OU
‐ One way password sync
‐ Alternate Login ID
Prepare and Download DirSync
• Logon to the Portal
• Select Users and groups and then
activate DirSync
‐ Select Users and Groups and
click Set up Active Directory
synchronization
‐ Activate Directory
Synchronization
• Wait for Sync to enable
• Review all documentation, follow the
implementation steps, and download
Sync appliance
Form DirSync server
Download DirSync
Install AAD Sync
Install AAD Sync
Install AAD Sync
Install AAD Sync
Install AAD Sync
Install AAD Sync
Install AAD Sync
Install AAD Sync
Install AAD Sync
Install AAD Sync
Install AAD Sync
Install AAD Sync
34
Synchronisation Rules Editor
35
Synchronisation Rules Editor
36
Synchronisation Rules Editor
37
Running Synchronisation
38
Running Synchronisation
39
Finalising Synchronisation
Other Considerations
Alternate Login ID
When your on-premises UPN is non-routable on the public internet and you
can’t easily update UPN suffixes
Requires Windows Server 2012 R2 for AD FS*
Requires comfort with FIM and editing Management Agents
Office Client Passive Authentication
• SSO with passive authentication
‐ Works with WSFED and SAML 2.0
• Went Tech Preview in Nov 2014
• Requires Office Client updates
‐ Move to Active Directory
Authentication Library (ADAL)
‐ OAUTH for passive authentication
‐ Support for MFA with AAD
‐ CAC/PIV support
SAML 2.0
Works with Office 365 – Identity program
• What is it?
‐ Qualification of third party identity
providers for federation with Office 365.
Microsoft supports Office 365 only
when qualified third party identity
providers are used.
• Program Requirements
‐ Published Qualification Requirements
‐ Published Technical Integration Docs
‐ Automated Testing Tool
‐ Self Testing work by Partner
‐ Predictable and Shorter Qualification
‐ http://aka.ms/ssoproviders
*For representative purposes
only.
WS-Trust & WS-
Federation
SAML (passive
auth)
• Flexibility to reuse
existing identity
provider investments
• Confidence that the
solution is qualified by
Microsoft
• Coordinated support
between the partner
and Microsoft
Customer
Benefits
Office 365 Federation Options
Suitable for medium, large
enterprises including
educational organizations
Suitable for medium, large
enterprises including
educational organizations
Suitable for educational
organizations
For organizations that
need to use SAML 2.0
Closing Thoughts
The end to end Microsoft Stack
WS-Federation
WS-Trust
Agenda
Identity Management in Office 365
Identity Scenarios
Synchronisation Demo
Add-ons and More to Think About




Resources
• Use third-party identity providers to
implement single sign-on
• Deployment scenarios for Office 365
with single sign-on and Azure
• Choosing a sign-in model for Office
365
• Password hash sync simplifies user
management for Office 365
• Directory Integration Tools
• Using Alternate Login IDs with
Azure Active Directory
• Office 365 SAML 2.0 Federation
Implementer’s Guide
• Simplified login to Yammer from
Office 365
• Multi-Factor Authentication for
Office 365
• Office 365 User Account
Management

More Related Content

PPTX
Protect Identities and Access to resources with Azure Active Directory
PPTX
Securing your Azure Identity Infrastructure
PDF
ざっくり解説 LINE ログイン
PPTX
Single Sign-On security issue in Cloud Computing
PPTX
Supporting architecture for office 365 spo
DOCX
Microsoft Windows Azure - Developer’s Guide Access Control in the Windows Azu...
PPTX
Interesting EMS Sessions for Ignite 2018
PPTX
CoLabora March 2022 - Improve security posture by implementing new Azure AD ...
Protect Identities and Access to resources with Azure Active Directory
Securing your Azure Identity Infrastructure
ざっくり解説 LINE ログイン
Single Sign-On security issue in Cloud Computing
Supporting architecture for office 365 spo
Microsoft Windows Azure - Developer’s Guide Access Control in the Windows Azu...
Interesting EMS Sessions for Ignite 2018
CoLabora March 2022 - Improve security posture by implementing new Azure AD ...

What's hot (19)

PPTX
SPSNL17 - Securing Office 365 and Microsoft Azure like a rock star (or groupi...
PPTX
Managing enterprise applications, permissions, and consent in Azure Active Di...
PPTX
Community call: Develop multi tenant apps with the Microsoft identity platform
PDF
Swiz DAO
PDF
Active Directory & LDAP | Security for Elasticsearch
PPTX
MongoDB.local Atlanta: Introduction to Serverless MongoDB
PDF
Secure Your Cloud Environment with Azure Active Directory (AD)
PPTX
What's acs
PPTX
Assessing security of your Active Directory
PDF
Programming with Azure Active Directory
PDF
Cqrs journey guide
PDF
2019-06-04 aOS Strasbourg - Technique 3 - MS Threat Protection - Seyfallah Ta...
PDF
Microsoft AZ-204 Exam Dumps
PDF
Microsoft Cloud Identity and Access Management Poster - Atidan
PPTX
Web Single sign on system
PPTX
Webinar: Extend The Power of The ForgeRock Identity Platform Through Scripting
PDF
Windows identityfoundationwhitepaperfordevelopers rtw
PDF
Managing enterprise applications, permissions, and consent in Azure Active Di...
PDF
SPSNL17 - Secure Collaboration: Start classifying, labeling, and protecting y...
SPSNL17 - Securing Office 365 and Microsoft Azure like a rock star (or groupi...
Managing enterprise applications, permissions, and consent in Azure Active Di...
Community call: Develop multi tenant apps with the Microsoft identity platform
Swiz DAO
Active Directory & LDAP | Security for Elasticsearch
MongoDB.local Atlanta: Introduction to Serverless MongoDB
Secure Your Cloud Environment with Azure Active Directory (AD)
What's acs
Assessing security of your Active Directory
Programming with Azure Active Directory
Cqrs journey guide
2019-06-04 aOS Strasbourg - Technique 3 - MS Threat Protection - Seyfallah Ta...
Microsoft AZ-204 Exam Dumps
Microsoft Cloud Identity and Access Management Poster - Atidan
Web Single sign on system
Webinar: Extend The Power of The ForgeRock Identity Platform Through Scripting
Windows identityfoundationwhitepaperfordevelopers rtw
Managing enterprise applications, permissions, and consent in Azure Active Di...
SPSNL17 - Secure Collaboration: Start classifying, labeling, and protecting y...
Ad

Similar to SYDSP - Office 365 and Cloud Identity - What does it mean for me? (20)

PPTX
SPSVB - Office 365 and Cloud Identity - What Does It Mean for Me?
PDF
JAXSPUG January 2016 - Microsoft Cloud Identities in Azure and Office 365
PPTX
SPIntersection 2016 - MICROSOFT CLOUD IDENTITIES IN AZURE AND OFFICE 365
PPTX
SPS Sydney - Office 365 and Cloud Identity – What does it mean for me?
PPTX
Understanding Identity Management with Office 365
PPTX
Office 365 MCSA TechEd
PPTX
70 346 Managing office 365 identities
PDF
Office 365 identity
PPTX
2. Day 2 - Identify and SSO
PPTX
Understanding Office 365’s Identity Solutions: Deep Dive - EPC Group
PDF
Office 365 and Cloud Identity – What Does It Mean For Me?
PDF
Office 365 Identity Management - SMBNation 2015
PDF
O365con14 - moving from on-premises to online, the road to follow
PPTX
Microsoft Office 365 Directory Synchronization and Federation Options
PPTX
1. Day 1 - Office 365 Trainning
PPTX
CoLabora - Identity in a World of Cloud - June 2015
PPTX
Brian Desmond - Identity and directory synchronization with office 365 and wi...
PDF
Identity and Authentication in Office 2013 and Office 365 from Microsoft
PDF
Andy Malone - The new office 365 for it pro's
PPTX
Identity Management for Office 365 and Microsoft Azure
SPSVB - Office 365 and Cloud Identity - What Does It Mean for Me?
JAXSPUG January 2016 - Microsoft Cloud Identities in Azure and Office 365
SPIntersection 2016 - MICROSOFT CLOUD IDENTITIES IN AZURE AND OFFICE 365
SPS Sydney - Office 365 and Cloud Identity – What does it mean for me?
Understanding Identity Management with Office 365
Office 365 MCSA TechEd
70 346 Managing office 365 identities
Office 365 identity
2. Day 2 - Identify and SSO
Understanding Office 365’s Identity Solutions: Deep Dive - EPC Group
Office 365 and Cloud Identity – What Does It Mean For Me?
Office 365 Identity Management - SMBNation 2015
O365con14 - moving from on-premises to online, the road to follow
Microsoft Office 365 Directory Synchronization and Federation Options
1. Day 1 - Office 365 Trainning
CoLabora - Identity in a World of Cloud - June 2015
Brian Desmond - Identity and directory synchronization with office 365 and wi...
Identity and Authentication in Office 2013 and Office 365 from Microsoft
Andy Malone - The new office 365 for it pro's
Identity Management for Office 365 and Microsoft Azure
Ad

More from Scott Hoag (20)

PPTX
SharePoint Conference 2018 - Understanding Office 365 Usage Reporting
PPTX
SharePoint Conference 2018 - Securing Office 365 and SharePoint Online with A...
PDF
Global Azure Bootcamp 2018 - Azure Security Center
PDF
Global Azure Bootcamp 2018 - Azure Network Security
PPTX
SPIntersection 2016 - TO THE CLOUD! USING IAAS AS A HOSTING PROVIDER FOR SHAR...
PPTX
JAXSPUG April 2016 - Staying in the Know with Office 365
PPTX
SPSDC - To the Cloud! Using IaaS as a Hosting Provider for SharePoint
PPTX
SPSNYC SharePoint Worst Practices
PPTX
March Sydney Office 365 Meetup - Office 365 and Hybrid Solutions... what work...
PPTX
SPSVB - Office 365 and Hybrid Solutions... what works for my organization?
PPTX
SPSVB - To the Cloud! Using IaaS as a Hosting Provider for SharePoint
PPTX
SPS Sydney - To the Cloud! Utilising Azure as a Cloud Hosting Provider for Sh...
PPTX
SPSCBR - Pitfalls of Migrating to SharePoint 2013
PPTX
Canberra SPUG - February 2014 - Pitfalls of Migrating to SharePoint 2013
PPTX
Sydney SPUG - February 2014 - Pitfalls of Migrating to SharePoint 2013
PPTX
SPSNYC - Authentication, Authorization, and Identity – More than meets the eye…
PPTX
SPT15 To the Cloud! Utilizing AWS and Azure as Cloud Hosting Providers for Sh...
PPTX
Getting Started with Office 365
PPTX
Authentication, Authorization, and Identity – More than meets the eye…
PPTX
FEDSPUG - SharePoint 2013 - A Brief Capability Overview
SharePoint Conference 2018 - Understanding Office 365 Usage Reporting
SharePoint Conference 2018 - Securing Office 365 and SharePoint Online with A...
Global Azure Bootcamp 2018 - Azure Security Center
Global Azure Bootcamp 2018 - Azure Network Security
SPIntersection 2016 - TO THE CLOUD! USING IAAS AS A HOSTING PROVIDER FOR SHAR...
JAXSPUG April 2016 - Staying in the Know with Office 365
SPSDC - To the Cloud! Using IaaS as a Hosting Provider for SharePoint
SPSNYC SharePoint Worst Practices
March Sydney Office 365 Meetup - Office 365 and Hybrid Solutions... what work...
SPSVB - Office 365 and Hybrid Solutions... what works for my organization?
SPSVB - To the Cloud! Using IaaS as a Hosting Provider for SharePoint
SPS Sydney - To the Cloud! Utilising Azure as a Cloud Hosting Provider for Sh...
SPSCBR - Pitfalls of Migrating to SharePoint 2013
Canberra SPUG - February 2014 - Pitfalls of Migrating to SharePoint 2013
Sydney SPUG - February 2014 - Pitfalls of Migrating to SharePoint 2013
SPSNYC - Authentication, Authorization, and Identity – More than meets the eye…
SPT15 To the Cloud! Utilizing AWS and Azure as Cloud Hosting Providers for Sh...
Getting Started with Office 365
Authentication, Authorization, and Identity – More than meets the eye…
FEDSPUG - SharePoint 2013 - A Brief Capability Overview

Recently uploaded (20)

PPTX
A Presentation on Artificial Intelligence
PPTX
Big Data Technologies - Introduction.pptx
PDF
Reach Out and Touch Someone: Haptics and Empathic Computing
PPTX
Digital-Transformation-Roadmap-for-Companies.pptx
PDF
Approach and Philosophy of On baking technology
PDF
Mobile App Security Testing_ A Comprehensive Guide.pdf
PPTX
KOM of Painting work and Equipment Insulation REV00 update 25-dec.pptx
PDF
Per capita expenditure prediction using model stacking based on satellite ima...
PDF
Chapter 3 Spatial Domain Image Processing.pdf
PDF
Advanced methodologies resolving dimensionality complications for autism neur...
PDF
Network Security Unit 5.pdf for BCA BBA.
PPTX
Cloud computing and distributed systems.
PDF
Build a system with the filesystem maintained by OSTree @ COSCUP 2025
PDF
Encapsulation_ Review paper, used for researhc scholars
PPT
Teaching material agriculture food technology
PDF
Agricultural_Statistics_at_a_Glance_2022_0.pdf
PDF
Peak of Data & AI Encore- AI for Metadata and Smarter Workflows
PPTX
VMware vSphere Foundation How to Sell Presentation-Ver1.4-2-14-2024.pptx
PDF
NewMind AI Weekly Chronicles - August'25 Week I
PDF
KodekX | Application Modernization Development
A Presentation on Artificial Intelligence
Big Data Technologies - Introduction.pptx
Reach Out and Touch Someone: Haptics and Empathic Computing
Digital-Transformation-Roadmap-for-Companies.pptx
Approach and Philosophy of On baking technology
Mobile App Security Testing_ A Comprehensive Guide.pdf
KOM of Painting work and Equipment Insulation REV00 update 25-dec.pptx
Per capita expenditure prediction using model stacking based on satellite ima...
Chapter 3 Spatial Domain Image Processing.pdf
Advanced methodologies resolving dimensionality complications for autism neur...
Network Security Unit 5.pdf for BCA BBA.
Cloud computing and distributed systems.
Build a system with the filesystem maintained by OSTree @ COSCUP 2025
Encapsulation_ Review paper, used for researhc scholars
Teaching material agriculture food technology
Agricultural_Statistics_at_a_Glance_2022_0.pdf
Peak of Data & AI Encore- AI for Metadata and Smarter Workflows
VMware vSphere Foundation How to Sell Presentation-Ver1.4-2-14-2024.pptx
NewMind AI Weekly Chronicles - August'25 Week I
KodekX | Application Modernization Development

SYDSP - Office 365 and Cloud Identity - What does it mean for me?

  • 1. Office 365 and Cloud Identity What does it mean for me? Scott Hoag Applied Information Sciences
  • 3. Agenda Identity Management in Office 365 Identity Scenarios Synchronisation Demo Add-ons and More to Think About 1 2 3 4
  • 5. Terminology What is Identity Management? “Identity management (IdM) describes the management of individual principals, their authentication, authorisation, and privileges within or across system and enterprise boundaries with the goal of increasing security and productivity while decreasing cost, downtime and repetitive tasks.” https://en.wikipedia.org/wiki/Identity_management
  • 6. Determining which actions an authenticated entity is authorized to perform on the network Terminology Verifying that a user, device, or service such as an application provided on a network server is the entity that it claims to be. Authentication Authorization
  • 7. Terminology  Single Sign On (SSO) is the ability for two disjointed Identity Providers (IDP) to trust each other such that a user logged in to one does not need to log in again for the second  Relying Party (RP) is the system that relies on the IDP to authenticate a user Security Assertion Markup Language (SAML) SAML is a public standard managed by OASIS. SAML is the identity token and also the protocol. WSFED is used for web browser-based authentication with an IDP. WS-Trust is used by Office client apps to authenticate.* WS-Federation (WSFED) / WS-Trust
  • 8. Identity Synchronisation and Federation WS-Federation WS-Trust SAML 2.0 Metadata Shibboleth Graph API
  • 9. Microsoft Identity Services User Microsoft Account Ex: alice@outlook.com User Organizational Account Ex: alice@contoso.com Microsoft Account Azure Active Directory
  • 10. Azure Active Directory What is AAD? “Azure Active Directory is a comprehensive identity and access management cloud solution that provides a robust set of capabilities to manage users and groups and help secure access to applications including Microsoft online services like Office 365 and a world of non-Microsoft SaaS applications.”
  • 14. Choosing a Model Cloud Identity Zero on-premises servers On-premises directory restructuring Pilots and Proof of Concept
  • 15. Choosing a Model Synchronized Identity Federation is not required Simple Sign On is acceptable
  • 16. Choosing a Model Federated Identity Already have ADFS or a 3rd party IDP Require immediate disable or Sign-in Audit SSO is required Multiple Forests CAC or on-premises MFA Business requires it
  • 17. Choosing a Model On your terms
  • 18. 18 Synchronisation Landscape Feature Azure Active Directory Synchronization Tool (DirSync) Azure Active Directory Synchronization Services (AAD Sync) Azure Active Directory Connect Forefront Identity Manager 2010 R2 (FIM) Connect to single on- premises AD forest X X PP X Connect to multiple on- premises AD forests X PP X Connect to single on- premises LDAP directory CS X Connect to multiple on- premises LDAP directories CS X Connect to on-premises AD and on-premises LDAP directories CS X Connect to custom systems (i.e. SQL, Oracle, MySQL, etc.) X Synchronize customer defined attributes (directory extensions) CS
  • 20. The Setup What are we going to do? • Office 365 E3 Tenant • Configure Sync ‐ Users in targeted OU ‐ One way password sync ‐ Alternate Login ID
  • 21. Prepare and Download DirSync • Logon to the Portal • Select Users and groups and then activate DirSync ‐ Select Users and Groups and click Set up Active Directory synchronization ‐ Activate Directory Synchronization • Wait for Sync to enable • Review all documentation, follow the implementation steps, and download Sync appliance Form DirSync server Download DirSync
  • 41. Alternate Login ID When your on-premises UPN is non-routable on the public internet and you can’t easily update UPN suffixes Requires Windows Server 2012 R2 for AD FS* Requires comfort with FIM and editing Management Agents
  • 42. Office Client Passive Authentication • SSO with passive authentication ‐ Works with WSFED and SAML 2.0 • Went Tech Preview in Nov 2014 • Requires Office Client updates ‐ Move to Active Directory Authentication Library (ADAL) ‐ OAUTH for passive authentication ‐ Support for MFA with AAD ‐ CAC/PIV support SAML 2.0
  • 43. Works with Office 365 – Identity program • What is it? ‐ Qualification of third party identity providers for federation with Office 365. Microsoft supports Office 365 only when qualified third party identity providers are used. • Program Requirements ‐ Published Qualification Requirements ‐ Published Technical Integration Docs ‐ Automated Testing Tool ‐ Self Testing work by Partner ‐ Predictable and Shorter Qualification ‐ http://aka.ms/ssoproviders *For representative purposes only. WS-Trust & WS- Federation SAML (passive auth) • Flexibility to reuse existing identity provider investments • Confidence that the solution is qualified by Microsoft • Coordinated support between the partner and Microsoft Customer Benefits
  • 44. Office 365 Federation Options Suitable for medium, large enterprises including educational organizations Suitable for medium, large enterprises including educational organizations Suitable for educational organizations For organizations that need to use SAML 2.0
  • 46. The end to end Microsoft Stack WS-Federation WS-Trust
  • 47. Agenda Identity Management in Office 365 Identity Scenarios Synchronisation Demo Add-ons and More to Think About    
  • 48. Resources • Use third-party identity providers to implement single sign-on • Deployment scenarios for Office 365 with single sign-on and Azure • Choosing a sign-in model for Office 365 • Password hash sync simplifies user management for Office 365 • Directory Integration Tools • Using Alternate Login IDs with Azure Active Directory • Office 365 SAML 2.0 Federation Implementer’s Guide • Simplified login to Yammer from Office 365 • Multi-Factor Authentication for Office 365 • Office 365 User Account Management