1. MS Online IDs              2. MS Online IDs + Dir Sync           3. Federated IDs + Dir SyncAppropriate for            ...
Microsoft Office 365 ServicesBronze Sky customer premises                                    Trust            Federation  ...
Federated vs. Non-Federated Summary                                                                          Office 2010, ...
DirSyncActive Directory                   METAVERSE
Identity Co-Existence
Application Co-Existence
Application Co-Existence
lD85BkxzEE2NilRewNm0CQ==
Authentication flow (passive profile)               Customer                  Microsoft Office 365  Active Directory      ...
Authentication flow (active profile)               Customer                 Microsoft Office 365  Active Directory        ...
AD FS 2.0 deployment options                Active               Directory   AD FS 2.0               AD FS 2.0       AD FS...
Active            DirectoryAD FS 2.0               AD FS 2.0       AD FS 2.0 Server                  Server          Serve...
Active                                  Active            Directory                               DirectoryAD FS 2.0      ...
Active                          Active            Directory                       DirectoryAD FS 2.0                      ...
Active                                            Directory   AD FS 2.0                    AD FS 2.0               AD FS 2...
Active              Directory  AD FS 2.0               AD FS 2.0   Server                  ServerInternalExternal         ...
W.A.A.D.Already used in:
W.A.A.D.W.A.A.D.W.A.A.D.
Supporting architecture for office 365 spo
Supporting architecture for office 365 spo
Supporting architecture for office 365 spo
Supporting architecture for office 365 spo
Supporting architecture for office 365 spo
Supporting architecture for office 365 spo
Supporting architecture for office 365 spo
Supporting architecture for office 365 spo
Supporting architecture for office 365 spo
Supporting architecture for office 365 spo
Supporting architecture for office 365 spo
Supporting architecture for office 365 spo
Supporting architecture for office 365 spo
Supporting architecture for office 365 spo
Supporting architecture for office 365 spo
Supporting architecture for office 365 spo
Supporting architecture for office 365 spo
Supporting architecture for office 365 spo
Supporting architecture for office 365 spo
Supporting architecture for office 365 spo
Upcoming SlideShare
Loading in...5
×

Supporting architecture for office 365 spo

703

Published on

0 Comments
0 Likes
Statistics
Notes
  • Be the first to comment

  • Be the first to like this

No Downloads
Views
Total Views
703
On Slideshare
0
From Embeds
0
Number of Embeds
1
Actions
Shares
0
Downloads
18
Comments
0
Likes
0
Embeds 0
No embeds

No notes for slide
  • Note: Passwords are NOT synced. If you want to use your on-premise passwords in Office 365/Azure, you will have to deploy ADFS.Future release of DirSync might support Password Synchronization** Functionality nor a release date have been confirmed by Microsoft. As far as I understood, this sync will not really sync the password, but it will rather use the password’s hash
  • http://social.technet.microsoft.com/wiki/contents/articles/3286.ad-fs-2-0-how-to-use-fiddler-web-debugger-to-analyze-a-ws-federation-passive-sign-in.aspx
  • Supporting architecture for office 365 spo

    1. 1. 1. MS Online IDs 2. MS Online IDs + Dir Sync 3. Federated IDs + Dir SyncAppropriate for Appropriate for Appropriate for • Smaller organizations without • Orgs with AD on-premise • Larger enterprise organizations AD on-premise with AD on-premise ProsPros • Users and groups mastered on- Pros • No servers required on- premise • SSO with corporate cred premise • Enables co-existence scenarios • Users and groups mastered on- premise Cons • Password policy controlled on-Cons • No SSO premise • No SSO • No 2FA • 2FA solutions possible • No 2FA (strong authentication) • 2 sets of credentials to manage • Enables co-existence scenarios • 2 sets of credentials to with differing password policies manage with differing • Single server deployment Cons password policies • High availability server • Users and groups mastered in deployments required the cloud
    2. 2. Microsoft Office 365 ServicesBronze Sky customer premises Trust Federation Exchange Gateway Online Active Directory Authentication Federation Server platform SharePoint 2.0 IdP OnlineIdP MS Online Directory Provisioning Sync Directory Lync AD platform Store Online Service connector Admin Portal
    3. 3. Federated vs. Non-Federated Summary Office 2010, or Office ActiveSync, POP, Outlook Outlook Outlook 2007 or Outlook Web 2007 SP2 IMAP, Entourage 2010 2007 2010 Application SharePoint Online Win 7 Win 7 Vista/XP Win 7/Vista/XPMS Online IDs Online ID Online ID Online ID Online ID Online ID Online IDFederated IDs,domain joined AD credentials
    4. 4. DirSyncActive Directory METAVERSE
    5. 5. Identity Co-Existence
    6. 6. Application Co-Existence
    7. 7. Application Co-Existence
    8. 8. lD85BkxzEE2NilRewNm0CQ==
    9. 9. Authentication flow (passive profile) Customer Microsoft Office 365 Active Directory AD FS 2.0 Server Federation Gateway ` Client Exchange Online (joined to CorpNet)
    10. 10. Authentication flow (active profile) Customer Microsoft Office 365 Active Directory AD FS 2.0 Server Federation Gateway ` Client Exchange Online (joined to CorpNet)
    11. 11. AD FS 2.0 deployment options Active Directory AD FS 2.0 AD FS 2.0 AD FS 2.0 Server Server Server Proxy AD FS 2.0 Server Proxy Internal user Enterprise DMZ
    12. 12. Active DirectoryAD FS 2.0 AD FS 2.0 AD FS 2.0 Server Server Server Proxy AD FS 2.0 Server ProxyInternal user Enterprise DMZ
    13. 13. Active Active Directory DirectoryAD FS 2.0 AD FS 2.0 AD FS 2.0 AD FS 2.0 Server Server Server ServerInternal External user Enterprise user IAAS
    14. 14. Active Active Directory DirectoryAD FS 2.0 AD FS 2.0 Server ServerInternal External user Enterprise user IAAS
    15. 15. Active Directory AD FS 2.0 AD FS 2.0 AD FS 2.0 Server Server Server LB ENDPOINT IP SEC GATEWAY AD FS 2.0 DEVICE ServerCLOUD SERVICE Enterprise Windows Azure
    16. 16. Active Directory AD FS 2.0 AD FS 2.0 Server ServerInternalExternal IAAS user
    17. 17. W.A.A.D.Already used in:
    18. 18. W.A.A.D.W.A.A.D.W.A.A.D.
    1. A particular slide catching your eye?

      Clipping is a handy way to collect important slides you want to go back to later.

    ×