SlideShare a Scribd company logo
1 of 15
Azure AD & MDM Options
Design Decisions
• Azure AD Authorization options: Hash Sync Vs Pass Through
• Azure AD: Register Vs Join
• Azure AD MFA: Authenticator Vs YubiKey Vs Hello
Azure AD
AD Federated Authentication
On-Prem AD
Authentication sent to Federation Server
Internet
Perimeter
Azure AD
On-premises
Federation
Proxy
On-Prem
Federation Server
Cloud Authentication vs Federation (ADFS)
Cloud Federation
Authentication Location In Cloud On-Prem
Server Requirements None
Two or more AD FS servers & WAP
servers (in the perimeter/DMZ network)
Network Requirements
None(PHS)/
Outbound Internet Access(PTA)
Inbound Internet Access &
Network load balancing
Advantages
-Cost effective & Easiest deployment
-Can login even if AD is down
-High availability & Disaster recovery
-Use Azure AD Identity Protection
- More Intune feature sets
-Authentication happens on-Prem
-Immediate Account Lockout
-Use ADFS Claim Rules
-Azure AD Premium not required
-Custom MFA provider
AD Password Hash Sync
ADConnect On-premAD
Password Hash Sync
Password validated against Azure Hash*
Internet Intranet
Azure AD
*MD4+salt+PBKDF2+HMAC-SHA256
AD Pass Through Authentication
ADConnect On-premAD
Credentials sent to On-Prem agent
Internet Intranet
AuthN
Agent
Azure AD
AAD Password Hash Sync Vs Pass Through Auth
PHS PTA
Password Location Azure AD (hash) On-Prem
Account Lockout/Disable Next Cycle (disable) Immediate
Azure AD Identity Protection
Yes
(Require Azure AD Premium P2 licenses)
Advantages
-Cost effective & Easiest deployment
-Can login even if AD is down
-Authentication happens on-Prem
-Works with Azure Conditional
access
Azure AD: Register vs Join
Registering a device to Azure AD enables you to manage a device’s identity. When combined with a
mobile device management(MDM) solution such as Intune, allows you to create conditional access
rules that enforce access from devices to meet your standards for security and compliance
Joining a device is an extension to registering a device; Provides all benefits of registration in
addition to changing the local state of a device. This enables your users to sign-in to a device using
an organizational work or school account
Azure AD: Register vs Join
Register Join Hybrid
Device Ownership Personal (BYOD) Firm Issued Firm Issued
Device Type Win10 Devices
Win8.1-10, Android, IOS
(For devices that are not joined to an on-
premises AD)
Win7-10 PC’s
(For devices that are joined to an on-
premises AD)
Registration/
Management
• To manually register devices with Azure
AD
• MDM (Intune)
• To manually register devices with Azure
AD
• To change the local state of a device
• MDM (Intune)
• To automatically register devices with
Azure AD
• To change the local state of a device
• SCCM + GP
Additional
Functionality
• Cloud + SSO
• Conditional access using Intune
• AD Connect + Device writeback
• Windows Hello
• Cloud + SSO
• Conditional access using Intune
• AD Connect + Device writeback
• Windows Hello
• Enterprise State Roaming
• SSO
• Access Win32 apps that rely on AD
auth.
MFA Deployment: Decision Matrix
Planning Considerations Decision Points
Azure MFA verification options Authenticator, Call, SMS
Network definition* Named locations or trusted IPs
Azure conditional access policies* Cloud Apps, Users/Groups, Access Controls
Azure MFA registration policy MFA for Everyone Or Limited to Admin Groups
Remember MFA Yes/No (No of Days)
Azure MFA rollout for users Pilot Deployment, Full Scale Rollout
On-premises integration with Azure MFA Use with Legacy Apps, On-prem AD FS/Radius Apps?
Azure AD: 2FA Options
Windows Hello Microsoft Authenticator FIDO2 Security Keys
Intune Registration Methods
14
Thank you
Authentication Decision Tree

More Related Content

What's hot

Enterprise Mobility Suite-Microsoft Intune
Enterprise Mobility Suite-Microsoft IntuneEnterprise Mobility Suite-Microsoft Intune
Enterprise Mobility Suite-Microsoft Intune
Lai Yoong Seng
 
Azure Overview Arc
Azure Overview ArcAzure Overview Arc
Azure Overview Arc
rajramab
 

What's hot (20)

Azure Active Directory 利用開始への第一歩
Azure Active Directory 利用開始への第一歩Azure Active Directory 利用開始への第一歩
Azure Active Directory 利用開始への第一歩
 
Top 10 AWS Identity and Access Management (IAM) Best Practices (SEC301) | AWS...
Top 10 AWS Identity and Access Management (IAM) Best Practices (SEC301) | AWS...Top 10 AWS Identity and Access Management (IAM) Best Practices (SEC301) | AWS...
Top 10 AWS Identity and Access Management (IAM) Best Practices (SEC301) | AWS...
 
Understanding Azure AD
Understanding Azure ADUnderstanding Azure AD
Understanding Azure AD
 
End to End Guide Windows AutoPilot Process via Intune
End to End Guide Windows AutoPilot Process via IntuneEnd to End Guide Windows AutoPilot Process via Intune
End to End Guide Windows AutoPilot Process via Intune
 
Cloud computing intro
Cloud computing introCloud computing intro
Cloud computing intro
 
FSlogix ODFC POC Guide (version 1.3)
FSlogix ODFC POC Guide (version 1.3)FSlogix ODFC POC Guide (version 1.3)
FSlogix ODFC POC Guide (version 1.3)
 
VSICM8_M02.pptx
VSICM8_M02.pptxVSICM8_M02.pptx
VSICM8_M02.pptx
 
Azure AD Presentation - @ BITPro - Ajay
Azure AD Presentation - @ BITPro - AjayAzure AD Presentation - @ BITPro - Ajay
Azure AD Presentation - @ BITPro - Ajay
 
Introduction to Azure
Introduction to AzureIntroduction to Azure
Introduction to Azure
 
Enterprise Mobility Suite-Microsoft Intune
Enterprise Mobility Suite-Microsoft IntuneEnterprise Mobility Suite-Microsoft Intune
Enterprise Mobility Suite-Microsoft Intune
 
Cloud computing by Google Cloud Platform - Presentation
Cloud computing by Google Cloud Platform - PresentationCloud computing by Google Cloud Platform - Presentation
Cloud computing by Google Cloud Platform - Presentation
 
A Study in Borderless Over Perimeter
A Study in Borderless Over PerimeterA Study in Borderless Over Perimeter
A Study in Borderless Over Perimeter
 
Integrating your on-premises Active Directory with Azure and Office 365
Integrating your on-premises Active Directory with Azure and Office 365Integrating your on-premises Active Directory with Azure and Office 365
Integrating your on-premises Active Directory with Azure and Office 365
 
Get started With Microsoft Azure Virtual Machine
Get started With Microsoft Azure Virtual MachineGet started With Microsoft Azure Virtual Machine
Get started With Microsoft Azure Virtual Machine
 
20190319 AWS Black Belt Online Seminar Amazon FSx for Lustre
20190319 AWS Black Belt Online Seminar Amazon FSx for Lustre20190319 AWS Black Belt Online Seminar Amazon FSx for Lustre
20190319 AWS Black Belt Online Seminar Amazon FSx for Lustre
 
Azure App Service Deep Dive
Azure App Service Deep DiveAzure App Service Deep Dive
Azure App Service Deep Dive
 
Microsoft Intune - Empowering Enterprise Mobility - Presented by Atidan
Microsoft Intune - Empowering Enterprise Mobility - Presented by Atidan Microsoft Intune - Empowering Enterprise Mobility - Presented by Atidan
Microsoft Intune - Empowering Enterprise Mobility - Presented by Atidan
 
Active Directory Domain Services.pptx
Active Directory Domain Services.pptxActive Directory Domain Services.pptx
Active Directory Domain Services.pptx
 
Azure Overview Arc
Azure Overview ArcAzure Overview Arc
Azure Overview Arc
 
Microsoft Azure
Microsoft AzureMicrosoft Azure
Microsoft Azure
 

Similar to Azure AD Options

O365-AzureAD Identity management
O365-AzureAD Identity managementO365-AzureAD Identity management
O365-AzureAD Identity management
David Pechon
 
Get your Hybrid Identity in 4 steps with Azure AD Connect
Get your Hybrid Identity in 4 steps with Azure AD ConnectGet your Hybrid Identity in 4 steps with Azure AD Connect
Get your Hybrid Identity in 4 steps with Azure AD Connect
Ronny de Jong
 
Supporting architecture office 365 on windows azure
Supporting architecture office 365 on windows azure  Supporting architecture office 365 on windows azure
Supporting architecture office 365 on windows azure
Jethro Seghers
 
Premier Webcast - Identity Management with Windows Azure AD
Premier Webcast - Identity Management with Windows Azure ADPremier Webcast - Identity Management with Windows Azure AD
Premier Webcast - Identity Management with Windows Azure AD
uberbaum
 
20160400 Technet- Hybrid identity and access management with Azure AD Premium
20160400 Technet- Hybrid identity and access management with Azure AD Premium20160400 Technet- Hybrid identity and access management with Azure AD Premium
20160400 Technet- Hybrid identity and access management with Azure AD Premium
Robin Vermeirsch
 

Similar to Azure AD Options (20)

Preparing your enteprise for Hybrid AD Join and Conditional Access
Preparing your enteprise for Hybrid AD Join and Conditional AccessPreparing your enteprise for Hybrid AD Join and Conditional Access
Preparing your enteprise for Hybrid AD Join and Conditional Access
 
Cloud Security Fundamentals - St. Louis O365 Users Group
Cloud Security Fundamentals - St. Louis O365 Users GroupCloud Security Fundamentals - St. Louis O365 Users Group
Cloud Security Fundamentals - St. Louis O365 Users Group
 
M365 meetup hybrid identity well protected
M365 meetup hybrid identity well protectedM365 meetup hybrid identity well protected
M365 meetup hybrid identity well protected
 
Colabora.dk - Azure PTA vs ADFS vs Desktop SSO
Colabora.dk - Azure PTA vs ADFS vs Desktop SSOColabora.dk - Azure PTA vs ADFS vs Desktop SSO
Colabora.dk - Azure PTA vs ADFS vs Desktop SSO
 
Azure PTA vs ADFS vs Desktop SSO
Azure PTA vs ADFS vs Desktop SSOAzure PTA vs ADFS vs Desktop SSO
Azure PTA vs ADFS vs Desktop SSO
 
SCUGBE_Lowlands_Unite_2017_Achieving productivity without an on premises infr...
SCUGBE_Lowlands_Unite_2017_Achieving productivity without an on premises infr...SCUGBE_Lowlands_Unite_2017_Achieving productivity without an on premises infr...
SCUGBE_Lowlands_Unite_2017_Achieving productivity without an on premises infr...
 
Atea ems the next level
Atea   ems the next levelAtea   ems the next level
Atea ems the next level
 
Azure Community Tour 2019 - AZUGDK
Azure Community Tour 2019 - AZUGDKAzure Community Tour 2019 - AZUGDK
Azure Community Tour 2019 - AZUGDK
 
O365-AzureAD Identity management
O365-AzureAD Identity managementO365-AzureAD Identity management
O365-AzureAD Identity management
 
Understanding Cloud Identities - SMBNation 2015
Understanding Cloud Identities - SMBNation 2015Understanding Cloud Identities - SMBNation 2015
Understanding Cloud Identities - SMBNation 2015
 
Get your Hybrid Identity in 4 steps with Azure AD Connect
Get your Hybrid Identity in 4 steps with Azure AD ConnectGet your Hybrid Identity in 4 steps with Azure AD Connect
Get your Hybrid Identity in 4 steps with Azure AD Connect
 
Azure with citrix by bipeen sinha
Azure with citrix by bipeen sinhaAzure with citrix by bipeen sinha
Azure with citrix by bipeen sinha
 
Supporting architecture office 365 on windows azure
Supporting architecture office 365 on windows azure  Supporting architecture office 365 on windows azure
Supporting architecture office 365 on windows azure
 
Supporting architecture office 365 on windows azure
Supporting architecture office 365 on windows azure  Supporting architecture office 365 on windows azure
Supporting architecture office 365 on windows azure
 
SMB Authentication with Azure Ad
SMB Authentication with Azure AdSMB Authentication with Azure Ad
SMB Authentication with Azure Ad
 
Premier Webcast - Identity Management with Windows Azure AD
Premier Webcast - Identity Management with Windows Azure ADPremier Webcast - Identity Management with Windows Azure AD
Premier Webcast - Identity Management with Windows Azure AD
 
Hitchhiker's Guide to Azure AD - SPS St Louis 2018
Hitchhiker's Guide to Azure AD - SPS St Louis 2018Hitchhiker's Guide to Azure AD - SPS St Louis 2018
Hitchhiker's Guide to Azure AD - SPS St Louis 2018
 
20160400 Technet- Hybrid identity and access management with Azure AD Premium
20160400 Technet- Hybrid identity and access management with Azure AD Premium20160400 Technet- Hybrid identity and access management with Azure AD Premium
20160400 Technet- Hybrid identity and access management with Azure AD Premium
 
AzureAAD
AzureAADAzureAAD
AzureAAD
 
Identity Management for Office 365 and Microsoft Azure
Identity Management for Office 365 and Microsoft AzureIdentity Management for Office 365 and Microsoft Azure
Identity Management for Office 365 and Microsoft Azure
 

Recently uploaded

Hyatt driving innovation and exceptional customer experiences with FIDO passw...
Hyatt driving innovation and exceptional customer experiences with FIDO passw...Hyatt driving innovation and exceptional customer experiences with FIDO passw...
Hyatt driving innovation and exceptional customer experiences with FIDO passw...
FIDO Alliance
 
TrustArc Webinar - Unified Trust Center for Privacy, Security, Compliance, an...
TrustArc Webinar - Unified Trust Center for Privacy, Security, Compliance, an...TrustArc Webinar - Unified Trust Center for Privacy, Security, Compliance, an...
TrustArc Webinar - Unified Trust Center for Privacy, Security, Compliance, an...
TrustArc
 
CORS (Kitworks Team Study 양다윗 발표자료 240510)
CORS (Kitworks Team Study 양다윗 발표자료 240510)CORS (Kitworks Team Study 양다윗 발표자료 240510)
CORS (Kitworks Team Study 양다윗 발표자료 240510)
Wonjun Hwang
 

Recently uploaded (20)

How to Check GPS Location with a Live Tracker in Pakistan
How to Check GPS Location with a Live Tracker in PakistanHow to Check GPS Location with a Live Tracker in Pakistan
How to Check GPS Location with a Live Tracker in Pakistan
 
Introduction to FIDO Authentication and Passkeys.pptx
Introduction to FIDO Authentication and Passkeys.pptxIntroduction to FIDO Authentication and Passkeys.pptx
Introduction to FIDO Authentication and Passkeys.pptx
 
Vector Search @ sw2con for slideshare.pptx
Vector Search @ sw2con for slideshare.pptxVector Search @ sw2con for slideshare.pptx
Vector Search @ sw2con for slideshare.pptx
 
الأمن السيبراني - ما لا يسع للمستخدم جهله
الأمن السيبراني - ما لا يسع للمستخدم جهلهالأمن السيبراني - ما لا يسع للمستخدم جهله
الأمن السيبراني - ما لا يسع للمستخدم جهله
 
Hyatt driving innovation and exceptional customer experiences with FIDO passw...
Hyatt driving innovation and exceptional customer experiences with FIDO passw...Hyatt driving innovation and exceptional customer experiences with FIDO passw...
Hyatt driving innovation and exceptional customer experiences with FIDO passw...
 
WebRTC and SIP not just audio and video @ OpenSIPS 2024
WebRTC and SIP not just audio and video @ OpenSIPS 2024WebRTC and SIP not just audio and video @ OpenSIPS 2024
WebRTC and SIP not just audio and video @ OpenSIPS 2024
 
TrustArc Webinar - Unified Trust Center for Privacy, Security, Compliance, an...
TrustArc Webinar - Unified Trust Center for Privacy, Security, Compliance, an...TrustArc Webinar - Unified Trust Center for Privacy, Security, Compliance, an...
TrustArc Webinar - Unified Trust Center for Privacy, Security, Compliance, an...
 
2024 May Patch Tuesday
2024 May Patch Tuesday2024 May Patch Tuesday
2024 May Patch Tuesday
 
Event-Driven Architecture Masterclass: Integrating Distributed Data Stores Ac...
Event-Driven Architecture Masterclass: Integrating Distributed Data Stores Ac...Event-Driven Architecture Masterclass: Integrating Distributed Data Stores Ac...
Event-Driven Architecture Masterclass: Integrating Distributed Data Stores Ac...
 
Microsoft CSP Briefing Pre-Engagement - Questionnaire
Microsoft CSP Briefing Pre-Engagement - QuestionnaireMicrosoft CSP Briefing Pre-Engagement - Questionnaire
Microsoft CSP Briefing Pre-Engagement - Questionnaire
 
UiPath manufacturing technology benefits and AI overview
UiPath manufacturing technology benefits and AI overviewUiPath manufacturing technology benefits and AI overview
UiPath manufacturing technology benefits and AI overview
 
AI mind or machine power point presentation
AI mind or machine power point presentationAI mind or machine power point presentation
AI mind or machine power point presentation
 
CORS (Kitworks Team Study 양다윗 발표자료 240510)
CORS (Kitworks Team Study 양다윗 발표자료 240510)CORS (Kitworks Team Study 양다윗 발표자료 240510)
CORS (Kitworks Team Study 양다윗 발표자료 240510)
 
The Zero-ETL Approach: Enhancing Data Agility and Insight
The Zero-ETL Approach: Enhancing Data Agility and InsightThe Zero-ETL Approach: Enhancing Data Agility and Insight
The Zero-ETL Approach: Enhancing Data Agility and Insight
 
Simplifying Mobile A11y Presentation.pptx
Simplifying Mobile A11y Presentation.pptxSimplifying Mobile A11y Presentation.pptx
Simplifying Mobile A11y Presentation.pptx
 
Event-Driven Architecture Masterclass: Engineering a Robust, High-performance...
Event-Driven Architecture Masterclass: Engineering a Robust, High-performance...Event-Driven Architecture Masterclass: Engineering a Robust, High-performance...
Event-Driven Architecture Masterclass: Engineering a Robust, High-performance...
 
Frisco Automating Purchase Orders with MuleSoft IDP- May 10th, 2024.pptx.pdf
Frisco Automating Purchase Orders with MuleSoft IDP- May 10th, 2024.pptx.pdfFrisco Automating Purchase Orders with MuleSoft IDP- May 10th, 2024.pptx.pdf
Frisco Automating Purchase Orders with MuleSoft IDP- May 10th, 2024.pptx.pdf
 
Continuing Bonds Through AI: A Hermeneutic Reflection on Thanabots
Continuing Bonds Through AI: A Hermeneutic Reflection on ThanabotsContinuing Bonds Through AI: A Hermeneutic Reflection on Thanabots
Continuing Bonds Through AI: A Hermeneutic Reflection on Thanabots
 
How we scaled to 80K users by doing nothing!.pdf
How we scaled to 80K users by doing nothing!.pdfHow we scaled to 80K users by doing nothing!.pdf
How we scaled to 80K users by doing nothing!.pdf
 
Six Myths about Ontologies: The Basics of Formal Ontology
Six Myths about Ontologies: The Basics of Formal OntologySix Myths about Ontologies: The Basics of Formal Ontology
Six Myths about Ontologies: The Basics of Formal Ontology
 

Azure AD Options

  • 1. Azure AD & MDM Options
  • 2. Design Decisions • Azure AD Authorization options: Hash Sync Vs Pass Through • Azure AD: Register Vs Join • Azure AD MFA: Authenticator Vs YubiKey Vs Hello
  • 4. AD Federated Authentication On-Prem AD Authentication sent to Federation Server Internet Perimeter Azure AD On-premises Federation Proxy On-Prem Federation Server
  • 5. Cloud Authentication vs Federation (ADFS) Cloud Federation Authentication Location In Cloud On-Prem Server Requirements None Two or more AD FS servers & WAP servers (in the perimeter/DMZ network) Network Requirements None(PHS)/ Outbound Internet Access(PTA) Inbound Internet Access & Network load balancing Advantages -Cost effective & Easiest deployment -Can login even if AD is down -High availability & Disaster recovery -Use Azure AD Identity Protection - More Intune feature sets -Authentication happens on-Prem -Immediate Account Lockout -Use ADFS Claim Rules -Azure AD Premium not required -Custom MFA provider
  • 6. AD Password Hash Sync ADConnect On-premAD Password Hash Sync Password validated against Azure Hash* Internet Intranet Azure AD *MD4+salt+PBKDF2+HMAC-SHA256
  • 7. AD Pass Through Authentication ADConnect On-premAD Credentials sent to On-Prem agent Internet Intranet AuthN Agent Azure AD
  • 8. AAD Password Hash Sync Vs Pass Through Auth PHS PTA Password Location Azure AD (hash) On-Prem Account Lockout/Disable Next Cycle (disable) Immediate Azure AD Identity Protection Yes (Require Azure AD Premium P2 licenses) Advantages -Cost effective & Easiest deployment -Can login even if AD is down -Authentication happens on-Prem -Works with Azure Conditional access
  • 9. Azure AD: Register vs Join Registering a device to Azure AD enables you to manage a device’s identity. When combined with a mobile device management(MDM) solution such as Intune, allows you to create conditional access rules that enforce access from devices to meet your standards for security and compliance Joining a device is an extension to registering a device; Provides all benefits of registration in addition to changing the local state of a device. This enables your users to sign-in to a device using an organizational work or school account
  • 10. Azure AD: Register vs Join Register Join Hybrid Device Ownership Personal (BYOD) Firm Issued Firm Issued Device Type Win10 Devices Win8.1-10, Android, IOS (For devices that are not joined to an on- premises AD) Win7-10 PC’s (For devices that are joined to an on- premises AD) Registration/ Management • To manually register devices with Azure AD • MDM (Intune) • To manually register devices with Azure AD • To change the local state of a device • MDM (Intune) • To automatically register devices with Azure AD • To change the local state of a device • SCCM + GP Additional Functionality • Cloud + SSO • Conditional access using Intune • AD Connect + Device writeback • Windows Hello • Cloud + SSO • Conditional access using Intune • AD Connect + Device writeback • Windows Hello • Enterprise State Roaming • SSO • Access Win32 apps that rely on AD auth.
  • 11. MFA Deployment: Decision Matrix Planning Considerations Decision Points Azure MFA verification options Authenticator, Call, SMS Network definition* Named locations or trusted IPs Azure conditional access policies* Cloud Apps, Users/Groups, Access Controls Azure MFA registration policy MFA for Everyone Or Limited to Admin Groups Remember MFA Yes/No (No of Days) Azure MFA rollout for users Pilot Deployment, Full Scale Rollout On-premises integration with Azure MFA Use with Legacy Apps, On-prem AD FS/Radius Apps?
  • 12. Azure AD: 2FA Options Windows Hello Microsoft Authenticator FIDO2 Security Keys

Editor's Notes

  1. https://samcogan.com/azure-active-directory-is-not-active-directory/
  2. https://samcogan.com/azure-active-directory-is-not-active-directory/ https://docs.microsoft.com/en-us/azure/active-directory/fundamentals/active-directory-whatis
  3. https://docs.microsoft.com/en-us/azure/active-directory/hybrid/how-to-connect-pta-how-it-works https://docs.microsoft.com/en-us/azure/active-directory/hybrid/how-to-connect-pta
  4. Azure AD Identity Protection require Azure AD Premium P2 licenses.
  5. https://docs.microsoft.com/en-us/azure/active-directory/hybrid/how-to-connect-password-hash-synchronization https://docs.microsoft.com/en-us/azure/active-directory/hybrid/whatis-phs
  6. https://docs.microsoft.com/en-us/azure/active-directory/hybrid/how-to-connect-pta-how-it-works https://docs.microsoft.com/en-us/azure/active-directory/hybrid/how-to-connect-pta
  7. Azure AD Identity Protection require Azure AD Premium P2 licenses.
  8. https://docs.microsoft.com/en-us/azure/active-directory/devices/overview
  9. https://docs.microsoft.com/en-us/azure/active-directory/devices/overview#summary
  10. Trusted IPs under Azure MFA Service Configuration need only be configured when you are not using Azure Conditional Access Policies Trusted IP ranges need only be defined when the Azure Active Directory tenant is managed (i.e. not federated with Active Directory Federation Services) Multi-Factor Authentication
  11. https://blogs.technet.microsoft.com/microscott/managing-windows-10-with-intune-the-many-ways-to-enrol/
  12. https://blogs.technet.microsoft.com/microscott/managing-windows-10-with-intune-the-many-ways-to-enrol/