SlideShare a Scribd company logo
1 of 36
Download to read offline
MANAGEABILITY
Taking Conditional Access
to the next level
Peter van der Woude & Ronny de Jong
MANAGEABILITY
MANAGEABILITY
Session objectives and
takeaways
Overview of conditional access for devices and mobile apps accessing O365
Overview of conditional access to on-prem Exchange and SharePoint
Sneak-peak into upcoming features
MANAGEABILITY
Conditional Access
On-Premises
applications
Application
Per-service
Managed client app
Other
Location (IP range)
Risk profile
Devices
Is domain joined
Is compliant
Platform type
Not lost/stolen
User attributes
User identity
Group memberships
Allow
Block
MFA
Enroll
MANAGEABILITY
Functionality…
• CA for mobile devices;
• CA for domain joined PC’s;
• CA for mobile apps w/o MDM;
• CA for on-prem resources
• CA for advanced scenario’s (ADFS);
MANAGEABILITY
…by solution
• via Configuration Manager;
• via Microsoft Intune;
• via Microsoft Intune MAM w/o MDM;
• via Azure AD (SaaS);
• via ADFS (Advanced scenario’s);
MANAGEABILITY
MANAGEABILITY
MANAGEABILITY
MANAGEABILITY
MANAGEABILITY
MANAGEABILITY
MANAGEABILITYMANAGEABILITY
Conditional Access for
mobile devices
MANAGEABILITY
Deploying conditional access
1.
• Define compliance criteria for devices managed by Intune or SCCM
2.
• Define access criteria for a specific O365 service
Conditions Main options Defined where?
Compliance criteria for managed devices Password, Encryption, Device
Health, OS versions
Intune compliance policy
SCCM compliance policy
Mobile platforms iOS, Android, Windows 10 Mobile
Conditional access policies
Desktop platforms Windows 7, 8.1, 10
Client app types Exchange ActiveSync clients, Rich
client apps, Browser
O365 services Exchange Online, SharePoint
Online, Skype for Business,
Dynamics CRM
Users All users in tenant, targeted SGs,
exempted SGs
MANAGEABILITY
Unified Enrollment
Azure AD
Device object
- device id
- isManage
d
- MDMStatu
s
Quarantine Website
Step 1: Enroll
device
Outlook App
Access control from Outlook for iOS and Android
4
Register device in
Azure AD
Outlook
Cloud
Service
1
(Workplace Join +
management)
3
Enroll into Intune
4
Intune
Set device
management/
compliance
status5
6Access Outlook
Cloud service
with
AAD token 7
8
Get EAS service
access token for
user
9Get Corporate
email
1
0
Email delivered
Redirect to
Intune
2
Office 365
Email service
MANAGEABILITY
Preparing devices: mobile
Azure AD Join for work-owned mobile devices in Windows 10
Add work or school account for personal devices in Windows 10
Add account, Workplace join in other Windows versions or platforms (iOS, Android)
Windows 10 with Microsoft Intune or 3rd party supported MDMs
Requires MDM app configuration in Azure AD for Windows 10
iOS and Android with Microsoft Intune
MANAGEABILITYMANAGEABILITY
Conditional Access for
domain joined PCs
MANAGEABILITYConditional Access for PCs
1.
2.
3.
4.
Management Windows 7 Windows 8.1 Windows 10
AD domain joined* Supported Supported Supported
AD domain joined*
+ SCCM Managed
Supported Supported Supported
AAD registered +
Intune managed
Not supported Supported Supported
Azure Domain
Joined + Intune
managed
Not supported Not supported Supported
MANAGEABILITY
Pre-requisites for CA with Office Desktop on
Domain Joined Windows PCs
Office 2016 or Office 2013 with Modern Authentication
enabled
AAD auto-registration
■ GP or SCCM can be used to enable auto-registration
■ Windows 7 requires an MSI to be deployed
ADFS claims rules to block down-level Office from
external network locations
■ In near future, EXO and SPO will expose PS cmdlets to disable non-modern authentication
MANAGEABILITYMANAGEABILITY
Condition Access for mobile
apps w/o MDM
MANAGEABILITY
Mobile app management
MANAGED MOBILE PRODUCTIVITY
Managed
apps
Personal
apps
Personal apps
Managed apps
Corporate
data
Personal
data
Multi-identity policy
Personal apps
Managed
apps
Copy Paste Save
Save to
personal storage
Paste to
personal
app
Email
attachment
MANAGEABILITY
Customer Scenario
■Ensure that only Intune MAM enabled
applications can access O365/SaaS apps
■Prevent apps that aren’t MAM “enlightened”
■Prevent EAS mail clients (native iOS/Android mail
clients)
Considerations
■Intune MAM enabled apps are put on an
Conditional Access for
managed mobile apps
MANAGEABILITY
Preparing devices: domain
joinedService Connection Point for discovery (all Windows versions!)
If federated, issuance transform rules for computer authentication upon registration
Windows Installer package for non-Windows 10/Windows Server 2016 computers
Windows 7, 8.0, 8.1, Server 2008 R2, Server 2012 and Server 2012
R2
Windows 10 Anniversary Update/Windows Server 2016 registers without policy set
Windows 10 November 2015 Update requires the policy set to trigger registration
Windows 8.1 responds to policy, can also use Windows Installer package
Help with requirements setup – with caveats!
Key for lifecycle management of computers and devices
MANAGEABILITYMANAGEABILITY
Condition Access for on-
prem resources
MANAGEABILITY
Conditional Access for
Exchange on-premises•
• Exchange 2010 or later
•
•
MANAGEABILITY
On-Prem Exchange CA
Architecture
EAS Client
Attempt email
connection
1
Block
If not managed,
block device
3
On Prem
Exchange Server
2010/2013
Who does what?
Intune: Evaluate policy,
manage device state and
mark device record in AAD
Exchange Server:
Provides API and
infrastructure for
quarantine
1
0
If managed,
email access is
granted
Unified Enrollment
Register EAS
email client
7
Create EASID to
device ID binding
8
Set device management/ compliance status
6
Azure AD DRS
Device
object
- device id
- isManage
d
- MDMStatu
s
- EASIDsAzure AD
Quarantine email
Step 1: Enroll
device
Step 2: Register
EAS client
(Workplace Join +
management)
4
Intune
5
Register device in
Azure AD
5 Enroll into Intune
2
Block non Managed
devices
9
Allow Managed device
MANAGEABILITY
Azure Web App Proxy
•
•
•
MANAGEABILITY
Preparing devices for device-
based CA policyAutomatically register with Azure AD once requirements are set
Device is not associated with a user in Windows 10
Azure AD Connect for registration and lifecycle management of computers and devices
Windows Installer package for non-Windows 10/non-Windows Server 2016 computers
Device registers by an end-user initiated experience
Device is associated with user
Experience registers device with Azure AD and enrolls it with MDM
Alternative for personal devices is to use Mobile Application Management (MAM)
MANAGEABILITYMANAGEABILITY
Conditional Access for
advanced scenario’s (ADFS)
MANAGEABILITY
On-premises applications and
access controlYou can publish on-prem apps through Azure AD
They show in the ‘applications’ tab in the management portal and the ‘myapps’ portal for the user
You can set Device-based CA policy to control access the same way as O365 apps and SaaS apps
Don’t miss: EMS320: Using Azure AD to enable and manage access to on-premises applications
Require device write-back in Azure AD Connect
AD FS in Windows Server 2016 required for Windows 10 authentication
MANAGEABILITYMANAGEABILITY
FAQ
MANAGEABILITYFAQs
•
• No, CA will trump ABQ
•
1. Turn CA off for EAS with Basic Auth; but on for Android and iOS modern auth
apps
2. Configure ADFS to block EAS
3. Exchange ActiveSync ABQ to only allow the Outlook app
•
• We’re working on it.
• For now the main options are:
• Allow all Macs
• Block all Macs
• Exempt Mac users
MANAGEABILITYFAQs cont’d
•
• Recommended for reporting, but not required
•
• ADFS
• OWA app will soon leave the app stores
•
• Azure AD admin console will include Device CA polices (public preview soon)
• Both write to the same back-end AAD policy
• Azure AD console also includes MFA and network based policy
• Plan to consolidate in the new Azure admin console (aka Ibiza)
MANAGEABILITY
14:45 – 15:45
Ten most common mistakes
when deploying ADFS & Hybrid
Identity and how to avoid them
Raymond Comvalius & Sander Berkouwer
MANAGEABILITY
MANAGEABILITY
<Titel>
<Tekst>

More Related Content

What's hot

(ENT305) Develop an Enterprise-wide Cloud Adoption Strategy | AWS re:Invent 2014
(ENT305) Develop an Enterprise-wide Cloud Adoption Strategy | AWS re:Invent 2014(ENT305) Develop an Enterprise-wide Cloud Adoption Strategy | AWS re:Invent 2014
(ENT305) Develop an Enterprise-wide Cloud Adoption Strategy | AWS re:Invent 2014Amazon Web Services
 
Cloud Security Architecture.pptx
Cloud Security Architecture.pptxCloud Security Architecture.pptx
Cloud Security Architecture.pptxMoshe Ferber
 
CAF presentation 09 16-2020
CAF presentation 09 16-2020CAF presentation 09 16-2020
CAF presentation 09 16-2020Michael Nichols
 
Introduction to Azure monitor
Introduction to Azure monitorIntroduction to Azure monitor
Introduction to Azure monitorPraveen Nair
 
(DVO315) Log, Monitor and Analyze your IT with Amazon CloudWatch
(DVO315) Log, Monitor and Analyze your IT with Amazon CloudWatch(DVO315) Log, Monitor and Analyze your IT with Amazon CloudWatch
(DVO315) Log, Monitor and Analyze your IT with Amazon CloudWatchAmazon Web Services
 
Azure Security and Management
Azure Security and ManagementAzure Security and Management
Azure Security and ManagementAllen Brokken
 
Launch AWS Faster using Automated Landing Zones - AWS Online Tech Talks
Launch AWS Faster using Automated Landing Zones - AWS Online Tech TalksLaunch AWS Faster using Automated Landing Zones - AWS Online Tech Talks
Launch AWS Faster using Automated Landing Zones - AWS Online Tech TalksAmazon Web Services
 
Azure Cloud Governance
Azure Cloud GovernanceAzure Cloud Governance
Azure Cloud GovernanceJonathan Wade
 
Azure key vault
Azure key vaultAzure key vault
Azure key vaultRahul Nath
 
Architecting for Success: Designing Secure GCP Landing Zone for Enterprises
Architecting for Success: Designing Secure GCP Landing Zone for EnterprisesArchitecting for Success: Designing Secure GCP Landing Zone for Enterprises
Architecting for Success: Designing Secure GCP Landing Zone for EnterprisesBhuvaneswari Subramani
 
Introduction To Cloud Computing
Introduction To Cloud ComputingIntroduction To Cloud Computing
Introduction To Cloud Computingkevnikool
 
AWS Control Tower
AWS Control TowerAWS Control Tower
AWS Control TowerCloudHesive
 
Introduction to Azure
Introduction to AzureIntroduction to Azure
Introduction to AzureRobert Crane
 

What's hot (20)

(ENT305) Develop an Enterprise-wide Cloud Adoption Strategy | AWS re:Invent 2014
(ENT305) Develop an Enterprise-wide Cloud Adoption Strategy | AWS re:Invent 2014(ENT305) Develop an Enterprise-wide Cloud Adoption Strategy | AWS re:Invent 2014
(ENT305) Develop an Enterprise-wide Cloud Adoption Strategy | AWS re:Invent 2014
 
Cloud Security Architecture.pptx
Cloud Security Architecture.pptxCloud Security Architecture.pptx
Cloud Security Architecture.pptx
 
CAF presentation 09 16-2020
CAF presentation 09 16-2020CAF presentation 09 16-2020
CAF presentation 09 16-2020
 
Introduction to Azure monitor
Introduction to Azure monitorIntroduction to Azure monitor
Introduction to Azure monitor
 
Security & Compliance in AWS
Security & Compliance in AWSSecurity & Compliance in AWS
Security & Compliance in AWS
 
(DVO315) Log, Monitor and Analyze your IT with Amazon CloudWatch
(DVO315) Log, Monitor and Analyze your IT with Amazon CloudWatch(DVO315) Log, Monitor and Analyze your IT with Amazon CloudWatch
(DVO315) Log, Monitor and Analyze your IT with Amazon CloudWatch
 
Azure Security and Management
Azure Security and ManagementAzure Security and Management
Azure Security and Management
 
Launch AWS Faster using Automated Landing Zones - AWS Online Tech Talks
Launch AWS Faster using Automated Landing Zones - AWS Online Tech TalksLaunch AWS Faster using Automated Landing Zones - AWS Online Tech Talks
Launch AWS Faster using Automated Landing Zones - AWS Online Tech Talks
 
Azure Cloud Governance
Azure Cloud GovernanceAzure Cloud Governance
Azure Cloud Governance
 
Cloud Security (AWS)
Cloud Security (AWS)Cloud Security (AWS)
Cloud Security (AWS)
 
AWS Security Fundamentals
AWS Security FundamentalsAWS Security Fundamentals
AWS Security Fundamentals
 
Cloud Security Fundamentals Webinar
Cloud Security Fundamentals WebinarCloud Security Fundamentals Webinar
Cloud Security Fundamentals Webinar
 
AWS Cloud Adoption Framework
AWS Cloud Adoption Framework AWS Cloud Adoption Framework
AWS Cloud Adoption Framework
 
Azure key vault
Azure key vaultAzure key vault
Azure key vault
 
Architecting for Success: Designing Secure GCP Landing Zone for Enterprises
Architecting for Success: Designing Secure GCP Landing Zone for EnterprisesArchitecting for Success: Designing Secure GCP Landing Zone for Enterprises
Architecting for Success: Designing Secure GCP Landing Zone for Enterprises
 
Security Architectures on AWS
Security Architectures on AWSSecurity Architectures on AWS
Security Architectures on AWS
 
Introduction To Cloud Computing
Introduction To Cloud ComputingIntroduction To Cloud Computing
Introduction To Cloud Computing
 
AWS Control Tower
AWS Control TowerAWS Control Tower
AWS Control Tower
 
AWS Architecting In The Cloud
AWS Architecting In The CloudAWS Architecting In The Cloud
AWS Architecting In The Cloud
 
Introduction to Azure
Introduction to AzureIntroduction to Azure
Introduction to Azure
 

Viewers also liked (14)

logo-foleez
logo-foleezlogo-foleez
logo-foleez
 
van Oord
van Oordvan Oord
van Oord
 
Identify Your Buyer & What THEY Value
Identify Your Buyer & What THEY ValueIdentify Your Buyer & What THEY Value
Identify Your Buyer & What THEY Value
 
Chemistry homework help
Chemistry homework helpChemistry homework help
Chemistry homework help
 
Partes de la planta.docx blnca
Partes de la planta.docx  blncaPartes de la planta.docx  blnca
Partes de la planta.docx blnca
 
08 CX Day Suomen paras asiakasteko - CXPA Finland - Sirte Pihlaja
08 CX Day Suomen paras asiakasteko - CXPA Finland - Sirte Pihlaja08 CX Day Suomen paras asiakasteko - CXPA Finland - Sirte Pihlaja
08 CX Day Suomen paras asiakasteko - CXPA Finland - Sirte Pihlaja
 
Law homework help
Law homework helpLaw homework help
Law homework help
 
Entrada fecha, calculo edad..
Entrada fecha, calculo edad..Entrada fecha, calculo edad..
Entrada fecha, calculo edad..
 
AIDA ICITET
AIDA ICITETAIDA ICITET
AIDA ICITET
 
Artificer Certificate
Artificer CertificateArtificer Certificate
Artificer Certificate
 
CV Lupita Montemayor
CV Lupita MontemayorCV Lupita Montemayor
CV Lupita Montemayor
 
Yograj tiwari121
Yograj tiwari121Yograj tiwari121
Yograj tiwari121
 
Telo cheloveka
Telo chelovekaTelo cheloveka
Telo cheloveka
 
DIPLOMA GEOMETRA.gif
DIPLOMA GEOMETRA.gifDIPLOMA GEOMETRA.gif
DIPLOMA GEOMETRA.gif
 

Similar to Taking conditional access to the next level

Cloud Security Fundamentals - St. Louis O365 Users Group
Cloud Security Fundamentals - St. Louis O365 Users GroupCloud Security Fundamentals - St. Louis O365 Users Group
Cloud Security Fundamentals - St. Louis O365 Users GroupJ.D. Wade
 
#EVRYWhatsNext EMS Slide Deck
#EVRYWhatsNext EMS Slide Deck#EVRYWhatsNext EMS Slide Deck
#EVRYWhatsNext EMS Slide DeckOlav Tvedt
 
Modern Management for Identiteter og Enheter – Azure AD, Intune og Windows 10
Modern Management for Identiteter og Enheter – Azure AD, Intune og Windows 10Modern Management for Identiteter og Enheter – Azure AD, Intune og Windows 10
Modern Management for Identiteter og Enheter – Azure AD, Intune og Windows 10MVP Dagen
 
Atea ems the next level
Atea   ems the next levelAtea   ems the next level
Atea ems the next levelPer Larsen
 
Empower Enterprise Mobility with Microsoft EMS
Empower Enterprise Mobility with Microsoft EMSEmpower Enterprise Mobility with Microsoft EMS
Empower Enterprise Mobility with Microsoft EMSKris Wagner
 
Ewug.dk notes from the trenches
Ewug.dk  notes from the trenchesEwug.dk  notes from the trenches
Ewug.dk notes from the trenchesPer Larsen
 
System Center 2012 R2 Configuration Manager (SCCM) with Windows Intune
System Center 2012 R2 Configuration Manager (SCCM) with Windows IntuneSystem Center 2012 R2 Configuration Manager (SCCM) with Windows Intune
System Center 2012 R2 Configuration Manager (SCCM) with Windows IntuneAmit Gatenyo
 
Wally Mead - Managing mobile devices with system center 2012 r2 configuration...
Wally Mead - Managing mobile devices with system center 2012 r2 configuration...Wally Mead - Managing mobile devices with system center 2012 r2 configuration...
Wally Mead - Managing mobile devices with system center 2012 r2 configuration...Nordic Infrastructure Conference
 
Wally Mead - Deploying a system center 2012 r2 configuration manager environm...
Wally Mead - Deploying a system center 2012 r2 configuration manager environm...Wally Mead - Deploying a system center 2012 r2 configuration manager environm...
Wally Mead - Deploying a system center 2012 r2 configuration manager environm...Nordic Infrastructure Conference
 
Premier Webcast - Identity Management with Windows Azure AD
Premier Webcast - Identity Management with Windows Azure ADPremier Webcast - Identity Management with Windows Azure AD
Premier Webcast - Identity Management with Windows Azure ADuberbaum
 
ECMDay2015 - Peter Daalmans – Master your Mac OS X Operating System with Conf...
ECMDay2015 - Peter Daalmans – Master your Mac OS X Operating System with Conf...ECMDay2015 - Peter Daalmans – Master your Mac OS X Operating System with Conf...
ECMDay2015 - Peter Daalmans – Master your Mac OS X Operating System with Conf...Kenny Buntinx
 
Llunitebe2018 ten practical tips to secure your corporate data with microsoft...
Llunitebe2018 ten practical tips to secure your corporate data with microsoft...Llunitebe2018 ten practical tips to secure your corporate data with microsoft...
Llunitebe2018 ten practical tips to secure your corporate data with microsoft...Kenny Buntinx
 
Experts Live Europe 2017 - Windows 10 and the cloud - why the future needs hy...
Experts Live Europe 2017 - Windows 10 and the cloud - why the future needs hy...Experts Live Europe 2017 - Windows 10 and the cloud - why the future needs hy...
Experts Live Europe 2017 - Windows 10 and the cloud - why the future needs hy...Alexander Benoit
 
Atea ems roadshow - windows 10 management i en cloud first world
Atea   ems roadshow - windows 10 management i en cloud first worldAtea   ems roadshow - windows 10 management i en cloud first world
Atea ems roadshow - windows 10 management i en cloud first worldPer Larsen
 
Windows Server 2012 R2 Jump Start - AIP
Windows Server 2012 R2 Jump Start - AIPWindows Server 2012 R2 Jump Start - AIP
Windows Server 2012 R2 Jump Start - AIPPaulo Freitas
 
Microsoft Intune y Gestión de Identidad Corporativa
Microsoft Intune y Gestión de Identidad Corporativa Microsoft Intune y Gestión de Identidad Corporativa
Microsoft Intune y Gestión de Identidad Corporativa Plain Concepts
 
Next Level Learning IT Track - Windows 10
Next Level Learning IT Track - Windows 10Next Level Learning IT Track - Windows 10
Next Level Learning IT Track - Windows 10Microsoft Education AU
 
Building mobile back ends with windows azure mobile services
Building mobile back ends with windows azure mobile servicesBuilding mobile back ends with windows azure mobile services
Building mobile back ends with windows azure mobile servicesAidan Casey
 

Similar to Taking conditional access to the next level (20)

Cloud Security Fundamentals - St. Louis O365 Users Group
Cloud Security Fundamentals - St. Louis O365 Users GroupCloud Security Fundamentals - St. Louis O365 Users Group
Cloud Security Fundamentals - St. Louis O365 Users Group
 
#EVRYWhatsNext EMS Slide Deck
#EVRYWhatsNext EMS Slide Deck#EVRYWhatsNext EMS Slide Deck
#EVRYWhatsNext EMS Slide Deck
 
Modern Management for Identiteter og Enheter – Azure AD, Intune og Windows 10
Modern Management for Identiteter og Enheter – Azure AD, Intune og Windows 10Modern Management for Identiteter og Enheter – Azure AD, Intune og Windows 10
Modern Management for Identiteter og Enheter – Azure AD, Intune og Windows 10
 
Atea ems the next level
Atea   ems the next levelAtea   ems the next level
Atea ems the next level
 
Empower Enterprise Mobility with Microsoft EMS
Empower Enterprise Mobility with Microsoft EMSEmpower Enterprise Mobility with Microsoft EMS
Empower Enterprise Mobility with Microsoft EMS
 
Ewug.dk notes from the trenches
Ewug.dk  notes from the trenchesEwug.dk  notes from the trenches
Ewug.dk notes from the trenches
 
System Center 2012 R2 Configuration Manager (SCCM) with Windows Intune
System Center 2012 R2 Configuration Manager (SCCM) with Windows IntuneSystem Center 2012 R2 Configuration Manager (SCCM) with Windows Intune
System Center 2012 R2 Configuration Manager (SCCM) with Windows Intune
 
Wally Mead - Managing mobile devices with system center 2012 r2 configuration...
Wally Mead - Managing mobile devices with system center 2012 r2 configuration...Wally Mead - Managing mobile devices with system center 2012 r2 configuration...
Wally Mead - Managing mobile devices with system center 2012 r2 configuration...
 
Wally Mead - Deploying a system center 2012 r2 configuration manager environm...
Wally Mead - Deploying a system center 2012 r2 configuration manager environm...Wally Mead - Deploying a system center 2012 r2 configuration manager environm...
Wally Mead - Deploying a system center 2012 r2 configuration manager environm...
 
Premier Webcast - Identity Management with Windows Azure AD
Premier Webcast - Identity Management with Windows Azure ADPremier Webcast - Identity Management with Windows Azure AD
Premier Webcast - Identity Management with Windows Azure AD
 
Windows 10: all you need to know!
Windows 10: all you need to know!Windows 10: all you need to know!
Windows 10: all you need to know!
 
ECMDay2015 - Peter Daalmans – Master your Mac OS X Operating System with Conf...
ECMDay2015 - Peter Daalmans – Master your Mac OS X Operating System with Conf...ECMDay2015 - Peter Daalmans – Master your Mac OS X Operating System with Conf...
ECMDay2015 - Peter Daalmans – Master your Mac OS X Operating System with Conf...
 
Llunitebe2018 ten practical tips to secure your corporate data with microsoft...
Llunitebe2018 ten practical tips to secure your corporate data with microsoft...Llunitebe2018 ten practical tips to secure your corporate data with microsoft...
Llunitebe2018 ten practical tips to secure your corporate data with microsoft...
 
Experts Live Europe 2017 - Windows 10 and the cloud - why the future needs hy...
Experts Live Europe 2017 - Windows 10 and the cloud - why the future needs hy...Experts Live Europe 2017 - Windows 10 and the cloud - why the future needs hy...
Experts Live Europe 2017 - Windows 10 and the cloud - why the future needs hy...
 
Atea ems roadshow - windows 10 management i en cloud first world
Atea   ems roadshow - windows 10 management i en cloud first worldAtea   ems roadshow - windows 10 management i en cloud first world
Atea ems roadshow - windows 10 management i en cloud first world
 
Resume 4
Resume 4Resume 4
Resume 4
 
Windows Server 2012 R2 Jump Start - AIP
Windows Server 2012 R2 Jump Start - AIPWindows Server 2012 R2 Jump Start - AIP
Windows Server 2012 R2 Jump Start - AIP
 
Microsoft Intune y Gestión de Identidad Corporativa
Microsoft Intune y Gestión de Identidad Corporativa Microsoft Intune y Gestión de Identidad Corporativa
Microsoft Intune y Gestión de Identidad Corporativa
 
Next Level Learning IT Track - Windows 10
Next Level Learning IT Track - Windows 10Next Level Learning IT Track - Windows 10
Next Level Learning IT Track - Windows 10
 
Building mobile back ends with windows azure mobile services
Building mobile back ends with windows azure mobile servicesBuilding mobile back ends with windows azure mobile services
Building mobile back ends with windows azure mobile services
 

Taking conditional access to the next level

  • 1. MANAGEABILITY Taking Conditional Access to the next level Peter van der Woude & Ronny de Jong
  • 3. MANAGEABILITY Session objectives and takeaways Overview of conditional access for devices and mobile apps accessing O365 Overview of conditional access to on-prem Exchange and SharePoint Sneak-peak into upcoming features
  • 4. MANAGEABILITY Conditional Access On-Premises applications Application Per-service Managed client app Other Location (IP range) Risk profile Devices Is domain joined Is compliant Platform type Not lost/stolen User attributes User identity Group memberships Allow Block MFA Enroll
  • 5. MANAGEABILITY Functionality… • CA for mobile devices; • CA for domain joined PC’s; • CA for mobile apps w/o MDM; • CA for on-prem resources • CA for advanced scenario’s (ADFS);
  • 6. MANAGEABILITY …by solution • via Configuration Manager; • via Microsoft Intune; • via Microsoft Intune MAM w/o MDM; • via Azure AD (SaaS); • via ADFS (Advanced scenario’s);
  • 14. MANAGEABILITY Deploying conditional access 1. • Define compliance criteria for devices managed by Intune or SCCM 2. • Define access criteria for a specific O365 service Conditions Main options Defined where? Compliance criteria for managed devices Password, Encryption, Device Health, OS versions Intune compliance policy SCCM compliance policy Mobile platforms iOS, Android, Windows 10 Mobile Conditional access policies Desktop platforms Windows 7, 8.1, 10 Client app types Exchange ActiveSync clients, Rich client apps, Browser O365 services Exchange Online, SharePoint Online, Skype for Business, Dynamics CRM Users All users in tenant, targeted SGs, exempted SGs
  • 15. MANAGEABILITY Unified Enrollment Azure AD Device object - device id - isManage d - MDMStatu s Quarantine Website Step 1: Enroll device Outlook App Access control from Outlook for iOS and Android 4 Register device in Azure AD Outlook Cloud Service 1 (Workplace Join + management) 3 Enroll into Intune 4 Intune Set device management/ compliance status5 6Access Outlook Cloud service with AAD token 7 8 Get EAS service access token for user 9Get Corporate email 1 0 Email delivered Redirect to Intune 2 Office 365 Email service
  • 16. MANAGEABILITY Preparing devices: mobile Azure AD Join for work-owned mobile devices in Windows 10 Add work or school account for personal devices in Windows 10 Add account, Workplace join in other Windows versions or platforms (iOS, Android) Windows 10 with Microsoft Intune or 3rd party supported MDMs Requires MDM app configuration in Azure AD for Windows 10 iOS and Android with Microsoft Intune
  • 18. MANAGEABILITYConditional Access for PCs 1. 2. 3. 4. Management Windows 7 Windows 8.1 Windows 10 AD domain joined* Supported Supported Supported AD domain joined* + SCCM Managed Supported Supported Supported AAD registered + Intune managed Not supported Supported Supported Azure Domain Joined + Intune managed Not supported Not supported Supported
  • 19. MANAGEABILITY Pre-requisites for CA with Office Desktop on Domain Joined Windows PCs Office 2016 or Office 2013 with Modern Authentication enabled AAD auto-registration ■ GP or SCCM can be used to enable auto-registration ■ Windows 7 requires an MSI to be deployed ADFS claims rules to block down-level Office from external network locations ■ In near future, EXO and SPO will expose PS cmdlets to disable non-modern authentication
  • 21. MANAGEABILITY Mobile app management MANAGED MOBILE PRODUCTIVITY Managed apps Personal apps Personal apps Managed apps Corporate data Personal data Multi-identity policy Personal apps Managed apps Copy Paste Save Save to personal storage Paste to personal app Email attachment
  • 22. MANAGEABILITY Customer Scenario ■Ensure that only Intune MAM enabled applications can access O365/SaaS apps ■Prevent apps that aren’t MAM “enlightened” ■Prevent EAS mail clients (native iOS/Android mail clients) Considerations ■Intune MAM enabled apps are put on an Conditional Access for managed mobile apps
  • 23. MANAGEABILITY Preparing devices: domain joinedService Connection Point for discovery (all Windows versions!) If federated, issuance transform rules for computer authentication upon registration Windows Installer package for non-Windows 10/Windows Server 2016 computers Windows 7, 8.0, 8.1, Server 2008 R2, Server 2012 and Server 2012 R2 Windows 10 Anniversary Update/Windows Server 2016 registers without policy set Windows 10 November 2015 Update requires the policy set to trigger registration Windows 8.1 responds to policy, can also use Windows Installer package Help with requirements setup – with caveats! Key for lifecycle management of computers and devices
  • 25. MANAGEABILITY Conditional Access for Exchange on-premises• • Exchange 2010 or later • •
  • 26. MANAGEABILITY On-Prem Exchange CA Architecture EAS Client Attempt email connection 1 Block If not managed, block device 3 On Prem Exchange Server 2010/2013 Who does what? Intune: Evaluate policy, manage device state and mark device record in AAD Exchange Server: Provides API and infrastructure for quarantine 1 0 If managed, email access is granted Unified Enrollment Register EAS email client 7 Create EASID to device ID binding 8 Set device management/ compliance status 6 Azure AD DRS Device object - device id - isManage d - MDMStatu s - EASIDsAzure AD Quarantine email Step 1: Enroll device Step 2: Register EAS client (Workplace Join + management) 4 Intune 5 Register device in Azure AD 5 Enroll into Intune 2 Block non Managed devices 9 Allow Managed device
  • 27. MANAGEABILITY Azure Web App Proxy • • •
  • 28. MANAGEABILITY Preparing devices for device- based CA policyAutomatically register with Azure AD once requirements are set Device is not associated with a user in Windows 10 Azure AD Connect for registration and lifecycle management of computers and devices Windows Installer package for non-Windows 10/non-Windows Server 2016 computers Device registers by an end-user initiated experience Device is associated with user Experience registers device with Azure AD and enrolls it with MDM Alternative for personal devices is to use Mobile Application Management (MAM)
  • 30. MANAGEABILITY On-premises applications and access controlYou can publish on-prem apps through Azure AD They show in the ‘applications’ tab in the management portal and the ‘myapps’ portal for the user You can set Device-based CA policy to control access the same way as O365 apps and SaaS apps Don’t miss: EMS320: Using Azure AD to enable and manage access to on-premises applications Require device write-back in Azure AD Connect AD FS in Windows Server 2016 required for Windows 10 authentication
  • 32. MANAGEABILITYFAQs • • No, CA will trump ABQ • 1. Turn CA off for EAS with Basic Auth; but on for Android and iOS modern auth apps 2. Configure ADFS to block EAS 3. Exchange ActiveSync ABQ to only allow the Outlook app • • We’re working on it. • For now the main options are: • Allow all Macs • Block all Macs • Exempt Mac users
  • 33. MANAGEABILITYFAQs cont’d • • Recommended for reporting, but not required • • ADFS • OWA app will soon leave the app stores • • Azure AD admin console will include Device CA polices (public preview soon) • Both write to the same back-end AAD policy • Azure AD console also includes MFA and network based policy • Plan to consolidate in the new Azure admin console (aka Ibiza)
  • 34. MANAGEABILITY 14:45 – 15:45 Ten most common mistakes when deploying ADFS & Hybrid Identity and how to avoid them Raymond Comvalius & Sander Berkouwer