Automating Business Process via MuleSoft Composer | Bangalore MuleSoft Meetup...
GWAVACon 2015: MVP - Benutzerverzeichnisstandardisierung, so wird's gemacht!
1.
2.
3.
4.
5. Windows Server 2012+ &
Azure AD
Windows Server 2012+ &
Azure AD / Azure Services
On-Premises Outsourcing Hybrid Cloud
On-Premises Outsourcing Hybrid Cloud
24. Azure AD Connect
Consolidated deployment
assistant for your identity
bridge components
• Express Settings
• Multi-forest support
• Password # Sync
• Streamlined fed setup with ADFS
• Configurable Sync settings
DirSync
Azure AD Sync
FIM+Azure AD
Connector
Sync Engine
On-boarding to Azure AD & Office 365
ADFS
http://blogs.technet.com/b/ad/archive/2014/12/15/azure-ad-connect-one-simple-fast-lightweight-tool-to-connect-active-directory-and-azure-active-directory.aspx
ADFS
ADFS is optional, can addresses complex
enterprise deployments
Domain Join SSO, Enforcement of AD login policy,
Smart Card or 3rd party MFA
25. Enable login to Azure AD/Office 365 or
other ADFS apps for users stored in
LDAP directories
Consolidate app authentication and
authorization across different account
stores
Supports any LDAP v3 directory
Support across sync and sign-in
coming to Azure AD Connect at a later
date
ADFS
ADDSLDAP
Directories
Azure AD
LOB Apps
Cloud
SaaS
Azure
Office 365
Partner
Resources
27. • Monitor ADFS service for reliable
& highly available authentication
• Email notification for critical
alerts
• Analyze ADFS logins for usage &
capacity planning based on app,
authentication, network location
& failures
• Perform forensic analysis on top
users with bad passwords
• Troubleshoot with easy access to
critical performance counters
28.
29. On-Premises
applications
Introducing ‘Conditional Access Control’
Application
Business sensitivity
Other
Inside corp. network
Outside corp. network
Risk profile
Devices
Authenticated
MDM Managed (Intune)
Compliant with policies
Not lost/stolen
User attributes
User identity
Group memberships
Auth strength (MFA)
Conditional access
control
30. Discover & Authenticate
Device Registration with the Azure AD Device Registration Service
user @ device
Contoso
dan@contoso.com
Contoso
dan@contoso.com