SlideShare a Scribd company logo
1 of 29
Download to read offline
Vartti tunnista
Azure Active Directory
Mika Seitsonen
Kouluttajanne Mika Seitsonen
• Faktat
• M.Sc., University of Nottingham, U.K.
• DI, Lappeenrannan teknillinen yliopisto
• Co-author of "Inside Active Directory"
• Sovelto
• Senior-konsultti, vt. osaamisaluevastaava:
Teknologia-asiantuntijat
• Microsoft Certified Trainer (MCT) vuodesta
1997, Microsoft Certification ID 414xxx
• MCSE: Communications
• MCSA: Office 365, Windows 2008, Windows 7
• MS: Implementing Microsoft Azure
Infrastructure Solutions
• Yhteystiedot
• e-mail mika.seitsonen@sovelto.fi
• Twitter @MikaSeitsonen
• Moottoriurheil(ija)un innokas seuraaja
• Kuvattuna Päijänteen Ympäriajo:ssa 2009
Identity considerations: Cloud, Sync or Federated?

 

Cloud identity provides a
solution where all identity
resides in the cloud
Federated identity allows
customers to retain all
authentication on-premises
Identity sync enables
customers to bridge their
existing identity into the cloud
B2B federated identity allows
customers to securely share and
collaborate with each other
Self-service Single
sign on
•••••••••••
Username
Identity as the control plane
Simple
connection
Cloud
SaaS
Azure
Office 365Public
cloud
Other
Directories
Windows Server
Active Directory
On-premises Microsoft Azure Active Directory
A comprehensive identity and access
management cloud solution.
It combines directory services,
advanced identity governance,
application access management and
a rich standards-based platform for
developers
It is available in 3 editions: free, Basic
and Premium
What is Azure Active Directory?
No Object Limit No Object Limit
No Limit
Advanced Security
Reports
Yes(Advanced)**
Premium
+ Basic
Features
Group-based access management/provisioning Yes Yes
Self-Service Password Reset for cloud users Yes Yes
Company Branding (Logon Pages/Access Panel customization) Yes Yes
SLA Yes Yes
Kurantti informaatio osoitteessa
https://msdn.microsoft.com/en-us/library/dn532272.aspx
Azure Active Directory Connect*
Microsoft Azure
Active Directory
Other Directories
PowerShell
LDAP v3
SQL (ODBC)
Web Services
( SOAP, JAVA,
REST)
*
Azure Active Directory Connect
Consolidated deployment assistant for your
identity bridge components
Progressive learning while configuring the
components
ADFS is optional
DirSync
Azure Active
Directory Sync
FIM+Azure Active
Directory Connector
Sync Engine
Microsoft Azure
Microsoft Azure
SaaS appsMicrosoft Azure
Active DirectoryOther Directories
Microsoft Azure Active Directory
Identities and applications in one place.
Web Apps
(Azure Active Directory
Application Proxy)
SaaS apps Integrated
custom apps
Other Directories
Microsoft Azure
Active Directory
Corporate
Network
DMZ
https://app1-
contoso.msappproxy.net/
A connector that auto connects to the cloud service
http://app1
IT professional
alerts.
alerts.
How it works
http://myapps.microsoft.com
http://myapps.microsoft.com
Azure Active Directory 12-month investments
Business to
Business Business to
Consumers
Device
Registration
Administrative
Units
Cloud Domain
Joined
(Windows 10)
Conditional
Access
Roles Based Access Control
Today RBAC to Azure
Subscription
Tomorrow RBAC to 3rd Party SASS apps
Reade
r
SasS
SasS
Contributor
SasS
Owne
r
SasS
SasS
SasS
Sas
S
Sas
S
Reade
r
ContributorOwne
r
Assign roles to users and groups
at subscription, resource group, or
resource level
Assignments inherit down the
hierarchy
Use built-in roles with pre-
configured permissions (at
preview)
Create custom roles (post
preview)
B2B: cross-organization collaboration
“I need to let my partners access my company’s apps using their own credentials.”
Share without complex
configuration or duplicate
users.
A user at a large partner may log into
my company’s apps with their Active
Directory usernames and passwords.
A user at a smaller partner may log
into my company’s apps with their
Office 365 usernames and passwords.
Admin configures sharing for
cloud apps.
“I can’t email my 25 MB file and need
to share it with a partner using
Box.com.”
Seamlessly provide Azure
Active Directory to customers
& partners
For example, a user at a partner can
set up everyone in their company.
Users can bring their own email-based
or social identities.
Contoso
Azure Active Directory
Global admins
Org-wide permissions
Manage global settings
Create structure and policy
Delegate permissions and resources
Regional admins
Manage regional users,
devices, and applications
Set local policy
Regional policy and app
management
“Must login with MFA”
“Have license/access to regional
apps”
Support for distributed
organizational models
Autonomous mgmt. while
keeping common identity and
org boundary
Delegate administration to
subsidiaries
User management
App procurement and mgmt.
Scope policy
US East Germany India
AsiaEuropeNorth Am
Administrative Units: In private preview
Azure Active Directory B2C offering is tailored for enterprises who serve large populations (100’s of
thousands to millions) of individual customers, and whose business success depends upon consumer
adoption of web applications for improving customer satisfaction and reducing operational costs.
Azure Active Directory B2C(Business-to-Consumer )
Azure Active Directory B2Cwill include :
Self-Service User registration
Login with Social IdP or create your own credentials
Optional MFA
Bulk user import tools
SSO to multiple web sites
User interface customization
Cloud Domain Join makes it possible to connect work-owned
Windows devices to your company’s Azure Active Directory
tenancy in the cloud. Users can sign-in to Windows with their
cloud-hosted work credentials and enjoy modern Windows
experiences.
Cloud Domain
Joined Devices
Enterprise compliant Services
Roaming Settings, Windows backup/Restore, Store access…
Data stored in enterprise compliant backend services onAzure.
Noneedto addapersonal Microsoft account.
SSO from the desktop to org resources
SSO from desktop toOffice365 and1,000’s ofenterprise apps,
websites andresources.
Access enterprise-curated Store andinstall apps using awork account.
Management
Automatic MDMenrollment during first-run experience.
Support for hybrid environments
Traditional Domain Joined PCs also benefit from CloudDomain Join
functionality whenthe on-prem Active Directory is connectedwith an
Azure Active Directory in thecloud.
Cloud Domain Join
Mitä sinun pitää tehdä (ellet ole jo tehnyt)
• Luo ja sen jälkeen kokeile maksutonta Office 365 -tilausta
• http://products.office.com/fi-FI/try
• Luo ja sen jälkeen kokeile maksutonta Intune-tilausta
• http://www.microsoft.com/en-us/server-cloud/products/microsoft-intune/try.aspx
• Muista kirjautua O365-tililläsi
• Luo ja sen jälkeen kokeile maksutonta Azure-tilausta
• http://azure.microsoft.com
• Huom: vaatii luottokortin numeron, luottokorttia ei laskuteta
26
Lisäinformaatiota
• EMS-testiympäristö minuuteissa käyttöön
http://simon-may.com/get-started-enterprise-mobility-suite-minutes/
• Oma labra pystyyn
http://blogs.technet.com/b/mydigitalworkthoughts/
27
Sovelton kursseja aiheen tiimoilta
• Microsoft kumppaneille
• Business Anywhere (vain Microsoft-kumppaneille) 26.1. tai 4.5.
• Partner Practice Enablement: Microsoft Enterprise Mobility Suite (EMS) 23.-24.2. tai 23.-24.3.
• Kaikille asiantuntijoille
• Microsoft Intune hallinta 22.-23.4.
• 55065 Microsoft Azure IT-asiantuntijoille 11.-13.3.
• 20533 Implementing Microsoft Azure Infrastructure Solutions 13.-15.4.
• 20532 Developing Microsoft Azure Solutions 10.-13.3.
28
KIITOS!
29

More Related Content

What's hot

What's hot (20)

Azure Identity and access management
Azure   Identity and access managementAzure   Identity and access management
Azure Identity and access management
 
Microsoft 365 Enterprise Security with E5 Overview
Microsoft 365 Enterprise Security with E5 OverviewMicrosoft 365 Enterprise Security with E5 Overview
Microsoft 365 Enterprise Security with E5 Overview
 
Microsoft Azure - Introduction to microsoft's public cloud
Microsoft Azure - Introduction to microsoft's public cloudMicrosoft Azure - Introduction to microsoft's public cloud
Microsoft Azure - Introduction to microsoft's public cloud
 
48. Azure Active Directory - Part 1
48. Azure Active Directory - Part 148. Azure Active Directory - Part 1
48. Azure Active Directory - Part 1
 
Windows Azure Virtual Machines
Windows Azure Virtual MachinesWindows Azure Virtual Machines
Windows Azure Virtual Machines
 
Azure storage
Azure storageAzure storage
Azure storage
 
Access Security - Privileged Identity Management
Access Security - Privileged Identity ManagementAccess Security - Privileged Identity Management
Access Security - Privileged Identity Management
 
Azure role based access control (rbac)
Azure role based access control (rbac)Azure role based access control (rbac)
Azure role based access control (rbac)
 
Az 104 session 3 azure compute
Az 104 session 3 azure compute Az 104 session 3 azure compute
Az 104 session 3 azure compute
 
Azure Information Protection
Azure Information ProtectionAzure Information Protection
Azure Information Protection
 
Introduction to Microsoft Azure
Introduction to Microsoft AzureIntroduction to Microsoft Azure
Introduction to Microsoft Azure
 
Azure 101
Azure 101Azure 101
Azure 101
 
Microsoft Azure Overview
Microsoft Azure OverviewMicrosoft Azure Overview
Microsoft Azure Overview
 
Introduction to Azure
Introduction to AzureIntroduction to Azure
Introduction to Azure
 
Azure: PaaS or IaaS
Azure: PaaS or IaaSAzure: PaaS or IaaS
Azure: PaaS or IaaS
 
Introduction to Azure AD and Azure AD B2C
Introduction to Azure AD and Azure AD B2CIntroduction to Azure AD and Azure AD B2C
Introduction to Azure AD and Azure AD B2C
 
Windows Azure Active Directory
Windows Azure Active DirectoryWindows Azure Active Directory
Windows Azure Active Directory
 
Azure governance v4.0
Azure governance v4.0Azure governance v4.0
Azure governance v4.0
 
Microsoft Azure Training - [3] Azure Accounts, Subscriptions and Admin Roles ...
Microsoft Azure Training - [3] Azure Accounts, Subscriptions and Admin Roles ...Microsoft Azure Training - [3] Azure Accounts, Subscriptions and Admin Roles ...
Microsoft Azure Training - [3] Azure Accounts, Subscriptions and Admin Roles ...
 
Foster Employee Engagement and Create a Digital Culture Through Microsoft Mod...
Foster Employee Engagement and Create a Digital Culture Through Microsoft Mod...Foster Employee Engagement and Create a Digital Culture Through Microsoft Mod...
Foster Employee Engagement and Create a Digital Culture Through Microsoft Mod...
 

Viewers also liked

Windows Azure Active Directory
Windows Azure Active DirectoryWindows Azure Active Directory
Windows Azure Active Directory
Pavel Revenkov
 
Look into Azure Active Directory
Look into Azure Active DirectoryLook into Azure Active Directory
Look into Azure Active Directory
Enrique Lima
 
Understanding Windows Azure’s Active Directory (AD) and PowerShell Tools
Understanding Windows Azure’s Active Directory (AD) and PowerShell ToolsUnderstanding Windows Azure’s Active Directory (AD) and PowerShell Tools
Understanding Windows Azure’s Active Directory (AD) and PowerShell Tools
EPC Group
 
Windows Azure Active Directory: Identity Management in the Cloud
Windows Azure Active Directory: Identity Management in the CloudWindows Azure Active Directory: Identity Management in the Cloud
Windows Azure Active Directory: Identity Management in the Cloud
Chris Dufour
 
Windows Azure Active Directory - from Atidan
Windows Azure Active Directory - from AtidanWindows Azure Active Directory - from Atidan
Windows Azure Active Directory - from Atidan
David J Rosenthal
 

Viewers also liked (20)

CIS 2014: Azure Active Directory (Sean Deuby)
CIS 2014: Azure Active Directory (Sean Deuby)CIS 2014: Azure Active Directory (Sean Deuby)
CIS 2014: Azure Active Directory (Sean Deuby)
 
Azure Active Directory, Practical Guide
Azure Active Directory, Practical GuideAzure Active Directory, Practical Guide
Azure Active Directory, Practical Guide
 
Windows Azure Active Directory
Windows Azure Active DirectoryWindows Azure Active Directory
Windows Azure Active Directory
 
Look into Azure Active Directory
Look into Azure Active DirectoryLook into Azure Active Directory
Look into Azure Active Directory
 
Understanding Windows Azure’s Active Directory (AD) and PowerShell Tools
Understanding Windows Azure’s Active Directory (AD) and PowerShell ToolsUnderstanding Windows Azure’s Active Directory (AD) and PowerShell Tools
Understanding Windows Azure’s Active Directory (AD) and PowerShell Tools
 
Windows Azure Active Directory: Identity Management in the Cloud
Windows Azure Active Directory: Identity Management in the CloudWindows Azure Active Directory: Identity Management in the Cloud
Windows Azure Active Directory: Identity Management in the Cloud
 
Microsoft Azure Active Directory
Microsoft Azure Active DirectoryMicrosoft Azure Active Directory
Microsoft Azure Active Directory
 
Integrating your on-premises Active Directory with Azure and Office 365
Integrating your on-premises Active Directory with Azure and Office 365Integrating your on-premises Active Directory with Azure and Office 365
Integrating your on-premises Active Directory with Azure and Office 365
 
Implementing Azure Active Directory Connect and more
Implementing Azure Active Directory Connect and moreImplementing Azure Active Directory Connect and more
Implementing Azure Active Directory Connect and more
 
Azure Active Directory : on fait le point
Azure Active Directory : on fait le pointAzure Active Directory : on fait le point
Azure Active Directory : on fait le point
 
Microsoft System Center 2016 Technical Preview
Microsoft System Center 2016 Technical PreviewMicrosoft System Center 2016 Technical Preview
Microsoft System Center 2016 Technical Preview
 
Windows azure best practices - Dmitry Martynov
Windows azure best practices - Dmitry MartynovWindows azure best practices - Dmitry Martynov
Windows azure best practices - Dmitry Martynov
 
Windows Azure Active Directory - from Atidan
Windows Azure Active Directory - from AtidanWindows Azure Active Directory - from Atidan
Windows Azure Active Directory - from Atidan
 
Martin Simecek, Microsoft
Martin Simecek, Microsoft	Martin Simecek, Microsoft
Martin Simecek, Microsoft
 
Azure intoduksjon for it pro 02 data protection public
Azure intoduksjon for it pro 02 data protection publicAzure intoduksjon for it pro 02 data protection public
Azure intoduksjon for it pro 02 data protection public
 
Azure Introduction for IT Pros #1 Mobility
Azure Introduction for IT Pros #1 MobilityAzure Introduction for IT Pros #1 Mobility
Azure Introduction for IT Pros #1 Mobility
 
Microsoft Azure Rights Management
Microsoft Azure Rights ManagementMicrosoft Azure Rights Management
Microsoft Azure Rights Management
 
Scu2016 Azure Best practices
Scu2016 Azure Best practicesScu2016 Azure Best practices
Scu2016 Azure Best practices
 
Cloud Based Rights Management with Azure RMS
Cloud Based Rights Management with Azure RMSCloud Based Rights Management with Azure RMS
Cloud Based Rights Management with Azure RMS
 
Massive Lift & Shift Migrations to Microsoft Azure with the Microsoft Migrati...
Massive Lift & Shift Migrations to Microsoft Azure with the Microsoft Migrati...Massive Lift & Shift Migrations to Microsoft Azure with the Microsoft Migrati...
Massive Lift & Shift Migrations to Microsoft Azure with the Microsoft Migrati...
 

Similar to Azure Active Directory

MS Cloud Identity and Access Infographic 2015 (1)
MS Cloud Identity and Access Infographic 2015 (1)MS Cloud Identity and Access Infographic 2015 (1)
MS Cloud Identity and Access Infographic 2015 (1)
Luís Serra Libório
 
O365-AzureAD Identity management
O365-AzureAD Identity managementO365-AzureAD Identity management
O365-AzureAD Identity management
David Pechon
 
Active Directory Proposal
Active Directory ProposalActive Directory Proposal
Active Directory Proposal
MJ Ferdous
 
Identity and Access Management from Microsoft and Razor Technology
Identity and Access Management from Microsoft and Razor TechnologyIdentity and Access Management from Microsoft and Razor Technology
Identity and Access Management from Microsoft and Razor Technology
David J Rosenthal
 

Similar to Azure Active Directory (20)

Microsoft Cloud Identity and Access Management Poster - Atidan
Microsoft Cloud Identity and Access Management Poster - AtidanMicrosoft Cloud Identity and Access Management Poster - Atidan
Microsoft Cloud Identity and Access Management Poster - Atidan
 
JoTechies - Cloud identity
JoTechies - Cloud identityJoTechies - Cloud identity
JoTechies - Cloud identity
 
MS Cloud Identity and Access Infographic 2015 (1)
MS Cloud Identity and Access Infographic 2015 (1)MS Cloud Identity and Access Infographic 2015 (1)
MS Cloud Identity and Access Infographic 2015 (1)
 
Ms cloud identity and access infographic 2015
Ms cloud identity and access infographic 2015Ms cloud identity and access infographic 2015
Ms cloud identity and access infographic 2015
 
Cloud Identity and Access Management
Cloud Identity and Access ManagementCloud Identity and Access Management
Cloud Identity and Access Management
 
Hitchhiker's Guide to Azure AD - SPS St Louis 2018
Hitchhiker's Guide to Azure AD - SPS St Louis 2018Hitchhiker's Guide to Azure AD - SPS St Louis 2018
Hitchhiker's Guide to Azure AD - SPS St Louis 2018
 
Agile IT EMS webinar series, session 1
Agile IT EMS webinar series, session 1Agile IT EMS webinar series, session 1
Agile IT EMS webinar series, session 1
 
15th December 2016 - Microsoft Paddington Vuzion Partner Event
15th December 2016 - Microsoft Paddington Vuzion Partner Event15th December 2016 - Microsoft Paddington Vuzion Partner Event
15th December 2016 - Microsoft Paddington Vuzion Partner Event
 
O365-AzureAD Identity management
O365-AzureAD Identity managementO365-AzureAD Identity management
O365-AzureAD Identity management
 
Active Directory Proposal
Active Directory ProposalActive Directory Proposal
Active Directory Proposal
 
Microsoft Azure Kimlik Yönetimi
Microsoft Azure Kimlik YönetimiMicrosoft Azure Kimlik Yönetimi
Microsoft Azure Kimlik Yönetimi
 
Identity Management for Office 365 and Microsoft Azure
Identity Management for Office 365 and Microsoft AzureIdentity Management for Office 365 and Microsoft Azure
Identity Management for Office 365 and Microsoft Azure
 
SPIntersection 2016 - MICROSOFT CLOUD IDENTITIES IN AZURE AND OFFICE 365
SPIntersection 2016 - MICROSOFT CLOUD IDENTITIES IN AZURE AND OFFICE 365SPIntersection 2016 - MICROSOFT CLOUD IDENTITIES IN AZURE AND OFFICE 365
SPIntersection 2016 - MICROSOFT CLOUD IDENTITIES IN AZURE AND OFFICE 365
 
Análisis de riesgos en Azure y protección de la información
Análisis de riesgos en Azure y protección de la informaciónAnálisis de riesgos en Azure y protección de la información
Análisis de riesgos en Azure y protección de la información
 
Identity and Access Management from Microsoft and Razor Technology
Identity and Access Management from Microsoft and Razor TechnologyIdentity and Access Management from Microsoft and Razor Technology
Identity and Access Management from Microsoft and Razor Technology
 
SCU Berlín | Cloud identity for maximum productivity
 SCU Berlín | Cloud identity for maximum productivity SCU Berlín | Cloud identity for maximum productivity
SCU Berlín | Cloud identity for maximum productivity
 
2018 November - AZUGDK - Azure AD
2018 November - AZUGDK - Azure AD 2018 November - AZUGDK - Azure AD
2018 November - AZUGDK - Azure AD
 
Introduction to Active Directory
Introduction to Active DirectoryIntroduction to Active Directory
Introduction to Active Directory
 
Securing your Azure Identity Infrastructure
Securing your Azure Identity InfrastructureSecuring your Azure Identity Infrastructure
Securing your Azure Identity Infrastructure
 
How your SharePoint setup can benefit from Azure capabilities
How your SharePoint setup can benefit from Azure capabilitiesHow your SharePoint setup can benefit from Azure capabilities
How your SharePoint setup can benefit from Azure capabilities
 

More from Sovelto

More from Sovelto (20)

LOISTO-palvelu
LOISTO-palveluLOISTO-palvelu
LOISTO-palvelu
 
Sovelto Channel -esittely
Sovelto Channel -esittelySovelto Channel -esittely
Sovelto Channel -esittely
 
Windows 10 hallinnan näkökulmasta
Windows 10 hallinnan näkökulmastaWindows 10 hallinnan näkökulmasta
Windows 10 hallinnan näkökulmasta
 
Windows 10 käyttäjän näkökulmasta
Windows 10 käyttäjän näkökulmastaWindows 10 käyttäjän näkökulmasta
Windows 10 käyttäjän näkökulmasta
 
Tilaisuuden avaus: Kalaparvi liikkuu
Tilaisuuden avaus: Kalaparvi liikkuuTilaisuuden avaus: Kalaparvi liikkuu
Tilaisuuden avaus: Kalaparvi liikkuu
 
Ansaintamallin voi muuttaa
Ansaintamallin voi muuttaaAnsaintamallin voi muuttaa
Ansaintamallin voi muuttaa
 
Osallista ihmiset mukaan muutokseen
Osallista ihmiset mukaan muutokseen Osallista ihmiset mukaan muutokseen
Osallista ihmiset mukaan muutokseen
 
Ajankohtaista tutkimustietoa
Ajankohtaista tutkimustietoaAjankohtaista tutkimustietoa
Ajankohtaista tutkimustietoa
 
Yhteisöllinen tuottavuus liiketoiminnan tukena
Yhteisöllinen tuottavuus liiketoiminnan tukenaYhteisöllinen tuottavuus liiketoiminnan tukena
Yhteisöllinen tuottavuus liiketoiminnan tukena
 
Hyvinvointi ja tuottavuus
Hyvinvointi ja tuottavuusHyvinvointi ja tuottavuus
Hyvinvointi ja tuottavuus
 
Tietotyön uusi kulttuuri
Tietotyön uusi kulttuuriTietotyön uusi kulttuuri
Tietotyön uusi kulttuuri
 
Intune ja Azure RMS
Intune ja Azure RMSIntune ja Azure RMS
Intune ja Azure RMS
 
3D-tulostaminen ja sen hyödyt käytännössä
3D-tulostaminen ja sen hyödyt käytännössä3D-tulostaminen ja sen hyödyt käytännössä
3D-tulostaminen ja sen hyödyt käytännössä
 
​Tervetuloa tutustumaan tehokkaampaan tuotekehitykseen
​Tervetuloa tutustumaan tehokkaampaan tuotekehitykseen ​Tervetuloa tutustumaan tehokkaampaan tuotekehitykseen
​Tervetuloa tutustumaan tehokkaampaan tuotekehitykseen
 
Seminaarin avaussanat
Seminaarin avaussanatSeminaarin avaussanat
Seminaarin avaussanat
 
Esimiehen työ on palvelua, Tilannejohtaminen
Esimiehen työ on palvelua, TilannejohtaminenEsimiehen työ on palvelua, Tilannejohtaminen
Esimiehen työ on palvelua, Tilannejohtaminen
 
Miten yritysarkkitehtuurilla kehitetään strategista johtamista
 Miten yritysarkkitehtuurilla kehitetään strategista johtamista Miten yritysarkkitehtuurilla kehitetään strategista johtamista
Miten yritysarkkitehtuurilla kehitetään strategista johtamista
 
Miten yritysarkkitehtuurilla parannetaan strategista johtamista?
Miten yritysarkkitehtuurilla parannetaan strategista johtamista?Miten yritysarkkitehtuurilla parannetaan strategista johtamista?
Miten yritysarkkitehtuurilla parannetaan strategista johtamista?
 
Case Kouvolan kaupunki: Millaisia haasteita olemme kohdanneet kokonaisarkkite...
Case Kouvolan kaupunki: Millaisia haasteita olemme kohdanneet kokonaisarkkite...Case Kouvolan kaupunki: Millaisia haasteita olemme kohdanneet kokonaisarkkite...
Case Kouvolan kaupunki: Millaisia haasteita olemme kohdanneet kokonaisarkkite...
 
Mitä tapahtuu, jos mitään ei tehdä?
Mitä tapahtuu, jos mitään ei tehdä?Mitä tapahtuu, jos mitään ei tehdä?
Mitä tapahtuu, jos mitään ei tehdä?
 

Recently uploaded

Structuring Teams and Portfolios for Success
Structuring Teams and Portfolios for SuccessStructuring Teams and Portfolios for Success
Structuring Teams and Portfolios for Success
UXDXConf
 

Recently uploaded (20)

Secure Zero Touch enabled Edge compute with Dell NativeEdge via FDO _ Brad at...
Secure Zero Touch enabled Edge compute with Dell NativeEdge via FDO _ Brad at...Secure Zero Touch enabled Edge compute with Dell NativeEdge via FDO _ Brad at...
Secure Zero Touch enabled Edge compute with Dell NativeEdge via FDO _ Brad at...
 
PLAI - Acceleration Program for Generative A.I. Startups
PLAI - Acceleration Program for Generative A.I. StartupsPLAI - Acceleration Program for Generative A.I. Startups
PLAI - Acceleration Program for Generative A.I. Startups
 
THE BEST IPTV in GERMANY for 2024: IPTVreel
THE BEST IPTV in  GERMANY for 2024: IPTVreelTHE BEST IPTV in  GERMANY for 2024: IPTVreel
THE BEST IPTV in GERMANY for 2024: IPTVreel
 
Structuring Teams and Portfolios for Success
Structuring Teams and Portfolios for SuccessStructuring Teams and Portfolios for Success
Structuring Teams and Portfolios for Success
 
Unpacking Value Delivery - Agile Oxford Meetup - May 2024.pptx
Unpacking Value Delivery - Agile Oxford Meetup - May 2024.pptxUnpacking Value Delivery - Agile Oxford Meetup - May 2024.pptx
Unpacking Value Delivery - Agile Oxford Meetup - May 2024.pptx
 
Optimizing NoSQL Performance Through Observability
Optimizing NoSQL Performance Through ObservabilityOptimizing NoSQL Performance Through Observability
Optimizing NoSQL Performance Through Observability
 
Agentic RAG What it is its types applications and implementation.pdf
Agentic RAG What it is its types applications and implementation.pdfAgentic RAG What it is its types applications and implementation.pdf
Agentic RAG What it is its types applications and implementation.pdf
 
Measures in SQL (a talk at SF Distributed Systems meetup, 2024-05-22)
Measures in SQL (a talk at SF Distributed Systems meetup, 2024-05-22)Measures in SQL (a talk at SF Distributed Systems meetup, 2024-05-22)
Measures in SQL (a talk at SF Distributed Systems meetup, 2024-05-22)
 
Custom Approval Process: A New Perspective, Pavel Hrbacek & Anindya Halder
Custom Approval Process: A New Perspective, Pavel Hrbacek & Anindya HalderCustom Approval Process: A New Perspective, Pavel Hrbacek & Anindya Halder
Custom Approval Process: A New Perspective, Pavel Hrbacek & Anindya Halder
 
IESVE for Early Stage Design and Planning
IESVE for Early Stage Design and PlanningIESVE for Early Stage Design and Planning
IESVE for Early Stage Design and Planning
 
Buy Epson EcoTank L3210 Colour Printer Online.pdf
Buy Epson EcoTank L3210 Colour Printer Online.pdfBuy Epson EcoTank L3210 Colour Printer Online.pdf
Buy Epson EcoTank L3210 Colour Printer Online.pdf
 
Behind the Scenes From the Manager's Chair: Decoding the Secrets of Successfu...
Behind the Scenes From the Manager's Chair: Decoding the Secrets of Successfu...Behind the Scenes From the Manager's Chair: Decoding the Secrets of Successfu...
Behind the Scenes From the Manager's Chair: Decoding the Secrets of Successfu...
 
Speed Wins: From Kafka to APIs in Minutes
Speed Wins: From Kafka to APIs in MinutesSpeed Wins: From Kafka to APIs in Minutes
Speed Wins: From Kafka to APIs in Minutes
 
Free and Effective: Making Flows Publicly Accessible, Yumi Ibrahimzade
Free and Effective: Making Flows Publicly Accessible, Yumi IbrahimzadeFree and Effective: Making Flows Publicly Accessible, Yumi Ibrahimzade
Free and Effective: Making Flows Publicly Accessible, Yumi Ibrahimzade
 
ECS 2024 Teams Premium - Pretty Secure
ECS 2024   Teams Premium - Pretty SecureECS 2024   Teams Premium - Pretty Secure
ECS 2024 Teams Premium - Pretty Secure
 
Connecting the Dots in Product Design at KAYAK
Connecting the Dots in Product Design at KAYAKConnecting the Dots in Product Design at KAYAK
Connecting the Dots in Product Design at KAYAK
 
Syngulon - Selection technology May 2024.pdf
Syngulon - Selection technology May 2024.pdfSyngulon - Selection technology May 2024.pdf
Syngulon - Selection technology May 2024.pdf
 
FDO for Camera, Sensor and Networking Device – Commercial Solutions from VinC...
FDO for Camera, Sensor and Networking Device – Commercial Solutions from VinC...FDO for Camera, Sensor and Networking Device – Commercial Solutions from VinC...
FDO for Camera, Sensor and Networking Device – Commercial Solutions from VinC...
 
Linux Foundation Edge _ Overview of FDO Software Components _ Randy at Intel.pdf
Linux Foundation Edge _ Overview of FDO Software Components _ Randy at Intel.pdfLinux Foundation Edge _ Overview of FDO Software Components _ Randy at Intel.pdf
Linux Foundation Edge _ Overview of FDO Software Components _ Randy at Intel.pdf
 
Extensible Python: Robustness through Addition - PyCon 2024
Extensible Python: Robustness through Addition - PyCon 2024Extensible Python: Robustness through Addition - PyCon 2024
Extensible Python: Robustness through Addition - PyCon 2024
 

Azure Active Directory

  • 1. Vartti tunnista Azure Active Directory Mika Seitsonen
  • 2. Kouluttajanne Mika Seitsonen • Faktat • M.Sc., University of Nottingham, U.K. • DI, Lappeenrannan teknillinen yliopisto • Co-author of "Inside Active Directory" • Sovelto • Senior-konsultti, vt. osaamisaluevastaava: Teknologia-asiantuntijat • Microsoft Certified Trainer (MCT) vuodesta 1997, Microsoft Certification ID 414xxx • MCSE: Communications • MCSA: Office 365, Windows 2008, Windows 7 • MS: Implementing Microsoft Azure Infrastructure Solutions • Yhteystiedot • e-mail mika.seitsonen@sovelto.fi • Twitter @MikaSeitsonen • Moottoriurheil(ija)un innokas seuraaja • Kuvattuna Päijänteen Ympäriajo:ssa 2009
  • 3. Identity considerations: Cloud, Sync or Federated?     Cloud identity provides a solution where all identity resides in the cloud Federated identity allows customers to retain all authentication on-premises Identity sync enables customers to bridge their existing identity into the cloud B2B federated identity allows customers to securely share and collaborate with each other
  • 4. Self-service Single sign on ••••••••••• Username Identity as the control plane Simple connection Cloud SaaS Azure Office 365Public cloud Other Directories Windows Server Active Directory On-premises Microsoft Azure Active Directory
  • 5. A comprehensive identity and access management cloud solution. It combines directory services, advanced identity governance, application access management and a rich standards-based platform for developers It is available in 3 editions: free, Basic and Premium What is Azure Active Directory?
  • 6. No Object Limit No Object Limit No Limit Advanced Security Reports Yes(Advanced)** Premium + Basic Features Group-based access management/provisioning Yes Yes Self-Service Password Reset for cloud users Yes Yes Company Branding (Logon Pages/Access Panel customization) Yes Yes SLA Yes Yes Kurantti informaatio osoitteessa https://msdn.microsoft.com/en-us/library/dn532272.aspx
  • 7.
  • 8. Azure Active Directory Connect* Microsoft Azure Active Directory Other Directories PowerShell LDAP v3 SQL (ODBC) Web Services ( SOAP, JAVA, REST) *
  • 9. Azure Active Directory Connect Consolidated deployment assistant for your identity bridge components Progressive learning while configuring the components ADFS is optional DirSync Azure Active Directory Sync FIM+Azure Active Directory Connector Sync Engine
  • 11. SaaS appsMicrosoft Azure Active DirectoryOther Directories
  • 12. Microsoft Azure Active Directory Identities and applications in one place. Web Apps (Azure Active Directory Application Proxy) SaaS apps Integrated custom apps Other Directories
  • 13. Microsoft Azure Active Directory Corporate Network DMZ https://app1- contoso.msappproxy.net/ A connector that auto connects to the cloud service http://app1
  • 20. Azure Active Directory 12-month investments Business to Business Business to Consumers Device Registration Administrative Units Cloud Domain Joined (Windows 10) Conditional Access
  • 21. Roles Based Access Control Today RBAC to Azure Subscription Tomorrow RBAC to 3rd Party SASS apps Reade r SasS SasS Contributor SasS Owne r SasS SasS SasS Sas S Sas S Reade r ContributorOwne r Assign roles to users and groups at subscription, resource group, or resource level Assignments inherit down the hierarchy Use built-in roles with pre- configured permissions (at preview) Create custom roles (post preview)
  • 22. B2B: cross-organization collaboration “I need to let my partners access my company’s apps using their own credentials.” Share without complex configuration or duplicate users. A user at a large partner may log into my company’s apps with their Active Directory usernames and passwords. A user at a smaller partner may log into my company’s apps with their Office 365 usernames and passwords. Admin configures sharing for cloud apps. “I can’t email my 25 MB file and need to share it with a partner using Box.com.” Seamlessly provide Azure Active Directory to customers & partners For example, a user at a partner can set up everyone in their company. Users can bring their own email-based or social identities.
  • 23. Contoso Azure Active Directory Global admins Org-wide permissions Manage global settings Create structure and policy Delegate permissions and resources Regional admins Manage regional users, devices, and applications Set local policy Regional policy and app management “Must login with MFA” “Have license/access to regional apps” Support for distributed organizational models Autonomous mgmt. while keeping common identity and org boundary Delegate administration to subsidiaries User management App procurement and mgmt. Scope policy US East Germany India AsiaEuropeNorth Am Administrative Units: In private preview
  • 24. Azure Active Directory B2C offering is tailored for enterprises who serve large populations (100’s of thousands to millions) of individual customers, and whose business success depends upon consumer adoption of web applications for improving customer satisfaction and reducing operational costs. Azure Active Directory B2C(Business-to-Consumer ) Azure Active Directory B2Cwill include : Self-Service User registration Login with Social IdP or create your own credentials Optional MFA Bulk user import tools SSO to multiple web sites User interface customization
  • 25. Cloud Domain Join makes it possible to connect work-owned Windows devices to your company’s Azure Active Directory tenancy in the cloud. Users can sign-in to Windows with their cloud-hosted work credentials and enjoy modern Windows experiences. Cloud Domain Joined Devices Enterprise compliant Services Roaming Settings, Windows backup/Restore, Store access… Data stored in enterprise compliant backend services onAzure. Noneedto addapersonal Microsoft account. SSO from the desktop to org resources SSO from desktop toOffice365 and1,000’s ofenterprise apps, websites andresources. Access enterprise-curated Store andinstall apps using awork account. Management Automatic MDMenrollment during first-run experience. Support for hybrid environments Traditional Domain Joined PCs also benefit from CloudDomain Join functionality whenthe on-prem Active Directory is connectedwith an Azure Active Directory in thecloud. Cloud Domain Join
  • 26. Mitä sinun pitää tehdä (ellet ole jo tehnyt) • Luo ja sen jälkeen kokeile maksutonta Office 365 -tilausta • http://products.office.com/fi-FI/try • Luo ja sen jälkeen kokeile maksutonta Intune-tilausta • http://www.microsoft.com/en-us/server-cloud/products/microsoft-intune/try.aspx • Muista kirjautua O365-tililläsi • Luo ja sen jälkeen kokeile maksutonta Azure-tilausta • http://azure.microsoft.com • Huom: vaatii luottokortin numeron, luottokorttia ei laskuteta 26
  • 27. Lisäinformaatiota • EMS-testiympäristö minuuteissa käyttöön http://simon-may.com/get-started-enterprise-mobility-suite-minutes/ • Oma labra pystyyn http://blogs.technet.com/b/mydigitalworkthoughts/ 27
  • 28. Sovelton kursseja aiheen tiimoilta • Microsoft kumppaneille • Business Anywhere (vain Microsoft-kumppaneille) 26.1. tai 4.5. • Partner Practice Enablement: Microsoft Enterprise Mobility Suite (EMS) 23.-24.2. tai 23.-24.3. • Kaikille asiantuntijoille • Microsoft Intune hallinta 22.-23.4. • 55065 Microsoft Azure IT-asiantuntijoille 11.-13.3. • 20533 Implementing Microsoft Azure Infrastructure Solutions 13.-15.4. • 20532 Developing Microsoft Azure Solutions 10.-13.3. 28