SINGLE & SAME SIGN-ON ASPECTS OF AZURE ACTIVE DIRECTORY
TRAINER INFO
Harold Baele – MCT at RealDolmen Education [email protected] - @hbaele
Trainer since 2000 on
• Operating Systems, Networking, AD
• Exchange
• Office 365 & Azure
D
EFINITIONS…
Signing in means requesting validation
= authentication
Verifying access to a resource/application
= authorization
SSO…
SINGLE sign-on: ONE authentication, ONE credential, multiple authorizations
I DENTITY STORES
Web Application Proxy +
AD FS
Microsoft Account
C
ENTRALIZEI
DENTITY CONTROL,
NOT THE STOREMicrosoft Azure Active Directory
On-premises
Microsoft Azure
Windows Server Active Directory
Azure Active Directory (AAD)
Consumer identity providers
PCs and devices
Microsoft apps
Third-party cloud/hosting
Enable single sign-on across multiple cloud and on-premises applications with Active Directory Federation Services (ADFS)
Integrate cloud with on-premises Active Directory with Active Directory
Synchronization
Create and manage identities in the cloud
Help secure access to on-premises and cloud apps with Microsoft Azure Multi- Factor Authentication
Use Azure Active Directory (AAD) to manage Office 365 with other Microsoft and external cloud services
I
DENTITY AND ACCESS MANAGEMENT: P
RODUCTS Enable single sign-on between on-premises and cloud identities
M
ICROSOFTA
ZUREBuild applications using any language, tool, or framework
Integrate public cloud solution with the existing IT environment
99.95% monthly SLA CLOUD PLATFORM
USAGE-BASED SERVICES
An open and flexible cloud platform that enables you to quickly build, deploy,
& manage solutions across a global network of Microsoft- managed datacenters.
Caching Identity Service bus Media CDN Integration HPC Analytics
APP SERVICES
Websites Virtual
machines Cloud
services Mobile services
COMPUTE
SQL
database HDInsight Tables Blob storage
STORAGE
Services grouped as Compute, Storage, Network and Application Services
Distinct Rates for each of these Service “meters”
Customers are billed for usage against one or more of these meters
M
ICROSOFTA
ZUREI
AAS
M
ICROSOFTA
ZUREP
LATFORM AS AS
ERVICE(P
AAS)
W
HAT ISM
ICROSOFTA
ZUREA
CTIVED
IRECTORY?
A comprehensive identity and access management cloud solution
Azure Active Directory combines directory services, advanced identity governance, application access
management, and a rich standards- based platform for developers
Microsoft Azure Active Directory
Premium is an advanced offering that includes Identity and Access
Management (IAM) capabilities for on- premises, hybrid, and cloud
environments
DEMO
Creating an AAD
E
XAMPLEAAD: O
FFICE365
Windows Azure Active Directory Exchange
Online SharePoint
Online
Skype for Business
Online
Office 365 ProPlus Yammer
I
DENTITY OPTIONS COMPARISONAppropriate for
• Smaller orgs without AD on-premise
Pros
• No servers required on- premise
Cons
• No SSO
• No 2FA
• 2 sets of credentials to manage with differing
Appropriate for
• Medium/Large orgs with AD on-premise
Pros
• Users and groups mastered on-premise
• Enables co-existence scenarios
Cons
• Same SO
• No 2FA
• 2 sets of credentials to manage with differing
Appropriate for
• Larger enterprise orgs with AD on-premise Pros
• SSO with corporate credentials
• IDs mastered on- premise
• Password policy controlled on-premise
• 2FA solutions possible
• Enables co-existence scenarios
P
ASSWORD SYNC VERSUSS
INGLES
IGN-O
NPassword sync Single Sign-On (ADFS)
Same password to access resources
Control password policies on premises
Support for multi-factor authentication
No password re-entry if on premises
Authentication occurs in on-premises directory
Client access filtering
S
INGLES
IGN ONS
ETUP Needs DirSync aka Azure AD Connect (no password sync)
Add Domain (returns details for proof of ownership)
Single source AD DS: Connect ADFS with Microsoft Office 365
Single source AAD: use AAD application proxy
I
DENTITYF
EDERATIONA
UTHENTICATION FLOW(P
ASSIVE/W
EB PROFILE)
`
Client (joined to CorpNet)
Authentication platform AD FS 2.0 Server
Exchange Online or SharePoint Online Active Directory
Customer Microsoft Online Services
Logon (SAML 1.1) Token UPN:[email protected]
Source User ID: ABC123 Auth Token
UPN:[email protected] Unique ID: 254729
I
DENTITYF
EDERATIONA
UTHENTICATION FLOW(R
ICHC
LIENTP
ROFILE)
Authentication platform AD FS 2.0 Server
Active Directory
Customer Microsoft Online Services
Logon (SAML 1.1) Token UPN:[email protected] Source User ID: ABC123
Auth Token
UPN:[email protected] Unique ID: 254729
P
REPARING FORI
DENTITYF
EDERATION High availability design for AD FS 2.0
Every User must have a User Principal Name
UPN suffix must match a validated domain in Office 365
[email protected]
(preferably built to match e-mail address)
DEMO
Portal logon office 365
C
ENTRALLY MANAGED IDENTITIES AND ACCESSP
REINTEGRATEDS
AAS
APPS IN THE APPLICATION GALLERYA
UTHENTICATION PROTOCOLS SUPPORTED OAUTH 2.0
OpenID Connect
WS-Federation
SAML 2.0
Info: https://azure.microsoft.com/en-
us/documentation/articles/active-directory- authentication-scenarios/
A
PPLICATIONS TYPES SUPPORTED Web applications using oAUTH and need a shortcut in the apps portal of Azure
Officially supported applications in the Azure gallery
Applications accessible using
application proxy (needs
A
CCESSP
ANEL http://myapps.microsoft.com
This is where users can discover the applications they have access to.
Features of the Access Panel
Users can change the password associated with their organizational account.
Users can edit multi-factor authentication-related contact and preference settings.
Users can view details about their account.
Needs a browser extension on first use
A
CCESSP
ANEL FOR IOS 7 & A
NDROID Provides SSO to Apps
integrated with your Azure Active Directory
Full parity with the web-based Application Access Panel
DEMO
Single SignOn Twitter using AAD
D
IRECTORY SYNC– A
ZUREAD C
ONNECT Synchronizes users, groups, and contacts to Microsoft Azure Active Directory
Users can have a different password in Microsoft
Azure Active Directory than they have for on-premises
P
REPARING FORA
ZUREAD C
ONNECTDEMO
Sync ADDS with AAD using Azure Connect
W
HAT ISA
ZURE MULTI-
FACTOR AUTHENTICATION?
A stand-alone Azure Identity and Access management service
Needs AAD Premium.
Prevents unauthorized access to both on-premises and cloud
applications by providing an
additional level of authentication.
A
ND THE SECOND FACTOR IS…
U
SER SETUPMFA
User required to setup
Also needed for password reset
DEMO
Logon with Multi Factor Authenctication
S
ELFR
ESETP
ASSWORD OPTIONS1, ….
2, ….
3, ….
4, ….
5, ….
(M
OBILE)
DEVICE MANAGEMENT ANDAAD
DEMO
Windows 10 AAD domain join
T HANK Y OU
WWW.REALDOLMEN.COM
Follow us on:
Selected presentations are available on: