Azure Active Directory Your Cloud Identity Brian Mansure Azure Specialist bmansure@enpointe.com
Agenda What Azure Active Directory is What Azure Active Directory is not Hybrid Identity Features Roadmap
Mobility is the new normal 66% 25% 33% of employees use personal devices for work purposes.* of all software will be available on a SaaS delivery by 2020.** of employees that typically work on employer premises, also frequently work away from their desks.*** *CEB The Future of Corporate ITL: 203-2017. 2013. **Forrester Application Adoption Trends: The Rise Of SaaS ***CEB IT Impact Report: Five Key Findings on Driving Employee Productivity Q1 2014.
Devices Apps Data
The current reality
People-centric approach Devices Apps Data Enable your users Unify your environment Protect your data
What is Azure Active Directory? Azure Active Directory (Azure AD) is Microsoft s multi-tenant cloud based directory and identity management service It combines directory services, advanced identity governance, application access management and a rich standards-based platform for developers Available in 3 editions: Free, Basic and Premium
Windows Azure Active Directory You host it, on-premises / Cloud You manage the infrastructure and the data Core Services: Active Directory services Kerberos authentication NTLM authentication Active Directory Lightweight Directory Services (AD LDS) Active Directory Federated Services (AD FS) Active Directory Certificate Services (AD CS) Active directory Rights Management Services (AD RMS) Microsoft hosts it in their datacenters Microsoft manages the infrastructure You manage the data Core Services: Windows Azure Active Directory services Federated authentication WS-Federation SAML Oauth 2.0 More to come Windows Azure Access Control Service (ACS)
Windows Azure Active Directory Runs from 28 datacenters spread across the globe with automated failover The directory behind Office 365 On average 14 billion authentications every week 99.9% availability guarantee (Basic and Premium)
* Azure Active Directory Connect * PowerShell SQL (ODBC) Microsoft Azure Active Directory LDAP v3 Web Services ( SOAP, JAVA, REST) Other Directories
Hybrid Identity Delivering a seamless user authentication experience = Same Sign-on Users will be able to have a single set of credentials to access their cloud applications but will be prompted for username and password = Single Sign-on Users will experience true single sign-on for cloud applications and on-premises applications alike Windows Azure Conference 2014
Other Directories Microsoft Azure Active Directory SaaS apps
Other Directories Microsoft Azure SaaS apps Web Apps (Azure Active Directory Application Proxy) Integrated custom apps
Centrally managed identities and access IT professional
alerts. Monitor and protect access to enterprise apps
alerts. Monitor and protect access to enterprise apps
How Azure Multi Factor Authentication works
http://myapps.microsoft.com
http://myapps.microsoft.com
Cloud App Discovery SSO with SaaS AD Agent Logs Active Directory Cloud App Discovery
Discover all SaaS apps in use within your organization 10x as many Cloud apps are in use than IT estimates Source: Help Net Security 2014 Azure Active Directory Cloud App Discovery Comprehensive reporting SaaS app category Number of users Utilization volume
Rich standards-based platform for developers
Azure Active Directory Looking Forward Business to Business Business to Consumers Azure AD Directory Domain Services Administrative Units Conditional Access Cloud Domain Joined (Windows 10)
Identity as the control plane Simple connection Self-service Single sign on Windows Server Active Directory Other Directories Username Azure Public cloud SaaS Office 365 On-premises Microsoft Azure Active Directory Cloud
Directory as a Service 500,000 Object Limit No Object Limit No Object Limit Common Features User/Group Management (add/update/delete) Yes Yes Yes SSO to pre-integrated SAAS Applications /Custom Apps 10 apps per user 10 apps per user No Limit User-Based access management/provisioning Yes Yes Yes Self-Service Password Change for cloud users Yes Yes Yes Connect (Sync engine that extends on-premises directories to Azure Active Directory) * Yes Yes Yes Security Reports/Audit 3 Basic Reports 3 Basic Reports Advanced Security Reports Premium + Basic Features Group-based access management/provisioning Yes Yes Self-Service Password Reset for cloud users Yes Yes Company Branding (Logon Pages/Access Panel customization) Yes Yes Application Proxy Yes Yes SLA Yes Yes Self-Service Group Management Yes Self-Service Password Reset/Change with on-premises write-back Yes Advanced Usage Reporting Yes Premium Features Multi-Factor Authentication (Cloud and On-premises (MFA Server)) MIM CAL + MIM Server Administrative Units Cloud App Discovery Conditional Access : MFA per application (in Preview) Automated password roll-over (in Preview) Yes Yes Yes Yes Yes Yes Connect health Yes
Enterprise Mobility Suite Microsoft Azure Active Directory Premium Security reports, audit reports and multi-factor authentication Self-service password reset and group management Connection between Active Directory and Azure Active Directory Mobile device settings management Windows Intune Mobile application management Selective wipe Microsoft Azure Rights Management Information protection Connection to onpremises assets Bring your own key Detect threats fast with behavioral analytics Advanced Threat Analytics Adapt as fast as your enemies Reduce false positives
THANK YOU QUESTIONS? Brian Mansure Azure Specialist bmansure@enpointe.com