Getting Started with Azure AD and Hybrid Identities



Similar documents
Making Peace with the User Profile Service. Todd Klindt & Shane Young Rackspace

Mod 2: User Management

PowerShell and Office 365. Presentation created for Simplex-IT Developed by Sarah Dutkiewicz

SPHOL300 Synchronizing Profile Pictures from On-Premises AD to SharePoint Online

Office 365 deployment checklists

Presented by: Robert Crane BE MBA MVP

Agenda. Federation using ADFS and Extensibility options. Office 365 Identity overview. Federation and Synchronization

Get started with cloud hybrid search for SharePoint

Office 365 deploym. ployment checklists. Chapter 27

WHITE PAPER BT Sync, the alternative for DirSync during Migrations

LAB 2: Identity Management

Exchange Deployment Options: On-premises, cloud, or hybrid? Jeff Mealiffe Principal Program Manager Microsoft

Managing Office 365 Identities and Services 20346C; 5 Days, Instructor-led

Course 20346: Managing Office 365 Identities and Services

Managing Office 365 Identities and Services

Managing Office 365 Identities and Services

Mod 3: Office 365 DirSync, Single Sign-On & ADFS

Microsoft Designing and Deploying Microsoft Exchange Server 2016

Cloud-Accelerated Hybrid Scenarios with SharePoint and Office 365

Microsoft SharePoint Architectural Models

Microsoft Azure for IT Professionals 55065A; 3 days

Configuring Single Sign-On from the VMware Identity Manager Service to Office 365

Hybrid Architecture. Office 365. On-premises Exchange org (Exchange 2007+) Provisioned via DirSync. Secure Mail flow

Webinar Self-service in Microsoft Azure AD Premium

365 Services. 1.1 Configuring Access Manager Prerequisite Adding the Office 365 Metadata. docsys (en) 2 August 2012

Bill Fiddes Learning and Development Specialist Rob Latino Program Manager in Office 365 Support

Designing a Windows Server 2008 Active Directory Infrastructure and Services

Introductions. Christopher Cognetta Practice Manager Client Field Engineering Microsoft Dynamics CRM MVP

Enabling and Managing Office 365

Table of Contents Introduction... 2 Azure ADSync Requirements/Prerequisites:... 2 Software Requirements... 2 Hardware Requirements...

Implementing Microsoft Azure Infrastructure Solutions

PassTest. Bessere Qualität, bessere Dienstleistungen!

Microsoft Office 365 Courseware

Migrating Exchange Server to Office 365

Section 1, Configuring Access Manager, on page 1 Section 2, Configuring Office 365, on page 4 Section 3, Verifying Single Sign-On Access, on page 5

Quality Management Consultancy

Developing Microsoft Azure Solutions 20532B; 5 Days, Instructor-led

SSC2016: SharePoint 2016 Administrator s Survival Camp

Extend your Exchange On Premises Organization to the Cloud

Implementing Microsoft Azure Infrastructure Solutions 20533B; 5 Days, Instructor-led

Course 20533B: Implementing Microsoft Azure Infrastructure Solutions

Office 365 from the ground to the cloud

Course Description. Course Audience. Course Outline. Course Page - Page 1 of 5. Microsoft Azure Fundamentals M Length: 2 days Price: $ 1,295.

Designing for Office 365 Infrastructure

LAB 1: Installing Active Directory Federation Services

Dell One Identity Cloud Access Manager How to Configure Microsoft Office 365

Ondřej Výšek Sales Lead, Microsoft MVP.

Microsoft Azure Multi-Factor authentication. (Concept Overview Part 1)

Centrify Cloud Connector Deployment Guide

Course Outline. Microsoft Azure Fundamentals Course 10979A: 2 days Instructor Led. About this Course. Audience Profile. At Course Completion

Microsoft Enterprise Mobility Suite

Course Designing and Deploying Microsoft Exchange Server 2016

This guide identifies two possible enterprise integration scenarios for NetScaler and Azure AD.

Azure AD Connect with Single Sign-on on Azure Tenant

Manage all your Office365 users and licenses

Planning, Implementing and Managing a Microsoft SharePoint 2003 Infrastructure

Deploy the client as an Azure RemoteApp program

Advanced Self-Service Deployment

Before you begin with an Exchange 2010 hybrid deployment Sign up for Office 365 for an Exchange 2010 hybrid deployment... 10

SINGLE & SAME SIGN-ON ASPECTS

Course 20533: Implementing Microsoft Azure Infrastructure Solutions

webnetwork Office 365 SSO integration v

MICROSOFT EXAM QUESTIONS & ANSWERS

test questions and answers:

Implementing Microsoft Azure Infrastructure Solutions

6436: Designing a Windows Server 2008 Active Directory Infrastructure and Services (5 Days)

Introduction to Unified Device Management with Intune and System Center Configuration Manager

NCTA Cloud Architecture

DottsConnected SHAREPOINT 2010 ADMIN TRAINING. Exercise 1: Create Dedicated Service Accounts in Active Directory

What s New in SharePoint 2016 (On- Premise) for IT Pros

Implementing Microsoft Azure Infrastructure Solutions

Cloud & Datacenter Monitoring with System Center Operations Manager

Microsoft. Official Course. Introduction to Active Directory Domain Services. Module 2

First experiences using SharePoint 2016 Preview running on Windows 2016 Preview and SQL 2016 Preview.

Advanced Solutions of Microsoft SharePoint Server 2013 (20332) H6C76S

Designing a Microsoft SharePoint 2010 Infrastructure

20247D: Configuring and Deploying a Private Cloud

Coveo Platform 7.0. Microsoft SharePoint Connector Guide

Before you begin with an Exchange 2010 hybrid deployment Sign up for Office 365 for an Exchange 2010 hybrid deployment... 10

Integration of Office 365 with existing faculty SSO

Implementing Microsoft Azure Infrastructure Solutions

How To - Implement Single Sign On Authentication with Active Directory

Implementing Microsoft Azure Infrastructure Solutions

SharePoint 2010

MS 20532B - Developing Microsoft Azure Solutions

Configuring and Deploying a Private Cloud

Configuring and Troubleshooting Internet Information Services in Windows Server 2008

10974B: Deploying and Migrating Windows Servers

Implementing and Managing Windows Server 2008 Hyper-V

ITMC 2079 MCTS Configuring and Administering Microsoft SharePoint 2010

Transcription:

Getting Started with Azure AD and Hybrid Identities Jason Himmelstein, SharePoint MVP Office 365 Advisory Services Manager @sharepointlhorn http://www.sharepointlonghorn.com Todd Klindt, SharePoint MVP SharePoint Principal Architect @toddklindt http://www.toddklindt.com/blog

Who is this Todd Klindt guy? SharePoint MVP since 2006 Speaker, writer, consultant, Aquarius, Iowa Native Fan of all sorts of Microsoft technologies Personal Blog www.toddklindt.com/blog Twitter me! @toddklindt If you re not already sick of him http://www.toddklindt.com/netcast

That other guy Jason something SharePoint Server MVP Office 365 Advisory Services Manager, Rackspace ITPro enthusiast, Business Intelligence geek, & general technology fan boy Re-installed Texan, die-hard Spurs, Longhorns, & Jaguars fan Geek Blog: www.sharepointlonghorn.com On the Twitters: @sharepointlhorn GitHub: www.github.com/jasonhimmelstein

Agenda History lesson Defining Terminology Active Directory Core Concepts & Concerns Topology & Security Use Cases Homework

History lesson

History lesson The dark days SharePoint 2003 & 2007

History lesson Age of enlightenment - SharePoint 2010

History lesson Age of the Internet - SharePoint 2013

Defining Terminology

Defining Terminology Active Directory DirSync User Principal Name ADFS Azure Active Directory Azure AD Connect Identity as a Service

Azure AD Connect: Your Identity Bridge Azure AD Connect (sync + sign on) LDAP Active Directory

Hybrid Identity management Azure Active Directory Connect Consolidated deployment assistant for your identity bridge components Common monitoring for your identity bridge components

Active Directory Core Concepts & Concerns FSMO roles, AD DNS, WINS, NETBIOS, etc Dirty, dirty directories 2003 (Everyone group) --> 2008 (Authenticated Users group) IsCriticalSystemObject objects not synced (like Domain Users) UPN issues around migration Schema extensions

Topology & Security ADFS vs DirSync Multifactor Auth

Same Sign On scenario

Single Sign On scenario

Highly Available Auth scenario

Use Cases Old environment moving to a new Hybrid Estate New Farm Identities Extranet situations

Pre-requisites for Installing Azure AD Connect Office 365 tenant 1 Registered Domain URL 2 Machines 1 AD Domain Controller (ADDC) Windows 2003 or later 1 Domain member server Windows 2008 or greater But really, Windows 2012 R2

Downloads Package downloads on member server Azure AD Connect http://go.microsoft.com/fwlink/?linkid=615771&clcid=0x409 PowerShell Bits Windows PowerShell cmdlets for Office 365 management and deployment https://www.microsoft.com/en-us/download/details.aspx?id=35588 Microsoft Online Services Sign-In Assistant for IT Professionals RTW http://www.microsoft.com/en-us/download/details.aspx?id=41950 Azure AD Module for Windows PowerShell http://go.microsoft.com/fwlink/p/?linkid=236297

CSSA (The Cloud Search Service Application) Introduced in the August 2015 CU for SharePoint 2013 Combines on-prem Search index and SharePoint Online Search Not Federation Search results are not separated Does not require a Search index on-prem Allows cloud services to include on-prem content Getting Comfortable with the new hybrid Cloud Search Service in SharePoint 2013

What are we can do It s not over complicating things it s fun! Using PowerShell to manage Office 365 How screw up and lose friends Tales of woe from the field & what not to do Licensing a cat Creating accounts, syncing them & applying licenses

Param( ) [Parameter(Mandatory=$true)] [ValidateNotNullOrEmpty()] [string] $User Real world example # Add the Active Directory bits and not complain if they're already there Import-Module ActiveDirectory -ErrorAction SilentlyContinue

# Add the Azure Active Directory module Import-Module MSOnline # Define AD group that is synced to AAD and is used for ODFB audience $syncgroupname = "CloudSync" $syncgroup =Get-ADGroup $syncgroupname

# Location to AAD Connect manual sync EXE $syncclient = "C:\Program Files\Microsoft Azure AD Sync\Bin\DirectorySyncClientCmd.exe" # Name of the Azure License to apply $license = "reseller-account:enterprisepack"

# Azure AD domain suffix $aadsuffix = "rackhybrid4.com" # First, add the user to the group Add-ADGroupMember -Identity $syncgroupname - Members $User # Remind them to recompile their SharePoint audience Write-Host "You'll need to recompile your SharePoint audience to reflect the group change"

# Sync up to Azure AD & $syncclient # Now tweak the user in Azure AD # First connect Connect-MsolService # Get the user $aaduser = "$user@$aadsuffix"

# Set the user's location. Without that the license will fail Set-MsolUser -UserPrincipalName $aaduser - UsageLocation "US" # Set the user's license Set-MsolUserLicense -UserPrincipalName $aaduser - AddLicenses $license

MIM (Microsoft Identity Management) The next version of FIM ILM MIIS What are they trying to hide? Better cloud and Windows 10 & 2016 support Don t upgrade SharePoint FIM AD Team Blog Post

The Hybrid Picker Helps you configure your hybrid options Requires August 2015 CU Shows up in Admin Tenant Console Plan for the SharePoint Hybrid Picker

Links For Clicking The Microsoft Cloud Show episode on Azure AD dev

Q & A