Hybrid Cloud Identity and Access Management Challenges



Similar documents
SINGLE & SAME SIGN-ON ASPECTS

Implementing Microsoft Azure Infrastructure Solutions

Course 20533: Implementing Microsoft Azure Infrastructure Solutions

Bill Fiddes Learning and Development Specialist Rob Latino Program Manager in Office 365 Support

Microsoft Azure for IT Professionals 55065A; 3 days

Cloud Computing. Chapter 1 Introducing Cloud Computing

AZP: Microsoft Azure Infrastructure for IT Professional

Cloud Computing. Chapter 1 Introducing Cloud Computing

Where are Organizations Today? The Cloud. The Current and Future State of IT When, Where, and How To Leverage the Cloud. The Cloud and the Players

MS 20532B - Developing Microsoft Azure Solutions

Implementing Microsoft Azure Infrastructure Solutions 20533B; 5 Days, Instructor-led

WHITEPAPER. 13 Questions You Must Ask When Integrating Office 365 With Active Directory

Course 20533B: Implementing Microsoft Azure Infrastructure Solutions

Managing Office 365 Identities and Services

Overview of Microsoft Enterprise Mobility Suite (EMS) Cloud University

Azure Active Directory

Implementing Microsoft Azure Infrastructure Solutions

Windows Server 2012 / Windows 8 Audit Fundamentals

Cloud Computing. Chapter 1 Introducing Cloud Computing

Implementing Microsoft Azure Infrastructure Solutions

Creating a Single Sign on Web Portal using Azure. Robert Crane Office 365

INTEGRATE OFFICE 365 WITH ON-PREMISE ERP

Managing Office 365 Identities and Services 20346C; 5 Days, Instructor-led

Course 20346: Managing Office 365 Identities and Services

Webinar Self-service in Microsoft Azure AD Premium

Managing Office 365 Identities and Services

Cloud Computing Technology

Enterprise Mobility Services

Agenda. Enterprise challenges. Hybrid identity. Mobile device management. Data protection. Offering details

Enterprise Mobility Suite (EMS) Sean Lewis Principal Partner Technology Strategist

Agenda. Federation using ADFS and Extensibility options. Office 365 Identity overview. Federation and Synchronization

CLOUD COMPUTING. A Primer

NCSU SSO. Case Study

Cloud-Accelerated Hybrid Scenarios with SharePoint and Office 365

Public Cloud Offerings and Private Cloud Options. Week 2 Lecture 4. M. Ali Babar

Microsoft SharePoint Architectural Models

Introductions. KPMG Presenters: Jay Schulman - Managing Director, Advisory - KPMG National Leader Identity and Access Management

Cloud Computing An Elephant In The Dark

Cloud SingularLogic:

Daren Kinser Auditor, UCSD Jennifer McDonald Auditor, UCSD

Identity and Access Management for the Hybrid Enterprise

Integrating Active Directory Federation Services (ADFS) with Office 365 through IaaS

1 The intersection of IAM and the cloud

Planning your Microsoft Application Strategy in a Cloud Crazy World. Steve Soper Senior Managing Partner

Security Best Practices for Microsoft Azure Applications

Microsoft Azure Multi-Factor authentication. (Concept Overview Part 1)

Designing for Office 365 Infrastructure

Cloud Platforms in the Enterprise

Microsoft Implementing Microsoft Azure Infrastructure Solutions

Implementing Microsoft Azure Infrastructure Solutions

Session 5. Mixing and matching Public, Private and Hybrid Clouds for maximum benefits

Identity. Provide. ...to Office 365 & Beyond

SHAREPOINT HYBRID AND IMPLICATIONS OF 2016

The Top 3 Identity Management Considerations When Implementing Google Apps for the Enterprise

Extend and Enhance AD FS

Introduction to Cloud Services

Server & Cloud Management

Platforms in the Cloud

Build A private PaaS.

The increasing popularity of mobile devices is rapidly changing how and where we

Ondřej Výšek Sales Lead, Microsoft MVP.

Microsoft Enterprise Mobility Suite

Microsoft Enterprise Mobility Suite

PROVIDING SINGLE SIGN-ON TO AMAZON EC2 APPLICATIONS FROM AN ON-PREMISES WINDOWS DOMAIN

Architectural Implications of Cloud Computing

Cloud Computing. Chapter 1 Introducing Cloud Computing

Course Outline. Microsoft Azure Fundamentals Course 10979A: 2 days Instructor Led. About this Course. Audience Profile. At Course Completion

Cloud Courses Description

Private Cloud 201 How to Build a Private Cloud

VMware on VMware: Private Cloud Case Study Customer Presentation

Virtualization and Cloud Computing

Hybrid Cloud Computing: Security Aspects and Challenges

NE-20247D Configuring and Deploying a Private Cloud

Outline. What is cloud computing? History Cloud service models Cloud deployment forms Advantages/disadvantages

ArcGIS for Server: In the Cloud

Identity & Access Management The Cloud Perspective. Andrea Themistou 08 October 2015

Identity + Mobile Management + Security = Enterprise Mobility Suite

Azure and Its Competitors

Enabling and Managing Office 365

MS 20247C Configuring and Deploying a Private Cloud

Hosting Models. Business Model Software (as a Service) Platform (as a Service) Infrastructure (as a Service) On Premises. Applications. Data.

Three Ways to Integrate Active Directory with Your SaaS Applications OKTA WHITE PAPER. Okta Inc. 301 Brannan Street, Suite 300 San Francisco CA, 94107

Identity and Access Management for the Cloud What You Need to Know About Managing Access to Your Clouds

NCTA Cloud Architecture

How To Compare Cloud Computing To Cloud Platforms And Cloud Computing

Cloud Platforms Today: The Big Picture

White paper Contents

Manage all your Office365 users and licenses

Office365 Adoption eguide. Identity and Mobility Challenges. Okta Inc. 301 Brannan Street San Francisco, CA

White. Paper. Enterprises Need Hybrid SSO Solutions to Bridge Internal IT and SaaS. January 2013

Extending your datacenter to the cloud

Single Sign-on for Office 365, Microsoft Azure and On-Premises Environments:

Total Cost of Ownership Overview ADFS vs OneLogin WHITEPAPER

Transcription:

Hybrid Cloud Identity and Access Management Challenges

Intro: Timothy P. McAliley timothy.mcaliley@microsoft.com Microsoft Premier Field Engineer, SQL Server, Washington, DC CISA, CISM, CISSP, ITIL V3, MCSA, MCSE, MCITP, MCTS, MCT, PMP www.itprocamp.com www.meetup.com/mfcf-dc

Key Take-Aways Know the general definitions of Hybrid Cloud Identity & Access Management Know the challenges of Hybrid Cloud Identity & Access Management

Agenda Cloud Primer What Is Hybrid Identity & Access Management (IAM)? What Are The Challenges Of Hybrid IAM? Example of Hybrid IAM Capabilities From A Cloud Service Provider Resources

Cloud Primer

Cloud Primer Spot Quiz: What Document Provides Key Recommendations for Defining Cloud Computing? Answer: NIST Special Publication 800-145, The NIST Definition of Cloud Computing

Cloud Primer What Is In The NIST SP 800-145, Definition of Cloud Computing? Essential Characteristics: On-demand self-service. Broad network access. Resource pooling. Rapid elasticity. Measured service.

Cloud Primer What Is In The NIST SP 800-145, Definition of Cloud Computing? Service Models: Software as a Service (SaaS) Platform as a Service (PaaS) Infrastructure as a Service (IaaS) Identity and Access Management as a Service (IAMaaS)

Cloud Primer

Cloud Primer What Is In The NIST SP 800-145, Definition of Cloud Computing? Deployment Models: Private Cloud Community Cloud Public Cloud Hybrid Cloud

Cloud Trends By 2015, 50% of all new application independent software vendors will be pure SaaS providers. Through 2015, more than 90% of private cloud computing deployments will be for infrastructure as a service. By 2015, 50% of large global enterprises will rely on external cloud computing services for at least one of their top 10 revenue-generating processes. By 2016, all large global enterprises will use some level of public cloud services. Through 2020, the most common use of cloud services will be a hybrid model combining on-premises and external cloud services. Gartner: Cloud Computing Innovation Key Initiative Overview, 2014

Cloud Providers Amazon - Offerings include Amazon Web Services (AWS). Google - Offerings include the Google Cloud Platform. IBM - Offerings include enabling technologies to build private clouds and services for public cloud applications, platforms and infrastructure. Microsoft - Offerings include Microsoft Azure for public cloud, and Windows Server and Systems Center for private cloud. salesforce.com - Offerings include sales, marketing and customer service application services and platform services. VMware -Offerings include vcloud Hybrid Service for public cloud and the vcloud Suite for private cloud. Gartner: Cloud Computing Innovation Key Initiative Overview, 2014

What Is Microsoft Azure?

What Is Hybrid Identity & Access Management (IAM)?

What Is Hybrid Identity & Access Management (IAM)? Hybrid Identity: Identity solutions which span on-premises and cloud-based capabilities Creating a single user identity for authentication and authorization to all resources, regardless of location. Configuration and Administration of On-Premise and Cloud-Based Account & Authentication Management On-Premise and Cloud-Based Resource Access

What Is Hybrid Identity & Access Management (IAM)?

What Are The Challenges Of Hybrid IAM?

What Are The Challenges Of Hybrid IAM? Gartner Views on Cloud IAM Challenges: Identity management to the cloud being able to send something from the enterprise to the cloud. Identity management from the cloud being able to send something that exists somewhere else, to your organizations. Identity management within the cloud to cloud. Gartner- 2013

What Are The Challenges Of Hybrid IAM? Protection of Organizational Information User Productivity & Mobility The Consumerization of IT / BYOD Account Provisioning/Management Password Synchronization User/Group Change Synchronization Enterprise Access to SaaS Applications Operational Risks

Example of Hybrid IAM Capabilities From A Cloud Service Provider

Example of Hybrid IAM Capabilities From A Cloud Service Provider Microsoft Active Directory Extend On-Premises Active Directory Into the Cloud Azure Active Directory Multi-Factor Authentication

What is Azure Active Directory?

Identity

Identity across multiple devices

Flexible access makes for happy users

Extend On-Premises Active Directory Into the Cloud Azure AD Connect Azure AD Connect is the single tool and guided experience for connecting your on-premises directories with Azure Active Directory Synchronization - This part is made up of the the components and functionality previously released as Dirsync and AAD Sync. This is the part that is responsible for creating users and groups. It is also responsible for making sure that the information on users and groups in your on-premises environment, matches in the cloud. AD FS - This is an optional part of Azure AD Connect and can be used to setup a hybrid environment using an on-premises AD FS infrastructure. This part can be used by organization's to address complex deployments that include such things as domain join SSO, Enforcement of AD login policy and smart card or 3rd party MFA. Health Monitoring - For complex deployments using AD FS, Azure AD Connect Health can provide robust monitoring of your federation servers and provide a central location in the Azure portal to view this activity. NOTE: Dirsync and AAD Sync are longer being released individually, and all future improvements will be included in updates to Azure AD Connect, so that you always know where to get the most current functionality. Until the GA release of Azure AD Connect you can continue use Azure AD Sync for new production deployments.

Extend On-Premises Active Directory Into the Cloud Azure AD Connect

Extend On-Premises Active Directory Into the Cloud Run Domain Controllers on Azure VMs as Part of Your On-Premise AD

Centrally managed identities and access

Common identity with sync & federation

Monitor & protect access to enterprise apps

Monitor & protect access to enterprise apps

What is Azure multi-factor authentication?

How it works

Your directory on the cloud

Selection of pre-integrated SaaS apps

Example workload: single sign-on to 2,400+ SaaS apps

Resources

Resources Gartner: Cloud Computing Innovation Key Initiative Overview, 2014 https://www.gartner.com/doc/2718918?ref=sitesearch&sthkw=cloud&fnl=search&srcid=1-3478922254 GCN Special Report: Breaking Through the Security Cloud http://gcn.com/microsites/2015/snapshot-qts-cybersecurity/03-iam-essential-for-hybridclouds.aspx Microsoft Azure Compliance Portal http://azure.microsoft.com/en-us/support/trust-center/compliance/ Microsoft Azure Handbook http://i.microsoft.com/global/en/in/renderingassets/assets/microsoft-azure-handbook.pdf Microsoft Azure Whitepapers http://www.microsoft.com/en-in/download/details.aspx?id=36391

Resources Microsoft Azure Portal http://azure.microsoft.com Microsoft Virtual Academy Azure Rights Management/Azure Active Directory Courses http://www.microsoftvirtualacademy.com/ Microsoft TechNet Virtual Labs https://technet.microsoft.com/en-us/virtuallabs NIST Special Publication 800-145, The NIST Definition of Cloud Computing http://csrc.nist.gov/publications/nistpubs/800-145/sp800-145.pdf

Summary Cloud Primer What Is Hybrid Identity & Access Management (IAM)? What Are The Challenges Of Hybrid IAM? Example of Hybrid IAM Capabilities From A Cloud Service Provider Resources

Key Take-Aways Know the general definitions of Hybrid Cloud Identity & Access Management Know the challenges of Hybrid Cloud Identity & Access Management

Thank You!!