SlideShare una empresa de Scribd logo
1 de 36
Scenario Based Overview
Azure AD Premium
Today’s session
• Scenario based overview of what Azure AD Premium has to offer
• Technical overview of presented scenario’s
• Demo of each of the scenario’s
• Q&A about Azure AD Premium
Scenario’s
1. Can I have a secure platform for all my SaaS applications?
2. How can I provide SSO for my users
• For my internal users
• In a BYOD world
• For partners
3. Can leverage the platform for my current applications?
Scenario’s
4. Can I implement additional security to the platform?
5. Can I leverage the platform for my own applications and API’s?
6. How can I monitoring and audit trials for all my applications?
It’s all about your identity
Demo LAB
On Premise
²
CLT01 (BYOD)
Azure AD
MGMT01
(Azure AD Connect + PTA +
Legacy App)
SYNC Identities (+passwords)
Self Servicing (Groups + Passwords)
DC01
SaaS Applications
Web Server
(WordPress)
MGMT02
(Azure AD Proxy)
Azure
Azure Domain Service
AD Services
For Azure
DS-TEST
(Legacy AD Integrated App)
Can I have a secure platform for
all my SaaS applications?
DEMO 1
How can I provide SSO for my
users?
Sign-in Options Today
Complexity
Value
Cloud only
Accounts
AAD Connect
+ AD FS
SSO + NO PWD
AAD Connect
Cloud Accounts
AAD Connect
+ PHS
Pass Trough Authentication
Contoso Corpnet
AAD STS
AD App
Proxy
1 2
3
4
5
6
78
Connector
2
5
SSO
Contoso Corpnet
AAD STS
12
3
6
4
Sign-in Options (Future)
Complexity
Value
Cloud only
Accounts
AAD Connect
+ AD FS
SSOAAD Connect
+ PTA and SSO
AAD Connect
+ PHS and SSO
AAD Connect
Cloud Accounts
AAD Connect
+ PHS
SSO For BYOD
• User get’s Primary Refresh Token (PRT)
• Contains user AND device claims
• Can be checked using: dsregcmd.exe /status
• Limited browser support (Web Account Manager API)
• Edge
• Iexplore
• Works with Windows Hello for Business
SSO – Side note
• SSO in AAD always requires identification
 FIX: Use domain hints
- OpenID: add &domain_hint=demolab.be
- WSFed: add &whr=demolab.be
- SAML: Use AuthN
- ADAL: Pass domain_hint
DEMO 2
Can leverage the platform for
my current applications?
AD Services for Azure resources
AD Services for Azure resources
• Drawbacks
• Needs PHS
• Flat structure (no OU’s)
• Limited GPO’s
• No trust between on-prem AD and cloud AD
• Will give you
• LDAP/AD functionality for your (legacy) Azure workloads
Access on prem applications
Azure Active Directory
Corporate
Network
DMZ
Connector
Application Proxy
https://whoami.demolab.be
http://whoami
Connector
Access on prem applications
Azure Active Directory
Corporate
Network
DMZ
Connector
Application Proxy
https://whoami.demolab.be
http://whoami.
Connector
Access on prem applications
Azure Active Directory
Corporate
Network
DMZ
Connector
Application Proxy
https://whoami.demolab.be
http://whoami.
Connector
SAML
Domain
Controller
SSO for on prem applications
Azure Active Directory
Corporate
Network
DMZ
Connector
Application Proxy
https://whoami.demolab.be
http://whoami.
Connector
SAML
Domain
Controller
SSO for on prem applications
Azure Active Directory
Corporate
Network
DMZ
Connector
Application Proxy
https://whoami.demolab.be
http://whoami.
Connector
SAML
Domain
Controller
Get token (KCD)
SSO for on prem applications
Azure Active Directory
Corporate
Network
DMZ
Connector
Application Proxy
https://whoami.demolab.be
http://whoami.
Connector
SAML
Domain
Controller
Get token (KCD)
SSO for on prem applications
Azure Active Directory
Corporate
Network
DMZ
Connector
Application Proxy
https://whoami.demolab.be
http://whoami.
Connector
SAML
Domain
Controller
Kerberos
Get token (KCD)
DEMO 3
Can I implement additional
security to the platform?
AAD Premium
MFA
Identity
Protection
Conditional
Access
Self Service
PWD Reset
Governance
Tooling
DEMO 4
Can I leverage the platform for
my own applications and API’s?
DEMO 5
How can I have monitoring and
audit trials for my (cloud)
applications?
DEMO 6
Questions
Thank you
Robin Vermeirsch
rovr@xylos.com
Twitter: rovr_xylos

Más contenido relacionado

Último

Bring back lost lover in USA, Canada ,Uk ,Australia ,London Lost Love Spell C...
Bring back lost lover in USA, Canada ,Uk ,Australia ,London Lost Love Spell C...Bring back lost lover in USA, Canada ,Uk ,Australia ,London Lost Love Spell C...
Bring back lost lover in USA, Canada ,Uk ,Australia ,London Lost Love Spell C...
amilabibi1
 
If this Giant Must Walk: A Manifesto for a New Nigeria
If this Giant Must Walk: A Manifesto for a New NigeriaIf this Giant Must Walk: A Manifesto for a New Nigeria
If this Giant Must Walk: A Manifesto for a New Nigeria
Kayode Fayemi
 
Chiulli_Aurora_Oman_Raffaele_Beowulf.pptx
Chiulli_Aurora_Oman_Raffaele_Beowulf.pptxChiulli_Aurora_Oman_Raffaele_Beowulf.pptx
Chiulli_Aurora_Oman_Raffaele_Beowulf.pptx
raffaeleoman
 
Uncommon Grace The Autobiography of Isaac Folorunso
Uncommon Grace The Autobiography of Isaac FolorunsoUncommon Grace The Autobiography of Isaac Folorunso
Uncommon Grace The Autobiography of Isaac Folorunso
Kayode Fayemi
 

Último (18)

Dreaming Marissa Sánchez Music Video Treatment
Dreaming Marissa Sánchez Music Video TreatmentDreaming Marissa Sánchez Music Video Treatment
Dreaming Marissa Sánchez Music Video Treatment
 
Dreaming Music Video Treatment _ Project & Portfolio III
Dreaming Music Video Treatment _ Project & Portfolio IIIDreaming Music Video Treatment _ Project & Portfolio III
Dreaming Music Video Treatment _ Project & Portfolio III
 
Report Writing Webinar Training
Report Writing Webinar TrainingReport Writing Webinar Training
Report Writing Webinar Training
 
ICT role in 21st century education and it's challenges.pdf
ICT role in 21st century education and it's challenges.pdfICT role in 21st century education and it's challenges.pdf
ICT role in 21st century education and it's challenges.pdf
 
Digital collaboration with Microsoft 365 as extension of Drupal
Digital collaboration with Microsoft 365 as extension of DrupalDigital collaboration with Microsoft 365 as extension of Drupal
Digital collaboration with Microsoft 365 as extension of Drupal
 
Bring back lost lover in USA, Canada ,Uk ,Australia ,London Lost Love Spell C...
Bring back lost lover in USA, Canada ,Uk ,Australia ,London Lost Love Spell C...Bring back lost lover in USA, Canada ,Uk ,Australia ,London Lost Love Spell C...
Bring back lost lover in USA, Canada ,Uk ,Australia ,London Lost Love Spell C...
 
Thirunelveli call girls Tamil escorts 7877702510
Thirunelveli call girls Tamil escorts 7877702510Thirunelveli call girls Tamil escorts 7877702510
Thirunelveli call girls Tamil escorts 7877702510
 
AWS Data Engineer Associate (DEA-C01) Exam Dumps 2024.pdf
AWS Data Engineer Associate (DEA-C01) Exam Dumps 2024.pdfAWS Data Engineer Associate (DEA-C01) Exam Dumps 2024.pdf
AWS Data Engineer Associate (DEA-C01) Exam Dumps 2024.pdf
 
If this Giant Must Walk: A Manifesto for a New Nigeria
If this Giant Must Walk: A Manifesto for a New NigeriaIf this Giant Must Walk: A Manifesto for a New Nigeria
If this Giant Must Walk: A Manifesto for a New Nigeria
 
My Presentation "In Your Hands" by Halle Bailey
My Presentation "In Your Hands" by Halle BaileyMy Presentation "In Your Hands" by Halle Bailey
My Presentation "In Your Hands" by Halle Bailey
 
Chiulli_Aurora_Oman_Raffaele_Beowulf.pptx
Chiulli_Aurora_Oman_Raffaele_Beowulf.pptxChiulli_Aurora_Oman_Raffaele_Beowulf.pptx
Chiulli_Aurora_Oman_Raffaele_Beowulf.pptx
 
Uncommon Grace The Autobiography of Isaac Folorunso
Uncommon Grace The Autobiography of Isaac FolorunsoUncommon Grace The Autobiography of Isaac Folorunso
Uncommon Grace The Autobiography of Isaac Folorunso
 
Busty Desi⚡Call Girls in Sector 51 Noida Escorts >༒8448380779 Escort Service-...
Busty Desi⚡Call Girls in Sector 51 Noida Escorts >༒8448380779 Escort Service-...Busty Desi⚡Call Girls in Sector 51 Noida Escorts >༒8448380779 Escort Service-...
Busty Desi⚡Call Girls in Sector 51 Noida Escorts >༒8448380779 Escort Service-...
 
lONG QUESTION ANSWER PAKISTAN STUDIES10.
lONG QUESTION ANSWER PAKISTAN STUDIES10.lONG QUESTION ANSWER PAKISTAN STUDIES10.
lONG QUESTION ANSWER PAKISTAN STUDIES10.
 
Aesthetic Colaba Mumbai Cst Call girls 📞 7738631006 Grant road Call Girls ❤️-...
Aesthetic Colaba Mumbai Cst Call girls 📞 7738631006 Grant road Call Girls ❤️-...Aesthetic Colaba Mumbai Cst Call girls 📞 7738631006 Grant road Call Girls ❤️-...
Aesthetic Colaba Mumbai Cst Call girls 📞 7738631006 Grant road Call Girls ❤️-...
 
The workplace ecosystem of the future 24.4.2024 Fabritius_share ii.pdf
The workplace ecosystem of the future 24.4.2024 Fabritius_share ii.pdfThe workplace ecosystem of the future 24.4.2024 Fabritius_share ii.pdf
The workplace ecosystem of the future 24.4.2024 Fabritius_share ii.pdf
 
Sector 62, Noida Call girls :8448380779 Noida Escorts | 100% verified
Sector 62, Noida Call girls :8448380779 Noida Escorts | 100% verifiedSector 62, Noida Call girls :8448380779 Noida Escorts | 100% verified
Sector 62, Noida Call girls :8448380779 Noida Escorts | 100% verified
 
Causes of poverty in France presentation.pptx
Causes of poverty in France presentation.pptxCauses of poverty in France presentation.pptx
Causes of poverty in France presentation.pptx
 

Destacado

How Race, Age and Gender Shape Attitudes Towards Mental Health
How Race, Age and Gender Shape Attitudes Towards Mental HealthHow Race, Age and Gender Shape Attitudes Towards Mental Health
How Race, Age and Gender Shape Attitudes Towards Mental Health
ThinkNow
 
Social Media Marketing Trends 2024 // The Global Indie Insights
Social Media Marketing Trends 2024 // The Global Indie InsightsSocial Media Marketing Trends 2024 // The Global Indie Insights
Social Media Marketing Trends 2024 // The Global Indie Insights
Kurio // The Social Media Age(ncy)
 

Destacado (20)

2024 State of Marketing Report – by Hubspot
2024 State of Marketing Report – by Hubspot2024 State of Marketing Report – by Hubspot
2024 State of Marketing Report – by Hubspot
 
Everything You Need To Know About ChatGPT
Everything You Need To Know About ChatGPTEverything You Need To Know About ChatGPT
Everything You Need To Know About ChatGPT
 
Product Design Trends in 2024 | Teenage Engineerings
Product Design Trends in 2024 | Teenage EngineeringsProduct Design Trends in 2024 | Teenage Engineerings
Product Design Trends in 2024 | Teenage Engineerings
 
How Race, Age and Gender Shape Attitudes Towards Mental Health
How Race, Age and Gender Shape Attitudes Towards Mental HealthHow Race, Age and Gender Shape Attitudes Towards Mental Health
How Race, Age and Gender Shape Attitudes Towards Mental Health
 
AI Trends in Creative Operations 2024 by Artwork Flow.pdf
AI Trends in Creative Operations 2024 by Artwork Flow.pdfAI Trends in Creative Operations 2024 by Artwork Flow.pdf
AI Trends in Creative Operations 2024 by Artwork Flow.pdf
 
Skeleton Culture Code
Skeleton Culture CodeSkeleton Culture Code
Skeleton Culture Code
 
PEPSICO Presentation to CAGNY Conference Feb 2024
PEPSICO Presentation to CAGNY Conference Feb 2024PEPSICO Presentation to CAGNY Conference Feb 2024
PEPSICO Presentation to CAGNY Conference Feb 2024
 
Content Methodology: A Best Practices Report (Webinar)
Content Methodology: A Best Practices Report (Webinar)Content Methodology: A Best Practices Report (Webinar)
Content Methodology: A Best Practices Report (Webinar)
 
How to Prepare For a Successful Job Search for 2024
How to Prepare For a Successful Job Search for 2024How to Prepare For a Successful Job Search for 2024
How to Prepare For a Successful Job Search for 2024
 
Social Media Marketing Trends 2024 // The Global Indie Insights
Social Media Marketing Trends 2024 // The Global Indie InsightsSocial Media Marketing Trends 2024 // The Global Indie Insights
Social Media Marketing Trends 2024 // The Global Indie Insights
 
Trends In Paid Search: Navigating The Digital Landscape In 2024
Trends In Paid Search: Navigating The Digital Landscape In 2024Trends In Paid Search: Navigating The Digital Landscape In 2024
Trends In Paid Search: Navigating The Digital Landscape In 2024
 
5 Public speaking tips from TED - Visualized summary
5 Public speaking tips from TED - Visualized summary5 Public speaking tips from TED - Visualized summary
5 Public speaking tips from TED - Visualized summary
 
ChatGPT and the Future of Work - Clark Boyd
ChatGPT and the Future of Work - Clark Boyd ChatGPT and the Future of Work - Clark Boyd
ChatGPT and the Future of Work - Clark Boyd
 
Getting into the tech field. what next
Getting into the tech field. what next Getting into the tech field. what next
Getting into the tech field. what next
 
Google's Just Not That Into You: Understanding Core Updates & Search Intent
Google's Just Not That Into You: Understanding Core Updates & Search IntentGoogle's Just Not That Into You: Understanding Core Updates & Search Intent
Google's Just Not That Into You: Understanding Core Updates & Search Intent
 
How to have difficult conversations
How to have difficult conversations How to have difficult conversations
How to have difficult conversations
 
Introduction to Data Science
Introduction to Data ScienceIntroduction to Data Science
Introduction to Data Science
 
Time Management & Productivity - Best Practices
Time Management & Productivity -  Best PracticesTime Management & Productivity -  Best Practices
Time Management & Productivity - Best Practices
 
The six step guide to practical project management
The six step guide to practical project managementThe six step guide to practical project management
The six step guide to practical project management
 
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
 

20161103 Cloud Brew - Microsoft Azure Active Directory Premium

  • 2. Today’s session • Scenario based overview of what Azure AD Premium has to offer • Technical overview of presented scenario’s • Demo of each of the scenario’s • Q&A about Azure AD Premium
  • 3. Scenario’s 1. Can I have a secure platform for all my SaaS applications? 2. How can I provide SSO for my users • For my internal users • In a BYOD world • For partners 3. Can leverage the platform for my current applications?
  • 4. Scenario’s 4. Can I implement additional security to the platform? 5. Can I leverage the platform for my own applications and API’s? 6. How can I monitoring and audit trials for all my applications?
  • 5. It’s all about your identity
  • 6. Demo LAB On Premise ² CLT01 (BYOD) Azure AD MGMT01 (Azure AD Connect + PTA + Legacy App) SYNC Identities (+passwords) Self Servicing (Groups + Passwords) DC01 SaaS Applications Web Server (WordPress) MGMT02 (Azure AD Proxy) Azure Azure Domain Service AD Services For Azure DS-TEST (Legacy AD Integrated App)
  • 7. Can I have a secure platform for all my SaaS applications?
  • 9. How can I provide SSO for my users?
  • 10. Sign-in Options Today Complexity Value Cloud only Accounts AAD Connect + AD FS SSO + NO PWD AAD Connect Cloud Accounts AAD Connect + PHS
  • 11. Pass Trough Authentication Contoso Corpnet AAD STS AD App Proxy 1 2 3 4 5 6 78 Connector 2
  • 13. Sign-in Options (Future) Complexity Value Cloud only Accounts AAD Connect + AD FS SSOAAD Connect + PTA and SSO AAD Connect + PHS and SSO AAD Connect Cloud Accounts AAD Connect + PHS
  • 14. SSO For BYOD • User get’s Primary Refresh Token (PRT) • Contains user AND device claims • Can be checked using: dsregcmd.exe /status • Limited browser support (Web Account Manager API) • Edge • Iexplore • Works with Windows Hello for Business
  • 15. SSO – Side note • SSO in AAD always requires identification  FIX: Use domain hints - OpenID: add &domain_hint=demolab.be - WSFed: add &whr=demolab.be - SAML: Use AuthN - ADAL: Pass domain_hint
  • 17. Can leverage the platform for my current applications?
  • 18. AD Services for Azure resources
  • 19. AD Services for Azure resources • Drawbacks • Needs PHS • Flat structure (no OU’s) • Limited GPO’s • No trust between on-prem AD and cloud AD • Will give you • LDAP/AD functionality for your (legacy) Azure workloads
  • 20. Access on prem applications Azure Active Directory Corporate Network DMZ Connector Application Proxy https://whoami.demolab.be http://whoami Connector
  • 21. Access on prem applications Azure Active Directory Corporate Network DMZ Connector Application Proxy https://whoami.demolab.be http://whoami. Connector
  • 22. Access on prem applications Azure Active Directory Corporate Network DMZ Connector Application Proxy https://whoami.demolab.be http://whoami. Connector SAML Domain Controller
  • 23. SSO for on prem applications Azure Active Directory Corporate Network DMZ Connector Application Proxy https://whoami.demolab.be http://whoami. Connector SAML Domain Controller
  • 24. SSO for on prem applications Azure Active Directory Corporate Network DMZ Connector Application Proxy https://whoami.demolab.be http://whoami. Connector SAML Domain Controller Get token (KCD)
  • 25. SSO for on prem applications Azure Active Directory Corporate Network DMZ Connector Application Proxy https://whoami.demolab.be http://whoami. Connector SAML Domain Controller Get token (KCD)
  • 26. SSO for on prem applications Azure Active Directory Corporate Network DMZ Connector Application Proxy https://whoami.demolab.be http://whoami. Connector SAML Domain Controller Kerberos Get token (KCD)
  • 28. Can I implement additional security to the platform?
  • 31. Can I leverage the platform for my own applications and API’s?
  • 33. How can I have monitoring and audit trials for my (cloud) applications?

Notas del editor

  1. AAD brings you secure to access cloud and on premise applications with: Single identity Self service capabilities SSO experience  In a secure way - according to today’s enterprise standards
  2. Content Self servicing Add applications Add-In Wordpress
  3. Content Self servicing Add applications WordPress
  4. User Enters username into the login box. Optionally domain or User can be populated via accelerators User gets a 401 Challenge User contacts the DC for a Kerberos ticket for the SPN DC returns Kerberos ticket Client sends the Kerberos ticket to AAD STS AAD Validates the Kerberos ticket and returns a token
  5. https://jairocadena.com/2016/11/08/how-sso-works-in-windows-10-devices/ Troubleshooting: dsregcmd.exe /status
  6. DEMO PTA SSO (Kerberos) Desktop SSO BYOD
  7. DEMO *
  8. Graph API Reports