20160400 technet- hybrid identity and access management with azure ad premium

26
IT Pro Webinar Microsoft Robin Vermeirsch Sr. IT consultant | XYLOS [email protected] @rovr_xylos Hybrid Identity & Access Management Azure Active Directory (Premium)

Upload: robin-vermeirsch

Post on 14-Apr-2017

83 views

Category:

Presentations & Public Speaking


0 download

TRANSCRIPT

Page 1: 20160400 Technet- Hybrid identity and access management with Azure AD Premium

IT Pro WebinarMicrosoft

Robin VermeirschSr. IT consultant | [email protected]@rovr_xylos

Hybrid Identity & Access ManagementAzure Active Directory (Premium)

Page 2: 20160400 Technet- Hybrid identity and access management with Azure AD Premium

Introduction

Azure Active Directory

Page 3: 20160400 Technet- Hybrid identity and access management with Azure AD Premium

Cloud security in a changing world

• Slow IT can drive business to cloud

• Rise of shadow IT through acquired cloud functionalities

• Securing data & identities end-to-end becomes a real challenge

• IT needs to adapt and we need tooling that can help us

Page 4: 20160400 Technet- Hybrid identity and access management with Azure AD Premium
Page 5: 20160400 Technet- Hybrid identity and access management with Azure AD Premium
Page 6: 20160400 Technet- Hybrid identity and access management with Azure AD Premium

Overview Azure AD IDaaS

Azure Active Directory

Page 7: 20160400 Technet- Hybrid identity and access management with Azure AD Premium

Azure AD Premium

Secure hybrid Identity Platform

Hybrid Application Integration

Self ServiceCapabilities

Next Gen Logging & Reporting

Azure AD

Page 8: 20160400 Technet- Hybrid identity and access management with Azure AD Premium

Azure AD Premium

Secure hybrid Identity Platform

Application Integration

Self ServiceCapabilities

Next Gen Logging & Reporting

Azure AD

Page 9: 20160400 Technet- Hybrid identity and access management with Azure AD Premium

Lab setup

²

CLT01 (BYOD)

Azure AD

Azure AD Connect

SYNC Identities (+passwords)Self Servicing (Groups + Passwords)

DC01

APP02(Inventory Application)

SaaS Applications

Web Server(WordPress)

APP03(Azure AD Proxy

Azure MFA)

Page 10: 20160400 Technet- Hybrid identity and access management with Azure AD Premium

Demo

Azure AD Premium

Page 11: 20160400 Technet- Hybrid identity and access management with Azure AD Premium

Secure hybrid Identity Platform

• Bring active directory identities to the cloud

• Provisioning of AD groups/devices/membership

• Extensive support for complex federation/synchronization• Multi forest• Mix Cloud & Synced Identities• Password Sync vs on premise authentication• Support for Exchange hybrid

Page 12: 20160400 Technet- Hybrid identity and access management with Azure AD Premium

Azure AD Premium

Secure hybrid Identity Platform

Application Integration

Self ServiceCapabilities

Next Gen Logging & Reporting

Azure AD

Page 13: 20160400 Technet- Hybrid identity and access management with Azure AD Premium

How does it work?²

BYOD

AAD JOIN

On Prem APPAD

Azure AD

SaaS Applications

Token based authentication

Azure AD Connect

SYNC Identities (+passwords)Self Servicing (Groups + Passwords) SSO (Azure)

SSO (Azure)

Company Laptop

SSO (Kerberos)

SSO (ADFS)

Win10 only

Page 14: 20160400 Technet- Hybrid identity and access management with Azure AD Premium

Demo

Azure AD Premium

Page 15: 20160400 Technet- Hybrid identity and access management with Azure AD Premium

Application Integration

• Quickly integrate SaaS applications

• Publish and secure on premise applications

• Unified platform for security and access policies

• Allow easy access for end users

• Context aware authentication policies

Page 16: 20160400 Technet- Hybrid identity and access management with Azure AD Premium

Azure AD Premium

Secure hybrid Identity Platform

Application Integration

Self ServiceCapabilities

Next Gen Logging & Reporting

Azure AD

Page 17: 20160400 Technet- Hybrid identity and access management with Azure AD Premium

Demo

Azure AD Premium

Page 18: 20160400 Technet- Hybrid identity and access management with Azure AD Premium

Self Service Capabilities

• Allow approval based group management• In the cloud• On premise (with sync back)

• Allow approval based application access (within portal)

• Allow self service passwords resets

Page 19: 20160400 Technet- Hybrid identity and access management with Azure AD Premium

Azure AD Premium

Secure hybrid Identity Platform

Application Integration

Self ServiceCapabilities

Next Gen Logging & Reporting

Azure AD

Page 20: 20160400 Technet- Hybrid identity and access management with Azure AD Premium

Demo

Azure AD Premium

Page 21: 20160400 Technet- Hybrid identity and access management with Azure AD Premium

Next Gen Logging & Reporting

• Reports about application access and usage

• Integration with on premise Microsoft Identity Manager

• Integration with ADFS (AAD Connect Health)

• Supports B2B and B2C

• Anomalous Activity Reporting using machine learning

Page 22: 20160400 Technet- Hybrid identity and access management with Azure AD Premium

Preview Features

• Support for other identities• B2B• B2C

• Azure AD Connect for Azure VM’s

• Azure AD Identity protection

• Privilege Identity Management

• Administrative Units

Page 23: 20160400 Technet- Hybrid identity and access management with Azure AD Premium

Some Extras

• Microsoft Identity Manager included for free

• Included in the Enterprise Mobility Suite

• Cloud App Discovery

Page 24: 20160400 Technet- Hybrid identity and access management with Azure AD Premium

Future

• More integration with hybrid deployments

• Release of Cloud App Security (Former Addalom) – 1st April

• More:• https://blogs.technet.microsoft.com/ad/• https://azure.microsoft.com/en-us/blog/topics/identity-access-management/• https://www.microsoft.com/en-us/server-cloud/roadmap/

Page 25: 20160400 Technet- Hybrid identity and access management with Azure AD Premium

Questions?

Azure AD

Page 26: 20160400 Technet- Hybrid identity and access management with Azure AD Premium

Thank you

Robin VermeirschConsultant

[email protected]

@rovr_xylos

https://be.linkedin.com/in/robinver

www.xylos.com