azr209. r2-identity-management-for-hybrid-it.aspx

39
Identity and Windows Azure Rory Braybrook AZR209

Upload: logan-wells

Post on 05-Jan-2016

215 views

Category:

Documents


1 download

TRANSCRIPT

Page 1: AZR209.  r2-identity-management-for-hybrid-it.aspx

Identity and Windows Azure

Rory Braybrook AZR209

Page 2: AZR209.  r2-identity-management-for-hybrid-it.aspx
Page 3: AZR209.  r2-identity-management-for-hybrid-it.aspx

AAD allows you to move your I&AM to the cloud and

manage access to both cloud and

on-premise resources

Page 4: AZR209.  r2-identity-management-for-hybrid-it.aspx

AAD

ACS

Graph

APIADAL

SSO

Overview

Page 5: AZR209.  r2-identity-management-for-hybrid-it.aspx

AAD ≠ ADin cloud

ADD ≠ AD in Azure VM

AD AAD

Page 6: AZR209.  r2-identity-management-for-hybrid-it.aspx

ADAD Domain Services

AD Lightweight Directory Services

AD Federation Services

AD Certificate Services

AD Rights Management Services

Corporate environment

Kerberos, LDAP, DNS

AADAzure Active Directory

Azure Access Control Service

AD RMS (Preview)

Cloud

REST, SAML-P, WS-Federation, OAuth, Graph API

Page 7: AZR209.  r2-identity-management-for-hybrid-it.aspx

http://blogs.technet.com/b/in_the_cloud/archive/2013/08/09/what-s-new-in-2012-r2-identity-management-for-hybrid-it.aspx

Page 8: AZR209.  r2-identity-management-for-hybrid-it.aspx

AAD – one size fits all

Small companies Main repository

Large companiesProjection of on-premise AD

Page 9: AZR209.  r2-identity-management-for-hybrid-it.aspx

Concepts

Security Token Service

Claims-based application

Identity Provider

Service Provider

Windows Identity Foundation

Federation

Page 10: AZR209.  r2-identity-management-for-hybrid-it.aspx

Office 365SharePoint

Online

Exchange Online

Lync Online

AAD

Page 11: AZR209.  r2-identity-management-for-hybrid-it.aspx

Users

Attributes

Authentication

AADtargets

Page 12: AZR209.  r2-identity-management-for-hybrid-it.aspx

Printers

Management

of devices

AADdoesn’t support

Group policy

Page 13: AZR209.  r2-identity-management-for-hybrid-it.aspx

AAD supports SaaS

Googledocs

Sales force

Dropbox

GitHub

Skype

Yammer

Skydrive

Box

And many others …

Page 14: AZR209.  r2-identity-management-for-hybrid-it.aspx

AD is hierarchical

C# API

Based on

Use

Page 15: AZR209.  r2-identity-management-for-hybrid-it.aspx

ADD is not hierarchical

Graph API based on REST

Based on

Use

Graph Theory

Page 16: AZR209.  r2-identity-management-for-hybrid-it.aspx

Management

Customer

Looks after

Tenant

Data

Microsoft

Supports infrastructure

Page 17: AZR209.  r2-identity-management-for-hybrid-it.aspx

Demo

Lap around the AAD Portal

Page 18: AZR209.  r2-identity-management-for-hybrid-it.aspx

From: Microsoft – Active Directory from on-premises to the cloud

Page 19: AZR209.  r2-identity-management-for-hybrid-it.aspx

AAD is an ever moving target

Initial samples uses PowerShell

Later samples Tools & wizards

Authentication - currently no charge (other than MFA)

Page 20: AZR209.  r2-identity-management-for-hybrid-it.aspx

Demo

VS 2012 – AAD Tooling

Page 21: AZR209.  r2-identity-management-for-hybrid-it.aspx
Page 22: AZR209.  r2-identity-management-for-hybrid-it.aspx
Page 23: AZR209.  r2-identity-management-for-hybrid-it.aspx
Page 24: AZR209.  r2-identity-management-for-hybrid-it.aspx
Page 25: AZR209.  r2-identity-management-for-hybrid-it.aspx

Federate AD and AAD using ADFS

ADFS

Repository (e.g. AD) attributes can be configured in a variety of ways

Claims rules language for manipulating attributes

Allow / deny access

AAD

Fixed set - others can be extracted via the Graph API

No functionality

No functionality

Page 26: AZR209.  r2-identity-management-for-hybrid-it.aspx

Synchronise or Federate?Dirsync

A single server is needed

Simple architecture

Same Sign On - users will be prompted for credentials when accessing Office 365

ADFSRedundant and scaled out ADFS servers

ADFS Proxies, load balancers, certificate management are required

Single Sign On (SSO)

Page 27: AZR209.  r2-identity-management-for-hybrid-it.aspx

http://technet.microsoft.com/en-us/library/jj573650.aspx

Page 28: AZR209.  r2-identity-management-for-hybrid-it.aspx

Manipulate AAD using Graph API

AAD Use token in REST call to

graph endpoint

Token issue

d

Use OAuth endpoint to get token

Page 29: AZR209.  r2-identity-management-for-hybrid-it.aspx

Graph API REST interface

Create

Read

Update

Delete

POST

GET

PATCH

DELETE

Page 30: AZR209.  r2-identity-management-for-hybrid-it.aspx

Demo

Graph Explorer

Page 31: AZR209.  r2-identity-management-for-hybrid-it.aspx

AAL now ADAL

AAL(In cloud)Tenants

Namespaces

ADAL

ADFS2012 R2

(On premise)OAuth2

JWT

AAL(In cloud)Tenants

Namespaces

Page 32: AZR209.  r2-identity-management-for-hybrid-it.aspx

AAD handles demand

Since2010

200 BillionAuthenticationsprocessed

50 MillionActive user accounts

Average

week

4.7 BillionAuthenticationrequests

420,000Different domains

2 minutes 1 Million authentications processed

1 second Receives 9,000 requests

0.7 second per authentication

for

in

Page 33: AZR209.  r2-identity-management-for-hybrid-it.aspx

Demo

SSO

Page 34: AZR209.  r2-identity-management-for-hybrid-it.aspx

AAD allows you to move your I&AM to the cloud and

manage access to both cloud and

on-premise resources

Page 35: AZR209.  r2-identity-management-for-hybrid-it.aspx

ResourcesVittorio Bertocci

Cloud Identity blog - http://www.cloudidentity.com/blog/

Azure blog - http://blogs.msdn.com/b/windowsazure/

Azure Active Directory Graph - http://blogs.msdn.com/b/aadgraphteam/

Active Directory Team blog - http://blogs.technet.com/b/ad/

.NET Web Development and Tools blog - http://blogs.msdn.com/b/webdev/

Page 36: AZR209.  r2-identity-management-for-hybrid-it.aspx

Related contentOther Identity topics

ARC312 The Identity Jigsaw PuzzleMDC320 The Business Mechanix “Bourne Identity” OUC204 Overview of Microsoft Office 365 Identity Management

Find Me LaterAround and about TechEd

Page 37: AZR209.  r2-identity-management-for-hybrid-it.aspx

Every Windows Azure session you attendgives youa chanceto win thisepic t-shirt.We’re givingaway one perAzure session.

Sharks with freakin’

lasers as a Service.

Only on Windows Azure.

Page 38: AZR209.  r2-identity-management-for-hybrid-it.aspx

Evaluate this session and you could win instantly!

Head to...aka.ms/te

Page 39: AZR209.  r2-identity-management-for-hybrid-it.aspx

© 2013 Microsoft Corporation. All rights reserved.Microsoft, Windows and other product names are or may be registered trademarks and/or trademarks in the U.S. and/or other countries.MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.