Sunteți pe pagina 1din 15

August 1, 2019

Azure Active Directory

DXC Proprietary and Confidential


Microsoft Azure Active Directory
 A multi-tenant service that provides enterprise-level identity and
access management for the cloud.
 Manage users and access to cloud resources.
 Extend your on premise Active Directory to the cloud.
 Provide single-sign-on (SSO) across your cloud applications.
 Reduce risks by enabling multi-factor authentication.
 Support development’s need to build secure directory integrated
applications for the enterprise.

DXC Proprietary and Confidential August


August 1, 20192
1, 2019
Windows AD VS Azure AD

DXC Proprietary and Confidential August 1, 2019 3


Azure AD Features

DXC Proprietary and Confidential August 1, 2019 4


Application Access Overview

Software-as-a-Service (SaaS) Applications

Organizations increasingly rely on SaaS applications to support business activities.


Microsoft Azure AD enables easy integration to many of today’s popular SaaS applications, such
as Salesforce, Box, Google Apps, DocuSign, etc.

Tenets of Integrating SaaS Apps w/Microsoft Azure AD

Single Sign-On (SSO) enables users to access their applications using their organizational ID.
Centralized application access management.
Unified monitoring and reporting.

DXC Proprietary and Confidential August 1, 2019 5


Support for Single Sign-On

Federation-based Single Sign-On

Users are automatically signed in to applications using their credentials


from Microsoft Azure AD.

Password-based Single Sign-On


Users are automatically signed in to applications using their credentials
from the 3rd party application

DXC Proprietary and Confidential August 1, 2019 6


Multi-Factor Authentication (MFA)

A method of authentication requiring the use of more than one verification


method to authenticate a user.
Mobile Application
Automated Phone Call
Text Message

How it works?

Requiring any two or more verification methods


Something you know (typically a password)
Something you have (a trusted device that is not easily duplicated, like a
phone)

DXC Proprietary and Confidential August 1, 2019 7


Active Directory Integration with Azure Active
Directory

DXC Proprietary and Confidential August 1, 2019 8


Directory Sync

Synchronizes Users, Groups, and


Contacts to Windows Azure AD.

Users will have a different password in


Windows Azure AD than they have for the
on-premise AD.

DXC Proprietary and Confidential August 1, 2019 9


Azure Active Directory Sync (“AAD Sync”)

Azure Active Directory Sync (“AAD Sync”)


New “One Sync” Tool, replaces DirSync
Available for download

Features
Onboard Multi-Forest Server AD Deployments to Azure AD
Advanced provisioning, mapping and filtering rules
Map multiple on-premises Exchange organizations to a single Azure AD
tenant

DXC Proprietary and Confidential August 1, 2019 10


Running Windows Server AD on
Azure Virtual Machines

DXC Proprietary and Confidential August 1, 2019 11


Why Server AD in a Azure VM

Business Drivers
Support for pre-requisites for existing applications, such as SharePoint.
High Availability Solutions for SQL Server Databases using Always-On Availability
Groups.
Disaster Recovery solution for branch offices and a limited set of VM’s.
Dev/Test Workloads.

DXC Proprietary and Confidential August 1, 2019 12


Azure VM Considerations
From an Existing Physical Machine
P2V a physical machine and move to Windows Azure
Move the DC’s VHD file to Windows Azure
Create the VM from the VHD
Attach data disk (caching turned off)
Don’t use D:\ ( temporary physical disk)

Put logs and account DB on attached disk to avoid data loss

DXC Proprietary and Confidential August 1, 2019 13


Attached document for Azure AD

DXC Proprietary and Confidential August 1, 2019 14


Thank you.

DXC Proprietary and Confidential

S-ar putea să vă placă și