AZR320: Integration with Windows Azure...

34

Transcript of AZR320: Integration with Windows Azure...

Page 1: AZR320: Integration with Windows Azure …download.microsoft.com/documents/hk/technet/techdays2013...•AZR320: Integration with Windows Azure AD and Office 365 –Identity and Access
Page 2: AZR320: Integration with Windows Azure …download.microsoft.com/documents/hk/technet/techdays2013...•AZR320: Integration with Windows Azure AD and Office 365 –Identity and Access

AZR320: Integration with Windows Azure AD and Office 365 – Identity and Access Management

Page 3: AZR320: Integration with Windows Azure …download.microsoft.com/documents/hk/technet/techdays2013...•AZR320: Integration with Windows Azure AD and Office 365 –Identity and Access

• OSP126: An Introduction to Windows Azure Active Directory and Office 365

• AZR314: Integration with Windows Azure AD and Office 365 – Provisioning and Synchronization

• AZR320: Integration with Windows Azure AD and Office 365 – Identity and Access Management

• OSP269: A tour through integration scenarios with Windows Azure AD and Office 365

Page 4: AZR320: Integration with Windows Azure …download.microsoft.com/documents/hk/technet/techdays2013...•AZR320: Integration with Windows Azure AD and Office 365 –Identity and Access
Page 5: AZR320: Integration with Windows Azure …download.microsoft.com/documents/hk/technet/techdays2013...•AZR320: Integration with Windows Azure AD and Office 365 –Identity and Access

Directory Management

Managing directory data (on-

prem and cloud).

Access Management

Controlling the AuthN/Z of

users and other identities

We’re spending time here

Page 6: AZR320: Integration with Windows Azure …download.microsoft.com/documents/hk/technet/techdays2013...•AZR320: Integration with Windows Azure AD and Office 365 –Identity and Access
Page 7: AZR320: Integration with Windows Azure …download.microsoft.com/documents/hk/technet/techdays2013...•AZR320: Integration with Windows Azure AD and Office 365 –Identity and Access
Page 8: AZR320: Integration with Windows Azure …download.microsoft.com/documents/hk/technet/techdays2013...•AZR320: Integration with Windows Azure AD and Office 365 –Identity and Access
Page 9: AZR320: Integration with Windows Azure …download.microsoft.com/documents/hk/technet/techdays2013...•AZR320: Integration with Windows Azure AD and Office 365 –Identity and Access

Appropriate for

• Smaller to medium/large orgs

Pros

• No additional hardware

requirements

Cons

• No SSO

• No 2FA

• 2 sets of credentials to

manage with differing

password policies

• IDs mastered in the cloud

Appropriate for

• Larger enterprise orgs with AD

on-premises

Pros

• SSO with corporate cred

• IDs mastered on-premises

• Password policy controlled on-

premises

• 2FA solutions possible

• Client Access Filtering

Cons

• High availability server

deployments required

Page 10: AZR320: Integration with Windows Azure …download.microsoft.com/documents/hk/technet/techdays2013...•AZR320: Integration with Windows Azure AD and Office 365 –Identity and Access
Page 11: AZR320: Integration with Windows Azure …download.microsoft.com/documents/hk/technet/techdays2013...•AZR320: Integration with Windows Azure AD and Office 365 –Identity and Access

Contoso customer premises

AD

Azure Active

Directory Sync

Identity Services

Provisioning

platform

Lync

Online

SharePoint

Online

Exchange

Online

Active Directory

Federation Server 2.0

Trust

IdPDirectory

Store

Admin Portal/

PowerShell

Authentication

platform

Office 365 Desktop

Setup

Windows Azure Active Directory

IdP

Office

365 ProPlus

Page 12: AZR320: Integration with Windows Azure …download.microsoft.com/documents/hk/technet/techdays2013...•AZR320: Integration with Windows Azure AD and Office 365 –Identity and Access

Use third-party identity providers to implement single sign-on

Page 13: AZR320: Integration with Windows Azure …download.microsoft.com/documents/hk/technet/techdays2013...•AZR320: Integration with Windows Azure AD and Office 365 –Identity and Access
Page 14: AZR320: Integration with Windows Azure …download.microsoft.com/documents/hk/technet/techdays2013...•AZR320: Integration with Windows Azure AD and Office 365 –Identity and Access

AD

ADFS

AD

ADFS 1

AD

ADFS 2

???

Page 15: AZR320: Integration with Windows Azure …download.microsoft.com/documents/hk/technet/techdays2013...•AZR320: Integration with Windows Azure AD and Office 365 –Identity and Access

OnRamp for Office 365

Page 16: AZR320: Integration with Windows Azure …download.microsoft.com/documents/hk/technet/techdays2013...•AZR320: Integration with Windows Azure AD and Office 365 –Identity and Access
Page 17: AZR320: Integration with Windows Azure …download.microsoft.com/documents/hk/technet/techdays2013...•AZR320: Integration with Windows Azure AD and Office 365 –Identity and Access

• UPN constraints:• cannot have dot ‘.’ immediately preceding ‘@’• [email protected] valid

[email protected] invalid

• cannot exceed 113 chars (64 for username, 48 for domain)

• cannot contain ! # $ % & \ * + - / = ? ^ _` { | } ~ < > ( )

• cannot have duplicate UPNs

• Connectivity Analyzer• Test your setup:

https://testconnectivity.microsoft.com/?tabid=client

Page 18: AZR320: Integration with Windows Azure …download.microsoft.com/documents/hk/technet/techdays2013...•AZR320: Integration with Windows Azure AD and Office 365 –Identity and Access
Page 19: AZR320: Integration with Windows Azure …download.microsoft.com/documents/hk/technet/techdays2013...•AZR320: Integration with Windows Azure AD and Office 365 –Identity and Access

http://www.outlook.com/contoso.com

Page 20: AZR320: Integration with Windows Azure …download.microsoft.com/documents/hk/technet/techdays2013...•AZR320: Integration with Windows Azure AD and Office 365 –Identity and Access
Page 21: AZR320: Integration with Windows Azure …download.microsoft.com/documents/hk/technet/techdays2013...•AZR320: Integration with Windows Azure AD and Office 365 –Identity and Access

Web Clients• Office 2010, Office 2007

SP2 with SharePoint

Online

• Outlook Web Application

Remember last user

Exchange Clients• Office 2010, Office 2007

SP2

• Active Sync/POP/IMAP

• Entourage

Can save credentials

Rich Applications (SIA)• Lync Online

• Office Subscriptions

• CRM Rich Client

Can save credentials

SSO IDs (on corp

network)

Cloud IDs

No Prompt

Username and Password

Cloud ID

AD credentials

SSO IDs (not on corp

network)

Username and Password

AD credentials

Username

Username and Password

Cloud ID

AD credentials

Username and Password

AD credentials

Username and Password

Username and Password

Cloud ID

AD credentials

Username and Password

AD credentials

Page 22: AZR320: Integration with Windows Azure …download.microsoft.com/documents/hk/technet/techdays2013...•AZR320: Integration with Windows Azure AD and Office 365 –Identity and Access
Page 23: AZR320: Integration with Windows Azure …download.microsoft.com/documents/hk/technet/techdays2013...•AZR320: Integration with Windows Azure AD and Office 365 –Identity and Access
Page 24: AZR320: Integration with Windows Azure …download.microsoft.com/documents/hk/technet/techdays2013...•AZR320: Integration with Windows Azure AD and Office 365 –Identity and Access

http://technet.microsoft.com/en-us/library/hh526961(v=ws.10).aspx

Page 25: AZR320: Integration with Windows Azure …download.microsoft.com/documents/hk/technet/techdays2013...•AZR320: Integration with Windows Azure AD and Office 365 –Identity and Access

`

Client

(joined to CorpNet)

Authentication platformAD FS 2.0 Server

Exchange Online or

SharePoint Online

Active Directory

Customer Windows Azure Active Directory

Logon (SAML 1.1) Token

UPN:[email protected]

Source User ID: ABC123

Auth Token

UPN:[email protected]

Unique ID: 254729

Page 26: AZR320: Integration with Windows Azure …download.microsoft.com/documents/hk/technet/techdays2013...•AZR320: Integration with Windows Azure AD and Office 365 –Identity and Access

`

Client

(joined to CorpNet)

Authentication platformAD FS 2.0 Server

Lync Online

Active Directory

Customer Windows Azure Active Directory

Logon (SAML 1.1) Token

UPN:[email protected]

Source User ID: ABC123

Auth Token

UPN:[email protected]

Unique ID: 254729

Page 27: AZR320: Integration with Windows Azure …download.microsoft.com/documents/hk/technet/techdays2013...•AZR320: Integration with Windows Azure AD and Office 365 –Identity and Access

Customer Windows Azure Active Directory

`

Client

(joined to CorpNet)

Authentication platformAD FS 2.0 Server

Exchange Online

Active Directory

Logon (SAML 1.1) Token

UPN:[email protected]

Source User ID: ABC123

Auth Token

UPN:[email protected]

Unique ID: 254729

Basic Auth Credentilas

Username/Password

Page 28: AZR320: Integration with Windows Azure …download.microsoft.com/documents/hk/technet/techdays2013...•AZR320: Integration with Windows Azure AD and Office 365 –Identity and Access

Structure Description Considerations

Matching domains Internal Domain and External domain are

the same i.e. contoso.com, and publically

routable

No special requirements. Good to go!

Register and verify them all.

Multiple (sub)

domains

Internal domain is a sub domain of the

external domain i.e. corp.contoso.com

Requires Domains registered in order,

primary then sub domains

.local domain Internal domain is not publicly “registered”

i.e. contoso.local

Domain ownership can’t be verified,

must use a different domain

• Requires all users to get new UPN

• Use SMTP address if possible

• Smart Card issues?

Multiple distinct UPN

suffixes in single

forest

Mix of users having login UPNs under

different domains

i.e. contoso.com & fabrikam.com

• Must use SupportMultipleDomain

switch in PowerShell when

configuring federation

• Sub domains require additional work

Multi Forest Multiple UPN Domains Register all domains. Same as Multiple

distinct UPN suffixes consideration

Page 29: AZR320: Integration with Windows Azure …download.microsoft.com/documents/hk/technet/techdays2013...•AZR320: Integration with Windows Azure AD and Office 365 –Identity and Access
Page 31: AZR320: Integration with Windows Azure …download.microsoft.com/documents/hk/technet/techdays2013...•AZR320: Integration with Windows Azure AD and Office 365 –Identity and Access

DMZINTRANET

AD FS

AD

DS

AD FS

Proxy

2FA

module

Access Application

Redirect to Authentication

platform

Types User Name

Generate SAML token

for authentication

platform

Redirect Back

Present ticket to

Application

Install 3rd party auth

provider ADFS proxy

2FA

Service

Authenticate 2FA

Authenticate 2FA

response

Smartcard Access

Other 2FA Access

Authentication

platform

Windows Azure Active Directory

Page 32: AZR320: Integration with Windows Azure …download.microsoft.com/documents/hk/technet/techdays2013...•AZR320: Integration with Windows Azure AD and Office 365 –Identity and Access
Page 33: AZR320: Integration with Windows Azure …download.microsoft.com/documents/hk/technet/techdays2013...•AZR320: Integration with Windows Azure AD and Office 365 –Identity and Access

DMZINTRANET

AD FS

AD

DS

AD FS

Proxy

2FA

Service

Authenticate 2FA

Allow internal Outlook via ADFS proxy

Send Creds to Exchange Proxy Auth

Evaluate Client

Access Rules, issue

SAML Token

Send Creds to Exchange Proxy Auth

Disable passive

pages on proxy

VPN

Connect to

internal network

Strong Auth VPN to internal network

Authentication

platform

Windows Azure Active Directory

Page 34: AZR320: Integration with Windows Azure …download.microsoft.com/documents/hk/technet/techdays2013...•AZR320: Integration with Windows Azure AD and Office 365 –Identity and Access