Managing Identities in the Microsoft Cloud

21
MANAGING IDENTITIES IN THE MICROSOFT CLOUD Wim Buysse Click icon to add picture

Transcript of Managing Identities in the Microsoft Cloud

Page 1: Managing Identities in the Microsoft Cloud

MANAGING IDENTITIES IN THE MICROSOFT CLOUD

Wim Buysse

Click icon to add picture

Page 2: Managing Identities in the Microsoft Cloud
Page 3: Managing Identities in the Microsoft Cloud

ENABLEYOURUSERS

USER

PROTECTYOURDATA

IT

WHY AZURE ACTIVE DIRECTORY?

Page 4: Managing Identities in the Microsoft Cloud

AM

YE OLDEN DAYS

I

Email

FILESERVERDATABAS

E

Page 5: Managing Identities in the Microsoft Cloud

AM

YE OLDEN DAYS

I

DIRECTORY SERVICES

Page 6: Managing Identities in the Microsoft Cloud

AM

YE OLDEN DAYS

I

DIRECTORY SERVICES

Page 7: Managing Identities in the Microsoft Cloud

TODAY’S MESH (MESS?)

EC2

ON-PREMISES PRIVATE CLOUDMANAGED DEVICES

Page 8: Managing Identities in the Microsoft Cloud

SELFSERVICE

SINGLESIGN-ON

•••••••••••Username

ADRESSING THE MESH (MESS?)SINGLESYNCH

CLOUD

SaaSAzure

Office 365Publiccloud

ACTIVE DIRECTORY

ON-PREMISES AZURE ACTIVE DIRECTORY

Page 9: Managing Identities in the Microsoft Cloud

TIP: CLOUD APP DISCOVERY

Page 10: Managing Identities in the Microsoft Cloud

EMPOWER YOURUSERS

CENTRALLY MANAGED IDENTITY & ACCESS

MONITOR & PROTECT CLOUD APP ACCESS

YOUR DIRECTORY IN THE CLOUD

WHAT IS IAM ALL ABOUT?

Page 11: Managing Identities in the Microsoft Cloud

AADCONNECT password hash sync

AADCONNECT

AD FS

AZURE ACTIVE DIRECTORY

AZURE ACTIVE DIRECTORY

YOUR DIRECTORY IN THE CLOUD

AZURE ACTIVE DIRECTORY

CLOUDIDENTITY

SYNCHEDIDENTITY

FEDERATEDIDENTITY

Page 12: Managing Identities in the Microsoft Cloud

DIRSYNC SHORTCOMINGS ADDRESSEDAADCONNECT REPLACES DIRSYNC

SYNCHRONIZE MULTIPLE FORESTS TO SINGLE TENANT

EXTENDING AZURE AD SCHEMA

IMPROVED RULES EDITOR

Page 13: Managing Identities in the Microsoft Cloud

APPLICATION INTEGRATION

SaaS APPS

OWN APPS

Page 14: Managing Identities in the Microsoft Cloud

CENTRALLY MANAGED IDENTITIES & ACCESS

SaaS APPS

AZURE ACTIVE DIRECTORY

Page 15: Managing Identities in the Microsoft Cloud

CENTRALLY MANAGED IDENTITIES & ACCESS

SaaS APPSAZURE

ACTIVE DIRECTORY

USER ATTRIBUTE

DEVICE

LOCATION

ALLOWBLOCK

MFA

Page 16: Managing Identities in the Microsoft Cloud

MONITOR & PROTECT CLOUD APP ACCESS

ULTIMATE SECURITY VS.

ULTIMATE USABILITY

Page 17: Managing Identities in the Microsoft Cloud

EMPOWER YOUR USERS

APPLICATION PORTAL

Page 18: Managing Identities in the Microsoft Cloud

EMPOWER YOUR USERSPASSWORD SELF-SERVICE

(Writeback)

Page 19: Managing Identities in the Microsoft Cloud

TAKE IT FURTHER: B2B COLLABORATION

I NEED MY PARTNERS TO ACCESS MY ENTERPRISE APPLICATIONS USING THEIR OWN CREDENTIALS

› PARTNER MANAGED IDENTITIES

› SHARING INVITATION MODEL› CONTROL APPLICATION

ACCESS

Page 20: Managing Identities in the Microsoft Cloud

TAKE IT FURTHER: B2CI HAVE AN ONLINE APPLICATION AND I NEED INDIVIDUAL CUSTOMERS TO SIGN-UP AND ENROLL FOR IT

› SELF SERVICE REGISTRATION› SUPPORT SOCIAL ACCOUNTS› MFA (OPTIONAL)

Page 21: Managing Identities in the Microsoft Cloud

KEY TAKEAWAYS

EC2

ON-PREMISES PRIVATE CLOUDMANAGED DEVICES

SIMPLICITYIS THE

ULTIMATE SOPHISTICATION