Active Directory Security Groups • User Data: LDAP and ADSI • Kerberos was not a problem, application servers were joined to domain and port 88 was open in the internal network • Kerberos tickets included group SIDs for access decisions Application Had Free Access to Corporate Identities Applications Ran Almost Entirely On-Premises • RPC to a DC was not a problem
Identity synchronization User attributes are synchronized using identity synchronization services, including a password hash; authentication is completed against Azure Active Directory User attributes are synchronized using identity synchronization tools; authentication is passed back through federation and completed against Windows Server Active Directory ADFS Microsoft Azure Active Directory
Connect Consolidated deployment assistant for your identity bridge components. All currently available sync engines will be replaced by the sync engine included in the Connect tool. Assisted deployment of ADFS will be available through Azure Active Directory Connect. ADFS is an optional component for authentication in hybrid implementation. Password sync can replace ADFS for more scenarios. DirSync Azure Active Directory Sync FIM+Azure Active Directory Connector ADFS
user Native AAD account Guest AAD account Can be Azure admin Can be Azure AD admin Microsoft Account (MSA) Work or School Account Cloud-based user Yes Yes Synchronized user No Yes Native AAD account No Yes Guest AAD account Yes Yes (B2B) Can be Azure admin Yes Yes Can be Azure AD admin Yes Yes
app for iPhone, iPad and Android devices Direct sign in to the SaaS web applications and mobile apps such as Salesforce1 and Workday Company-branded sign-in page and app launchers Create custom portals and app launching experiences Integrated self-service and approval workflows User Profile management including passwords and Multi- factor Authentication methods. End User experience
Microsoft Azure Active Directory HR apps OTHER DIRECTORIES PowerShell SQL (ODBC) LDAP v3 Web Services ( SOAP, JAVA, REST) Connect and sync on-premises directories with Azure Active Directory
SaaS apps OTHER DIRECTORIES 2700+ pre-integrated popular SaaS apps and self-service integration via templates Connect and sync on-premises directories with Azure Easily publish on-premises web apps via Application Proxy + custom apps Microsoft Azure
apps are in use than IT estimates • a feature of Azure Active Directory (AD) Premium that enables you to discover cloud applications being used by the people in your organization. With Cloud App Discovery, you can: • Find the cloud applications being used and measure that usage by number of users, volume of traffic or number of web requests to the application. • Identify the users that are using an application. • Export data for offline analysis. • Bring these applications under IT control and enable single sign on for user management.
on corpnet next to resources Multiple connectors can be deployed for redundancy, scale, multiple sites, and different resources Users connect to the cloud service that routes their traffic to resources via the connectors A connector that auto-connects to the cloud service DMZ https://app1- contoso.msappproxy.net/ Application Proxy http://app1