SlideShare a Scribd company logo
aOS Aix-en-Provence
21 Juin 201821 Juin 2018
aOS Aix-en-Provence n°3
aOS Aix-en-Provence
21 Juin 2018
Merci à nos sponsors
aOS Aix-en-Provence
21 Juin 2018
Seven ways Identity
enriches your Office 365
and Azure experience
Sander Berkouwer
CTO at SCCT scct.nl
Enterprise Mobility MVP
aOS Aix-en-Provence
21 Juin 2018
About me
Sander Berkouwer
I live in the Netherlands
I work at SCCT scct.nl
@SanderBerkouwer
@aOSComm
I have a passion for Active Directory and
Azure Active Directory.
I’ve been a Microsoft MVP for the last 9 years
I’ve been a VEEAM Vanguard for 3 years
aOS Aix-en-Provence
21 Juin 2018
Agenda
Single Sign-On
Device-based Conditional Access
Self-Service possibilities
Information Protection
Role-based Access Control
… All with Azure AD
aOS Aix-en-Provence
21 Juin 2018
1. Single Sign-On
aOS Aix-en-Provence
21 Juin 2018
Single Sign-On Access to Applications
Single Sign-On (SSO)
Single Sign-On uses one identity in one identity store
Allows people to be more productive, because:
• They only have to remember one set of credentials
• Most applications allow for silent SSO, so without prompts
• Passwords can be easily changed, if needed
Office 365 and Azure Active Directory
65% of organizations only use Azure AD for Office 365 access
3900+ more applications available in the Azure AD App Gallery
aOS Aix-en-Provence
21 Juin 2018
2. Azure AD Join and
Microsoft Intune
aOS Aix-en-Provence
21 Juin 2018
Five ways to join a Microsoft
environment
Azure
Active Directory
Azure
Active Directory
Azure
Active Directory
Azure
Active Directory
Azure
Active Directory
AD DS AD DS AD DS
AD DS
Azure AD DS
aOS Aix-en-Provence
21 Juin 2018
Hybrid Azure AD Join
Azure AD Join
Bring-Your-Own scenarios for Windows 10 devices
Hybrid Azure AD Join
Single Sign-On and Windows Hello for domain-joined devices
Hybrid Azure AD Join is enabled by default, when:
• You run Azure AD Connect v1.1.486.0, or up
• Computer objects are in scope for synchronization
• You run Windows 10 1607, or up
• Windows 10 RTM and 1511 need a group policy
• Windows 7, etc. need WorkPlace Join for legacy clients link
aOS Aix-en-Provence
21 Juin 2018
Microsoft Intune
Device Lifecycle Management
Microsoft Intune keeps devices compliant
aOS Aix-en-Provence
21 Juin 2018
3. Conditional Access
4. Identity Protection
aOS Aix-en-Provence
21 Juin 2018
Conditional Access
*****
Require MFA
Allow access
Deny access
Force
password reset
Limit access
Controls
Users
Devices
Location
Apps
Conditions
Machine
learning
Policies
Real time
Evaluation
Engine
Session
Risk
3
10TB
Effective
policy
aOS Aix-en-Provence
6 septembre 2016
5. Self-Service
aOS Aix-en-Provence
21 Juin 2018
Azure AD Self-Service Possibilities
Password Reset
Colleagues can reset their
password after initial
registration
Resets require Multi-Factor
Authentication (MFA)
http://aka.ms/sspr
Group Management
Colleagues can manage their
own groups, delegated groups
and group memberships
Gain access to applications
without IT
Expiration and naming
convention can be centrally
configured
aOS Aix-en-Provence
21 Juin 2018
6. Azure Information
Protection
aOS Aix-en-Provence
21 Juin 2018
Azure Information Protection
Comprehensive protection
Protection of sensitive data throughout the lifecycle
Inside and outside the organization
Detect ProtectClassify Monitor
C L O U DD E V I C E S O N P R E M I S E S
aOS Aix-en-Provence
21 Juin 2018
Lifecycle of a sensitive file
Data is created, imported,
& modified across
various locations
Data is detected
Across devices, cloud
services, on-prem
environments
Sensitive data is
classified & labeled
Based on sensitivity; used for
either protection policies or
retention policies
Data is protected based
on policy
Protection may in the
form of encryption,
permissions, visual
markings, retention,
deletion, or a DLP action
such as blocking sharing
Data travels across
various locations, shared
Protection is persistent,
travels with the data
Data is monitored
Reporting on data
sharing, usage, potential
abuse; take action &
remediate
Retain, expire, delete data
Via data governance policies
aOS Aix-en-Provence
21 Juin 2018
aOS Aix-en-Provence
21 Juin 2018
Role-based Access Control
Azure Active Directory
Manage access to resources throughout Azure
Azure KeyVault
Manage certificate-based access to resources throughout Azure
Azure AD Managed Service Identities (MSIs)
Manages access to IaaS-based resources, like VMs
Like Manage Service Accounts (MSAs) in Active Directory
aOS Aix-en-Provence
21 Juin 2018
ConcludingConcluding
aOS Aix-en-Provence
21 Juin 2018
Concluding
Synchronize your objects
And benefit from Single Sign-On with Azure Active Directory
Enable your colleagues
By allowing them conditional access
By letting them reset their passwords, etc.
Secure access
By leveraging Azure AD-based Role-based Access Control
aOS Aix-en-Provence
21 Juin 2018
Thank you!
Sander Berkouwer
CTO at SCCT scct.nl
Enterprise Mobility MVP
@SanderBerkouwer
aOS Aix-en-Provence
21 Juin 2018

More Related Content

PPTX
M365 updates for GDPR
PPTX
Microsoft TechDays Netherlands 2017 - Azure Information Protection Scanner
PPTX
C-Level tools for Cloud security
PPTX
Microsoft TechDays Netherlands 2017 - Azure Information Protection
PDF
Enterprise File Fabric for Igneous
PPTX
ATA meetup - Feb 2020 - DevSecOps
PPTX
Advanced data governance in Office 365
PPTX
Webinar Wednesday: Locking Up the Cloud
M365 updates for GDPR
Microsoft TechDays Netherlands 2017 - Azure Information Protection Scanner
C-Level tools for Cloud security
Microsoft TechDays Netherlands 2017 - Azure Information Protection
Enterprise File Fabric for Igneous
ATA meetup - Feb 2020 - DevSecOps
Advanced data governance in Office 365
Webinar Wednesday: Locking Up the Cloud

What's hot (20)

PPTX
2 Modern Security - Microsoft Information Protection
PPTX
Turning off the lights - Going all in with the Public Cloud (Lumagate Nordic ...
PPTX
SPS Geneva - Azure information protection
PDF
Sing Tel - Designing security into datacenter - Gerald Tang
PPTX
TechEvent Data Encryption in Azure
PDF
Information Map around the world in 80 clicks
PDF
Enterprise File Fabric for Genomics
PPTX
How can cas bs help
PPTX
Secure your Access to Cloud Apps using Microsoft Defender for Cloud Apps
PDF
Enterprise Data Mining for SQL Server Pros
PDF
Bloombase StoreSafe Intelligent Storage Firewall secures sensitive informatio...
PPTX
Bring Your Own Encryption | Seclore
PPTX
Azure information protection and SharePoint
PDF
Search for All with Elastic Workplace Search
PDF
VIOS Flyer Erasure Services
PPTX
Dutch Microsoft & Security Meetup - How to protect my data in Office 365?
PDF
The Enterprise File Fabric for Leonovus User Collaboration Interface (LUCI)
PDF
SMB Security Microsoft 365 - Deployment
PPTX
Cloud computing with MS Azure
2 Modern Security - Microsoft Information Protection
Turning off the lights - Going all in with the Public Cloud (Lumagate Nordic ...
SPS Geneva - Azure information protection
Sing Tel - Designing security into datacenter - Gerald Tang
TechEvent Data Encryption in Azure
Information Map around the world in 80 clicks
Enterprise File Fabric for Genomics
How can cas bs help
Secure your Access to Cloud Apps using Microsoft Defender for Cloud Apps
Enterprise Data Mining for SQL Server Pros
Bloombase StoreSafe Intelligent Storage Firewall secures sensitive informatio...
Bring Your Own Encryption | Seclore
Azure information protection and SharePoint
Search for All with Elastic Workplace Search
VIOS Flyer Erasure Services
Dutch Microsoft & Security Meetup - How to protect my data in Office 365?
The Enterprise File Fabric for Leonovus User Collaboration Interface (LUCI)
SMB Security Microsoft 365 - Deployment
Cloud computing with MS Azure
Ad

Similar to 21-06-2018 aOS Aix 3 Seven ways identity enriches your Office 365 and Azure experience- English - Sander Berkouwer (20)

PDF
2018-09-03 aOS Aachen - Leveraging Azure for SharePoint - Manojk
PPTX
What's new in Azure Active Directory and what's coming new ?
PDF
Moving Applications to the Cloud on Windows Azure 3rd Edition Dominic Betts
PDF
2018-10-23 6 B - How SharePoint benefits from Azure - Manoj v Karunarathne
PPTX
Integration of Things (Sam Vanhoutte @Iglooconf 2017)
PPTX
Make IT Pro's great again: Microsoft Azure for the SharePoint professional
PDF
Moving Applications to the Cloud on Windows Azure 3rd Edition Dominic Betts
PPTX
Office 365 Directory Synchronization
PDF
Experts Live Europe 2017 - Windows 10 and the cloud - why the future needs hy...
PPTX
Azure Community Tour 2019 - AZUGDK
PDF
Azure 101
PDF
1. introduction to_cloud_services_architecture
PDF
Moving Applications to the Cloud on Windows Azure 3rd Edition Dominic Betts
PPTX
Realize True Business Value With ThousandEyes
PPTX
Azure Overview Arc
PDF
Integrating Cloudera & Microsoft Azure
PPTX
Azure Cloud Services
PDF
Moving Applications To The Cloud On Windows Azure 3rd Edition Dominic Betts
PDF
Slides-Discover-Power-of-Live-Data(2).pdf
PDF
2025-07-15 EMEA Volledig Inzicht Dutch Webinar
2018-09-03 aOS Aachen - Leveraging Azure for SharePoint - Manojk
What's new in Azure Active Directory and what's coming new ?
Moving Applications to the Cloud on Windows Azure 3rd Edition Dominic Betts
2018-10-23 6 B - How SharePoint benefits from Azure - Manoj v Karunarathne
Integration of Things (Sam Vanhoutte @Iglooconf 2017)
Make IT Pro's great again: Microsoft Azure for the SharePoint professional
Moving Applications to the Cloud on Windows Azure 3rd Edition Dominic Betts
Office 365 Directory Synchronization
Experts Live Europe 2017 - Windows 10 and the cloud - why the future needs hy...
Azure Community Tour 2019 - AZUGDK
Azure 101
1. introduction to_cloud_services_architecture
Moving Applications to the Cloud on Windows Azure 3rd Edition Dominic Betts
Realize True Business Value With ThousandEyes
Azure Overview Arc
Integrating Cloudera & Microsoft Azure
Azure Cloud Services
Moving Applications To The Cloud On Windows Azure 3rd Edition Dominic Betts
Slides-Discover-Power-of-Live-Data(2).pdf
2025-07-15 EMEA Volledig Inzicht Dutch Webinar
Ad

More from aOS Community (20)

PPTX
Commencer le IaaS sur Azure - aOS Tahiti 03-03-2020
PPTX
Migrer vers O365. Quelles stragtégies? - aOS Tahiti 03-03-2020
PPTX
Passer des macro Excel à la power plateform - aOS Tahiti 03-03-2020
PDF
Serverless avec azure functions - aOS Tahiti 03-03-2020
PPTX
Passer des macro Excel à la power plateform - aOS Nouméa 28-02-2020
PDF
MS ignite : les nouveautés autour des content services et projet cortex - aOS...
PDF
Cybersecurité dans M365 - aOS Noumea 28-02-2020
PDF
Introduction a Power Automate - aOS Nouméa 28-02-2020
PDF
aOS Monaco 2019 - S3 - Présentation Varonis - Cloud Data Protection - Benjami...
PDF
aOS Monaco 2019 - S2 - Présentation ARKADIN - TEAMS Adoption - Laurent Pilo
PDF
aOS Monaco 2019 - C1 - Sécuriser sa messagerie sur Office 365 - Hakim Taoussi...
PDF
aOS Monaco 2019 - B7 - I Developed a SPFx solution, what to do next and how t...
PDF
aOS Monaco 2019 - B6 - Mister Governance and Doctor Teams - Jean-François Ber...
PDF
aOS Monaco 2019 - B5 - The good, the bad and the unexpected - a BOT story - K...
PDF
aOS Monaco 2019 - B4 - Three must have workflows with Microsoft Flow - Vlad C...
PDF
aOS Monaco 2019 - B3 - Create purchase request in PowerApps - Robi Voncina
PDF
aOS Monaco 2019 - B2 - Intégrer la Power Platform avec SharePoint - Patrick G...
PDF
aOS Monaco 2019 - B1 - Construire son infrastructure sur Azure un jeu d'enfan...
PDF
aOS Monaco 2019 - A7 - Sécurisez votre SI et vos services Office 365 partie 2...
PDF
aOS Monaco 2019 - A6 - Sécurisez votre SI et vos services Office 365 partie 1...
Commencer le IaaS sur Azure - aOS Tahiti 03-03-2020
Migrer vers O365. Quelles stragtégies? - aOS Tahiti 03-03-2020
Passer des macro Excel à la power plateform - aOS Tahiti 03-03-2020
Serverless avec azure functions - aOS Tahiti 03-03-2020
Passer des macro Excel à la power plateform - aOS Nouméa 28-02-2020
MS ignite : les nouveautés autour des content services et projet cortex - aOS...
Cybersecurité dans M365 - aOS Noumea 28-02-2020
Introduction a Power Automate - aOS Nouméa 28-02-2020
aOS Monaco 2019 - S3 - Présentation Varonis - Cloud Data Protection - Benjami...
aOS Monaco 2019 - S2 - Présentation ARKADIN - TEAMS Adoption - Laurent Pilo
aOS Monaco 2019 - C1 - Sécuriser sa messagerie sur Office 365 - Hakim Taoussi...
aOS Monaco 2019 - B7 - I Developed a SPFx solution, what to do next and how t...
aOS Monaco 2019 - B6 - Mister Governance and Doctor Teams - Jean-François Ber...
aOS Monaco 2019 - B5 - The good, the bad and the unexpected - a BOT story - K...
aOS Monaco 2019 - B4 - Three must have workflows with Microsoft Flow - Vlad C...
aOS Monaco 2019 - B3 - Create purchase request in PowerApps - Robi Voncina
aOS Monaco 2019 - B2 - Intégrer la Power Platform avec SharePoint - Patrick G...
aOS Monaco 2019 - B1 - Construire son infrastructure sur Azure un jeu d'enfan...
aOS Monaco 2019 - A7 - Sécurisez votre SI et vos services Office 365 partie 2...
aOS Monaco 2019 - A6 - Sécurisez votre SI et vos services Office 365 partie 1...

Recently uploaded (20)

PDF
GamePlan Trading System Review: Professional Trader's Honest Take
PDF
CIFDAQ's Market Wrap: Ethereum Leads, Bitcoin Lags, Institutions Shift
PDF
Event Presentation Google Cloud Next Extended 2025
PDF
Smarter Business Operations Powered by IoT Remote Monitoring
PDF
DevOps & Developer Experience Summer BBQ
PPTX
breach-and-attack-simulation-cybersecurity-india-chennai-defenderrabbit-2025....
PPTX
Effective Security Operations Center (SOC) A Modern, Strategic, and Threat-In...
PDF
HCSP-Presales-Campus Network Planning and Design V1.0 Training Material-Witho...
PPTX
Detection-First SIEM: Rule Types, Dashboards, and Threat-Informed Strategy
PPTX
Understanding_Digital_Forensics_Presentation.pptx
PDF
How Onsite IT Support Drives Business Efficiency, Security, and Growth.pdf
PDF
Reimagining Insurance: Connected Data for Confident Decisions.pdf
PDF
Peak of Data & AI Encore- AI for Metadata and Smarter Workflows
PDF
Newfamily of error-correcting codes based on genetic algorithms
PDF
REPORT: Heating appliances market in Poland 2024
PDF
CIFDAQ's Teaching Thursday: Moving Averages Made Simple
PDF
NewMind AI Weekly Chronicles - August'25 Week I
PDF
NewMind AI Monthly Chronicles - July 2025
PDF
solutions_manual_-_materials___processing_in_manufacturing__demargo_.pdf
PPTX
MYSQL Presentation for SQL database connectivity
GamePlan Trading System Review: Professional Trader's Honest Take
CIFDAQ's Market Wrap: Ethereum Leads, Bitcoin Lags, Institutions Shift
Event Presentation Google Cloud Next Extended 2025
Smarter Business Operations Powered by IoT Remote Monitoring
DevOps & Developer Experience Summer BBQ
breach-and-attack-simulation-cybersecurity-india-chennai-defenderrabbit-2025....
Effective Security Operations Center (SOC) A Modern, Strategic, and Threat-In...
HCSP-Presales-Campus Network Planning and Design V1.0 Training Material-Witho...
Detection-First SIEM: Rule Types, Dashboards, and Threat-Informed Strategy
Understanding_Digital_Forensics_Presentation.pptx
How Onsite IT Support Drives Business Efficiency, Security, and Growth.pdf
Reimagining Insurance: Connected Data for Confident Decisions.pdf
Peak of Data & AI Encore- AI for Metadata and Smarter Workflows
Newfamily of error-correcting codes based on genetic algorithms
REPORT: Heating appliances market in Poland 2024
CIFDAQ's Teaching Thursday: Moving Averages Made Simple
NewMind AI Weekly Chronicles - August'25 Week I
NewMind AI Monthly Chronicles - July 2025
solutions_manual_-_materials___processing_in_manufacturing__demargo_.pdf
MYSQL Presentation for SQL database connectivity

21-06-2018 aOS Aix 3 Seven ways identity enriches your Office 365 and Azure experience- English - Sander Berkouwer

  • 1. aOS Aix-en-Provence 21 Juin 201821 Juin 2018 aOS Aix-en-Provence n°3
  • 2. aOS Aix-en-Provence 21 Juin 2018 Merci à nos sponsors
  • 3. aOS Aix-en-Provence 21 Juin 2018 Seven ways Identity enriches your Office 365 and Azure experience Sander Berkouwer CTO at SCCT scct.nl Enterprise Mobility MVP
  • 4. aOS Aix-en-Provence 21 Juin 2018 About me Sander Berkouwer I live in the Netherlands I work at SCCT scct.nl @SanderBerkouwer @aOSComm I have a passion for Active Directory and Azure Active Directory. I’ve been a Microsoft MVP for the last 9 years I’ve been a VEEAM Vanguard for 3 years
  • 5. aOS Aix-en-Provence 21 Juin 2018 Agenda Single Sign-On Device-based Conditional Access Self-Service possibilities Information Protection Role-based Access Control … All with Azure AD
  • 6. aOS Aix-en-Provence 21 Juin 2018 1. Single Sign-On
  • 7. aOS Aix-en-Provence 21 Juin 2018 Single Sign-On Access to Applications Single Sign-On (SSO) Single Sign-On uses one identity in one identity store Allows people to be more productive, because: • They only have to remember one set of credentials • Most applications allow for silent SSO, so without prompts • Passwords can be easily changed, if needed Office 365 and Azure Active Directory 65% of organizations only use Azure AD for Office 365 access 3900+ more applications available in the Azure AD App Gallery
  • 8. aOS Aix-en-Provence 21 Juin 2018 2. Azure AD Join and Microsoft Intune
  • 9. aOS Aix-en-Provence 21 Juin 2018 Five ways to join a Microsoft environment Azure Active Directory Azure Active Directory Azure Active Directory Azure Active Directory Azure Active Directory AD DS AD DS AD DS AD DS Azure AD DS
  • 10. aOS Aix-en-Provence 21 Juin 2018 Hybrid Azure AD Join Azure AD Join Bring-Your-Own scenarios for Windows 10 devices Hybrid Azure AD Join Single Sign-On and Windows Hello for domain-joined devices Hybrid Azure AD Join is enabled by default, when: • You run Azure AD Connect v1.1.486.0, or up • Computer objects are in scope for synchronization • You run Windows 10 1607, or up • Windows 10 RTM and 1511 need a group policy • Windows 7, etc. need WorkPlace Join for legacy clients link
  • 11. aOS Aix-en-Provence 21 Juin 2018 Microsoft Intune Device Lifecycle Management Microsoft Intune keeps devices compliant
  • 12. aOS Aix-en-Provence 21 Juin 2018 3. Conditional Access 4. Identity Protection
  • 13. aOS Aix-en-Provence 21 Juin 2018 Conditional Access ***** Require MFA Allow access Deny access Force password reset Limit access Controls Users Devices Location Apps Conditions Machine learning Policies Real time Evaluation Engine Session Risk 3 10TB Effective policy
  • 14. aOS Aix-en-Provence 6 septembre 2016 5. Self-Service
  • 15. aOS Aix-en-Provence 21 Juin 2018 Azure AD Self-Service Possibilities Password Reset Colleagues can reset their password after initial registration Resets require Multi-Factor Authentication (MFA) http://aka.ms/sspr Group Management Colleagues can manage their own groups, delegated groups and group memberships Gain access to applications without IT Expiration and naming convention can be centrally configured
  • 16. aOS Aix-en-Provence 21 Juin 2018 6. Azure Information Protection
  • 17. aOS Aix-en-Provence 21 Juin 2018 Azure Information Protection Comprehensive protection Protection of sensitive data throughout the lifecycle Inside and outside the organization Detect ProtectClassify Monitor C L O U DD E V I C E S O N P R E M I S E S
  • 18. aOS Aix-en-Provence 21 Juin 2018 Lifecycle of a sensitive file Data is created, imported, & modified across various locations Data is detected Across devices, cloud services, on-prem environments Sensitive data is classified & labeled Based on sensitivity; used for either protection policies or retention policies Data is protected based on policy Protection may in the form of encryption, permissions, visual markings, retention, deletion, or a DLP action such as blocking sharing Data travels across various locations, shared Protection is persistent, travels with the data Data is monitored Reporting on data sharing, usage, potential abuse; take action & remediate Retain, expire, delete data Via data governance policies
  • 20. aOS Aix-en-Provence 21 Juin 2018 Role-based Access Control Azure Active Directory Manage access to resources throughout Azure Azure KeyVault Manage certificate-based access to resources throughout Azure Azure AD Managed Service Identities (MSIs) Manages access to IaaS-based resources, like VMs Like Manage Service Accounts (MSAs) in Active Directory
  • 21. aOS Aix-en-Provence 21 Juin 2018 ConcludingConcluding
  • 22. aOS Aix-en-Provence 21 Juin 2018 Concluding Synchronize your objects And benefit from Single Sign-On with Azure Active Directory Enable your colleagues By allowing them conditional access By letting them reset their passwords, etc. Secure access By leveraging Azure AD-based Role-based Access Control
  • 23. aOS Aix-en-Provence 21 Juin 2018 Thank you! Sander Berkouwer CTO at SCCT scct.nl Enterprise Mobility MVP @SanderBerkouwer