SlideShare a Scribd company logo
Complete Study Guide
Recently
Announced…
Identity
Integration
Options
2 3
Identity
Management
Overview
1
70 346 Managing office 365 identities
Verifying that a user, device, or service
such as an application provided on a
network server is the entity that it
claims to be.
Determining which actions an
authenticated entity is authorized to
perform on the network
the ability for two disjoint Identity Providers (IDP) to
trust each other such that a user logged into one does not need to log in again
for the second. YAUP is what you get if you don’t have SSO.
SAML is a public standard managed by
OASIS. SAML is the identity token and
also the protocol. SAML 2.0 is built on
SAML 1.1, ID-FF and Shibboleth.
The Relying Party (RP) is the system that relies on the Identity Provider to
authenticate a user.
WS-Federation is used for web browser
based authentication with an IDP. WS-
Trust is used by Office rich client apps
to authenticate.
User
Microsoft Account
User
Organizational Account
:
Microsoft Account Windows Azure Active Directory
Directory
store
Authentication
platform
Windows Azure
Active Directory
Your App
Cloud Identity
Single identity in the cloud
Suitable for small organizations
with no integration to on-
premises directories
Directory Synchronization
Single identity
suitable for medium
and large organizations
without federation
Federated Identity
Single federated identity
and credentials suitable
for medium and large
organizations
70 346 Managing office 365 identities
SAML2
Identity Provider
More Details on TechNet: http://aka.ms/sync
* Azure AD offers some 2FA features that are available with ADFS deployment on-premises.
Password Sync SSO with AD FS
Same password to access resources
Can control password policies on-
premises
Support for two factor authentication
*
No password re-entry if on premises
Client access filtering by IP or by time
schedule
Authentication occurs on-premises. Can
immediately block disabled accounts.
Change password available from web
Works with Forefront Identity Manager
Your data and applications
are under attack
Passwords are easily
compromised
Consumerization of IT has
only increased the scope of
vulnerability
Strengthening regulatory
requirements call for strongly
authenticating access

Users sign in from any device using
their existing username/password.
Users must also authenticate
using their phone or mobile
device before access is granted.
Credentials are checked
in Windows Azure AD.
Then Active Authentication
is triggered for additional
verification.
1
2
70 346 Managing office 365 identities
Azure Active Directory
GRAPH API
REST API for programmatic access to data in Azure AD
Can build multi-tenant applications, or custom LOB Apps
Azure Active Directory
Connector for FIM 2010 R2
Can be used for multi-forest synchronization and non-
AD sources
Public Beta starts on Connect soon
70 346 Managing office 365 identities
Cloud Identity Directory Sync Password Sync Graph API FIM Single Sign-On
Org size Small All All Large Large Large
Control of
attributes in
directory
Least control Full control via
on-premises
directory
Full control via
on-premises
directory
Can control core
attributes and
select optional
Can control core
attributes and
select optional
Full control via
on-premises
directory
Source of
authority
Cloud On-premises On-Premises Cloud On-premises On-premises
Hardware
requirements
No on-premises
hardware required
Windows Server
OS for DirSync
appliance
Windows Server
OS for DirSync
appliance
Machine to run
Powershell jobs
on
Federated Identity
Manager with
office 365
Connector
DirSync appliance
ADFS (or other
STS) deployment
Login experience Disjoint username,
password for on-
premises and
cloud
Enter credentials
twice
Disjoint username,
password for on-
premises and
cloud
Enter credentials
twice
Same username,
password for on-
premises and
cloud
Enter credentials
twice
Disjoint username,
password for on-
premises and
cloud
Enter credentials
twice
Disjoint username,
password for on-
premises and
cloud
Enter credentials
twice
Same username,
password for on-
premises and
cloud
Login once if on-
premises
Windows Azure
Active Directory
User
Cloud Identity
Ex: alice@contoso.com
Windows Azure
Active Directory
User
On-Premises Identity
Ex: DomainAlice
Directory
Synchronization
Cloud Identity
Ex: alice@contoso.com
AD
On-Premises Identity
Ex: DomainAlice
Directory
Synchronization
with one way
Password Hash
Cloud Identity
Ex: alice@contoso.com
AD
Windows Azure
Active Directory
User
Customers can exclude objects
from synchronizing to Office 365.
Scoping can be done at the
following levels:
AD Domain-based
Organizational Unit-based
User Attribute based
Additional filtering capabilities will
become available with the O365
Connector.
Preventing the synchronization of
specific attributes is not
supported.
On-Premises Identity
Ex: DomainAlice
Federation
using ADFS
AD
DirSync on FIM
AD
AD
Windows Azure
Active Directory
User
Number
Active
Directory
forests
See
consolidation
whitepaper
Use
Single Forest
DirSync
Use
Office 365
Connector
Use
Multi Forest
DirSync
Need on-
premises org
consolidation
Number
Exchange
Orgs
“Disjoint”
Account
Forests?
“Disjoint” account
forests and exchange
org accessed by
accounts in the same
forest?
Want to
consolidate
single forest?
After
consolidation
Single (1)
Multiple (>1)
Yes
None (0)Multiple (>1)
Start
After
consolidation
No
Single (1) Yes
Yes
No
No
Multi-forest decision flowchart
Suitable for small/medium
size organizations with AD
or Non-AD
Performance limitations apply with
PowerShell and Graph API provisioning
PowerShell requires scripting
experience
PowerShell option can be used where
the customer/partner may have
wrappers around PowerShell scripts
(eg: Self Service Provisioning)
Suitable for large organizations
with certain AD and Non-AD
scenarios
Complex multi-forest AD scenarios
Non-AD synchronization through
Microsoft premier deployment support
Requires Forefront Identity Manager
and additional software licenses
Windows Azure
Active Directory
User
On-Premises Identity
Ex: DomainAlice
Federation
AD
Non-AD
Directory
Synchronization
or
Suitable for educational organizations
Recommended where customers may use existing
non-ADFS Identity systems
Single sign-on
Secure token based authentication
Support for web clients and outlook (ECP) only
Microsoft supported for integration only, no
shibboleth deployment support
Requires on-premises servers & support
Works with AD and other directories on-premises
Shibboleth (SAML)
Works with AD & Non-AD
Suitable for medium, large enterprises
including educational organizations
Recommended option for Active Directory (AD)
based customers
Single sign-on
Secure token based authentication
Support for web and rich clients
Microsoft supported
Works for Office 365 Hybrid Scenarios
Requires on-premises servers, licenses & support
Works with AD
Suitable for medium, large enterprises
including educational organizations
Recommended where customers may use existing
non-ADFS Identity systems with AD or Non-AD
Single sign-on
Secure token based authentication
Support for web and rich clients
Third-party supported
Works for Office 365 Hybrid Scenarios
Requires on-premises servers, licenses & support
Verified through ‘works with Office 365’ program
Works for Office 365 Hybrid Scenarios
Works with Office 365 - Identity
http://aka.ms/SSOProviders
Qualified by MicrosoftReuse Investments
http://bit.ly/17D5Dq0
WS-Trust & WS-Federation
WS-Federation
SAML-P
Active Directory with ADFS
Block all external access to Office 365
based on the IP address of the
external client
Block all external access to Office 365
except Exchange Active Sync; all
other clients such as Outlook are
blocked.
Block all external access to Office 365
except for passive browser based
applications such as Outlook Web
Access or SharePoint Online
Windows Azure
Active Directory
User
Cloud Identity
Ex: alice@contoso.com
ISV apps or
SAAS providers
or Your App
Cloud Identity
Ex: alice@contoso.com
70 346 Managing office 365 identities
http://msdn.microsoft.com/en-au/
http://www.microsoftvirtualacademy.com/http://channel9.msdn.com/Events/TechEd/Australia/2013
http://technet.microsoft.com/en-au/
1. Keep up to date with all the latest Office 365 information at
http://ignite.office.com
http://fastTrack.office.com
http://office.microsoft.com
70 346 Managing office 365 identities

More Related Content

PDF
SCU Berlín | Cloud identity for maximum productivity
PPT
SSO Strategy Implementation Considerations
PDF
Microsoft Cloud Identity and Access Management Poster - Atidan
PPTX
SharePoint 2010 Extranets and Authentication: How will SharePoint 2010 connec...
PPTX
Claims Based Authentication A Beginners Guide
PPTX
How to deploy SharePoint 2010 to external users?
PPTX
Azure AD Presentation - @ BITPro - Ajay
PPTX
Federation Services
SCU Berlín | Cloud identity for maximum productivity
SSO Strategy Implementation Considerations
Microsoft Cloud Identity and Access Management Poster - Atidan
SharePoint 2010 Extranets and Authentication: How will SharePoint 2010 connec...
Claims Based Authentication A Beginners Guide
How to deploy SharePoint 2010 to external users?
Azure AD Presentation - @ BITPro - Ajay
Federation Services

What's hot (19)

PPTX
SPSVB - Office 365 and Cloud Identity - What Does It Mean for Me?
PDF
MS Cloud Identity and Access Infographic 2015 (1)
PPTX
Extending SharePoint 2010 to your customers and partners
PDF
Cloud Identity and Access Management
PPTX
CANARIE - What Do I Need to Connect with eduroam and Shibboleth
PPTX
Saml vs Oauth : Which one should I use?
PPTX
Certifications for Azure Developers
PPTX
Short Sales Overview of EmpowerID
PDF
Understanding Claim based Authentication
PPTX
Microsoft Azure Identity and O365
PPTX
JoTechies - Cloud identity
PPTX
Azure AD for browser-based application developers
PPTX
Developing Apps with Azure AD
PPT
OWASPSanAntonio_2006_08_SingleSignOn.ppt
PPT
CAS Enhancement
PPTX
Troubleshooting Federation, ADFS, and More
PPTX
Single sign on - benefits, challenges and case study : iFour consultancy
PDF
Claim based authentaication
PPT
Oim Poc1.0
SPSVB - Office 365 and Cloud Identity - What Does It Mean for Me?
MS Cloud Identity and Access Infographic 2015 (1)
Extending SharePoint 2010 to your customers and partners
Cloud Identity and Access Management
CANARIE - What Do I Need to Connect with eduroam and Shibboleth
Saml vs Oauth : Which one should I use?
Certifications for Azure Developers
Short Sales Overview of EmpowerID
Understanding Claim based Authentication
Microsoft Azure Identity and O365
JoTechies - Cloud identity
Azure AD for browser-based application developers
Developing Apps with Azure AD
OWASPSanAntonio_2006_08_SingleSignOn.ppt
CAS Enhancement
Troubleshooting Federation, ADFS, and More
Single sign on - benefits, challenges and case study : iFour consultancy
Claim based authentaication
Oim Poc1.0
Ad

Similar to 70 346 Managing office 365 identities (20)

PPTX
SPIntersection 2016 - MICROSOFT CLOUD IDENTITIES IN AZURE AND OFFICE 365
PDF
JAXSPUG January 2016 - Microsoft Cloud Identities in Azure and Office 365
PPTX
SYDSP - Office 365 and Cloud Identity - What does it mean for me?
PDF
Premier Webcast - Identity Management with Windows Azure AD
PPTX
SPS Sydney - Office 365 and Cloud Identity – What does it mean for me?
PPTX
Azure Global Bootcamp 2017 Azure AD Deployment
PDF
O365con14 - moving from on-premises to online, the road to follow
PPTX
Hitchhiker's Guide to Azure AD - SPS St Louis 2018
PDF
Office 365 identity
PDF
Office 365 Identity Management - SMBNation 2015
PPTX
What's new in Azure Active Directory and what's coming new ?
PPTX
2. Day 2 - Identify and SSO
PPSX
AzureAAD
PPTX
Azure AD App Proxy Login Scenarios with an On Premises Applications - TSPUG
PPTX
1. Day 1 - Office 365 Trainning
PPTX
Azure-AD.pptx
PPTX
Microsoft Azure AD architecture and features
PPTX
I1 - Securing Office 365 and Microsoft Azure like a rockstar (or like a group...
PPTX
Análisis de riesgos en Azure y protección de la información
PPTX
Understanding Identity Management with Office 365
SPIntersection 2016 - MICROSOFT CLOUD IDENTITIES IN AZURE AND OFFICE 365
JAXSPUG January 2016 - Microsoft Cloud Identities in Azure and Office 365
SYDSP - Office 365 and Cloud Identity - What does it mean for me?
Premier Webcast - Identity Management with Windows Azure AD
SPS Sydney - Office 365 and Cloud Identity – What does it mean for me?
Azure Global Bootcamp 2017 Azure AD Deployment
O365con14 - moving from on-premises to online, the road to follow
Hitchhiker's Guide to Azure AD - SPS St Louis 2018
Office 365 identity
Office 365 Identity Management - SMBNation 2015
What's new in Azure Active Directory and what's coming new ?
2. Day 2 - Identify and SSO
AzureAAD
Azure AD App Proxy Login Scenarios with an On Premises Applications - TSPUG
1. Day 1 - Office 365 Trainning
Azure-AD.pptx
Microsoft Azure AD architecture and features
I1 - Securing Office 365 and Microsoft Azure like a rockstar (or like a group...
Análisis de riesgos en Azure y protección de la información
Understanding Identity Management with Office 365
Ad

Recently uploaded (20)

PDF
5.Universal-Franchise-and-Indias-Electoral-System.pdfppt/pdf/8th class social...
PDF
Sunset Boulevard Student Revision Booklet
PDF
LDMMIA Reiki Yoga Workshop 15 MidTerm Review
PPTX
Information Texts_Infographic on Forgetting Curve.pptx
PPTX
UNDER FIVE CLINICS OR WELL BABY CLINICS.pptx
DOCX
UPPER GASTRO INTESTINAL DISORDER.docx
PDF
Mga Unang Hakbang Tungo Sa Tao by Joe Vibar Nero.pdf
PDF
High Ground Student Revision Booklet Preview
PDF
The Final Stretch: How to Release a Game and Not Die in the Process.
PPTX
Open Quiz Monsoon Mind Game Prelims.pptx
PDF
Origin of periodic table-Mendeleev’s Periodic-Modern Periodic table
PDF
Landforms and landscapes data surprise preview
PPTX
PPTs-The Rise of Empiresghhhhhhhh (1).pptx
PDF
Types of Literary Text: Poetry and Prose
PPTX
How to Manage Bill Control Policy in Odoo 18
PDF
Phylum Arthropoda: Characteristics and Classification, Entomology Lecture
PDF
LDMMIA Reiki Yoga S2 L3 Vod Sample Preview
PPTX
Open Quiz Monsoon Mind Game Final Set.pptx
PPTX
An introduction to Dialogue writing.pptx
PDF
3.The-Rise-of-the-Marathas.pdfppt/pdf/8th class social science Exploring Soci...
5.Universal-Franchise-and-Indias-Electoral-System.pdfppt/pdf/8th class social...
Sunset Boulevard Student Revision Booklet
LDMMIA Reiki Yoga Workshop 15 MidTerm Review
Information Texts_Infographic on Forgetting Curve.pptx
UNDER FIVE CLINICS OR WELL BABY CLINICS.pptx
UPPER GASTRO INTESTINAL DISORDER.docx
Mga Unang Hakbang Tungo Sa Tao by Joe Vibar Nero.pdf
High Ground Student Revision Booklet Preview
The Final Stretch: How to Release a Game and Not Die in the Process.
Open Quiz Monsoon Mind Game Prelims.pptx
Origin of periodic table-Mendeleev’s Periodic-Modern Periodic table
Landforms and landscapes data surprise preview
PPTs-The Rise of Empiresghhhhhhhh (1).pptx
Types of Literary Text: Poetry and Prose
How to Manage Bill Control Policy in Odoo 18
Phylum Arthropoda: Characteristics and Classification, Entomology Lecture
LDMMIA Reiki Yoga S2 L3 Vod Sample Preview
Open Quiz Monsoon Mind Game Final Set.pptx
An introduction to Dialogue writing.pptx
3.The-Rise-of-the-Marathas.pdfppt/pdf/8th class social science Exploring Soci...

70 346 Managing office 365 identities

  • 4. Verifying that a user, device, or service such as an application provided on a network server is the entity that it claims to be. Determining which actions an authenticated entity is authorized to perform on the network
  • 5. the ability for two disjoint Identity Providers (IDP) to trust each other such that a user logged into one does not need to log in again for the second. YAUP is what you get if you don’t have SSO. SAML is a public standard managed by OASIS. SAML is the identity token and also the protocol. SAML 2.0 is built on SAML 1.1, ID-FF and Shibboleth. The Relying Party (RP) is the system that relies on the Identity Provider to authenticate a user. WS-Federation is used for web browser based authentication with an IDP. WS- Trust is used by Office rich client apps to authenticate.
  • 6. User Microsoft Account User Organizational Account : Microsoft Account Windows Azure Active Directory
  • 8. Cloud Identity Single identity in the cloud Suitable for small organizations with no integration to on- premises directories Directory Synchronization Single identity suitable for medium and large organizations without federation Federated Identity Single federated identity and credentials suitable for medium and large organizations
  • 10. SAML2 Identity Provider More Details on TechNet: http://aka.ms/sync
  • 11. * Azure AD offers some 2FA features that are available with ADFS deployment on-premises. Password Sync SSO with AD FS Same password to access resources Can control password policies on- premises Support for two factor authentication * No password re-entry if on premises Client access filtering by IP or by time schedule Authentication occurs on-premises. Can immediately block disabled accounts. Change password available from web Works with Forefront Identity Manager
  • 12. Your data and applications are under attack Passwords are easily compromised Consumerization of IT has only increased the scope of vulnerability Strengthening regulatory requirements call for strongly authenticating access
  • 13.
  • 14. Users sign in from any device using their existing username/password. Users must also authenticate using their phone or mobile device before access is granted. Credentials are checked in Windows Azure AD. Then Active Authentication is triggered for additional verification. 1 2
  • 16. Azure Active Directory GRAPH API REST API for programmatic access to data in Azure AD Can build multi-tenant applications, or custom LOB Apps Azure Active Directory Connector for FIM 2010 R2 Can be used for multi-forest synchronization and non- AD sources Public Beta starts on Connect soon
  • 18. Cloud Identity Directory Sync Password Sync Graph API FIM Single Sign-On Org size Small All All Large Large Large Control of attributes in directory Least control Full control via on-premises directory Full control via on-premises directory Can control core attributes and select optional Can control core attributes and select optional Full control via on-premises directory Source of authority Cloud On-premises On-Premises Cloud On-premises On-premises Hardware requirements No on-premises hardware required Windows Server OS for DirSync appliance Windows Server OS for DirSync appliance Machine to run Powershell jobs on Federated Identity Manager with office 365 Connector DirSync appliance ADFS (or other STS) deployment Login experience Disjoint username, password for on- premises and cloud Enter credentials twice Disjoint username, password for on- premises and cloud Enter credentials twice Same username, password for on- premises and cloud Enter credentials twice Disjoint username, password for on- premises and cloud Enter credentials twice Disjoint username, password for on- premises and cloud Enter credentials twice Same username, password for on- premises and cloud Login once if on- premises
  • 20. Windows Azure Active Directory User On-Premises Identity Ex: DomainAlice Directory Synchronization Cloud Identity Ex: [email protected] AD
  • 21. On-Premises Identity Ex: DomainAlice Directory Synchronization with one way Password Hash Cloud Identity Ex: [email protected] AD Windows Azure Active Directory User
  • 22. Customers can exclude objects from synchronizing to Office 365. Scoping can be done at the following levels: AD Domain-based Organizational Unit-based User Attribute based Additional filtering capabilities will become available with the O365 Connector. Preventing the synchronization of specific attributes is not supported.
  • 23. On-Premises Identity Ex: DomainAlice Federation using ADFS AD DirSync on FIM AD AD Windows Azure Active Directory User
  • 24. Number Active Directory forests See consolidation whitepaper Use Single Forest DirSync Use Office 365 Connector Use Multi Forest DirSync Need on- premises org consolidation Number Exchange Orgs “Disjoint” Account Forests? “Disjoint” account forests and exchange org accessed by accounts in the same forest? Want to consolidate single forest? After consolidation Single (1) Multiple (>1) Yes None (0)Multiple (>1) Start After consolidation No Single (1) Yes Yes No No Multi-forest decision flowchart
  • 25. Suitable for small/medium size organizations with AD or Non-AD Performance limitations apply with PowerShell and Graph API provisioning PowerShell requires scripting experience PowerShell option can be used where the customer/partner may have wrappers around PowerShell scripts (eg: Self Service Provisioning)
  • 26. Suitable for large organizations with certain AD and Non-AD scenarios Complex multi-forest AD scenarios Non-AD synchronization through Microsoft premier deployment support Requires Forefront Identity Manager and additional software licenses
  • 27. Windows Azure Active Directory User On-Premises Identity Ex: DomainAlice Federation AD Non-AD Directory Synchronization or
  • 28. Suitable for educational organizations Recommended where customers may use existing non-ADFS Identity systems Single sign-on Secure token based authentication Support for web clients and outlook (ECP) only Microsoft supported for integration only, no shibboleth deployment support Requires on-premises servers & support Works with AD and other directories on-premises Shibboleth (SAML) Works with AD & Non-AD Suitable for medium, large enterprises including educational organizations Recommended option for Active Directory (AD) based customers Single sign-on Secure token based authentication Support for web and rich clients Microsoft supported Works for Office 365 Hybrid Scenarios Requires on-premises servers, licenses & support Works with AD Suitable for medium, large enterprises including educational organizations Recommended where customers may use existing non-ADFS Identity systems with AD or Non-AD Single sign-on Secure token based authentication Support for web and rich clients Third-party supported Works for Office 365 Hybrid Scenarios Requires on-premises servers, licenses & support Verified through ‘works with Office 365’ program Works for Office 365 Hybrid Scenarios Works with Office 365 - Identity
  • 31. Block all external access to Office 365 based on the IP address of the external client Block all external access to Office 365 except Exchange Active Sync; all other clients such as Outlook are blocked. Block all external access to Office 365 except for passive browser based applications such as Outlook Web Access or SharePoint Online
  • 32. Windows Azure Active Directory User Cloud Identity Ex: [email protected] ISV apps or SAAS providers or Your App Cloud Identity Ex: [email protected]
  • 35. 1. Keep up to date with all the latest Office 365 information at http://ignite.office.com http://fastTrack.office.com http://office.microsoft.com