Presentation is loading. Please wait.

Presentation is loading. Please wait.

Azure AD for the client management guy (or gal!)

Similar presentations


Presentation on theme: "Azure AD for the client management guy (or gal!)"— Presentation transcript:

1 Azure AD for the client management guy (or gal!)
Andre Della Monica Senior Content Developer Microsoft, SCCM & Intune @andredm7  Jeff Gilbert Senior Content Developer Microsoft, Azure AD @jeffgilb

2 Session overview General understanding of how Azure AD fits into the client management world. How to integrate on-premises AD with Azure AD. Find out what Azure AD admins are up to and when you might need their help.

3 Azure AD Microsoft’s cloud based directory and identity management service. Core directory services, identity governance, and application access management. Synchronize on-premises resource information and seamless integration with other services.

4 Connecting directories
Common identity for Office 365, Azure, and SaaS apps Azure AD Connect Azure AD Connect Health

5 Managing management Configuration Manager Intune Both?
Domain joined or you need fine grain control of settings management. Intune Non-domain joined, mobile devices (Azure AD join or add work or school account). Both? Handle some workloads with each.

6 Devices & Azure AD OOBE Experience
Azure AD Join or set up a work or school account Device registration

7 Enable Auto-MDM Auto-mobile device management (MDM) enrollment with Azure AD & Intune Enroll devices via Group Policy AD-joined PC running Windows 10, version 1709 Enterprise has MDM service already configured Enterprise AD must be registered with Azure AD

8 Demo

9 MFA Two-step authentication verification MFA in the cloud
Something you know (typically a password) Something you have (a trusted device that is not easily duplicated, like a phone) Something you are (biometrics) MFA in the cloud MFA on-premises

10 Conditional Access Azure AD & Intune Compliance policies
Access policies

11 Conditional access from Intune managed devices
6/19/2018 1:26 AM Conditional access from Intune managed devices SharePoint Online 7 Client signs in; Azure AD performs a redirect to Intune Client is directed to join the device to Azure AD or to add a work or school account Device begins enrollment Device enrolls in Intune and is registered in AAD Device management and compliance status is set in AAD AAD issues direct access token Client accesses service with direct access token Data is delivered to client 8 Company Portal Step 1: Enroll device 6 2 Intune Azure Active Directory 1 3 Device object device id isManaged MDMStatus Unified Enrollment 5 4 Microsoft Cloud © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

12 Demo

13 Questions ?


Download ppt "Azure AD for the client management guy (or gal!)"

Similar presentations


Ads by Google