Presentation is loading. Please wait.

Presentation is loading. Please wait.

Agenda AD to Windows Azure AD Sync Options Federation Architecture AD to AAD Quick start By Sachin Shetty.

Similar presentations


Presentation on theme: "Agenda AD to Windows Azure AD Sync Options Federation Architecture AD to AAD Quick start By Sachin Shetty."— Presentation transcript:

1 Agenda AD to Windows Azure AD Sync Options Federation Architecture AD to AAD Quick start By Sachin Shetty

2

3 User OrgID Organizational Account OnMicrosoft Account (Azure AD Account) Examples: Sachin@contoso.com sachin@contoso.onmicrosoft.com User Personal Services Organizational Services Live ID Microsoft Account Examples: Sachin@outlook.com sachin@live.com

4 Windows Intune Contoso customer premises AD Windows Azure Active Directory Provisioning platform CORP App Dynamics CRM Online Office 365 IdP Directory Store Admin Portal/ PowerShell/GRAPH Authentication platform IdP 1.Cloud Only / No Integration 2.Directory Synchronization 3.Directory and Federated SSO Joe@contoso. msonline.com shetty@contoso.com

5 Windows Intune Contoso customer premises AD Directory Sync (DirSync) Windows Azure Active Directory Provisioning platform CORP App Dynamics CRM Online Office 365 IdP Directory Store Admin Portal/ PowerShell/GRAPH Authentication platform IdP 1.No Integration 2.Directory Synchronization 3.Directory and Single sign-on (SSO)

6 Directory Synchronization Options Suitable for small/medium size organizations with AD or Non-AD Not a highly recommended option compared to DirSync or FIM Connector Performance limitations apply with PowerShell and Graph API provisioning PowerShell requires extensive scripting experience PowerShell option can be used where the customer/partner may have wrappers around PowerShell scripts (eg: Self Service Provisioning) As this is a custom solution, Microsoft support may not be able to help if there are issues PowerShell & Graph API Suitable for Organizations using Active Directory (AD) Supports Exchange Co-existence scenarios Coupled with AD FS, provides best option for federation and synchronization Does not require any additional software licenses Multi-forest available through MCS+Partners Suitable for large organizations with certain AD and Non-AD scenarios Complex multi-forest AD scenarios Non-AD synchronization through Microsoft premier deployment support Requires Forefront Identity Manager and additional software licenses Suitable for all organizations Supports Exchange Co-existence scenarios

7 Windows Intune Contoso customer premises AD Directory Sync (DirSync) Windows Azure Active Directory Provisioning platform Office 365 Dynamics CRM Online CORP App Active Directory Federation Server 2.0 Trust IdP Directory Store Admin Portal/ PowerShell/GRAPH Authentication platform IdP 1.No Integration 2.Directory Synchronization 3.Directory and Federated SSO

8 Federation options Suitable for educational organizations Recommended where customers may use existing non-AD FS Identity systems Single sign-on Secure token based authentication Support for web clients and outlook only Microsoft supported for integration only, no shibboleth deployment support Requires on-premises servers & support Works with AD and other directories on-premises Shibboleth Works with AD & Non-AD Suitable for medium, large enterprises including educational organizations Recommended option for Active Directory (AD) based customers Single sign-on Secure token based authentication Support for web and rich clients Microsoft supported Requires on-premises servers, licenses & support Suitable for medium, large enterprises including educational organizations Recommended where customers may use existing non-AD FS Identity systems with AD or Non-AD Single sign-on Secure token based authentication Support for web and rich clients Third-party supported Requires on-premises servers, licenses & support

9 1. No Integration Appropriate for Smaller orgs without AD on-premise Pros No servers required on- premise Same Domain name for users possible Cons No SSO No 2FA 2 sets of credentials to manage with differing password policies IDs mastered in the cloud 2. Directory Only Pros Users and groups mastered on-premise Enables co-existence Single server deployment Cons No 2FA until Spring 2013Spring 2013 2 sets of credentials to manage with differing password policies OR Manual / 3 rd Party password Sync OR use FIM No SSO 3. Directory and SSO Pros SSO with corporate cred IDs mastered on-premise Password policy controlled on-premise 2FA solutions possible Enables hybrid scenarios Location isolation Ideal for multiple forests Cons Additional Servers required for AD FS

10

11

12 Federated Architecture CorpNet Internet Active Directory Windows Azure AD AD FS + DirSync AD FS Proxy [Server2] [Server1]

13 UsersDedicated Federation Servers Federation server proxies NLB servers Comments <1,000001Deploy AD FS on two DCs 1,000–15,000222Install NLB on proxies 15,000–60,0002+1 for every 15,000 users 2+ Install NLB on proxies or use dedicated NLB implementation http://technet.microsoft.com/en-us/library/jj151794.aspx

14 Federated Architecture on Windows Azure! CorpNet Internet Active Directory Windows Azure AD AD FS + AD AD FS Proxy Windows Azure Subscription VPN DirSync

15 Quick Start Guide for Integrating a Single Forest On-Premises Active Directory with Windows Azure AD

16 Quickstart Guide Architecture Active Directory Windows Azure AD AD FS + DirSync AD FS Proxy [Server2] [Server1] Windows Server 2012

17

18

19

20 [On Server1]

21 What we’ve built so far CorpNet Internet Active Directory Windows Azure AD AD + AD FS Windows Azure Subscription VPN DirSync – Activated, not synced Domain Name – Added, not verified

22 Configure Inbound SSL Access Internet Windows Azure AD 157.56.167.107 mycloudservice.cloudapp.net CorpNet Internet Active Directory AD + AD FS Windows Azure Subscription VPN

23 [On Server1]

24

25 Final Configuration CorpNet Internet Active Directory Windows Azure AD AD FS + AD AD FS Proxy Windows Azure Subscription VPN DirSync DirSync – Activated + synced Domain Name – Added + verified

26 Document Step # PS Script Step # Component of ConfigurationActual Time Taken 11-2Initial Software Installation (pre-requisites)*,***1 min 12 sec 13Office 365 Readiness Tool5 min 48 sec 24-5Add Domain Name in Windows Azure AD27 sec 36Activate DirSync Support10 sec 47-14Install and Configure On-Premise AD FS Server1**2 min 53 sec 515-22Install and Configure AD FS Proxy Server2*, ***, ****6 min 12 sec 623-24Configure Windows Azure AD Federation Support41 sec 725-27Install and Configure DirSync3 min 26 sec

27


Download ppt "Agenda AD to Windows Azure AD Sync Options Federation Architecture AD to AAD Quick start By Sachin Shetty."

Similar presentations


Ads by Google