Azure AD for the client management guy (or gal!)

Slides:



Advertisements
Similar presentations
Azure AD & Office Logon with Username / Password 2. MFA challenge 3. Reply to MFA challenge -1-way or 2-way SMS -Phone call -Mobile Application.
Advertisements

SharePoint Server Exchange Server CORPORATE NETWORK Mobile devices PCs Browsers INTERNET DMZ Active Directory Policies Filter EAS Filter web access.
Empower Enterprise Mobility Jasbir Gill Azure Mobility.
Empowering people-centric IT Unified device management Access and information protection Desktop Virtualization Hybrid Identity.
Microsoft Ignite /25/2017 9:57 AM
Access and Information Protection Product Overview Andrew McMurray Technical Evangelist – Windows
Get identities to the cloud Mix on-premises and cloud identity for improved PC, mobile, and web productivity Cloud identities help you run your business.
Microsoft Virtual Academy Preparing for the Windows 8.1 MCSA Module 5: Managing Devices & Resource Access.
User and Device Management
Craig Pringle & Derek Moir
Slavko Kukrika MVP Connect Windows 10 to the Cloud – Cloud Join.
Tomaž Čebul Principal Consultant Microsoft Bring Your Own Device, kaj pa je to?
Enabling the Modern Workstyle with Windows 10 & Azure Active Directory Venkatesh Gopalakrishnan 2016 Redmond Summit | Identity Without Boundaries May 25,
EMS in action Hugh Simpson-Wells and Mark Riley 2016 Redmond Summit | Identity Without Boundaries
of employees use personal devices for work purposes.* of employees that typically work on employer premises, also frequently work away from their desks.***
Managing Devices in the Enterprise: From EMS zero to Hero in only 60 minutes Ken Goossens Herman Arnedo Mahr.
Today’s challenges Data Users Apps Devices
Active Directory Modernization Technical competitive comparison
Implementing and Managing Azure Multi-factor Authentication
Microsoft Ignite /27/2018 9:00 AM THR2016
Azure Active Directory - Business 2 Consumer
Microsoft Ignite /17/ :48 AM BRK3330
Conduct a successful pilot deployment of Microsoft Intune
Manage Windows devices in the complex hybrid cloud world of today
O365 & AZURE ADDS Mladen Baranek, Miadria
Conduct a successful pilot deployment of Microsoft Intune
SaaS Application Deep Dive
Windows 10 and the cloud: Why the future needs hybrid solutions
6/25/ :13 PM BRK1076 Make Windows devices more secure by taking them out of your existing infrastructure Chris Rhodes & Andrew Bettany MCTs & MVPs.
Microsoft Virtual Academy
The power of common identity across any cloud
Examine common architectures for hybrid identity
Protect sensitive information with Office 365 DLP
Secure Remote Access to on-premises Web Apps using Azure AD
Microsoft Ignite /31/ :08 AM
Microsoft 365 Business: Under the Hood
Windows 10 Subscription Activation
9/13/2018 4:54 PM BRK How to get Office 365 to the next level with Azure Active Directory Premium Brjann Brekkan Program Manager Lead – Customer.
Secure access to O365,SaaS and On-Premise apps with Azure AD & Intune
Microsoft Intune MAM without Device Enrollment
Welcome! Microsoft Tech Talks - Charlotte, NC
Microsoft Virtual Academy
A beginners guide to Mobile Device Management
The Road to Modern Management
Protect your OneDrive and SharePoint files on mobile devices
Office 365 Identity Management
Welcome! Power BI User Group (PUG)
Microsoft Ignite /20/2018 2:21 PM
Microsoft Virtual Academy
Access and Information Protection Product Overview October 2013
PCIT-B313 Hybrid Identity
Microsoft Ignite NZ October 2016 SKYCITY, Auckland
TechEd /7/ :16 AM © 2013 Microsoft Corporation. All rights reserved. Microsoft, Windows, and other product names are or may be registered.
Five mistakes to avoid when deploying Enterprise Mobility + Security
12/29/2018 8:46 AM © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN.
Microsoft Virtual Academy
Office 365 Development.
Surviving identity management in a hybrid world
System Center Marketing
4/15/2019 1:57 PM © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN.
TechEd /6/ :24 PM © 2013 Microsoft Corporation. All rights reserved. Microsoft, Windows, and other product names are or may be registered trademarks.
Azure Multi-Factor Authentication (MFA)
SCCM in hybrid world Predrag Jelesijević Microsoft 7/6/ :17 AM
SharePoint Online Assessment Results
Azure AD Simon May Technical Evangelist.
TechEd /18/ :51 PM © 2013 Microsoft Corporation. All rights reserved. Microsoft, Windows, and other product names are or may be registered.
11/19/2019 4:08 PM © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN.
11/25/ :29 AM © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN.
Microsoft Virtual Academy
Presentation transcript:

Azure AD for the client management guy (or gal!) Andre Della Monica Senior Content Developer Microsoft, SCCM & Intune @andredm7  Jeff Gilbert Senior Content Developer Microsoft, Azure AD @jeffgilb

Session overview General understanding of how Azure AD fits into the client management world. How to integrate on-premises AD with Azure AD. Find out what Azure AD admins are up to and when you might need their help.

Azure AD Microsoft’s cloud based directory and identity management service. Core directory services, identity governance, and application access management. Synchronize on-premises resource information and seamless integration with other services.

Connecting directories Common identity for Office 365, Azure, and SaaS apps Azure AD Connect Azure AD Connect Health

Managing management Configuration Manager Intune Both? Domain joined or you need fine grain control of settings management. Intune Non-domain joined, mobile devices (Azure AD join or add work or school account). Both? Handle some workloads with each.

Devices & Azure AD OOBE Experience Azure AD Join or set up a work or school account Device registration

Enable Auto-MDM Auto-mobile device management (MDM) enrollment with Azure AD & Intune Enroll devices via Group Policy AD-joined PC running Windows 10, version 1709 Enterprise has MDM service already configured Enterprise AD must be registered with Azure AD

Demo

MFA Two-step authentication verification MFA in the cloud Something you know (typically a password) Something you have (a trusted device that is not easily duplicated, like a phone) Something you are (biometrics) MFA in the cloud MFA on-premises

Conditional Access Azure AD & Intune Compliance policies Access policies

Conditional access from Intune managed devices 6/19/2018 1:26 AM Conditional access from Intune managed devices SharePoint Online 7 Client signs in; Azure AD performs a redirect to Intune Client is directed to join the device to Azure AD or to add a work or school account Device begins enrollment Device enrolls in Intune and is registered in AAD Device management and compliance status is set in AAD AAD issues direct access token Client accesses service with direct access token Data is delivered to client 8 Company Portal Step 1: Enroll device 6 2 Intune Azure Active Directory 1 3 Device object device id isManaged MDMStatus Unified Enrollment 5 4 Microsoft Cloud © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

Demo

Questions ?