M7: New Features for Office 365 Identity Management

Slides:



Advertisements
Similar presentations
Feature: Identity Management - Login © 2013 Microsoft Corporation. All rights reserved. Microsoft, Windows, Windows Vista and other product names are or.
Advertisements

Agenda AD to Windows Azure AD Sync Options Federation Architecture
MIX 09 4/15/ :14 PM © 2009 Microsoft Corporation. All rights reserved. Microsoft, Windows, Windows Vista and other product names are or may be registered.
Federated sign-in WS-Federation WS-Trust SAML 2.0 Metadata Shibboleth Graph API Synchronize accounts Authentication.
Feature: Web Client Keyboard Shortcuts © 2013 Microsoft Corporation. All rights reserved. Microsoft, Windows, Windows Vista and other product names are.
© 2012 Microsoft Corporation. All rights reserved. Microsoft, Windows, Windows Vista and other product names are or may be registered trademarks and/or.
© 2012 Microsoft Corporation. All rights reserved. Microsoft, Windows, Windows Vista and other product names are or may be registered trademarks and/or.
Feature: Customer Combiner and Modifier © 2013 Microsoft Corporation. All rights reserved. Microsoft, Windows, Windows Vista and other product names are.
© 2009 Microsoft Corporation. All rights reserved. Microsoft, Windows, Windows Vista and other product names are or.

Office 365: Identity and Access Solutions Suresh Menon Technology Specialist – Office 365 Microsoft Corporation India.
Get identities to the cloud Mix on-premises and cloud identity for improved PC, mobile, and web productivity Cloud identities help you run your business.
Advanced SQL Azure Database Name Title Microsoft Corporation.
Windows Azure SQL Data Sync Name Title Microsoft Corporation.
© 2009 Microsoft Corporation. All rights reserved. Microsoft, Windows, Windows Vista and other product names are or may be registered trademarks.
© 2008 Microsoft Corporation. All rights reserved. Microsoft, Windows, Windows Vista and other product names are or.

Recording Brief EMS Partner Bootcamp Variables Values Module Title
Identity; What you need to know to be in the Microsoft Cloud
Deployment Planning Services
Recording Brief EMS Partner Bootcamp Variables Values Module Title
Introduction to Windows Azure AppFabric
O365 & AZURE ADDS Mladen Baranek, Miadria
SaaS Application Deep Dive
6/17/2018 5:54 AM OSP322 Getting the best of both worlds, making the most of SharePoint hybrid search solutions Shyam Narayan Microsoft © 2013 Microsoft.
Microsoft Virtual Academy
Directory Synchronization in Office 365
Information Protection
Microsoft Dynamics NAV 2018 – what’s new
RMS Architecture EMS Partner Bootcamp TechReady 18 9/17/2018
Возможности Excel 2010, о которых следует знать
Windows Store for Business
SharePoint Online Management and Control
Deploying Office 365 ProPlus
Microsoft Virtual Academy
Enterprise Modernization
Azure Active Directory
Office 365 Identity Management
05 | AD to Windows Azure AD IT Professionals
Microsoft Virtual Academy
Azure AD Domain Services
Microsoft Virtual Academy
Access and Information Protection Product Overview October 2013
TechEd /24/2018 4:00 PM © 2013 Microsoft Corporation. All rights reserved. Microsoft, Windows, and other product names are or may be registered.
Migrating to Office 365 from Google mail and exchange
Microsoft Ignite NZ October 2016 SKYCITY, Auckland.
Title of Presentation 12/2/2018 3:48 PM
Microsoft Virtual Academy
Five mistakes to avoid when deploying Enterprise Mobility + Security
Office 365 Identity Management
Office 365 Identity Management
Microsoft Virtual Academy
M3: Guidance for choosing the right integration option
Surviving identity management in a hybrid world
Microsoft Ignite /24/2019 6:23 PM
2/27/2019 © 2014 Microsoft Corporation. All rights reserved. Microsoft, Windows, and other product names are or may be registered trademarks and/or trademarks.
Microsoft Virtual Academy
8/04/2019 9:13 PM © 2006 Microsoft Corporation. All rights reserved. Microsoft, Windows, Windows Vista and other product names are or may be registered.
One Marketing Template
4/20/ :04 PM © 2013 Microsoft Corporation. All rights reserved. Microsoft, Windows, and other product names are or may be registered trademarks and/or.
M6: Advanced Identity Management topics for Office 365
Виктор Хаджийски Катедра “Металургия на желязото и металолеене”
Office 365 Identity Management
Windows Azure Hybrid Architectures and Patterns
Шитманов Дархан Қаражанұлы Тарих пәнінің
Title of Presentation 5/24/2019 1:26 PM
Microsoft Virtual Academy
Azure AD Simon May Technical Evangelist.
Microsoft Virtual Academy
Presentation transcript:

M7: New Features for Office 365 Identity Management

Meet Paul Andrew | @pndrw Office 365 Technical Product Manager Office 365 datacenter, networking, identity management Passion for informing and inspiring IT Professionals to create simpler solutions to complex problems Meet Jono Luk Office Senior PM Manager Office Client & Cloud Identity infrastructure Long time Identity Management SME Passion for ensuring top-quality customer story and solutions

Recent features change the landscape 12/4/2018 Recent features change the landscape May 2013 Office 365 SSO with SAML 2.0 Identity Providers May 2013 Office 365 Adapter Jun 2013 Password hash sync added to DirSync Nov 2013 DirSync tool run on Domain Controllers Feb 2014 Multi Factor Authentication for Office 365 Feb 2014 Multi-Forest AD Feb 2014 Non-AD Synchronization Apr 2014 Alternate Sign-In ID to UPN May 2014 Password Sync Backup for Federated Sign-In May 2014 Azure Active Directory Sync Services Dec 2014 Office client passive authentication © 2014 Microsoft Corporation. All rights reserved. Microsoft, Windows, and other product names are or may be registered trademarks and/or trademarks in the U.S. and/or other countries. The information herein is for informational purposes only and represents the current view of Microsoft Corporation as of the date of this presentation. Because Microsoft must respond to changing market conditions, it should not be interpreted to be a commitment on the part of Microsoft, and Microsoft cannot guarantee the accuracy of any information provided after the date of this presentation. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

Windows Azure Active Directory Microsoft Lync Office 365 SSO with SAML 2.0 Identity Providers Shipped May 2013* 12/4/2018 * for early adopters Windows Azure Active Directory SAML-P Authentication Office 365 already supports: Microsoft Active Directory WS-Federation (qualified) Shibboleth Identity Providers Customers who need SSO with a SAML 2.0 identity provider can sign up for the early adopter program SAML2 Identity Provider User https://spsites.microsoft.com/sites/bosm/boswiki/Pages/SAML-P-Early-Adopter.aspx © 2012 Microsoft Corporation. All rights reserved. Microsoft, Windows, and other product names are or may be registered trademarks and/or trademarks in the U.S. and/or other countries. The information herein is for informational purposes only and represents the current view of Microsoft Corporation as of the date of this presentation. Because Microsoft must respond to changing market conditions, it should not be interpreted to be a commitment on the part of Microsoft, and Microsoft cannot guarantee the accuracy of any information provided after the date of this presentation. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

Office 365 Adapter Customer On-Premises Deployment Shipped May 2013 Federation & DirSync Deployment Prescriptive guidance for Partners or MCS to deploy the On-Premises components required in Azure Bundle these components with Services and/or support to appear as an ‘adapter’ What remains on-premises Existing AD infrastructure (required for other IT needs) VPN router Exchange coexistence servers, if required Where to find more Information Microsoft Download Center’s Office 365 Adapter: Deploying Office 365 Single Sign-On using Windows Azure Azure ADFS AD DirSync VPN Tunnel AD Replication VPN Router AD Customer On-Premises

More Details on TechNet: http://aka.ms/sync Windows Azure Active Directory Sync Tool Shipped June 2013 More Details on TechNet: http://aka.ms/sync Synchronizes user password hashes from on-prem AD to Azure AD (Office 365) Respects on-premises password policies. Can’t sync passwords for Federated Users, but can co- exist.

DirSync runs on a Domain Controller Microsoft Lync DirSync runs on a Domain Controller 12/4/2018 Shipped Nov 2013 Windows Azure Active Directory Only for up to 10,000 user objects. DirSync and AD Domain Controller © 2012 Microsoft Corporation. All rights reserved. Microsoft, Windows, and other product names are or may be registered trademarks and/or trademarks in the U.S. and/or other countries. The information herein is for informational purposes only and represents the current view of Microsoft Corporation as of the date of this presentation. Because Microsoft must respond to changing market conditions, it should not be interpreted to be a commitment on the part of Microsoft, and Microsoft cannot guarantee the accuracy of any information provided after the date of this presentation. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

Multi-Factor Authentication for Office 365 Microsoft Lync 12/4/2018 Shipped Feb 2014 Multi-Factor Authentication for Office 365 UPDATED Multi-Factor Authentication Phone call SMS message Mobile app Licensing Included in all Office 365 SKUs Prior to Jan 2014 this was available for Admin accounts only. Futures Seamless multi-factor authentication is planned in the next 12 months for Office client applications *For representative purposes only. © 2012 Microsoft Corporation. All rights reserved. Microsoft, Windows, and other product names are or may be registered trademarks and/or trademarks in the U.S. and/or other countries. The information herein is for informational purposes only and represents the current view of Microsoft Corporation as of the date of this presentation. Because Microsoft must respond to changing market conditions, it should not be interpreted to be a commitment on the part of Microsoft, and Microsoft cannot guarantee the accuracy of any information provided after the date of this presentation. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

Windows Azure Active Directory Microsoft Office Multi-forest AD 12/4/2018 Shipped Feb 2014 Windows Azure Active Directory Multi-forest AD support is available using Forefront Identity Manager 2010 R2. You also need the Windows Azure Active Directory Connector for FIM 2010 R2. Guidance is also available for merging AD Forests on TechNet. Federation using ADFS Forefront Identity Manager On-premises identity AD AD AD User © 2012 Microsoft Corporation. All rights reserved. Microsoft, Windows, and other product names are or may be registered trademarks and/or trademarks in the U.S. and/or other countries. The information herein is for informational purposes only and represents the current view of Microsoft Corporation as of the date of this presentation. Because Microsoft must respond to changing market conditions, it should not be interpreted to be a commitment on the part of Microsoft, and Microsoft cannot guarantee the accuracy of any information provided after the date of this presentation. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

Windows Azure Active Directory Microsoft Office Non-AD Synchronization 12/4/2018 Shipped Feb 2014 Windows Azure Active Directory Preferred option for Directory Synchronization with Non-AD Sources Non-AD support with Forefront Identity Manager 2010 R2 is available now FIM 2010 R2 Office 365 connector supports complex multi-forest topologies Federation using non-ADFS STS Office 365 Connector on FIM On-premises identity Non-AD (LDAP) User © 2012 Microsoft Corporation. All rights reserved. Microsoft, Windows, and other product names are or may be registered trademarks and/or trademarks in the U.S. and/or other countries. The information herein is for informational purposes only and represents the current view of Microsoft Corporation as of the date of this presentation. Because Microsoft must respond to changing market conditions, it should not be interpreted to be a commitment on the part of Microsoft, and Microsoft cannot guarantee the accuracy of any information provided after the date of this presentation. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

Alternate Login ID removing dependency on User Principal Name (UPN) Shipped April 2014 Alternate Login ID removing dependency on User Principal Name (UPN) The reliance on UPN has been removed and you can now select an alternate login ID for use with Office 365 and Azure AD in general. Use of UPN will still be the default. Through configuration you can select the Mail attribute or any other attribute in your on- premises Active Directory. This works with either synchronized identity or federated identity.

Password Sync Backup for Federated Sign-In Shipped May 2014 Backup Password Hash Sync Federated identity User accounts DirSync Tool AD FS This new backup option for Office 365 customers using federated sign-in provides the option to manually switch your domain in a short amount of time during outages such as on-premises power loss, internet connection interruption and any other on-premises outage. On-premises directory

Azure Active Directory Sync Services Targeted Q3 CY 2014 A new identity sync tool that provides customers with the ability to sync identity information from complex AD environments (i.e. multi-forest) and other identity directories such as Generic LDAP v3 (PowerShell, CSV etc.), Generic SQL through ODBC driver (MySQL, IBM, Oracle) and Generic Web Service (SOAP, JAVA, REST/JSON/XML) In beta as of June 2014

Office Client OAUTH Support Targeted End of 2014 Office Client OAUTH Support This feature enables Office rich client applications to work with third party Identity Providers and to work with the Windows Azure Multi-factor Authentication implementation.

M7 Summary: New Features for Office 365 Identity Management Great new features May 2013 Office 365 SSO with SAML 2.0 Identity Providers May 2013 Office 365 Adapter Jun 2013 Password hash sync added to DirSync Nov 2013 DirSync tool run on Domain Controllers Feb 2014 Multi Factor Authentication for Office 365 Feb 2014 Multi-Forest AD Feb 2014 Non-AD Synchronization Apr 2014 Alternate Sign-In ID to UPN May 2014 Password Sync Backup for Federated Sign-In May 2014 Azure Active Directory Sync Services Dec 2014 Office client passive authentication