Download presentation
Presentation is loading. Please wait.
Published byNoel George Modified over 8 years ago
1
EMS in action Hugh Simpson-Wells and Mark Riley 2016 Redmond Summit | Identity Without Boundaries #OCGUS16 @OCGUSOfficial
2
Traditionally at this point Active Directory HR SAP Another Dir
3
Active Directory HR Another Directory AAD Connect SSO
4
Active Directory HR AAD Connect SSO
5
What’s driving adoption of EMS?
6
AD Connect AADP Azure RMS Conditional access Mobile Device Management Agenda
7
AD is designed for on- premises Active Directory LDAP Kerberos
8
AAD is designed for the cloud Windows Azure Active Directory SAML-P RESTful Graph API OAUTH and OpenIDConnect WS-Federation Portal
9
AAD is designed for the cloud
13
APIs
14
Active Directory HR SSO Demo environment
15
Demo AD Connect
16
AADP
18
Demo AADP
19
Azure RMS
21
Conditional Access
22
Randomization
23
Demo Conditional Access Denied/Device Enrollment
24
Conditional Access On-premises
25
Overview
27
Demo Conditional Access
28
Active Directory Federation Services (ADFS) On-premises
29
Integration overview User attributes are synchronized including the password hash, Authentication can be completed against either Azure or Windows Server Active Directory User attributes are synchronized, Authentication is passed back through federation and completed against Windows Server Active Directory Synchronization Federation AD FS provides true SSO, conditional access to resources, Work Place Join for device registration and integrated Multi- Factor Authentication Microsoft Azure
30
AAD Connect with Single Sign-on O365 / Azure STS redirects authentication requests to AD FS STS User authentication is completed against AD Optionally passwords can be sync’d too, for quick fall-back AD
31
Active Directory Federation Services
32
Multi-Factor Configuration
33
Demo Active Directory Federation Services (ADFS)
34
Multi-Factor Authentication On-premises
35
AD DS or LDAP On-Premises Apps MFA Server Cloud MFA Cloud Apps 2 Azure Active Directory 1 How it works
36
MFA for Office 365 (included in Office 365 SKUs) MFA for Azure Administrators (included with Azure Subscription) Azure MFA (Included in AADP/EMS) Administrators can protect accounts with MFA●Administrator accounts only● Mobile app as a second factor●●● Phone call as second factor●●● SMS as second factor●●● App passwords for clients that don’t support MFA●●● Admin control over authentication methods● PIN mode● Fraud alert● MFA Reports● One-Time Bypass● Custom greetings for phone calls● Customizable caller ID for phone calls● Event Confirmation● Trusted IPs● Suspend MFA for remembered devices (Public Preview)●● MFA SDK● MFA for on-premises applications using MFA Server● MFA Versions – Feature Comparison
37
Authentication Methods Phone CallSMS (2-way) SMS (1-way) Authentication Code App Notification
38
Demo Multi-Factor Authentication
39
Mobile Device Management (MDM) Windows Intune
40
Mobile Device Management (MDM)
41
Demo Mobile Device Management
42
Mobile Application Management (MAM) Windows Intune
43
Mobile Application Management
44
MAM ‘enlightened’ apps https://www.microsoft.com/en-us/server-cloud/products/microsoft-intune/partners.aspx
45
Demo Mobile Application Management
46
What is driving EMS adoption?
Similar presentations
© 2024 SlidePlayer.com Inc.
All rights reserved.