Top Banner
Identity and Windows Azure Rory Braybrook AZR209
39
Welcome message from author
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
Page 1: AZR209.  r2-identity-management-for-hybrid-it.aspx.

Identity and Windows Azure

Rory Braybrook AZR209

Page 2: AZR209.  r2-identity-management-for-hybrid-it.aspx.
Page 3: AZR209.  r2-identity-management-for-hybrid-it.aspx.

AAD allows you to move your I&AM to the cloud and

manage access to both cloud and

on-premise resources

Page 4: AZR209.  r2-identity-management-for-hybrid-it.aspx.

AAD

ACS

Graph

APIADAL

SSO

Overview

Page 5: AZR209.  r2-identity-management-for-hybrid-it.aspx.

AAD ≠ ADin cloud

ADD ≠ AD in Azure VM

AD AAD

Page 6: AZR209.  r2-identity-management-for-hybrid-it.aspx.

ADAD Domain Services

AD Lightweight Directory Services

AD Federation Services

AD Certificate Services

AD Rights Management Services

Corporate environment

Kerberos, LDAP, DNS

AADAzure Active Directory

Azure Access Control Service

AD RMS (Preview)

Cloud

REST, SAML-P, WS-Federation, OAuth, Graph API

Page 7: AZR209.  r2-identity-management-for-hybrid-it.aspx.

http://blogs.technet.com/b/in_the_cloud/archive/2013/08/09/what-s-new-in-2012-r2-identity-management-for-hybrid-it.aspx

Page 8: AZR209.  r2-identity-management-for-hybrid-it.aspx.

AAD – one size fits all

Small companies Main repository

Large companiesProjection of on-premise AD

Page 9: AZR209.  r2-identity-management-for-hybrid-it.aspx.

Concepts

Security Token Service

Claims-based application

Identity Provider

Service Provider

Windows Identity Foundation

Federation

Page 10: AZR209.  r2-identity-management-for-hybrid-it.aspx.

Office 365SharePoint

Online

Exchange Online

Lync Online

AAD

Page 11: AZR209.  r2-identity-management-for-hybrid-it.aspx.

Users

Attributes

Authentication

AADtargets

Page 12: AZR209.  r2-identity-management-for-hybrid-it.aspx.

Printers

Management

of devices

AADdoesn’t support

Group policy

Page 13: AZR209.  r2-identity-management-for-hybrid-it.aspx.

AAD supports SaaS

Googledocs

Sales force

Dropbox

GitHub

Skype

Yammer

Skydrive

Box

And many others …

Page 14: AZR209.  r2-identity-management-for-hybrid-it.aspx.

AD is hierarchical

C# API

Based on

Use

Page 15: AZR209.  r2-identity-management-for-hybrid-it.aspx.

ADD is not hierarchical

Graph API based on REST

Based on

Use

Graph Theory

Page 16: AZR209.  r2-identity-management-for-hybrid-it.aspx.

Management

Customer

Looks after

Tenant

Data

Microsoft

Supports infrastructure

Page 17: AZR209.  r2-identity-management-for-hybrid-it.aspx.

Demo

Lap around the AAD Portal

Page 18: AZR209.  r2-identity-management-for-hybrid-it.aspx.

From: Microsoft – Active Directory from on-premises to the cloud

Page 19: AZR209.  r2-identity-management-for-hybrid-it.aspx.

AAD is an ever moving target

Initial samples uses PowerShell

Later samples Tools & wizards

Authentication - currently no charge (other than MFA)

Page 20: AZR209.  r2-identity-management-for-hybrid-it.aspx.

Demo

VS 2012 – AAD Tooling

Page 21: AZR209.  r2-identity-management-for-hybrid-it.aspx.
Page 22: AZR209.  r2-identity-management-for-hybrid-it.aspx.
Page 23: AZR209.  r2-identity-management-for-hybrid-it.aspx.
Page 24: AZR209.  r2-identity-management-for-hybrid-it.aspx.
Page 25: AZR209.  r2-identity-management-for-hybrid-it.aspx.

Federate AD and AAD using ADFS

ADFS

Repository (e.g. AD) attributes can be configured in a variety of ways

Claims rules language for manipulating attributes

Allow / deny access

AAD

Fixed set - others can be extracted via the Graph API

No functionality

No functionality

Page 26: AZR209.  r2-identity-management-for-hybrid-it.aspx.

Synchronise or Federate?Dirsync

A single server is needed

Simple architecture

Same Sign On - users will be prompted for credentials when accessing Office 365

ADFSRedundant and scaled out ADFS servers

ADFS Proxies, load balancers, certificate management are required

Single Sign On (SSO)

Page 27: AZR209.  r2-identity-management-for-hybrid-it.aspx.

http://technet.microsoft.com/en-us/library/jj573650.aspx

Page 28: AZR209.  r2-identity-management-for-hybrid-it.aspx.

Manipulate AAD using Graph API

AAD Use token in REST call to

graph endpoint

Token issue

d

Use OAuth endpoint to get token

Page 29: AZR209.  r2-identity-management-for-hybrid-it.aspx.

Graph API REST interface

Create

Read

Update

Delete

POST

GET

PATCH

DELETE

Page 30: AZR209.  r2-identity-management-for-hybrid-it.aspx.

Demo

Graph Explorer

Page 31: AZR209.  r2-identity-management-for-hybrid-it.aspx.

AAL now ADAL

AAL(In cloud)Tenants

Namespaces

ADAL

ADFS2012 R2

(On premise)OAuth2

JWT

AAL(In cloud)Tenants

Namespaces

Page 32: AZR209.  r2-identity-management-for-hybrid-it.aspx.

AAD handles demand

Since2010

200 BillionAuthenticationsprocessed

50 MillionActive user accounts

Average

week

4.7 BillionAuthenticationrequests

420,000Different domains

2 minutes 1 Million authentications processed

1 second Receives 9,000 requests

0.7 second per authentication

for

in

Page 33: AZR209.  r2-identity-management-for-hybrid-it.aspx.

Demo

SSO

Page 34: AZR209.  r2-identity-management-for-hybrid-it.aspx.

AAD allows you to move your I&AM to the cloud and

manage access to both cloud and

on-premise resources

Page 35: AZR209.  r2-identity-management-for-hybrid-it.aspx.

ResourcesVittorio Bertocci

Cloud Identity blog - http://www.cloudidentity.com/blog/

Azure blog - http://blogs.msdn.com/b/windowsazure/

Azure Active Directory Graph - http://blogs.msdn.com/b/aadgraphteam/

Active Directory Team blog - http://blogs.technet.com/b/ad/

.NET Web Development and Tools blog - http://blogs.msdn.com/b/webdev/

Page 36: AZR209.  r2-identity-management-for-hybrid-it.aspx.

Related contentOther Identity topics

ARC312 The Identity Jigsaw PuzzleMDC320 The Business Mechanix “Bourne Identity” OUC204 Overview of Microsoft Office 365 Identity Management

Find Me LaterAround and about TechEd

Page 37: AZR209.  r2-identity-management-for-hybrid-it.aspx.

Every Windows Azure session you attendgives youa chanceto win thisepic t-shirt.We’re givingaway one perAzure session.

Sharks with freakin’

lasers as a Service.

Only on Windows Azure.

Page 38: AZR209.  r2-identity-management-for-hybrid-it.aspx.

Evaluate this session and you could win instantly!

Head to...aka.ms/te

Page 39: AZR209.  r2-identity-management-for-hybrid-it.aspx.

© 2013 Microsoft Corporation. All rights reserved.Microsoft, Windows and other product names are or may be registered trademarks and/or trademarks in the U.S. and/or other countries.MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.