Top Banner
Making Sense of Microsoft Identities in a Hybrid World Jason Himmelstein, SharePoint MVP Office 365 Advisory Services Manager @sharepointlhorn http://www.sharepointlonghorn.com Todd Klindt, SharePoint MVP SharePoint Principal Architect @toddklindt http://www.toddklindt.com/blog
22
Welcome message from author
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
Page 1: Making sense of Microsoft Identities in a Hybrid world

Making Sense of Microsoft Identities in a Hybrid World

Jason Himmelstein, SharePoint MVPOffice 365 Advisory Services Manager@sharepointlhornhttp://www.sharepointlonghorn.com

Todd Klindt, SharePoint MVPSharePoint Principal Architect@toddklindthttp://www.toddklindt.com/blog

Page 2: Making sense of Microsoft Identities in a Hybrid world

www.rackspace.com

Who is this Todd Klindt guy?• SharePoint MVP since 2006• Speaker, writer, consultant, Aquarius, Iowa Native• Fan of all sorts of Microsoft technologies• Personal Blog

www.toddklindt.com/blog

• Twitter me! @toddklindt

• If you’re not already sick of him• http://www.toddklindt.com/netcast

Page 3: Making sense of Microsoft Identities in a Hybrid world

www.rackspace.com

That other guy… Jason something

• SharePoint Server MVP • Office 365 Advisory Services Manager, Rackspace• ITPro enthusiast, Business Intelligence geek,

& general technology fan boy• Writes good, Speaks ok, Smells delightful• Re-installed Texan, die-hard Spurs, Longhorns, & Jaguars

fan

• Geek Blog: www.sharepointlonghorn.com • On the Twitters: @sharepointlhorn • GitHub: www.github.com/jasonhimmelstein

Page 4: Making sense of Microsoft Identities in a Hybrid world

www.rackspace.com

Discount code: Klindt

Shameless self promotion

Discount code: RACKSPACE

Page 5: Making sense of Microsoft Identities in a Hybrid world

www.rackspace.com

• History lesson

• Defining Terminology

• Active Directory Core Concepts & Concerns

• Topology & Security

• Use Cases

• Homework

Agenda

Page 6: Making sense of Microsoft Identities in a Hybrid world

www.rackspace.com

• Bad news… we are ITPros! NO DEV TALK HERE

• Good news… The Microsoft Cloud Show covered the Azure AD dev topics recently!

• http://www.microsoftcloudshow.com/podcast/Episodes/087-catching-up-with-paul-schaeflein-on-azure-ad-improvements

Were you hoping for a dev focused talk?

Page 7: Making sense of Microsoft Identities in a Hybrid world

www.rackspace.com

History lesson

Page 8: Making sense of Microsoft Identities in a Hybrid world

www.rackspace.com

• The dark days – SharePoint 2003 & 2007

History lesson

Page 9: Making sense of Microsoft Identities in a Hybrid world

www.rackspace.com

• Age of enlightenment - SharePoint 2010

History lesson

Page 10: Making sense of Microsoft Identities in a Hybrid world

www.rackspace.com

• Age of the Internet - SharePoint 2013

History lesson

Page 11: Making sense of Microsoft Identities in a Hybrid world

www.rackspace.com

Defining Terminology

Page 12: Making sense of Microsoft Identities in a Hybrid world

www.rackspace.com

• Active Directory

• User Principal Name

• Azure Active Directory

• Identity as a Service

• DirSync

• ADFS

• Azure ADConnect

Defining Terminology

Page 13: Making sense of Microsoft Identities in a Hybrid world

www.rackspace.com

Azure AD Connect: Your Identity Bridge

Box

Citrix

Concur

GoToMeeting

Concur

Docusign

Azure AD Connect

(sync + sign on)

Active Directory

LDAP

Other identity stores

DropBox

Google apps

Jive

Salesforce

Servicenow

WorkdayCommonSign on

Page 14: Making sense of Microsoft Identities in a Hybrid world

www.rackspace.com

Hybrid Identity management

Azure AD Connect

Azure Active Directory ConnectConsolidated deployment assistant for your identity bridge components

Azure AD HealthCommon monitoring for your identity bridge components

Sync Services

DirSync

Azure AD Sync

FIM + Azure AD

Connector ADFS

ADFSHealth

Page 15: Making sense of Microsoft Identities in a Hybrid world

www.rackspace.com

• FSMO roles, AD DNS, WINS, NETBIOS, etc

• Dirty, dirty directories

• 2003 (Everyone group) --> 2008 (Authenticated Users group)

• UPN issues around migration

• Schema extensions

Active Directory Core Concepts & Concerns

Page 16: Making sense of Microsoft Identities in a Hybrid world

www.rackspace.com

• ADFS vs DirSync

• Multifactor Auth

Topology & Security

Page 17: Making sense of Microsoft Identities in a Hybrid world

www.rackspace.com

Same Sign On scenario

Page 18: Making sense of Microsoft Identities in a Hybrid world

www.rackspace.com

Single Sign On scenario

Page 19: Making sense of Microsoft Identities in a Hybrid world

www.rackspace.com

Highly Available Auth scenario

Page 20: Making sense of Microsoft Identities in a Hybrid world

www.rackspace.com

• Old environment moving to a new Hybrid Estate

• New Farm Identities

• Extranet situations

Use Cases

Page 21: Making sense of Microsoft Identities in a Hybrid world

www.rackspace.com

• Office 365 tenant

• Azure AD Trial

• 2 VMs– 1 AD Domain Controller (ADDC)

– 1 ADDConnect Server

• Download AADConnect

• If you want extra credit…– 1 additional VMs

• 1 ADFS Servers (in real world this would be 2 ADDCs & 2 ADFS with a load balancer)

– SSL cert

Homework

Page 22: Making sense of Microsoft Identities in a Hybrid world

Q & A