Top Banner
Complete Study Guide
36

Pass4sure 70-346 Managing Office 365 Identities

Apr 28, 2023

Download

Documents

Yunsoo Park
Welcome message from author
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
Page 1: Pass4sure 70-346 Managing Office 365 Identities

Complete Study Guide

Page 2: Pass4sure 70-346 Managing Office 365 Identities

Recently Announced…

Identity Integration Options

2 3

Identity Management Overview

1

Page 3: Pass4sure 70-346 Managing Office 365 Identities
Page 4: Pass4sure 70-346 Managing Office 365 Identities

Verifying that a user, device, or service

such as an application provided on a

network server is the entity that it

claims to be.

Determining which actions an

authenticated entity is authorized to

perform on the network

http://www.pass4sureexam.co/70-346.html

Page 5: Pass4sure 70-346 Managing Office 365 Identities

the ability for two disjoint Identity Providers (IDP) to

trust each other such that a user logged into one does not need to log in again

for the second. YAUP is what you get if you don’t have SSO.

SAML is a public standard managed by

OASIS. SAML is the identity token and

also the protocol. SAML 2.0 is built on

SAML 1.1, ID-FF and Shibboleth.

The Relying Party (RP) is the system that relies on the Identity Provider to

authenticate a user.

WS-Federation is used for web browser

based authentication with an IDP. WS-

Trust is used by Office rich client apps

to authenticate.

http://www.pass4sureexam.co/70-346.html

Page 6: Pass4sure 70-346 Managing Office 365 Identities

User

Microsoft Account

User

Organizational Account:

Microsoft Account Windows Azure Active Directory

http://www.pass4sureexam.co/70-346.html

Page 7: Pass4sure 70-346 Managing Office 365 Identities

Directory

store

Authentication

platform

Windows Azure

Active Directory

Your App

http://www.pass4sureexam.co/70-346.html

Page 8: Pass4sure 70-346 Managing Office 365 Identities

Cloud Identity

Single identity in the cloud

Suitable for small organizations

with no integration to on-

premises directories

Directory Synchronization

Single identity

suitable for medium

and large organizations

without federation

Federated Identity

Single federated identity

and credentials suitable

for medium and large

organizations

Page 9: Pass4sure 70-346 Managing Office 365 Identities

http://www.pass4sureexam.co/70-346.html

Page 10: Pass4sure 70-346 Managing Office 365 Identities

SAML2

Identity Provider

More Details on TechNet: http://aka.ms/sync

http://www.pass4sureexam.co/70-346.html

Page 11: Pass4sure 70-346 Managing Office 365 Identities

* Azure AD offers some 2FA features that are available with ADFS deployment on-premises.

Password Sync SSO with AD FS

Same password to access resources

Can control password policies on-

premises

Support for two factor authentication*

No password re-entry if on premises

Client access filtering by IP or by time

schedule

Authentication occurs on-premises. Can

immediately block disabled accounts.

Change password available from web

Works with Forefront Identity Manager

Page 12: Pass4sure 70-346 Managing Office 365 Identities

Your data and applications are under attack

Passwords are easily compromised

Consumerization of IT has only increased the scope of vulnerability

Strengthening regulatory requirements call for strongly authenticating access

http://www.pass4sureexam.co/70-346.html

Page 13: Pass4sure 70-346 Managing Office 365 Identities

http://www.pass4sureexam.co/70-346.html

Page 14: Pass4sure 70-346 Managing Office 365 Identities

Users sign in from any device using their existing username/password.

Users must also authenticate using their phone or mobile device before access is granted.

Credentials are checkedin Windows Azure AD. Then Active Authentication is triggered for additional verification.

1

2

Page 15: Pass4sure 70-346 Managing Office 365 Identities

http://www.pass4sureexam.co/70-346.html

Page 16: Pass4sure 70-346 Managing Office 365 Identities

Azure Active Directory GRAPH APIREST API for programmatic access to data in Azure AD

Can build multi-tenant applications, or custom LOB Apps

Azure Active Directory Connector for FIM 2010 R2Can be used for multi-forest synchronization and non-AD sources

Public Beta starts on Connect soon

http://www.pass4sureexam.co/70-346.html

Page 17: Pass4sure 70-346 Managing Office 365 Identities
Page 18: Pass4sure 70-346 Managing Office 365 Identities

Cloud Identity Directory Sync Password Sync Graph API FIM Single Sign-On

Org size Small All All Large Large Large

Control of

attributes in

directory

Least control Full control via

on-premises

directory

Full control via

on-premises

directory

Can control core

attributes and

select optional

Can control core

attributes and

select optional

Full control via

on-premises

directory

Source of

authority

Cloud On-premises On-Premises Cloud On-premises On-premises

Hardware

requirements

No on-premises

hardware required

Windows Server

OS for DirSync

appliance

Windows Server

OS for DirSync

appliance

Machine to run

Powershell jobs

on

Federated Identity

Manager with

office 365

Connector

DirSync appliance

ADFS (or other

STS) deployment

Login experience Disjoint username,

password for on-

premises and

cloud

Enter credentials

twice

Disjoint username,

password for on-

premises and

cloud

Enter credentials

twice

Same username,

password for on-

premises and

cloud

Enter credentials

twice

Disjoint username,

password for on-

premises and

cloud

Enter credentials

twice

Disjoint username,

password for on-

premises and

cloud

Enter credentials

twice

Same username,

password for on-

premises and

cloud

Login once if on-

premises

Page 19: Pass4sure 70-346 Managing Office 365 Identities

Windows Azure

Active Directory

User

Cloud IdentityEx: [email protected]

Page 20: Pass4sure 70-346 Managing Office 365 Identities

Windows Azure

Active Directory

User

On-Premises IdentityEx: Domain\Alice

Directory

Synchronization

Cloud IdentityEx: [email protected]

AD

Page 21: Pass4sure 70-346 Managing Office 365 Identities

On-Premises IdentityEx: Domain\Alice

Directory

Synchronization

with one way

Password Hash

Cloud IdentityEx: [email protected]

AD

Windows Azure

Active Directory

User

Page 22: Pass4sure 70-346 Managing Office 365 Identities

Customers can exclude objects from synchronizing to Office 365.

Scoping can be done at the following levels:AD Domain-based

Organizational Unit-based

User Attribute based

Additional filtering capabilities will become available with the O365 Connector.

Preventing the synchronization of specific attributes is not supported.

http://www.pass4sureexam.co/70-346.html

Page 23: Pass4sure 70-346 Managing Office 365 Identities

On-Premises IdentityEx: Domain\Alice

Federation

using ADFS

AD

DirSync on FIM

AD

AD

Windows Azure

Active Directory

User

http://www.pass4sureexam.co/70-346.html

Page 24: Pass4sure 70-346 Managing Office 365 Identities

Number Active

Directory forests

See consolidation whitepaper

UseSingle Forest

DirSync

UseOffice 365 Connector

UseMulti Forest

DirSync

Need on-premises org consolidation

Number Exchange

Orgs

“Disjoint” Account Forests?

“Disjoint” account forests and exchange

org accessed by accounts in the same

forest?

Want to consolidate

single forest?

After consolidation

Single (1)

Multiple (>1)

Yes

None (0)Multiple (>1)

Start

After consolidation

No

Single (1) Yes

Yes

No

No

Multi-forest decision flowchart

Page 25: Pass4sure 70-346 Managing Office 365 Identities

Suitable for small/medium size organizations with AD or Non-ADPerformance limitations apply with PowerShell and Graph API provisioning

PowerShell requires scripting experience

PowerShell option can be used where the customer/partner may have wrappers around PowerShell scripts (eg: Self Service Provisioning)

http://www.pass4sureexam.co/70-346.html

Page 26: Pass4sure 70-346 Managing Office 365 Identities

Suitable for large organizations with certain AD and Non-AD scenariosComplex multi-forest AD scenarios

Non-AD synchronization through Microsoft premier deployment support

Requires Forefront Identity Manager and additional software licenses

http://www.pass4sureexam.co/70-346.html

Page 27: Pass4sure 70-346 Managing Office 365 Identities

Windows Azure

Active Directory

User

On-Premises IdentityEx: Domain\Alice

Federation

AD

Non-AD

Directory

Synchronization

or

Page 28: Pass4sure 70-346 Managing Office 365 Identities

Suitable for educational organizations

Recommended where customers may use existing

non-ADFS Identity systems

Single sign-on

Secure token based authentication

Support for web clients and outlook (ECP) only

Microsoft supported for integration only, no

shibboleth deployment support

Requires on-premises servers & support

Works with AD and other directories on-premises

Shibboleth (SAML)

Works with AD & Non-AD

Suitable for medium, large enterprises

including educational organizations

Recommended option for Active Directory (AD)

based customers

Single sign-on

Secure token based authentication

Support for web and rich clients

Microsoft supported

Works for Office 365 Hybrid Scenarios

Requires on-premises servers, licenses & support

Works with AD

Suitable for medium, large enterprises

including educational organizations

Recommended where customers may use existing

non-ADFS Identity systems with AD or Non-AD

Single sign-on

Secure token based authentication

Support for web and rich clients

Third-party supported

Works for Office 365 Hybrid Scenarios

Requires on-premises servers, licenses & support

Verified through ‘works with Office 365’ program

Works for Office 365 Hybrid Scenarios

Works with Office 365 - Identity

Page 29: Pass4sure 70-346 Managing Office 365 Identities

http://aka.ms/SSOProviders

Qualified by MicrosoftReuse Investments

http://www.pass4sureexam.co/70-346.html

Page 30: Pass4sure 70-346 Managing Office 365 Identities

http://bit.ly/17D5Dq0

WS-Trust & WS-Federation

WS-Federation

SAML-P

Active Directory with ADFS

Page 31: Pass4sure 70-346 Managing Office 365 Identities

Block all external access to Office 365 based on the IP address of the external client

Block all external access to Office 365 except Exchange Active Sync; all other clients such as Outlook are blocked.

Block all external access to Office 365 except for passive browser based applications such as Outlook Web Access or SharePoint Online

http://www.pass4sureexam.co/70-346.html

Page 32: Pass4sure 70-346 Managing Office 365 Identities

Windows Azure

Active Directory

User

Cloud IdentityEx: [email protected]

ISV apps or

SAAS providers

or Your App

Cloud IdentityEx: [email protected]

Page 33: Pass4sure 70-346 Managing Office 365 Identities
Page 34: Pass4sure 70-346 Managing Office 365 Identities

http://msdn.microsoft.com/en-au/

http://www.microsoftvirtualacademy.com/http://channel9.msdn.com/Events/TechEd/Australia/2013

http://technet.microsoft.com/en-au/

Page 35: Pass4sure 70-346 Managing Office 365 Identities

1. Keep up to date with all the latest Office 365 information at

http://ignite.office.com

http://fastTrack.office.com

http://office.microsoft.com

Page 36: Pass4sure 70-346 Managing Office 365 Identities