Differences
This shows you the differences between two versions of the page.
| Both sides previous revision Previous revision Next revision | Previous revision | ||
| azure:az-500:hybrid_identity [2022/05/31 17:07] – mmuze | azure:az-500:hybrid_identity [2022/07/22 14:52] (current) – mmuze | ||
|---|---|---|---|
| Line 1: | Line 1: | ||
| ====== Hybrid Identity ====== | ====== Hybrid Identity ====== | ||
| + | * [[https:// | ||
| * **Hybrid Identity** refers to identity that integrates traditional/ | * **Hybrid Identity** refers to identity that integrates traditional/ | ||
| * **Azure AD Connect** is the service that integrates on-prem AD with Azure AD. | * **Azure AD Connect** is the service that integrates on-prem AD with Azure AD. | ||
| + | * Keep in mind the difference between authentication and authorization. | ||
| - | ===== Azure AD Features ===== | + | ===== Hybrid Identity Authentication ===== |
| + | * [[https:// | ||
| + | * There are three options for hybrid authentication | ||
| + | * password hash sync | ||
| + | * pass-thru authentication | ||
| + | * federated authentication | ||
| + | * [[https:// | ||
| + | |||
| + | ===== Azure AD Authentication | ||
| * **Password hash synchronization.** A sign-in method that synchronizes a hash of a users on-premises AD password with Azure AD. | * **Password hash synchronization.** A sign-in method that synchronizes a hash of a users on-premises AD password with Azure AD. | ||
| * **Pass-through authentication.** A sign-in method that allows users to use the same password on-premises and in the cloud, but doesn' | * **Pass-through authentication.** A sign-in method that allows users to use the same password on-premises and in the cloud, but doesn' | ||
| + | * Companies with a security requirement to immediately enforce on-premises user account states, password policies, and sign-in hours might use this authentication method. | ||
| + | * When a user authenticates against AAD it passes the request to on-prem AD via the auth agent to complete the authentication. | ||
| + | * PTA uses a lightweight on-premises agent that listens for and responds to password validation requests. | ||
| * **Federation integration.** Federation is an optional part of Azure AD Connect and can be used to configure a hybrid environment using an on-premises AD FS infrastructure. It also provides AD FS management capabilities such as certificate renewal and additional AD FS server deployments. | * **Federation integration.** Federation is an optional part of Azure AD Connect and can be used to configure a hybrid environment using an on-premises AD FS infrastructure. It also provides AD FS management capabilities such as certificate renewal and additional AD FS server deployments. | ||
| + | * You can setup password sync also for use as a backup in case the ADFS goes down. | ||
| * **Synchronization.** Responsible for creating users, groups, and other objects. As well as, making sure identity information for your on-premises users and groups is matching the cloud. This synchronization also includes password hashes. | * **Synchronization.** Responsible for creating users, groups, and other objects. As well as, making sure identity information for your on-premises users and groups is matching the cloud. This synchronization also includes password hashes. | ||
| * **Health Monitoring.** Azure AD Connect Health can provide robust monitoring and provide a central location in the Azure portal to view this activity. | * **Health Monitoring.** Azure AD Connect Health can provide robust monitoring and provide a central location in the Azure portal to view this activity. | ||
| + | * **Password writeback** is an option with AAD that will sync password changes made in AAD back to the on-prem AD. | ||
| + | * This does not require any inbound firewall rules; it works over the Azure Service Bus relay on the outbound connection of port 443. | ||
| + | |||
| + | === Choosing an authentication method === | ||
| + | * [[https:// | ||
| + | |||
| + | {{: | ||
| + | ===== Use Cases ===== | ||
| + | |||
| + | - Do you need on-premises Active Directory integration? | ||
| + | - If you do need on-premises Active Directory integration, | ||
| + | - If you do need on-premises Active Directory integration, | ||
| + | - If you need on-premises Active Directory integration, | ||
| + | ====== Azure AD Join ====== | ||
| + | * Azure AD Join allows a Windows 10/11 desktop to be joined to Azure AD for the purposes of controlling access to resources and enforcing requirements on devices. | ||
| + | * For example, an AAD joined BYOD phone could be Intune managed and be required to not be rooted or jail broken to access company resources. | ||
| + | ====== AD Connect ====== | ||
| + | * [[https:// | ||