Azure Active Directory? Windows AD vs Azure AD

Sharing is caring!

&NewLine;<p><strong>Azure Active Directory &lpar;AAD&rpar;<&sol;strong><&sol;p>&NewLine;&NewLine;&NewLine;&NewLine;<p>Azure Active Directory &lpar;Azure AD&rpar; is Microsoft’s cloud-based identity and access management service&comma; which helps your employees sign in and access resources&period; Azure AD is the backbone of the Office 365 system&comma; and it can sync with on-premise&nbsp&semi;Active Directory&nbsp&semi;and provide authentication to other cloud-based systems&comma; Internal resources&comma; such as apps&comma; intranet via OAuth&period;<&sol;p>&NewLine;&NewLine;&NewLine;&NewLine;<p><strong>Windows Active Directory<&sol;strong><&sol;p>&NewLine;&NewLine;&NewLine;&NewLine;<p>Windows Active Directory lives on-premise in servers called Domain Controllers &lpar;DC&rpar;&period; Each DC contains a catalogue of users and computers that are authorized to access resources on the network&period; Users authenticate to DCs via&nbsp&semi;Kerberos&nbsp&semi;or NTLM authentication&period;<&sol;p>&NewLine;&NewLine;&NewLine;&NewLine;<p><strong>Azure AD and Windows AD a<&sol;strong>re both created by Microsoft&comma; and they are both IAM systems&comma; but that’s pretty much where the comparisons stop&period; They are fundamentally different systems that exist in an interconnected enterprise environment&period;<&sol;p>&NewLine;&NewLine;&NewLine;&NewLine;<figure class&equals;"wp-block-table"><table><tbody><tr><td> <&sol;td><td><strong>Azure Active Directory<&sol;strong><&sol;td><td><strong>Windows Active Directory<&sol;strong><&sol;td><&sol;tr><tr><td>Communication <&sol;td><td>REST<&sol;td><td>LDAP<&sol;td><&sol;tr><tr><td>Authentication<&sol;td><td>Cloud-based protocols<&sol;td><td>Kerberos and NTLM<&sol;td><&sol;tr><tr><td>Network Organisation<&sol;td><td>Flat Structure of users into groups<&sol;td><td>OU&&num;8217&semi;s&comma; Domains and forests<&sol;td><&sol;tr><tr><td>Devices<&sol;td><td>Mobile Device Management <&sol;td><td>No MDM<&sol;td><&sol;tr><tr><td>Entitlement Management<&sol;td><td>Admins organised users into groups<&sol;td><td>Admins or data owners assign users to groups<&sol;td><&sol;tr><tr><td>Desktops<&sol;td><td>Windows desktops can join Endpoint management <&sol;td><td>Desktops are governed by GPOs<&sol;td><&sol;tr><tr><td>Servers<&sol;td><td>Uses Domain services to manage servers<&sol;td><td>Managed by GPOs or On-premise server management system<&sol;td><&sol;tr><&sol;tbody><&sol;table><&sol;figure>&NewLine;&NewLine;&NewLine;&NewLine;<p><strong>Directories&comma; Subscriptions and Users<&sol;strong><&sol;p>&NewLine;&NewLine;&NewLine;&NewLine;<p>It&&num;8217&semi;s Important to understand that Azure offers several cloud-based services&period; All of those services can use Azure AD to identify users and control access&period;<&sol;p>&NewLine;&NewLine;&NewLine;&NewLine;<p>When a company or organization signs up to use one of these offerings&comma; they are assigned a default&nbsp&semi;<em><strong>directory<&sol;strong><&sol;em>&comma; which is an instance of Azure AD&period; This directory holds the users and groups that will have access to each of the services the company has signed up for&period; This default directory is sometimes referred to as a&nbsp&semi;<em>tenant<&sol;em>&period; A tenant represents the organization and the default directory assigned to it&period; <&sol;p>&NewLine;&NewLine;&NewLine;&NewLine;<figure class&equals;"wp-block-image"><img src&equals;"https&colon;&sol;&sol;docs&period;microsoft&period;com&sol;en-us&sol;learn&sol;modules&sol;manage-users-and-groups-in-aad&sol;media&sol;2-users-subs-and-directories&period;png" alt&equals;"Conceptual art showing users&comma; directories&comma; and subscriptions in Azure"&sol;><&sol;figure>&NewLine;&NewLine;&NewLine;&NewLine;<p>An organization &lpar;tenant&rpar; always has one default Azure AD directory it&&num;8217&semi;s associated with&comma; however&comma; owners can create additional directories to support development or testing purposes&comma; or because they want to have separate directories to synchronize with their local Windows Server AD forests&period;<&sol;p>&NewLine;&NewLine;&NewLine;&NewLine;<p><em><strong>Subscriptions<&sol;strong><&sol;em> in Azure are both a billing entity and a security boundary&period; Resources such as virtual machines&comma; web sites&comma; and databases are always associated to a single subscription&period; If you belong to multiple directories&comma; you can switch the current directory you are working in through the <strong>Directory &plus; subscription<&sol;strong> button in the Azure portal header&period;<&sol;p>&NewLine;&NewLine;&NewLine;&NewLine;<p>Every <strong>user<&sol;strong> who needs access to Azure resources needs an Azure user account&period; A user account contains all the information needed to authenticate the user during the sign-on process&period; Once authenticated&comma; Azure AD builds an access token to authorize the user and determine what resources they can access and what they can do with those resources&period;<&sol;p>&NewLine;&NewLine;&NewLine;&NewLine;<p>You use the <strong>Azure Active Directory<&sol;strong> dashboard in the Azure portal to work with user objects&period; Keep in mind that you can only work with a single directory at a time &&num;8211&semi; but you can use the <strong>Directory &plus; Subscription<&sol;strong> panel to switch directories&period; <&sol;p>&NewLine;&NewLine;&NewLine;&NewLine;<p><&sol;p>&NewLine;&NewLine;&NewLine;&NewLine;<p><strong>Typically&comma; Azure AD defines users in three ways&colon;<&sol;strong><&sol;p>&NewLine;&NewLine;&NewLine;&NewLine;<ol class&equals;"wp-block-list"><li><strong>Cloud identities<&sol;strong>&nbsp&semi;&&num;8211&semi; These users exist only in Azure AD&period; Examples are administrator accounts and users that you manage yourself&period;&nbsp&semi;<&sol;li><&sol;ol>&NewLine;&NewLine;&NewLine;&NewLine;<p>2&period; <strong>Directory-synchronized identities<&sol;strong> &&num;8211&semi; These users exist in an on-premises Active Directory&period; A synchronization activity that occurs via <strong>Azure AD Connect<&sol;strong> brings these users into Azure&period; <&sol;p>&NewLine;&NewLine;&NewLine;&NewLine;<p>3&period; <strong>Guest users<&sol;strong> &&num;8211&semi; These users exist outside Azure&period; Examples are accounts from other cloud providers and Microsoft accounts such as an Xbox LIVE account&period; Their source is <strong>Invited user<&sol;strong>&period; This type of account is useful when external vendors or contractors need access to your Azure resources<&sol;p>&NewLine;