Azure Active Directory AD/ Identity Access Management; Migration from On Premise AD to the Azure AD

Sharing is caring!

<p><strong>Azure Active Directory<&sol;strong> is not designed to be the cloud version of Active Directory&period; It is not a domain controller or a directory in the cloud that will provide the exact same capabilities with the AD&period; Actually&comma; Azure Active Directory &lpar;Azure AD&rpar; is a multi-tenant&comma; cloud-based directory&comma; and identity management service&period;<&sol;p>&NewLine;<p>That’s why there is no actual &OpenCurlyDoubleQuote;migration” path from Active Directory to Azure Active Directory&period; You can synchronize your on-premises directories &lpar;Active Directory or other&rpar; to Azure Active Directory but not migrate your computer accounts&comma; group policies&comma; OU etc&period;<&sol;p>&NewLine;<p><a href&equals;"https&colon;&sol;&sol;docs&period;microsoft&period;com&sol;en-us&sol;azure&sol;active-directory&sol;fundamentals&sol;understand-azure-identity-solutions"><img class&equals;"aligncenter size-full wp-image-294" src&equals;"http&colon;&sol;&sol;www&period;thecloudxperts&period;co&period;uk&sol;wp-content&sol;uploads&sol;2018&sol;10&sol;azure-ad&period;png" alt&equals;"" width&equals;"441" height&equals;"355" &sol;><&sol;a><&sol;p>&NewLine;<p>&nbsp&semi;<&sol;p>&NewLine;<h2><strong>Some of Azure AD Features are&colon;<&sol;strong><&sol;h2>&NewLine;<ul>&NewLine;<li><strong>Application Management&colon; <&sol;strong>Azure Active Directory &lpar;Azure AD&rpar; provides secure and seamless access to cloud and on-premises applications&period; Users can sign in once to access Office 365 and other business applications from Microsoft&comma; thousands of software as a service &lpar;SaaS&rpar; applications&comma; on-premises applications&comma; and line of business &lpar;LOB&rpar; apps&period;<a href&equals;"https&colon;&sol;&sol;docs&period;microsoft&period;com&sol;en-us&sol;azure&sol;active-directory&sol;manage-apps&sol;what-is-application-management"><img class&equals;"aligncenter wp-image-296 size-medium" src&equals;"http&colon;&sol;&sol;www&period;thecloudxperts&period;co&period;uk&sol;wp-content&sol;uploads&sol;2018&sol;10&sol;migrate2-300x141&period;png" alt&equals;"" width&equals;"300" height&equals;"141" &sol;><&sol;a><&sol;li>&NewLine;<&sol;ul>&NewLine;<p>&nbsp&semi;<&sol;p>&NewLine;<ul>&NewLine;<li><strong>Azure AD Authentication&colon; <&sol;strong>Microsoft Azure Active Directory &lpar;Azure AD&rpar; includes features&comma; like Azure Multi-Factor Authentication &lpar;Azure MFA&rpar; and Azure AD self-service password reset &lpar;SSPR&rpar;&comma; to help administrators protect their organizations and users with additional authentication methods&period;<&sol;li>&NewLine;<&sol;ul>&NewLine;<p><img class&equals;"aligncenter size-medium wp-image-298" src&equals;"http&colon;&sol;&sol;www&period;thecloudxperts&period;co&period;uk&sol;wp-content&sol;uploads&sol;2018&sol;10&sol;methods-300x46&period;png" alt&equals;"" width&equals;"300" height&equals;"46" &sol;><&sol;p>&NewLine;<p>Some organisation can take security one step further by adding their own customizations on top of the global banned password list in what Microsoft calls the custom banned password list<&sol;p>&NewLine;<p>&nbsp&semi;<&sol;p>&NewLine;<ul>&NewLine;<li><strong>Conditional Access&colon; <&sol;strong>Conditional access is a capability of Azure Active Directory&period; With conditional access&comma; you can implement automated access control decisions for accessing your cloud apps that are based on conditions&period;  Here are ome common access concerns that conditional access can help you with&colon;<&sol;li>&NewLine;<&sol;ul>&NewLine;<pre><strong>Sign in Risk<&sol;strong>&colon; A sign-in risk is an indicator of the likelihood &lpar;high&comma; medium&comma; or low&rpar;&period;You can use the calculated sign-in risk level as condition in a conditional access policy&period;To use this condition&comma; you need to have Azure Active Directory Identity Protection enabled&period;&period;<&sol;pre>&NewLine;<pre><strong>Network Location&colon; <&sol;strong>Define conditions based on where a connection was attempted&period;like from trusted locations and selected locations<&sol;pre>&NewLine;<p>&nbsp&semi;<&sol;p>&NewLine;<pre><strong>Device Management&colon;<&sol;strong> Azure AD identifies the platform by using information provided by the device&comma; such as user agent&period; This condition is useful when a policy should apply only to an unmanaged device to provide additional session security&period;<&sol;pre>&NewLine;<pre><strong>Client Applications&colon;<&sol;strong> By using the client apps condition&comma; you can apply a policy to different types of applications&period; Examples are websites&comma;services&comma; mobile apps&comma; and desktop applications&period;<&sol;pre>&NewLine;<p>&nbsp&semi;<&sol;p>&NewLine;<ul>&NewLine;<li><strong>Identity Protection&colon;  <&sol;strong>Azure Active Directory Identity Protection is more than a monitoring and reporting tool&period; To protect your organization&&num;8217&semi;s identities&comma; you can configure risk-based policies that automatically respond to detected issues when a specified risk level has been reached&period; i&period;e Detect&comma; Investigate and Conditional Access&period;<&sol;li>&NewLine;<li><strong>Device Management&colon; <&sol;strong>Device management is the foundation of a device based on conditional access&period;  Through devices&comma; your users are getting access to your corporate assets&period; To protect your corporate assets&comma; as an IT administrator&comma; you want to have control over these devices&period; This enables you to make sure that your users are accessing your resources from devices that meet your standards for security and compliance&period;<&sol;li>&NewLine;<li>&NewLine;<pre><strong>Single-Sign-On &lpar;SSO&rpar;&colon;<&sol;strong> users don’t see additional authentication prompts when accessing work resources&period; The SSO functionality is even when they are not connected to the domain network available&period;<&sol;pre>&NewLine;<&sol;li>&NewLine;<li>&NewLine;<pre><strong>Enterprise compliant roaming<&sol;strong> &colon;Users don’t need to connect a Microsoft account &lpar;for example&comma; Hotmail&rpar; to see settings across devices&period;<&sol;pre>&NewLine;<&sol;li>&NewLine;<li>&NewLine;<pre><strong>Access to Windows Store for Business<&sol;strong>&colon; Your users can choose from an inventory of applications pre-selected by the organization&period;<&sol;pre>&NewLine;<&sol;li>&NewLine;<li>&NewLine;<pre><strong>Windows Hello<&sol;strong> support for secure and convenient access to work resources&period;<&sol;pre>&NewLine;<&sol;li>&NewLine;<li>&NewLine;<pre><strong>Restriction of access<&sol;strong> to apps from only devices that meet compliance policy&period;<&sol;pre>&NewLine;<&sol;li>&NewLine;<li>&NewLine;<pre><strong>Seamless access to on-premises resources<&sol;strong> when the device has line of sight to the on-premises domain controller&period;<&sol;pre>&NewLine;<&sol;li>&NewLine;<&sol;ul>&NewLine;<p>For domain services&comma; Azure offers a stand only service&comma; called &&num;8220&semi;Azure AD Domain Services &&num;8221&semi;  that you could use to replicate your existing Active Directory implementation to the cloud&period; It is a stand-alone service that can offer domain services to your Azure VMs and your directory-aware applications if you decide to move them to Azure infrastructure services&period; But with no replication to any other on-premises or cloud &lpar;in a VM&rpar; domain controller&period;<&sol;p>&NewLine;<p>If you want to migrate your domain controllers in the cloud to use them for the traditional task you could deploy domain controllers in Azure Virtual Machines and replicate via VPN&period;<&sol;p>&NewLine;<p><strong>So to conclude&comma;<&sol;strong> if you would like to extend the reach of your identities to the cloud you can start by synchronizing your Active Directory to Azure AD&period;<&sol;p>&NewLine;<p>&nbsp&semi;<&sol;p>&NewLine;<p>&nbsp&semi;<&sol;p>&NewLine;<p>Ref&colon; <a href&equals;"https&colon;&sol;&sol;docs&period;microsoft&period;com&sol;en-us&sol;azure&sol;active-directory&sol;fundamentals&sol;active-directory-deployment-plans">Microsoft<&sol;a><&sol;p>&NewLine;

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.