Reader small image

You're reading from  Mastering Identity and Access Management with Microsoft Azure - Second Edition

Product typeBook
Published inFeb 2019
PublisherPackt
ISBN-139781789132304
Edition2nd Edition
Tools
Right arrow
Author (1)
Jochen Nickel
Jochen Nickel
author image
Jochen Nickel

Jochen Nickel is a Cloud, Identity and Access Management Solution Architect with a clear focus and in-depth technical knowledge of Identity and Access Management. He is currently working for inovit GmbH in Switzerland leading and executing projects in the field of Identity and Access Management including Data Classification and Information protection. Jochen is focused on Microsoft Technologies, especially in the Enterprise Mobility + Security Suite, Office 365 and Azure. He is an established speaker at many technology conferences like Azure Bootcamps, TrustInTech Meetups or the Experts Live Switzerland and Europe.
Read more about Jochen Nickel

Right arrow

Chapter 11. Creating Identity Life Cycle Management in Azure

Handling the identity life cycle in cloud services is a highly requested topic; in particular, we are concerned about the handling of guest users in the Azure Active Directory, providing access to applications in the cloud and on-premise, including the sharing of information in a typical collaboration scenario. Precisely for this reason, we will discuss many use cases for handling guest users securely in your environment, and we will provide good usability for the users to access applications and data. We will also consider some helpful tools and services to automate your identity life cycle management. For sure, we can only provide a small footprint of ideas and references in this chapter, because there are many tasks and ideas to solve.

The chapter will be organized into the following sections:

  • Lab environment readiness
  • Handling the guest user life cycle
  • Azure services for automation

We will be working practically on different topics...

Lab environment readiness


For this chapter, we will need a configured second Azure AD with some test users inside. The users need to be licensed with Office 365 E3 or E5 licenses. The tenant and the associated public DNS configuration for the additional custom domain need to be done so that the users can send and receive emails. Chapter 1Building and Managing Azure Active Directory, provided you with the required technical references to be ready to use the lab configuration in this chapter. Testing the functionality with the Azure AD application proxy requires that you have finished the steps in Chapter 1, Building and Managing Azure Active Directory, or in Chapter 9Deploying Additional Applications on Azure AD; specifically, the Kerberos application publishing. We will do the configuration to provide external access to on-premise applications for guest users on the YD1APP01 virtual machine, as described in the following diagram:

Lab environment overview

 

 

In addition to the infrastructure...

Handling the guest user life cycle


In the following section, we will work through the different identity life cycle tasks for guest users. We will organize this section into specific use cases, as follows:

  • Use Case 1: Exploring the invitation process with different user types
  • Use Case 2: Using the Azure AD B2B portal
  • Use Case 3: Providing guest user access to on-premise apps

Now, we will start with the first use case.

Use Case 1 – Exploring the invitation process with different user types

In the following use case, we will explore the invitation process for different user types. We will use our global administrator to invite the following users:

  • Maria Lee
  • Jochen Nickel
  • Jenny Green
  • Susi Delgado

Note

The usernames need to be replaced with your names.

With the next steps, we will start the configuration:

  1. Open the Azure portal, https://portal.azure.com, as the global administrator, and navigate to the Azure AD blade.
  2. Navigate to Users | All users, as follows:

Guest user creation process in Azure AD portal

  1. Click...

Azure services for automation


This year, at Microsoft Ignite, Mark Wahl presented a new feature set. This feature set is called Azure AD Identity Governance, which is in private preview. I will give you an idea of the public information.

Identity is the control panel and merges user experience, business needs, and security requirements together. You need to ensure that the correct users get the right access to the correct and required resources at any time. Azure AD Identity Governance is the set of capabilities for this. They enable you to define access policies and monitor your identities. Microsoft is developing a complete suite of governance capabilities for Azure AD, including two powerful new features: Entitlement management and My Access.

 

Admins will be able to create policies for resources, such as groups, apps, and sites, with the upcoming entitlement management. It will provide the automated process of granting access to employees and partners. The My Access portal gives employees...

Summary


Working through this chapter, you saw how you can build a rich Azure B2B solution with an identity life cycle, including on-premise application access for guests. Furthermore, you also had an excellent introduction to the possible use cases and gaps. We also provided an overview of the upcoming Identity Governance features that Microsoft is developing, and the power that they will bring to the game; for example, there is a resource assignment based on roles and associated policies.

In the next chapter, we will deploy single-tenant and multi-tenant applications to your environment, and will provide an introduction to these concepts.

lock icon
The rest of the chapter is locked
You have been reading a chapter from
Mastering Identity and Access Management with Microsoft Azure - Second Edition
Published in: Feb 2019Publisher: PacktISBN-13: 9781789132304
Register for a free Packt account to unlock a world of extra content!
A free Packt account unlocks extra newsletters, articles, discounted offers, and much more. Start advancing your knowledge today.
undefined
Unlock this book and the full library FREE for 7 days
Get unlimited access to 7000+ expert-authored eBooks and videos courses covering every tech area you can think of
Renews at £13.99/month. Cancel anytime

Author (1)

author image
Jochen Nickel

Jochen Nickel is a Cloud, Identity and Access Management Solution Architect with a clear focus and in-depth technical knowledge of Identity and Access Management. He is currently working for inovit GmbH in Switzerland leading and executing projects in the field of Identity and Access Management including Data Classification and Information protection. Jochen is focused on Microsoft Technologies, especially in the Enterprise Mobility + Security Suite, Office 365 and Azure. He is an established speaker at many technology conferences like Azure Bootcamps, TrustInTech Meetups or the Experts Live Switzerland and Europe.
Read more about Jochen Nickel