Reader small image

You're reading from  Mastering Identity and Access Management with Microsoft Azure - Second Edition

Product typeBook
Published inFeb 2019
PublisherPackt
ISBN-139781789132304
Edition2nd Edition
Tools
Right arrow
Author (1)
Jochen Nickel
Jochen Nickel
author image
Jochen Nickel

Jochen Nickel is a Cloud, Identity and Access Management Solution Architect with a clear focus and in-depth technical knowledge of Identity and Access Management. He is currently working for inovit GmbH in Switzerland leading and executing projects in the field of Identity and Access Management including Data Classification and Information protection. Jochen is focused on Microsoft Technologies, especially in the Enterprise Mobility + Security Suite, Office 365 and Azure. He is an established speaker at many technology conferences like Azure Bootcamps, TrustInTech Meetups or the Experts Live Switzerland and Europe.
Read more about Jochen Nickel

Right arrow

Chapter 2. Understanding Identity Synchronization

The main component in a hybrid identity and access management solution is the connectivity between the on-premises Active Directory (AD)and the AzureActive Directory(AAD), including the related synchronization of objects and attributes. Microsoft tries to make the synchronization process straightforward without administrators needing to have the complete details of the system under the hood.

In this chapter, we'll discuss the essential identity-synchronization scenarios and tools for the successful implementation of a full hybrid identity life cycle management. We'll start with an overview of the Microsoft Identity Manager (MIM) and the Azure AD Connect tool, and then we can dive into the identity-synchronization scenarios. Afterward, we'll run through the different processes, the AD user account cleanup for a hybrid environment and all the crucial parts and steps of the identity synchronization in Azure AD Connect. The chapter will be rounded...

Technology overview


The Microsoft Identity Manager (MIM) 2016 or other identity management products are typically used to prepare the identities stored in the local Active Directory for cloud synchronization. The Azure AD Connect tool is generally used to synchronize the AD identities to the Azure AD to be used in connected software as a a service (SaaS) applications or other functionalities. The main advantage that MIM 2016 provides for this solution is to help with domain/forest consolidations, attribute normalization, and complete on-premise identity management with the help of workflows to support your business processes.

As you can see in the following diagram, MIM 2016 is also capable of synchronizing identities with the Azure AD. So, you're probably wondering which tool you should use to sync identities with Azure AD.

The short, practical answer for common scenarios is the Azure AD Connect tool because it supports all the provided synchronization functionality of the Microsoft Azure...

Synchronization scenarios


With the creation of a new Azure AD tenant, the directory information is managed independently from the on-premises AD forest by default. So, basically, a new onboarded user must be created in both directories: the Azure AD and the local AD. Unless you drive a cloud-only company, you always need to synchronize identities from the on-premises AD to the Azure AD tenant you own to provide a single identity. After the synchronization process is in place, Azure AD and AD can be viewed as one unique identity service. The following section provides you with several integration scenarios, including the user sign-in options. We will divide this section into the following situations:

  • Single-forest integration
  • Multi-forest integration
  • Multi Azure Active Directory Integration
  • Azure Active Directory Domain Services Integration
  • Stretched Active Directory to Azure IaaS
  • Azure Active Directory B2B Integration
  • Azure Active Directory and Microsoft Office 365 synchronization
  • Identity and password...

Synchronization terms and processes


In this section, we'll discuss and implement the practical use of the synchronization terms and procedures. We'll combine theory directly with practical use. For this reason, we'll install, configure, and run the processes immediately in the Azure AD Connect tool. To use the guidance, you should deploy a virtual machine with the domain controller role enabled.

Build the virtual machine on Azure or your local virtualization platform. An excellent option is to follow the guide at https://docs.microsoft.com/en-us/office365/enterprise/base-configuration-dev-test-environment with the usage of your free trial Azure or MSDN subscription. We provide you with a complete scripting solution in the code package of the book, or you can follow the instructions in Chapter 7, Deploying Solutions on Azure AD and ADFS.

We use the same domain name you used in Chapter 1Building and Managing Azure Active Directory. In our case, we use the domain name inovitlabs.ch. So, change...

Summary


In this chapter, we discussed the most important identity synchronization tools: Microsoft Identity Manager and Azure Active Directory Connect. We walked through the typical synchronization scenarios. Now you're able to adopt the best scenario for your requirements. In the Synchronization terms and processes section, we took a deep dive into the synchronization service, so you know exactly what's happening under the hood, which will help you to avoid mistakes and provide better troubleshooting for synchronization errors.

In the next chapter, we'll explore additional filtering, join attributes, declarative provisioning options, and generic connector usage.

lock icon
The rest of the chapter is locked
You have been reading a chapter from
Mastering Identity and Access Management with Microsoft Azure - Second Edition
Published in: Feb 2019Publisher: PacktISBN-13: 9781789132304
Register for a free Packt account to unlock a world of extra content!
A free Packt account unlocks extra newsletters, articles, discounted offers, and much more. Start advancing your knowledge today.
undefined
Unlock this book and the full library FREE for 7 days
Get unlimited access to 7000+ expert-authored eBooks and videos courses covering every tech area you can think of
Renews at £13.99/month. Cancel anytime

Author (1)

author image
Jochen Nickel

Jochen Nickel is a Cloud, Identity and Access Management Solution Architect with a clear focus and in-depth technical knowledge of Identity and Access Management. He is currently working for inovit GmbH in Switzerland leading and executing projects in the field of Identity and Access Management including Data Classification and Information protection. Jochen is focused on Microsoft Technologies, especially in the Enterprise Mobility + Security Suite, Office 365 and Azure. He is an established speaker at many technology conferences like Azure Bootcamps, TrustInTech Meetups or the Experts Live Switzerland and Europe.
Read more about Jochen Nickel