Reader small image

You're reading from  Mastering Identity and Access Management with Microsoft Azure

Product typeBook
Published inSep 2016
Reading LevelIntermediate
PublisherPackt
ISBN-139781785889448
Edition1st Edition
Languages
Tools
Concepts
Right arrow
Author (1)
Jochen Nickel
Jochen Nickel
author image
Jochen Nickel

Jochen Nickel is a Cloud, Identity and Access Management Solution Architect with a clear focus and in-depth technical knowledge of Identity and Access Management. He is currently working for inovit GmbH in Switzerland leading and executing projects in the field of Identity and Access Management including Data Classification and Information protection. Jochen is focused on Microsoft Technologies, especially in the Enterprise Mobility + Security Suite, Office 365 and Azure. He is an established speaker at many technology conferences like Azure Bootcamps, TrustInTech Meetups or the Experts Live Switzerland and Europe.
Read more about Jochen Nickel

Right arrow

Chapter 12. Advanced Considerations for Complex Scenarios

This chapter is the starting point of our journey to the advanced hybrid identity and access management islands, and of course, solutions. First, we will discuss some important additional business needs in complex hybrid environments, followed by the features required to complete the solution architecture for fulfilling these business requirements. We will stripe features for managing privileged identities and the associated protection mechanisms. Furthermore, we will discuss some aspects of device management, including the new Microsoft Enterprise Data Protection strategy. (Be aware that there is an other product with the same name.) On top of these feature sets, we will provide you with the relevant information for efficient certificate management. In this chapter we will cover the following topics:

  • Additional business needs in a complex hybrid environment

    • Is data classification really needed?

    • Why do we need identity protection?

    • Device...

Additional business needs in a complex hybrid environment


The following section introduces some important business requirements that need to be addressed by the identity and access management solution architecture. We will focus on the following business needs:

  • Data classification: This is necessary for the decision process regarding which cloud services can be used and data moved

  • Identity protection: This provides an effective protection against common security threats relative to identity management and your local Active Directory

  • Device and certificate management: This provides control over data leakage and enhanced authentication scenarios using conditional access

Is data classification really needed?

One of the most important discussions we have with our customers is about their uncertainty over which data and identity information can be stored securely in the cloud and how this data can be efficiently identified. In particular, organizations with multi-forest environments or organizations...

Advanced information for often-used additional features


To protect your organization from compromised accounts, identity attacks, and configuration issues we need to think about a combination of features in the on-premise and cloud environment in your hybrid identity and access management solution.

The following figure shows you the relevant products and features for a suitable Microsoft solution:

Privileged identity management and protection

In the following section we will discuss the four components to the solution shown in the previous figure. We will start from your local infrastructure and end with the relevant Azure Cloud services.

Microsoft Advanced Threat Analytics (ATA)

ATA is designed as an on premises platform that helps you to protect your environment against advanced attacks. The component is focused on automatically analysing, learning, and identifying normal and abnormal entity (user, devices, and resources) behavior. Combining this with privileged access management will provide...

Summary


After working through this chapter you will have received information about typical business needs in complex hybrid environments that need to be handled and fulfilled. The chapter provided you with three very common requirements and provided you with ideas to solve them. Furthermore, you should be able to address the various needs with new knowledge about the different components that can be used. We travelled through the identity management and protection solutions for on premise and cloud environments to increase your ability to manage and protect your organization's identities. We also gave you brief of insights into device management and enterprise data protection capabilities. With this knowledge you should now be able to understand and recognize the several solutions available and be able to talk professionally about them.

Do you want to know more? Stay with us for the following chapters, where we will explain technical architecture and configuration; we will also delve the...

lock icon
The rest of the chapter is locked
You have been reading a chapter from
Mastering Identity and Access Management with Microsoft Azure
Published in: Sep 2016Publisher: PacktISBN-13: 9781785889448
Register for a free Packt account to unlock a world of extra content!
A free Packt account unlocks extra newsletters, articles, discounted offers, and much more. Start advancing your knowledge today.
undefined
Unlock this book and the full library FREE for 7 days
Get unlimited access to 7000+ expert-authored eBooks and videos courses covering every tech area you can think of
Renews at $15.99/month. Cancel anytime

Author (1)

author image
Jochen Nickel

Jochen Nickel is a Cloud, Identity and Access Management Solution Architect with a clear focus and in-depth technical knowledge of Identity and Access Management. He is currently working for inovit GmbH in Switzerland leading and executing projects in the field of Identity and Access Management including Data Classification and Information protection. Jochen is focused on Microsoft Technologies, especially in the Enterprise Mobility + Security Suite, Office 365 and Azure. He is an established speaker at many technology conferences like Azure Bootcamps, TrustInTech Meetups or the Experts Live Switzerland and Europe.
Read more about Jochen Nickel