Search icon
Arrow left icon
All Products
Best Sellers
New Releases
Books
Videos
Audiobooks
Learning Hub
Newsletters
Free Learning
Arrow right icon
Mastering Identity and Access Management with Microsoft Azure

You're reading from  Mastering Identity and Access Management with Microsoft Azure

Product type Book
Published in Sep 2016
Publisher Packt
ISBN-13 9781785889448
Pages 692 pages
Edition 1st Edition
Languages
Concepts
Author (1):
Jochen Nickel Jochen Nickel
Profile icon Jochen Nickel

Table of Contents (22) Chapters

Mastering Identity and Access Management with Microsoft Azure
Credits
About the Author
About the Reviewer
www.PacktPub.com
Preface
1. Getting Started with a Cloud-Only Scenario 2. Planning and Designing Cloud Identities 3. Planning and Designing Authentication and Application Access 4. Building and Configuring a Suitable Azure AD 5. Shifting to a Hybrid Scenario 6. Extending to a Basic Hybrid Environment 7. Designing Hybrid Identity Management Architecture 8. Planning Authorization and Information Protection Options 9. Building Cloud from Common Identities 10. Implementing Access Control Mechanisms 11. Managing Transition Scenarios with Special Scenarios 12. Advanced Considerations for Complex Scenarios 13. Delivering Multi-Forest Hybrid Architectures 14. Installing and Configuring the Enhanced Identity Infrastructure 15. Installing and Configuring Information Protection Features 16. Choosing the Right Technology, Methods, and Future Trends

Chapter 10. Implementing Access Control Mechanisms

Now that we have already installed and configured our first hybrid identity and federation environment, it's time to take the next steps to get deeper into access control mechanisms. Let's configure the Azure MFA server to protect on-premise applications for the realization of typical conditional access scenarios. Furthermore, a suitable access control solution needs a modern information protection mechanism, such as Microsoft Rights Management services. We will configure this important component in the following chapter in order to fulfill security requirements in business-relevant use cases. After looking at the currently available technologies, we will configure the latest Windows Server 2016 features so as to learn more about the new and advanced security features of Active Directory Federation Services 4.0 and Web Application Proxy. In this chapter we will cover the following topics:

  • Extending the basic lab environment

  • Configuring conditional...

Extending the basic lab environment


Until now we have worked with our basic installed lab environment. However, to configure Windows Server 2016 features, we need to extend the current structure with two additional virtual machines:

ADS01

Domain Controller

2012 R2 Data Center

identitypluslabvnet-subnet2(10.0.2.0/24)

APP01

Application Server

2012 R2 Data Center

identitypluslabvnet-subnet2(10.0.2.0/24)

IDB01

Identity Bridge

ADFS and AAD Connect

2012 R2 Data Center

identitypluslabvnet-subnet2(10.0.2.0/24)

IDB03

New

Identity Bridge

ADFS 4.0

2016 TP5

identitypluslabvnet-subnet2(10.0.2.0/24)

URA01

Unified Remote Access

Web Application Proxy

2012 R2 Data Center

identitypluslabvnet-subnet2(10.0.1.0/24)

URA03

New

Unified Remote Access

Web Application Proxy

2016 TP5

identitypluslabvnet-subnet2(10.0.1.0/24)

To find out how to add additional virtual machines, follow the Add additional virtual machines section in Chapter 9, Building Cloud from Common Identities. After...

Configuring conditional access control


Before configuring conditional access control scenarios, we need to implement the Azure MFA server on the Identity Bridge server IDB01:

  1. Open https://manage.windowsazure.com in your preferred browser and log on with your global administrator credentials.

  2. Go to CONFIGURE | multifactor authentication | Manage service settings.

  3. To manage advanced settings and view reports, go to the portal | Manage advanced settings and view reports.

  4. DOWNLOADS: Download the Multi-Factor Authentication Server.

  5. Click Generate Activation Credentials.

    Note

    The Activation Credentials (valid for 10 minutes).

  6. Click Download.

Installing and configuring the Azure MFA server

After downloading the installation binaries, we need to install the Azure MFA server.

Note

Practical note:

We recommend changing the virtual machine size of IDB01 to an A2 (two cores, 3.5 GB memory).

  1. Log on to the ADFS Server IDB01 with the following credentials:

    • Username: Domain\AdminAccount

    • Password: YourPassword

  2. Double...

Enabling and configuring information protection


In this section we will enable and configure Azure Rights Management Services (Azure RMS) to provide extended access control mechanisms for information protection. This chapter builds on the introductory configuration of Azure RMS and will be extended in complex hybrid scenarios in the following chapters. Let's start the implementation!

Enabling and configuring Azure RMS

The next steps will provide you with guidance on how to enable Azure RMS on your tenant:

  1. Open your preferred browser and log on to https://manage.windowsazure.com with your global administrator rights.

  2. Select Active Directory and click RIGHTS MANAGEMENT.

  3. Activate Azure RMS.

  4. You should receive the new Rights Managements service status as Active.

Next, we will install the Azure Rights Management Administration Tool on the Identity Bridge Server IDB01 from the following link: http://bit.ly/1SBEM6q.

  1. Log on to the ADFS Server IDB01 with the following credentials:

    • Username: Domain\AdminAccount...

Configuring advanced security scenarios with Windows Server 2016


Now that we have configured the information protection capabilities, we want to get familiar with the new features of ADFS 4.0. For this reason, we will start with some quick win examples and go ahead to explore more and more features in this and upcoming chapters. Let's start with the Azure MFA integration. Are you ready?

Note

Recommendation

Change the two virtual machines IDB03 and URA03 to A2 (two cores, 3.5 GB memory) for a better user experience.

Azure MFA integration

In this section we will configure the Azure MFA integration to protect on-premises resources with a second factor and without an Azure MFA server installed.

  1. Log on to the ADFS Server IDB03 with the following credentials:

    • Username: Domain\AdminAccount

    • Password: YourPassword

  2. Open the AD FS Management console.

  3. Expand Service | Authentication Methods.

  4. Click Edit Multi-Factor Authentication Methods.

  5. Check Azure MFA.

  6. Open an evaluated PowerShell and type:

    •  Add-AzureAccount...

Summary


Yeah! We had our first basic experience with Azure MFA and RMS on-premises integration. We have also made our first small steps into discovering Windows Server 2016. Remember, this just the tip of the iceberg. You should now be able to configure and manage the access management part of the basic hybrid scenario. You should also be able to address and implement additional security features in order to fulfil higher security requirements.

We always recommend you need to build labs from scratch so as to understand all the important tasks required. Furthermore, it enables you to get a working demo environment to show off its functionality to your boss or co-workers.

To professional readers, we have prepared some highlights in the following chapters. Do you want to know them? Then go ahead, and it will be our pleasure to give you some additional hints for your practical work.

lock icon The rest of the chapter is locked
You have been reading a chapter from
Mastering Identity and Access Management with Microsoft Azure
Published in: Sep 2016 Publisher: Packt ISBN-13: 9781785889448
Register for a free Packt account to unlock a world of extra content!
A free Packt account unlocks extra newsletters, articles, discounted offers, and much more. Start advancing your knowledge today.
Unlock this book and the full library FREE for 7 days
Get unlimited access to 7000+ expert-authored eBooks and videos courses covering every tech area you can think of
Renews at €14.99/month. Cancel anytime}