Search icon
Arrow left icon
All Products
Best Sellers
New Releases
Books
Videos
Audiobooks
Learning Hub
Newsletters
Free Learning
Arrow right icon
Mastering Identity and Access Management with Microsoft Azure

You're reading from  Mastering Identity and Access Management with Microsoft Azure

Product type Book
Published in Sep 2016
Publisher Packt
ISBN-13 9781785889448
Pages 692 pages
Edition 1st Edition
Languages
Concepts
Author (1):
Jochen Nickel Jochen Nickel
Profile icon Jochen Nickel

Table of Contents (22) Chapters

Mastering Identity and Access Management with Microsoft Azure
Credits
About the Author
About the Reviewer
www.PacktPub.com
Preface
1. Getting Started with a Cloud-Only Scenario 2. Planning and Designing Cloud Identities 3. Planning and Designing Authentication and Application Access 4. Building and Configuring a Suitable Azure AD 5. Shifting to a Hybrid Scenario 6. Extending to a Basic Hybrid Environment 7. Designing Hybrid Identity Management Architecture 8. Planning Authorization and Information Protection Options 9. Building Cloud from Common Identities 10. Implementing Access Control Mechanisms 11. Managing Transition Scenarios with Special Scenarios 12. Advanced Considerations for Complex Scenarios 13. Delivering Multi-Forest Hybrid Architectures 14. Installing and Configuring the Enhanced Identity Infrastructure 15. Installing and Configuring Information Protection Features 16. Choosing the Right Technology, Methods, and Future Trends

Chapter 12. Advanced Considerations for Complex Scenarios

This chapter is the starting point of our journey to the advanced hybrid identity and access management islands, and of course, solutions. First, we will discuss some important additional business needs in complex hybrid environments, followed by the features required to complete the solution architecture for fulfilling these business requirements. We will stripe features for managing privileged identities and the associated protection mechanisms. Furthermore, we will discuss some aspects of device management, including the new Microsoft Enterprise Data Protection strategy. (Be aware that there is an other product with the same name.) On top of these feature sets, we will provide you with the relevant information for efficient certificate management. In this chapter we will cover the following topics:

  • Additional business needs in a complex hybrid environment

    • Is data classification really needed?

    • Why do we need identity protection?

    • Device...

Additional business needs in a complex hybrid environment


The following section introduces some important business requirements that need to be addressed by the identity and access management solution architecture. We will focus on the following business needs:

  • Data classification: This is necessary for the decision process regarding which cloud services can be used and data moved

  • Identity protection: This provides an effective protection against common security threats relative to identity management and your local Active Directory

  • Device and certificate management: This provides control over data leakage and enhanced authentication scenarios using conditional access

Is data classification really needed?

One of the most important discussions we have with our customers is about their uncertainty over which data and identity information can be stored securely in the cloud and how this data can be efficiently identified. In particular, organizations with multi-forest environments or organizations...

Advanced information for often-used additional features


To protect your organization from compromised accounts, identity attacks, and configuration issues we need to think about a combination of features in the on-premise and cloud environment in your hybrid identity and access management solution.

The following figure shows you the relevant products and features for a suitable Microsoft solution:

Privileged identity management and protection

In the following section we will discuss the four components to the solution shown in the previous figure. We will start from your local infrastructure and end with the relevant Azure Cloud services.

Microsoft Advanced Threat Analytics (ATA)

ATA is designed as an on premises platform that helps you to protect your environment against advanced attacks. The component is focused on automatically analysing, learning, and identifying normal and abnormal entity (user, devices, and resources) behavior. Combining this with privileged access management will provide...

Summary


After working through this chapter you will have received information about typical business needs in complex hybrid environments that need to be handled and fulfilled. The chapter provided you with three very common requirements and provided you with ideas to solve them. Furthermore, you should be able to address the various needs with new knowledge about the different components that can be used. We travelled through the identity management and protection solutions for on premise and cloud environments to increase your ability to manage and protect your organization's identities. We also gave you brief of insights into device management and enterprise data protection capabilities. With this knowledge you should now be able to understand and recognize the several solutions available and be able to talk professionally about them.

Do you want to know more? Stay with us for the following chapters, where we will explain technical architecture and configuration; we will also delve the...

lock icon The rest of the chapter is locked
You have been reading a chapter from
Mastering Identity and Access Management with Microsoft Azure
Published in: Sep 2016 Publisher: Packt ISBN-13: 9781785889448
Register for a free Packt account to unlock a world of extra content!
A free Packt account unlocks extra newsletters, articles, discounted offers, and much more. Start advancing your knowledge today.
Unlock this book and the full library FREE for 7 days
Get unlimited access to 7000+ expert-authored eBooks and videos courses covering every tech area you can think of
Renews at €14.99/month. Cancel anytime}