Reader small image

You're reading from  Mastering Identity and Access Management with Microsoft Azure

Product typeBook
Published inSep 2016
Reading LevelIntermediate
PublisherPackt
ISBN-139781785889448
Edition1st Edition
Languages
Tools
Concepts
Right arrow
Author (1)
Jochen Nickel
Jochen Nickel
author image
Jochen Nickel

Jochen Nickel is a Cloud, Identity and Access Management Solution Architect with a clear focus and in-depth technical knowledge of Identity and Access Management. He is currently working for inovit GmbH in Switzerland leading and executing projects in the field of Identity and Access Management including Data Classification and Information protection. Jochen is focused on Microsoft Technologies, especially in the Enterprise Mobility + Security Suite, Office 365 and Azure. He is an established speaker at many technology conferences like Azure Bootcamps, TrustInTech Meetups or the Experts Live Switzerland and Europe.
Read more about Jochen Nickel

Right arrow

Chapter 6.  Extending to a Basic Hybrid Environment

With this chapter, we will start to jump into our first hybrid identity and access management scenario. You will be guided through business-relevant information to plan and make the right decisions for a hybrid approach with a single On-Premise Active Directory forest. You will learn to adopt the relevant features, licensing models, and a common security strategy for typical legal requirements. Furthermore, you will also be in a position to build the first basics for the special requirements of a hybrid approach with a multi forest On-Premise Active Directory.

  • Identifying business needs for a hybrid approach

  • Choosing the correct features

  • Getting the benefits and costs

  • Applying the right security strategy for legal requirements

Identifying business needs for a hybrid approach


First, we will start to discuss important and relevant business needs of the hybrid identity and access management approach. We will divide this section into three parts:

  • Typical business needs - common use case and challenges

  • Enterprise Mobility context - supporting Enterprise Mobility with hybrid identity and access management

  • Enterprise cloud suite context - supporting Office 365 and Windows 10 clients on top of Enterprise Mobility

Typical business needs

As already touched upon in previous chapter's, companies usually have Active Directory as their local identity provider to authenticate users with a single sign-on scenario to access their applications. Larger companies have also made investments in On-Premise identity and access management tools to provide the capabilities for user provisioning, automation, and data integrity. In terms of Microsoft technologies, MIM 2016 or earlier versions of the product could be in place. But it doesn...

Choosing the correct features


In this section, we will provide you with an overview of the most important features to provide a suitable hybrid identity and access management platform. We will divide this section into the following feature parts:

  • MIM - On-Premise Identity Management

  • Azure AD Connect - First part of the identity bridge

  • Azure Active Directory Connect Health (part of Azure AD Connect binaries)

  • Active Directory Federation Services - second part of the identity bridge

  • Azure MFA Server

  • Azure Rights Management Connector

  • Bring Your Own Key (BYOK)

MIM 2016

MIM 2016 is the On-Premise IAM product. So if you want to integrate a native solution with the following capabilities it will be a good choice to take:

The following are new features is in MIM 2016:

  • Licensed with Azure AD Premium - remember Azure AD premium is part of EMS and ECS

  • Windows 10 support

  • Privileged Access Management (PAM) - also management of Windows Server 2016 in the near future

  • More self-service capabilities such as user unlock...

Getting the benefits and costs


In this section, we give you an idea about the different possibilities to buy the discussed licenses of the services. If you remember the tables from Chapter 1, Getting Started with a Cloud-Only Scenario , it will be clear that with a hybrid approach it makes sense to invest in Azure AD Premium, as you see in the following table:

Features

Azure AD

Premium

Self-Service Password Reset with On-Premises write-back

X

MIM server licenses

X

Advanced anomaly security reports

X

Advanced usage reporting

X

MFA (cloud users)

X

MFA (On-Premises users)

X

So, if you also use Office 365 and want to use other hybrid services, it would be great to take a look at EMS and ECS. To be up-to-date, use the following link: http://bit.ly/2atHFe1.

The following list shows you Microsoft's different sales models:

Note

Remember to use the licensing tools from Chapter 1, Getting Started with a Cloud-Only Scenario ! Azure RMS and Microsoft Intune...

Summary


After working through this chapter, you will be able to make the right business decisions and apply the key concepts about features, licensing, and security to planned basic hybrid infrastructure. Furthermore, you can now describe the basic need for data and identity classification. Additionally, you have taken first steps in mapping existing use cases and to providing good project marketing.

In the next chapter, we will start to design our hybrid identity architecture. We will focus on key design concepts with several capabilities. As an extra, we will start to enable strong authentication scenarios and advanced identity and authentication reporting features.

lock icon
The rest of the chapter is locked
You have been reading a chapter from
Mastering Identity and Access Management with Microsoft Azure
Published in: Sep 2016Publisher: PacktISBN-13: 9781785889448
Register for a free Packt account to unlock a world of extra content!
A free Packt account unlocks extra newsletters, articles, discounted offers, and much more. Start advancing your knowledge today.
undefined
Unlock this book and the full library FREE for 7 days
Get unlimited access to 7000+ expert-authored eBooks and videos courses covering every tech area you can think of
Renews at $15.99/month. Cancel anytime

Author (1)

author image
Jochen Nickel

Jochen Nickel is a Cloud, Identity and Access Management Solution Architect with a clear focus and in-depth technical knowledge of Identity and Access Management. He is currently working for inovit GmbH in Switzerland leading and executing projects in the field of Identity and Access Management including Data Classification and Information protection. Jochen is focused on Microsoft Technologies, especially in the Enterprise Mobility + Security Suite, Office 365 and Azure. He is an established speaker at many technology conferences like Azure Bootcamps, TrustInTech Meetups or the Experts Live Switzerland and Europe.
Read more about Jochen Nickel