Monday , February 27 2017

Designing Identity Solutions with Azure Active Directory

Lets go through Azure Active Directory and build a lab to test the features and functionalities. (Quick Overview)

  • Install and configure Azure AD Connect
  • Use Azure AD Connect to integrate Azure AD with your on-premises AD
  • Use Azure AD to authenticate with SaaS services
  • Cloud AD Discovery (It’s an Azure Active Directory Premium feature , if you don’t know what are the SaaS services your users are using ,you can deploy a agent on all the windows machines and get analytics out of the azure dashboard to decide on what all the applications you can use from the Azure Active directory application gallery (To get Single Sign On).)

Step 1 –

Need a Azure trial account – As it don’t have a On-premises server with Public IP . I will be building a lab on the cloud so that I can test the azure active directory.

New – Security + Identity – Creating a New Azure Active Directory –

clip_image002

Step 2 –

Now Login to the portal – Go to Active directory . As this point of time you have to switch back to the old portal to create a new active directory.

Azure Portal – Active Directories – Default Directory.

You can use the default active directory or create a new active directory in my case am create a new one. Using the default shouldn’t be an issue.

  • Add a New Directory
  • Creating a new azure administrator

clip_image004

clip_image006

clip_image008

Verifying my Azure administrator credentials –

clip_image010

Step 3 –

Preparing Azure Directory Sync Server –  (Assuming it as a On-prem Active Directory Server)

Create New Server

clip_image012

Updated Endpoints – Win2012R2AD.cloudapp.net:3389

to Remote desktop (Optional as I remember only 3389.)

clip_image014

Installed Active Directory on the Azure VM Created.

How to Install Active Directory on 2012 R2 –

http://www.careexchange.in/how-to-promote-windows-server-2012-as-a-domain-controller/

Download the latest Azure Active Directory Connect –

clip_image016

https://www.microsoft.com/en-us/download/confirmation.aspx?id=47594

Run the Setup Azure Active Directory Connect Server –

clip_image018

Doing a default installation.

clip_image020

Entering my Azure Active directory administrator credentials

clip_image022

entering my local domain controller credentials

clip_image024

clip_image026

clip_image028c

To do a force sync you have to browse to

C:\Program Files\Microsoft Azure AD Sync\Bin>DirectorySyncclientcmd.exe delta

clip_image030

Step 4 –

Now you can add the domain in the azure active directory.

clip_image032

Adding the Domain

clip_image034

It will ask you to verify the domain with an txt record add it . wait for sometime so that you can verify the domain and set it as an default domain

 

clip_image036

Step 5 –

Using an Application “Twitter” for Single Sign ON

clip_image038

clip_image040

Using an Application “Twitter Deck”

https://tweetdeck.twitter.com/#

clip_image041

Using an Application “Sales Force” with Microsoft Azure AD Single-ON with Azure Federation.

  • Azure Federation
  • Password Sync
  • Active Directory Federation Services  Single Sign On

clip_image043

Enter the Sales force URL –

clip_image045

 

clip_image047

Login to Sales force and Enable SAML –

clip_image048

clip_image050

clip_image051

Enable Azure SSO

clip_image052

Using an Application “Digicert”

Just enter the Credentials Manually when you add the application from gallery.

clip_image054

End user can use – To get the azure active directory portal.

myapps.microsoft.com

or

https://account.activedirectory.windowsazure.com/applications/

Azure Active Directory Premium provides Multi factor Authentication –

clip_image056

AppStore – Iphone Azure Authenticator in my case

Options

Call or Text

clip_image058clip_image060

My Apps – Azure Active Directory

 

clip_image062clip_image064

When you disable the Active directory account from the on premises for testing.

clip_image066

To test password write back features . (Azure Active Directory Premium Feature)

Enabling Password reset –

clip_image068

Activity Reports –

clip_image070

Adding Cloud App Discovery for analytics

clip_image072

clip_image074

Upgrading Azure Active directory free to Premium –

Open Azure AD Connect in the Active directory server –

clip_image076

Check Password writeback –

clip_image078

About Satheshwaran Manoharan

Satheshwaran Manoharan is an Microsoft Exchange Server MVP , Publisher of CareExchange.in Supporting/Deploying/Designing Microsoft Exchange for some years. Extensive experience on Microsoft Technologies.

Check Also

Outlook Cannot Logon System resources are critically Low

Microsoft Outlook 2016. Outlook Cannot Log on. Verify you are connected to the network and ...

Leave a Reply

Your email address will not be published.