You are on page 1of 3

AZURE ACTIVE DIRECTORY AND BENFITS

Single sign on to any cloud or on premises applications

Works with ios or mac andriod and windows devices

Protect on premises web applications with security remote access

Extend on prem ad to azure cloud easily

Protect sensitive data and applications

Reduces costs and enhance security

ADDS ---> On premises

ADD ---> Azure directory

ADFS : Active Directory Federation Service


ADCS : Active Directory Certified Service
ADRMS : Active Directory Rights Management services (protect intectual services)

All above services integrated on premises and these help of protocol Kerberos on port no 88
(udp) and LDAP on port no 389

In ADD works on SAML (secure asseceration markup language), OPEN ID(Authentication),


Oauthorisation

Active Directory is hierarchial whereas Azure AD is flat structure.

Azure AD supports Rest API

Once subscription in AZURE AD u can crreate tenant

Window Join

group creation

group type :

group name

group description

membership type
ways to assign access rights

i) Direct Assignment : The resource owner directly assigns the user to the resource.

ii) Group Assignment:

The resource owner assigns an Azure AD group to the resource, which automatically gives all of the
group members access to the resource.
Group membership is managed by both the group owner and the resource owner, letting either
owner add or remove members from the group

iii) Rule based Assignment : The resource owner creates a group and uses a rule to define which
users are assigned to a specific resource. The rule is based on attributes that are assigned to
individual users.

The resource owner manages the rule, determining which attributes and values are required to allow
access the resource.

iv) External authority assignment. Access comes from an external source, such as an on-premises
directory or a SaaS app. In this situation, the resource owner assigns a group to provide access to
the resource and then the external source manages the group members.

MFA(MULTI FACTOR AUTHENTICATION)

i) SOMETHING YOU KNOW : passwords


ii) SOMETHING YOU ARE : biometric
iii) SOMETHING YOU HAVE : rsa token

i & iii are microsoft azure uses general

AZURE ACTIVE DIRECTORY

CLOUD IDENTITY

DIRECTOR SYNC IDENTITIES

GUESTS
venkatrao 9502402050
91111871523
apgb0005069
3000

You might also like