This is the Part 1 of the Azure Active Directory Topic. In this session I introduce the Azure AD and talk about what it is, how it differentiates with on-premises Active Directory Domain Services (AD DS). Further, in this session I provide demos on how to create Azure AD Users from the Azure Portal, associate Custom domains with the Azure AD tenant and the Azure AD PowerShell module. As a bonus, I also talk about and demo how to create additional Azure AD directory within the subscription.
2. Shawn Ismail
Microsoft Azure MVP
Azure Active Directory- Part 1
Email: shawn@cloudranger.net | Twitter: @shawnismail | Blog: http://www.cloudranger.net | LinkedIn: https://www.linkedin.com/in/shawnismail
YouTube: https://www.youtube.com/c/CloudrangerNetwork
Slides: http://www.slideshare.net/shawnismail
3. Azure Active Directory – Part 1
What is Azure Active Directory?
• Cloud based directory and identity management service
• Secure access for organizations and users for applications in the cloud as well as on-premises
• Multitenant. Each Azure AD is distinct and separate from other Azure AD directories
• Can be used to provide:
• Access to applications
• Configure SSO –business partners added frequently
• Provision users and groups
• Expand on-premises AD implementation to Azure
• Information protection
• And plenty of other benefits
4. Azure Active Directory – Part 1
Microsoft Azure Active Directory vs on-premises Active Directory Domain Services
AD DS is a traditional server role on Windows Server; can be deployed on physical or virtual machines
Both Azure AD and AD DS store directory data and manage communication between users and resources,
including user logon processes, authentication, and directory searches.
• Azure AD is primarily an identity solution
• Flat structure; No OUs
• Cannot be queried through LDAP. Uses REST API over http(s) called AD Graph API
• Does not use Kerberos Authentication; Authentication is performed through SAML, WS-Federation, OpenID Connect & OAuth
5. Azure Active Directory – Part 1
What is an Azure tenant?
In Azure a “Tenant” means an organization (yourorganization.onmicrosoft.com)
A tenant has a dedicated instance of the Azure AD Service
Microsoft ensures (by design) that each tenant is isolated and separate
How to get a tenant?
Microsoft Online business services rely on Azure AD for sign-in and other identity needs
You most likely have a tenant with Azure AD with access to all of the Free features if you have: Azure, Microsoft
Office 365, Microsoft Intune, Microsoft Dynamics CRM Online
• Multiple directories can be created in a tenant
• Same subscription can have multiple Azure directories
6. Azure Active Directory – Part 1
Microsoft Azure Active Directory Editions
1. Azure Active Directory Free Edition
2. Azure Active Directory Basic
3. Azure Active Directory Premium P1
4. Azure Active Directory Premium P2
For full comparison of the editions: https://www.microsoft.com/en-cy/cloud-platform/azure-active-directory-features
7. Azure Active Directory – Part 1
Microsoft Azure Active Directory Editions
1. Azure Active Directory Free Edition
2. Azure Active Directory Basic
3. Azure Active Directory Premium P1
4. Azure Active Directory Premium P2
For full comparison of the editions: https://www.microsoft.com/en-cy/cloud-platform/azure-active-directory-features
8. Azure Active Directory – Part 1
Management of Azure AD Users & groups (DEMO)
2 ways to create & manage users:
1. Cloud identity (this is what we will focus on)
2. Directory-synchronized identities
Demo will concentrate on the new portal
9. Azure Active Directory – Part 1
Azure AD - Custom Domains (DEMO)
• Custom domain names can be added to the Azure AD tenant
• Done for simplicity of management
• The Domain used must be registered
• Must have access to DNS records. TXT record needs to be added for domain verification
• Each subscription can have up to 900 domain names
• Custom domain can be made the primary domain for the Azure tenant
So instead of yourtenantname.onmicrosoft.com you can have yourdomain.com
10. Azure Active Directory – Part 1
Management Azure AD with PowerShell
There are 2 PowerShell modules for Azure AD
1. Older: MSOnline module ; being deprecated, sometimes referred to as V1
2. Newer: Azure AD V2 module ; older cmdlets are being migrated
Azure Active Directory V1 PowerShell module (MSOnline Module):
https://docs.microsoft.com/en-us/powershell/msonline/v1/azureactivedirectory
Azure Active Directory V2 PowerShell module:
https://docs.microsoft.com/en-us/powershell/azuread/v2/azureactivedirectory
11. Training Site: http://www.cloudranger.net/azure-training
YouTube : https://www.youtube.com/c/CloudrangerNetwork
Slides : http://www.slideshare.net/shawnismail
Twitter : @shawnismail
Email : shawn@cloudranger.net
LinkedIn : https://www.linkedin.com/in/shawnismail
Thank you for viewing and please the videos on
Azure Active Directory – Part 1