The document discusses Microsoft identities in a hybrid world. It provides a history of identity management from SharePoint 2003 to the present. Key terminology is defined, including Active Directory, Azure Active Directory, and Azure AD Connect. Active Directory concepts and topology/security considerations are examined. Use cases for identity management scenarios are also explored.
Making sense of Microsoft Identities in a Hybrid world
1. Making Sense of Microsoft Identities
in a Hybrid World
Jason Himmelstein, SharePoint MVP
Office 365 Advisory Services Manager
@sharepointlhorn
http://www.sharepointlonghorn.com
2. www.rackspace.com
Jason Himmelstein
• SharePoint Server MVP
• Office 365 Advisory Services Manager, Rackspace
• ITPro enthusiast, Business Intelligence geek,
& general technology fan boy
• Re-installed Texan, die-hard Spurs, Longhorns, & Jaguars fan
• Geek Blog: www.sharepointlonghorn.com
• On the Twitters: @sharepointlhorn
• GitHub: www.github.com/jasonhimmelstein
3. www.rackspace.com
• Identity stuff
• History lesson
• Defining Terminology
• Active Directory Core Concepts & Concerns
• Topology & Security
• Use Cases
Agenda
4. www.rackspace.com
• Bad news… we are ITPros! NO DEV TALK HERE
• Good news… The Microsoft Cloud Show covered the Azure AD dev topics recently!
• http://www.microsoftcloudshow.com/podcast/Episodes/087-catching-up-with-paul-schaeflein-on-azure-ad-
improvements
Were you hoping for a dev focused talk?
19. www.rackspace.com
• Active Directory
• User Principal Name
• Azure Active Directory
• Identity as a Service
• DirSync
• ADFS
• Azure ADConnect
Defining Terminology
28. www.rackspace.com
Pre-requisites for Installing Azure AD Connect
• Office 365 tenant
• 1 Registered Domain URL
• 2 Machines
– 1 AD Domain Controller (ADDC)
• Windows 2003 or later
– 1 Domain member server
• Windows 2008 or greater
• But really, Windows 2012 R2
29. www.rackspace.com
Downloads
• Package downloads on member server
• Azure AD Connect
– http://go.microsoft.com/fwlink/?linkid=615771&clcid=0x409
• PowerShell Bits
– Windows PowerShell cmdlets for Office 365 management and deployment
• https://www.microsoft.com/en-us/download/details.aspx?id=35588
– Microsoft Online Services Sign-In Assistant for IT Professionals RTW
• http://www.microsoft.com/en-us/download/details.aspx?id=41950
– Azure AD Module for Windows PowerShell
• http://go.microsoft.com/fwlink/p/?linkid=236297
30. www.rackspace.com
CSSA (The Cloud Search Service Application)
• Introduced in the August 2015 CU for SharePoint 2013
• Combines on-prem Search index and SharePoint Online Search
• Not Federation
– Search results are not separated
– Does not require a Search index on-prem
• Allows cloud services to include onPrem content
• Todd Klindt’s blog post: Getting Comfortable with the new hybrid Cloud Search Service in SharePoint 2013
32. www.rackspace.com
# Add the Azure Active Directory module
Import-Module MSOnline
# Define AD group that is synced to AAD and is used for ODFB audience
$syncgroupname = "CloudSync"
$syncgroup =Get-ADGroup $syncgroupname
33. www.rackspace.com
# Location to AAD Connect manual sync EXE
$syncclient = "C:Program FilesMicrosoft Azure AD
SyncBinDirectorySyncClientCmd.exe"
# Name of the Azure License to apply
$license = "reseller-account:ENTERPRISEPACK"
34. www.rackspace.com
# Azure AD domain suffix
$aadsuffix = "rackhybrid4.com"
# First, add the user to the group
Add-ADGroupMember -Identity $syncgroupname -Members $User
# Remind them to recompile their SharePoint audience
Write-Host "You'll need to recompile your SharePoint audience to reflect the
group change"
35. www.rackspace.com
# Sync up to Azure AD
& $syncclient
# Now tweak the user in Azure AD
# First connect
Connect-MsolService
# Get the user
$aaduser = "$user@$aadsuffix"
36. www.rackspace.com
# Set the user's location. Without that the license will fail
Set-MsolUser -UserPrincipalName $aaduser -UsageLocation "US"
# Set the user's license
Set-MsolUserLicense -UserPrincipalName $aaduser -AddLicenses $license
37. www.rackspace.com
• The next version of FIM
– ILM
– MIIS
• Better cloud and Windows 10 & 2016 support
• Don’t upgrade SharePoint FIM
• AD Team Blog Post
MIM (Microsoft Identity Management)
38. www.rackspace.com
• Helps you configure your hybrid options
• Requires August 2015 CU
• Shows up in Admin Tenant Console
• Plan for the SharePoint Hybrid Picker
The Hybrid Picker