350 likes | 405 Views
Explore how Azure Active Directory enables secure productivity, identity governance, and timely access to resources for employees, partners, and devices. Learn best practices for managing identity lifecycle, governance, and security.
E N D
Modernize your identity lifecycle management with Azure Active Directory Keith Brintzenhofe, Group Program Manager Jasmine Perez, Program Manager 2 BRK3244
Digital Transformation is about connections Employees Customers Partners Distributors Suppliers Devices Things
Manage and secure with identity as the control plane Cloud Apps Partners &Customers Employees Identity Devices On-premises apps
Identity Governance is key in this new world The right controls that ensure secure productivity Governance Who has / should have accessto which resources? What are they doingwith that access? Are there effective organizational controls for managing access? Can auditors verify thatthe controls are working? Security The right people have the right access to resources Productivity Timely access to the right resources Learn more BRK3242 | Govern access to your resources with Azure Active Directory Identity Governance
Identity lifecycle management is the foundation Enabling secure productivity Identity Lifecycle Management Governance How quickly can a person have access to the resources they need, when they join my organization? How should the access change over time based on changes to the person’s status? How do I automate this process? How do I know if the process is working? Security The right controls that ensure secure productivity The right people have the right access to resources Productivity Timely access to the right resources
Identity lifecycle management Employees and contingent staff Onboard from on-premises AD or cloud HR (e.g., Workday) Drive productivity and agility with automation & delegation capabilities Enable users to manage their own credentials and use single identity to access both cloud & on-premises applications Business partners and suppliers Bring in users via B2B invites and API Partner users can self-request and be auto-provisioned Access reviews remove unnecessary guest accounts No access Identity 1st job role 2nd job role Learn more BRK3249 | Granting partners access to resources using Azure AD B2B
Digital transformation requires modernizing identity lifecycle management infrastructure IT infrastructure optimized for scale Existing IT infrastructure does not scale Existing IT infrastructure meets needs
Beginning of cloud transformation Provisioning Authentication • IT manages direct federation with cloud applications • IT manages provisioning & de-provisioning through custom solutions or manually • Existing IT infrastructure meets the needs Identity Management solution Other Applications HR Application Other User Directories On-premises Windows Server Active Directory Federation provider
Unmanaged Cloud adoption is the new standard Provisioning Authentication • Business success depends on cloud adoption • IT risk grows as business groups bypass IT • IT complexity grows with each cloud application • IT infrastructure not optimized for scale X Directory Synchronization Identity Management solution Other Applications HR Application Other User Directories On-premises Windows Server Active Directory Federation provider
Managing cloud applications at scale with Azure AD Provisioning Authentication • Every Office 365 & Microsoft Azure customer uses Azure AD • Simple click-through onboarding for pre-integrated applications Microsoft Azure Active Directory Directory Synchronization Identity Management solution Other Applications HR Application 1.1B 634K identities 3rd party apps in Azure AD Other User Directories On-premises Windows Server Active Directory Federation provider Learn more BRK3243 | Hybrid identity and access management best practices
Demo Onboarding cloud applications with Azure Active Directory
Managing cloud applications at scale with Azure AD Provisioning Authentication • Every Office 365 & Microsoft Azure customer uses Azure AD • Simple click-through onboarding for pre-integrated applications Microsoft Azure Active Directory Directory Synchronization Identity Management solution Other Applications HR Application 1.1B 634K identities 3rd party apps in Azure AD Other User Directories On-premises Windows Server Active Directory Federation provider Learn more BRK3243 | Hybrid identity and access management best practices
Achieving productivity & agility Provisioning Authentication • Automate birthright access with Dynamic Groups • Delegate access management with Access Reviews & Self-Service Application Access Microsoft Azure Active Directory Access Reviews Dynamic groups Directory Synchronization Identity Management solution Other Applications HR Application Other User Directories On-premises Windows Server Active Directory Federation provider
Demo Achieving productivity & agility with Azure Active Directory
Achieving productivity & agility Provisioning Authentication • Automate birthright access with Dynamic Groups • Delegate access management with Access Reviews & Self-Service Application Access Microsoft Azure Active Directory Access Reviews Dynamic groups Directory Synchronization Identity Management solution Other Applications HR Application Other User Directories On-premises Windows Server Active Directory Federation provider
Modernize Identity lifecycle management with Azure AD Provisioning Authentication • Onboard with least disruption to your existing processes & infrastructure • Trusted by thousands of customers Microsoft Azure Active Directory Access Reviews Dynamic groups Directory Synchronization Identity Management solution Other Applications HR Application 90K 90% paid Azure AD / EMS customers Of Fortune 500 companies Other User Directories On-premises Windows Server Active Directory Federation provider
Transformation to Cloud HR Provisioning Authentication • HR modernization is a key element of digital transformation • Workday is a leading Cloud HR provider • Azure AD now supports HR driven identity lifecycle management with Workday Microsoft Azure Active Directory Access Reviews Dynamic groups Directory Synchronization Identity Management solution Other Applications HR Application Other User Directories On-premises Windows Server Active Directory Federation provider
Demo HR-driven identity lifecycle management with Workday
Transformation to Cloud HR Provisioning Authentication • HR modernization is a key element of digital transformation • Workday is a leading Cloud HR provider • Azure AD now supports HR driven identity lifecycle management with Workday Microsoft Azure Active Directory Access Reviews Dynamic groups Directory Synchronization Identity Management solution Other Applications HR Application Other User Directories On-premises Windows Server Active Directory Federation provider
Enable employee productivity from day one • Enable users to manage their own credentials • Enable access to all applications from one place, including self-service access requests • Enable the employee to have impact on their first day
Demo Enable employee productivity from day one
Enable employee productivity from day one • Enable users to manage their own credentials • Enable access to all applications from one place, including self-service access requests • Enable the employee to have impact on their first day
Operationalize with rich analytics and monitoring • Monitor user activity from Azure portal • Integrate with your favorite Analytics tool
Demo Adding the power of analytics to identity lifecycle management
Operationalize with rich analytics and monitoring • Monitor user activity from Azure portal • Integrate with your favorite Analytics tool
Next steps screenshot of deployment plan screenshot of preview page screenshot of booth map Migrate apps to Azure AD aka.ms/migrateapps Manage user provisioning from Workday with Azure AD aka.ms/deploymentplans Visit us at the booth
Related sessions BRK3242 BRK3243 BRK3249 BRK2266 BRK3401 BRK2254 Govern access to your resources with Azure Active Directory Identity Governance Hybrid identity and access management best practices Granting partners access to resources using Azure AD B2B Streamlining your business processes using Microsoft Graph Azure AD security insights with Conditional Access, Identity Protection and reporting Azure Active Directory: New features and roadmap
Please evaluate this sessionYour feedback is important to us! Please evaluate this session through MyEvaluations on the mobile appor website. Download the app:https://aka.ms/ignite.mobileApp Go to the website: https://myignite.techcommunity.microsoft.com/evaluations