23
PREMIUM MANAGEMENT AND PROTECTION OF IDENTITY AND ACCESS WITH AZURE AD Speaker: Jan Vidar Elven Company: Skill AS Position: Enterprise Mobility MVP Cloud and Datacenter Architect

Jan Vidar Elven – Premium Management and Protection of Identity and Access with Azure AD

Embed Size (px)

Citation preview

Page 1: Jan Vidar Elven – Premium Management and Protection of Identity and Access with Azure AD

PREMIUM MANAGEMENT AND PROTECTION OF IDENTITY AND ACCESS WITH AZURE ADSpeaker: Jan Vidar ElvenCompany: Skill ASPosition: Enterprise Mobility MVPCloud and Datacenter Architect

Page 2: Jan Vidar Elven – Premium Management and Protection of Identity and Access with Azure AD

Who Am I?I am Jan Vidar Elven – Cloud and Datacenter Architect @ Skill ASI am from Sarpsborg, Norway I’m a Microsoft Most Valued ProfessionalEnterprise Mobility

I tweet from @skillriverI blog at systemcenterpoint.wordpress.comEmail me [email protected] not tweeting/blogging I like football!

Page 3: Jan Vidar Elven – Premium Management and Protection of Identity and Access with Azure AD

AGENDA – KEY TAKEAWAYS

Why Azure AD Identity Management, Protection and Health Monitoring?

Azure AD Privileged Identity Management Azure AD Identity Protection Azure AD Connect Health Azure Multi-Factor Authentication

Page 4: Jan Vidar Elven – Premium Management and Protection of Identity and Access with Azure AD

WHY AZURE AD MANAGEMENT AND PROTECTION?

Manage Azure AD administrator role access On-demand admin access Real-time risk event & vulnerability detection Monitor and gain insights Second layer of security

Page 5: Jan Vidar Elven – Premium Management and Protection of Identity and Access with Azure AD

REQUIREMENTS

For Privileged Identity Management + Identity Protection + Connect Health:

Azure AD Premium P2/EMS E5 Global Administrator Access to Configure

End Users: Azure AD Premium/EMS and Password Writeback for Policy Mitigation

Page 6: Jan Vidar Elven – Premium Management and Protection of Identity and Access with Azure AD

ENTERPRISE MOBILITY + SECURITY

Page 7: Jan Vidar Elven – Premium Management and Protection of Identity and Access with Azure AD

AZURE AD PRIVILEGED IDENTITY MANAGEMENT (PIM)

Key Features: Access Review Enable on-demand, "just in time" administrative access Reports on access history and administrator assignments Alerts about access and configurations to a privileged role

Page 8: Jan Vidar Elven – Premium Management and Protection of Identity and Access with Azure AD
Page 9: Jan Vidar Elven – Premium Management and Protection of Identity and Access with Azure AD

CONFIGURE AZURE AD PIM

1. Sign in Azure Portal with Global Administrator2. Select New > Security + Identity > Azure AD Privileged

Identity Management for your Azure AD tenant3. First admin will be:

a. Security administratorb. Privileged role administrator

Page 10: Jan Vidar Elven – Premium Management and Protection of Identity and Access with Azure AD

DEMO - AZURE AD PRIVILEGED IDENTITY MANAGEMENT

Page 11: Jan Vidar Elven – Premium Management and Protection of Identity and Access with Azure AD

AZURE AD IDENTITY PROTECTION

Key Features: Risk event detection and risk accounts Investigate risk events Risk-based conditional access policies:

Sign-in risk policy User risk policy (not for federated users in preview) MFA registration policy

Page 12: Jan Vidar Elven – Premium Management and Protection of Identity and Access with Azure AD
Page 13: Jan Vidar Elven – Premium Management and Protection of Identity and Access with Azure AD

CONFIGURE AZURE AD IDENTITY PROTECTION

1. Sign in Azure Portal with Global Administrator2. Select New > Security + Identity > Azure AD Identity

Protection for your Azure AD tenant

Page 14: Jan Vidar Elven – Premium Management and Protection of Identity and Access with Azure AD

DEMO - AZURE AD IDENTITY PROTECTION

Page 15: Jan Vidar Elven – Premium Management and Protection of Identity and Access with Azure AD

AZURE AD CONNECT HEALTH

Features: Azure AD Connect Health for Sync Azure AD Connect Health for ADFS/WAP Azure AD Connect Health for AD DS

(Preview)

Page 16: Jan Vidar Elven – Premium Management and Protection of Identity and Access with Azure AD

AZURE AD CONNECT HEALTH – HOW DOES IT WORK?

Page 17: Jan Vidar Elven – Premium Management and Protection of Identity and Access with Azure AD

CONFIGURE AZURE AD CONNECT HEALTH

1. Get Azure AD Premium2. Download, Install & Register Connect Health Agent:

a. AD FS/Proxy/WAP Health Agentb. AD DS Health Agentc. Azure AD Connect Server (>=version 1.0.9125.0)

3. Go to https://aka.ms/aadconnecthealth

Page 18: Jan Vidar Elven – Premium Management and Protection of Identity and Access with Azure AD

DEMO - AZURE AD CONNECT HEALTH

Page 19: Jan Vidar Elven – Premium Management and Protection of Identity and Access with Azure AD

AZURE MULTI-FACTOR AUTHENTICATION (MFA)

MFA Versions: MFA for Office 365 MFA for Azure Admins Azure MFA

Features: Selected Authentication Methods Admin Control

Page 20: Jan Vidar Elven – Premium Management and Protection of Identity and Access with Azure AD
Page 21: Jan Vidar Elven – Premium Management and Protection of Identity and Access with Azure AD

DEMO - AZURE MULTI-FACTOR AUTHENTICATION

Page 22: Jan Vidar Elven – Premium Management and Protection of Identity and Access with Azure AD

SUMMARY AND QUESTIONS?

Contact: E-mail: [email protected] Twitter: @skillriver Blog: http://systemcenterpoint.wordpress.com

Page 23: Jan Vidar Elven – Premium Management and Protection of Identity and Access with Azure AD

Silver Sponsors

Gold Sponsors

Bronze Sponsors