- Mastering Identity and Access Management with Microsoft Azure
- Jochen Nickel
- 248字
- 2021-07-02 12:57:26
Identity and password-hash synchronization including SSO options
By synchronizing identities and the associated password hashes from the on-premises AD to the Azure AD, we can build a basic scenario for smaller companies that don’t want to invest in an ADFS infrastructure. Also, there's no SSO required. With this scenario, the same password can be used to authenticate the user either in the cloud or on-premises, depending on what resource is being accessed. Furthermore, the Password Reset and Account Unlock features are available with an Azure AD Premium license. A requirement is Azure AD Connect with password-hash synchronization enabled. Optional password write-back is enabled.
The following diagram shows the identity and password-hash synchronization scenario:

To add SSO to the solution, you can enable Pass-through authentication and the seamless SSO feature in the Azure AD Connect tool. This is the most commonly recommended option from Microsoft to reduce complexity and put Azure AD in the role of the central system to provide authentication to your SaaS and on-premises Kerberos/Claims-based applications:

It's highly recommended you enable password-hash synchronization, so in case of an on-premises service interrupt, your users can still use cloud services. For now, you can read about this feature at https://docs.microsoft.com/en-us/azure/active-directory/hybrid/how-to-connect-pta.
- 數(shù)據(jù)恢復(fù)方法及案例分析
- 黑客大曝光:無線網(wǎng)絡(luò)安全(原書第3版)
- 白帽子講Web安全(紀念版)
- 計算機使用安全與防護
- 代碼審計:企業(yè)級Web代碼安全架構(gòu)
- 計算機網(wǎng)絡(luò)安全技術(shù)研究
- 局域網(wǎng)交換機安全
- 學(xué)電腦安全與病毒防范
- 解密數(shù)據(jù)恢復(fù)
- 編譯與反編譯技術(shù)實戰(zhàn)
- 黑客攻防實戰(zhàn)從入門到精通
- 網(wǎng)絡(luò)安全實戰(zhàn)詳解(企業(yè)專供版)
- 交換機·路由器·防火墻(第2版)
- 網(wǎng)絡(luò)空間安全法律問題研究
- 信息系統(tǒng)安全等級化保護原理與實踐