Posts

Azure AD Identity Protection (part 1 of 3)

Image
  To read part 2, please click  here To read part 3, please click  here Azure AD Identity Protection Explained Identity protection helps the organizations to achieve following tasks: Automate the detection and remediation of identity-based risk. Investigate the risks using data in the portal. Export risk detection data to third-party utilities for further analysis. Microsoft analyses 6.5 trillion signals per day generated by and fed to Identity Protection to identify as well as protect customers from the threats. These signals are also fed into tools like Conditional Access to make access decisions, or fed back to a security information and event management (SIEM) tool for further investigation according to your organization's enforced policies.   Risk Detection & Remediation Identity Protection can easily determine the risks in the following situations: Risk Detection Type Description Atypical travel Sign in from a...

Configure & Manage Synchronized Identities (part 4 of 4)

Image
  To read part 1, please click  here To read part 2, please click  here To read part 3, please click  here Manage Groups with Directory Synchronization Like user writeback feature, the group writeback feature can also write Microsoft 365 groups from Azure AD to on-premises AD. This feature is present as an optional feature in Azure AD Connect. In order to enable this feature, following pre-requisites must be achieved: Azure AD premium licenses for your tenant. A configured hybrid deployment between your Exchange on-premises organization as well as Office 365 and verify its functioning correctly.  Installed a supported version of Exchange on-premises.  Configured single sign-on using Azure AD Connect. You can see Microsoft 365 group in the selected on-premises container after the successful completion of synchronization represented as distribution groups in an on-premises AD.   Synchronizing Groups If you are planning to synchronize groups from AD ...

Configure & Manage Synchronized Identities (part 3 of 4)

Image
  To read part 1, please click  here To read part 2, please click  here To read part 4, please click  here   Manage Users with Directory Synchronization You have to perform some management tasks as the Security and Compliance Administrator so that users can efficiently synchronize as well as successfully deploy Azure AD Connect. These tasks are: Managing user accounts Recovering a user account that was accidentally deleted Recovering from unsynchronized deletes Enhanced user management Managing User Accounts Synchronized user accounts cannot be managed with the help of Microsoft 365 admin center or Exchange Online Admin Center (EAC) as all the synchronized attributes are not synchronized back to your on-premises environment. However, some additional attributes that are not available in your AD, can be managed in the Microsoft 365 admin center like: Microsoft 365 product licenses Advanced Exchange Online settings such as enabling In-place Archiving Recovering a U...

Configure & Manage Synchronized Identities (part 2 of 4)

Image
  To read part 1, please click  here To read part 3, please click  here To read part 4, please click  here   Set Up Azure AD Connect You can easily install Azure AD Connect by using either Express or Custom setup. Azure AD Connect Express Setup It is the most common option used by 90% of all the new installations as it can offer the configuration that works for the most common customer scenarios. It assumes: You have a single AD forest on-premises. You have an enterprise administrator account that can be used for the installation. You have less than 100,000 objects in your on-premises AD.  You get: Password hash synchronization from on-premises to Azure AD for single sign-on. A configuration that synchronizes users, groups, contacts, and Windows 10 computers.  Synchronization of all eligible objects in all domains and all OUs. Automatic upgrade is enabled to ensure you always use the latest available version.  Azure AD Connect Custom Setup It can ...

Configure & Manage Synchronized Identities (part 1 of 4)

Image
  To read part 2, please click  here To read part 3, please click  here To read part 4, please click  here   Configure Azure AD Connect Prerequisites If you want to install Azure AD Connect, then, you will require following- Azure AD An Azure AD tenant is available with an Azure free trial and you can use either The Azure Portal or The Office Portal to manage Azure AD Connect. You have to add and verify the domain you want to use in Azure AD. By default, an Azure AD tenant allows 50k objects and when you verify your domain, the limit is automatically increased to 300k objects. However, if you require more than 500k objects, then must possess a license like Office 365, Azure AD Basic, Azure AD Premium, or Enterprise Mobility and Security.   On-premises AD Windows 2003 or later must be AD schema version and forest functional level and as long as their requirements are met, domain controllers can run any version. If you are using password writeback featur...

Plan Directory Synchronization (part 3)

Image
  To read part 1, please click  here To read part 2, please click  here Plan Azure AD Connect Topologies If your organization have multiple forests for authentication, you should consider the following: Evaluate consolidating your forests- Generally, more overhead is required to maintain multiple forests, but if your organization needs separate forests, you have to simplify your on-premises environment. Use only in your primary logon forest- You should deploy Microsoft 365 only in your primary loon forest for your initial roll out of Microsoft 365. Although multi-forest hybrid deployment prerequisites are virtually identical to the hybrid deployment ones for a single-forest organization, they have following exceptions: Autodiscover- If you have shared domains across multiple Exchange forests, then, both mail routing as well as Autodiscover endpoints should be configured ad work properly between the Exchange forests before configuring your multi-forest hybrid deployment. C...

Plan Directory Synchronization (part 2)

Image
  To read part 1, please click  here To read part 3, please click  here Plan for Azure AD Connect Before starting your planning, you should know the answers of the following questions: On what server do you want to install Azure AD Connect? Do you require an Azure AD Connect failover scenario? Do you want to synchronize one or more Active Directories (or multiple Forests)? Do you want to synchronize all or only part of your Active Directory? Do you want to synchronize all object attributes or use specific filters? Do you want to use advanced configuration features like password synchronization, password writeback, or device writeback?   You have to consider the following issues with respect to password hash synchronization: To implement password hash synchronization, the user can authenticate with the help of same username and password as on-premises. Azure AD Connect can perform password hash synchronization and store it in the respective user object in Azure A...