Giter VIP home page Giter VIP logo

mcw-hybrid-identity's Introduction

Hybrid identity

Please Note: This workshop is archived and no longer being maintained. Content is read-only.

Contoso is a medium size financial services company with its headquarters in New York and a branch office in San Francisco. It is currently operating entirely on-premises, with the majority of its infrastructure running on the Windows platform. Contoso has recently upgraded its Active Directory environment to Windows Server 2016, and it is in the process of migrating its desktops from Windows 7 to Windows 10.

Contoso is facing challenges related to increased mobility of its workforce and providing access to its services to other financial partners. Contoso is looking to improve security while providing users with self-service capabilities around device, account, and password management. To drive better integration with partners, Contoso needs to provide access to some existing internal applications while maintaining a high level of security for applications hosted in the cloud and on premises while minimizing the effort required to manage customer identities.

May 2022

Target audience

  • Infrastructure Architect
  • Security Architect
  • IT Professional
  • Cloud Solution Architect

Abstracts

Workshop

In this workshop, you will learn how to implement different components of a hybrid identity solution that integrates an Active Directory forest with an Azure Active Directory tenant and leverages a number of Azure Active Directory features.

At the end of this workshop, you will be able to plan, design, and deploy a hybrid identity architecture. The architecture will include a secure, available, and resilient hybrid identity infrastructure for identity and access management.

Whiteboard design session

In this whiteboard design session, you will learn how to implement different components of a hybrid identity solution that integrates an Active Directory forest with an Azure Active Directory tenant and leverages a number of Azure Active Directory features, including pass-through authentication with Seamless Single Sign-On, Multi-Factor Authentication, Self-Service Password Reset, Azure AD Password Protection for Windows Server Active Directory, Hybrid Azure AD join, Windows Hello for Business, Microsoft Intune automatic enrollment, Azure AD Conditional Access, Azure AD Application Proxy, Azure AD B2B, and Azure AD B2C.

Continue to the Whiteboard design session documents folder.

Hands-on lab

This hands-on lab has been archived for the time being. It can still be found in the Archive folder of this repository, but may not be fully functioning or properly deploy.

Azure services and related products

  • Azure Active Directory
  • Azure AD Connect
  • Azure App Service
  • Passthrough authentication with Seamless Single Sign-On
  • Multi-Factor Authentication
  • Self-Service Password Reset
  • Azure AD Password Protection
  • Hybrid Azure AD join
  • Windows Hello for Business
  • Microsoft Intune automatic enrollment
  • Azure AD Conditional Access
  • Azure AD Application Proxy
  • Azure AD B2B
  • Azure AD B2C

Related references

Help & Support

We welcome feedback and comments from Microsoft SMEs & learning partners who deliver MCWs.

Having trouble?

  • First, verify you have followed all written lab instructions (including the Before the Hands-on lab document).
  • Next, submit an issue with a detailed description of the problem.
  • Do not submit pull requests. Our content authors will make all changes and submit pull requests for approval.

If you are planning to present a workshop, review and test the materials early! We recommend at least two weeks prior.

Please allow 5 - 10 business days for review and resolution of issues.

mcw-hybrid-identity's People

Contributors

benstegink avatar dawnmariedesjardins avatar dwnatwick avatar gwasham98 avatar justinndavis avatar kitskin avatar microsoft-github-operations[bot] avatar microsoftopensource avatar mwasham avatar paulopsgility avatar polichtm avatar timahenning avatar v-denisea avatar

Stargazers

 avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar

Watchers

 avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar

mcw-hybrid-identity's Issues

Whiteboard-slide 48

what is meant by the statement "different versions of the Microsoft Azure AD Connect Agent Updater service"? how is this relevant to the app proxy service?

2021 Q4 updates

HOL

  • Align with WDS solution – verify that all requirements and objectives in WDS are also covered in HOL
  • Explore password-less options with Windows Hello for Business and Windows Authenticator app
  • Add resiliency: Fail-over domain and pass-through agents

WDS

  • More discussion around Password-less authentication options
  • Issue #16 – point out the licensing requirements for Intune and why E5 may be needed
  • Issue #14 – more notes/discussion/reference in the WDS student guide on resiliency with Azure AD Connect

Workshop abstract is taken from a different workshop and has nothing to do with the Hybrid Identity

https://github.com/microsoft/MCW-Hybrid-identity#workshop
_In this workshop, you will learn to setup and configure a hybrid identity solution that integrates an existing on-premises identity solution with Azure. You will learn how to secure the virtual network by deploying a network virtual appliance and configure firewall rules and route tables. Additionally, you will set up access to the virtual network with a jump box and a site-to-site VPN connection.

At the end of the workshop, you will be better able to plan and design virtual networks in Azure with multiple subnets to filter and control network traffic. In addition, you will learn to create a virtual network and provision subnets, create route tables with required routes, build a management jump box, configure firewalls to control traffic flow, and configure site-to-site connectivity._
Feels like it belongs to some other workshop

Lab Guide Updates

  1. Exercise 1, Task6 Step 2 For Installing Azure AD Connect, it is mentioned to login to Azure Portal in Internet Explorer inside DC1 Virtual Machine. But Internet Explorer 11 does not support Azure portal and getting an error message as below.

There are few more instructions that suggest to login to azure portal from Internet Explorer inside DC1 Virtual Machine which has to be changed.

IE1

  1. Exercise 4, Task 4 step 1 For Installing pass through agent inside BDC-1 Virtual Machine, it is mentioned to open Azure Portal inside Internet Explorer and getting same error message as shown above.

June 2020 Update Suggestions

Here are our suggested updates for the June 2020 update. Please add any other suggestions or feedback to this issue.

  • Update diagrams to use new Azure icons
  • Re-screenshot the entire lab (much of them are out of date)
  • Add in Cloud Provisioning
  • Update AAD App Proxy to use myapplications.microsoft.com instead of "myapps"

Whiteboard - slide 45

how do we ensure that the staging AAD connect server has the same configuration settings as the production server?

Content Update Required

Hi,
Please find the following changes needed to be done in the guide:

  1. We see that throughout the guide, domain name is mentioned as Contoso.local whereas it should be corp.contoso.com everywhere in the lab guide. Here are few spots where you can find the domain name:

  2. Exercise 4: Task 3: Step 1: It should be specified which VM user needs to use here - BDC or Dc1.

  3. Exercise 4: Task 2: Step 28: In order for clients to fail-over to BDC-1 when DC-1 is off-line, the IP address of BDC-1 will need to be added as the Alternate DNS server within Internet Protocol Version 4 (TCP/IPv4) Properties on all clients. On each client device, repeat steps 10-15 in this task, but enter the internal IP address of BDC-1 as the Alternate DNS server address.

    • Can you please elaborate all clients:
  4. Exercise 4: Task 2: Step 11: This step says, Select Ethernet 2 next to Connections.

    • We didn't find Ethernet 2 whereas we got Ethernet.

Please have a look here.

Thanks

Workshop title

Hi Marcin,
I double checked. Correct casing for this workshop title is Hybrid identity (lower case i). When you're finalizing the workshop, please make sure to use that naming conventions for all document titles, folders and inside the documents. Thank you! Dawnmarie

Before Hands On Lab: Task 5.2

In my lab environment, the IE Enhanced Configuration was not disabled until a reboot was performed (was unable to access the Technet scripts until this took effect).

Task 3 Step 1

Seems basic, but I had my window small, so the Chevron for cloud shell did not show at the top. New folks may not even know it is there. I even tried search, and it does not come up. It no longer shows at the bottom, so the newer users need to know how to launch it. Another option could be to have them go to shell.azure.com on a new tab, which would give them a second window

Add notes to whiteboard slides

It would be great if the whiteboard slides had speaker notes, reference information on them. For example, slide 14 has a decision tree, and asks a question about signins natively supported by Azure AD. Not everyone knows what is natively supported, so we will have to go do some research when the client asks this question. Including the supporting information on this slide and others would be very helpful

Hands on and before hands on

#1: Exercise-1-> Task-11- Perform Hybrid Azure AD join- > Step-3
1

Problem: AGAyers does not have remote desktop rights to login to APP1 Server.

Recommendation :
Update AD scripts to add the user to “Remote Desktop Users” AD Group or add instructions in the lab guide to add user the remote desktop users group manually

#2: Exercise-2 - Task-10- Implement Azure AD Privileged Identity Management
2

Problem: This user(AGAyers) is not a member of the Engineering group. As per documentation, we are allowing access to the “Engineering” group only.

2 1

Recommendation.: Please update scripts to include AGAyers to Engineering Group, or update the documentation to use the correct user who is part of Engineering.

#3, Exercise 3:- Configure application access in hybrid scenarios - Task-6:-
Problem: Email-address value highlighted in below screenshot needs to be generalized.

3

Recommendation:- use jane.doe@< Fabrikam-Domain-name>

Before-the Hands on lab

Task 2 Step #1. The user may not see All Services, as the portal keeps changing. I defaulted to the new view and you don't see that. A better method instead of navigating is to type Subscriptionsin the top Search field......that will always find anything no matter how the portal view is configured.

More specific links

On the before document when i went there, its a cornucopia. Even though title mentioned, why not link directly to the docs. Also, the link took my out of the doc, versus opening a new tab. Maybe the produced version will fix that?

here
Review online documentation regarding Azure Active Directory at https://docs.microsoft.com/en-us/azure/active-directory/ focusing in particular on its integration with Active Directory and its B2B capabilities.

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.