{"id":1345,"date":"2019-11-25T01:00:00","date_gmt":"2019-11-25T01:00:00","guid":{"rendered":"http:\/\/inswwdev.azurewebsites.net\/au\/insights\/uncategorized\/identity-and-authentication-the-boss-of-all-bosses\/"},"modified":"2019-11-25T01:00:00","modified_gmt":"2019-11-25T01:00:00","slug":"identity-and-authentication-the-boss-of-all-bosses","status":"publish","type":"post","link":"https:\/\/www.insentragroup.com\/au\/insights\/geek-speak\/modern-workplace\/identity-and-authentication-the-boss-of-all-bosses\/","title":{"rendered":"Identity and Authentication &#8211; The Boss of All Bosses"},"content":{"rendered":"<p style=\"text-align: justify;\"><span>Hi folks! Pure Awesomeness back again! Yes, I know it\u2019s been a stupid amount of time since my last blog post but I\u2019m back\u2026back again to pump as much knowledge and wisdom into your cerebrums as one individual with the title of Pure Awesomeness can!<\/span><\/p>\n<p style=\"text-align: justify;\"><span>So, sit back, relax and begin digesting the content in this blog to know about Identity and Authentication in Office 365! Wait\u2026What? You\u2019re the Exchange guy, right? What is this foreign topic you speak of? Well my humble apprentice, Pure Awesomeness has decided to venture out into the big bad world of Identity and Authentication and take a slight detour from the ever-changing world of Exchange. I mean, let\u2019s face it\u2026without identity and authentication\u2026you\u2019d have no email! <\/span><\/p>\n<p style=\"text-align: justify;\"><span>Ready for this? Buckle up and enjoy!<\/span><\/p>\n<p style=\"text-align: justify;\"><span>So, you\u2019ve decided to move your on-premises workloads to Office 365. First of all, awesome decision! Secondly, have you decided on your identity and authentication model? YES\/NO \u2013 Please select one.<\/span><\/p>\n<p style=\"text-align: justify;\"><span>If you selected YES, proceed to GO, collect $200 and enjoy the benefits of your new identity and authentication model! *Queue the Carlton dance*<\/span><\/p>\n<p style=\"text-align: justify;\"><span>If you selected NO, read on and prepare to be amazed at all the authentication models available to you at your fingertips\u2026but first!&#8230;yes there\u2019s always a first\u2026and yes you knew this was coming\u2026subscribe to Insentragram<\/span><span>! <\/span><\/p>\n<p style=\"text-align: justify;\"><span>Identity\u2026what is it? Well, quite simply, it\u2019s who we are and how we are viewed by the world. It\u2019s the same concept when you combine identity with Office 365. Identities in this ever-expanding and changing world tells Office 365 who we are and how we are viewed across this giant platform allows us to gain access to the resources we need to get the job done, whether it be sending that all-important email through Exchange Online or sharing the latest cat meme across a Yammer network or Teams Channel. Yep, identity spans across these workloads as well. <\/span><\/p>\n<p style=\"text-align: justify;\"><span>But Pure Awesomeness, we want to know more about Yammer and Teams as well! I can help you with one for now. Check out this <a rel=\"noopener nofollow\" href=\"https:\/\/inswwdev.azurewebsites.net\/au\/3-awesome-ways-to-drive-employee-engagement-through-yammer\/\" target=\"_blank\">blog<\/a> by my sidekick Hugh Roberts (we came on board the Insentra train on the same day and almost 3.5 years later, I can call him my sidekick\u2026because I\u2019m just purely awesome).<\/span><\/p>\n<p style=\"text-align: justify;\"><span>Information about Teams will come in my next blog\u2026no it won\u2019t\u2026yes, it will\u2026maybe\u2026unless my sidekick beats me to it \ud83d\ude1b<\/span><\/p>\n<p style=\"text-align: justify;\"><span>Anyways, moving on to the topic of the hour\u2026identity.<\/span><\/p>\n<p style=\"text-align: justify;\"><span>By now you\u2019re probably wondering how I\u2019m supposed to dedicate an entire blog to identity. Well, identity is just one portion of the ever-growing world of Office 365. Combine it with authentication\/sign-in and you have an awesome blog written by a purely awesome individual\u2026me!<\/span><\/p>\n<p style=\"text-align: justify;\"><span>Ok, here we go\u2026<\/span><\/p>\n<p style=\"text-align: justify;\">With Office 365, you have a few identity\/sign-in models available and I\u2019ll expand on these models as you read on.<\/p>\n<h3 style=\"padding-bottom: 15px; margin-bottom: 30px; margin-top: 40px; border-bottom: 1px solid #f16020;\"><span>Cloud Only Identities<\/span><\/h3>\n<p style=\"text-align: justify;\"><span>In a nutshell, identities exist only in the cloud and all edits to these identities are done from the cloud. Meaning, you get married and change your surname\u2026it gets updated in the cloud. You want a new alias email address added called <a href=\"mailto:dothebartman@domain.com.au\">dothebartman@domain.com.au<\/a>&#8230; It gets added in the cloud. Pretty simple right? <\/span><\/p>\n<h3 style=\"padding-bottom: 15px; margin-bottom: 30px; margin-top: 40px; border-bottom: 1px solid #f16020;\"><span>Synchronised Identities<\/span><\/h3>\n<p style=\"text-align: justify;\"><span>Here\u2019s where things get interesting\u2026in a good way\u2026I promise. So, synchronised identities means that all your identities are synchronising in a synchronous approach to the identity platform where synchro\u2026scratch that\u2026basically, your on-premises Active Directory domain becomes the source of authority and all required accounts synchronise to Office 365 using a toolset called Azure Active Directory Connect (AADC). Everything you were able to do with your account in a cloud only identity model, now can only happen from on-premises, hence the term \u201csource of authority\u201d. <\/span><\/p>\n<p style=\"text-align: justify;\"><span>But did you know that AADC has various options available when configuring user sign-in methods? No? Sweet! That\u2019s what this blog is for. See the work of art screenshot below outlining the options available:<\/span><\/p>\n<p style=\"text-align: justify;\"><span><img decoding=\"async\" style=\"width: 851px; height: 442px;\" src=\"https:\/\/www.insentragroup.com\/wp-content\/uploads\/sites\/22\/2021\/02\/hambik_identity_blog_1.jpg\" alt=\"\" data-udi=\"umb:\/\/media\/15d7daec20314e1e962859fc4933824e\" title=\"\"><\/span><\/p>\n<p style=\"text-align: justify;\"><span>Don\u2019t worry, I\u2019ll explain each below but before I do, just know that this is how Microsoft lists the above options, from simple to set up, all the way through to complex:<\/span><\/p>\n<ul>\n<li><span>Password hash (or password synchronisation)<\/span><\/li>\n<li><span>Seamless SSO (single sign-on)<\/span><\/li>\n<li><span>Pass-through authentication (PTA)<\/span><\/li>\n<li><span>ADFS<\/span><\/li>\n<\/ul>\n<h3 style=\"padding-bottom: 15px; margin-bottom: 30px; margin-top: 40px; border-bottom: 1px solid #f16020;\"><span>Password Synchronisation<\/span><\/h3>\n<p style=\"text-align: justify;\"><span>Before you panic\u2026this is a secure way to sync your password to the cloud. AADC extracts the password hash and syncs to Azure Active Directory. There is absolutely no way to reveal or convert the password to plain text and all it takes to implement this is a single check box. See, simple!<\/span><\/p>\n<p style=\"text-align: justify;\"><span>But there is one catch to this model \u2013 if your on-premises account expired, users can still log into Office 365 using the password hash as Azure AD has no concept of account expiration. Look at the brighter side of this statement\u2026if your on-premises environment gets \u201ctaken out\u201d, whether it be cyber attack or a nuclear meltdown because Homer wasn\u2019t doing his job, password hash (or synchronisation) provides a form of DR. <\/span><\/p>\n<p style=\"text-align: justify;\"><span>Oh and before I forget\u2026if you change your password on-premises, the change is synchronised to Office 365 in about 2 minutes!<\/span><\/p>\n<h3 style=\"padding-bottom: 15px; margin-bottom: 30px; margin-top: 40px; border-bottom: 1px solid #f16020;\"><span>Seamless SSO<\/span><\/h3>\n<p style=\"text-align: justify;\"><span>Works with Password Synchronisation and as the name suggests, provides a single sign-on model without the need for additional infrastructure. Pretty cool right? The catch is that it only provides SSO capabilities to Office 365 for users inside the corporate network. Where your traditional federation model using ADFS or a 3<sup>rd<\/sup> party platform would provide SSO for users outside of the network, Seamless SSO through AADC only applies to internal users. It\u2019s supported with password synchronisation or PTA and is as simple as checking the \u201cEnable Single Sign-On\u201d box in the AADC configuration. You\u2019ll also need to do the following through GPO:<\/span><\/p>\n<ul>\n<li><span>Add <a href=\"https:\/\/autologon.microsoftazuread-sso.com\" rel=\"nofollow noopener\" target=\"_blank\">https:\/\/autologon.microsoftazuread-sso.com<\/a> to the Intranet Zone<\/span><\/li>\n<li><span>Enable \u201cAllow updates to status bar via script\u201d<\/span><\/li>\n<\/ul>\n<p><span>Next up, we have\u2026<\/span><\/p>\n<h3 style=\"padding-bottom: 15px; margin-bottom: 30px; margin-top: 40px; border-bottom: 1px solid #f16020;\"><span>Pass-Through Authentication (PTA)<\/span><\/h3>\n<p style=\"text-align: justify;\"><span>Want to enforce your on-premises Active Directory security and password policies? This is the sign-in model for you! Basically, allows the user to sign into both Office 365 and on-premises resources using the same password, where the password is validated against the on-premises directory. Nothing is stored in the cloud! <\/span><\/p>\n<p style=\"text-align: justify;\"><span>To enable PTA, a lightweight agent is deployed across the on-premises infrastructure and the beauty with this agent is that it\u2019s self-managed, meaning you, as the administrator, don\u2019t need to continually deploy the latest updates to the agent. It does it itself! There are, however, a few things to take note of when deploying PTA:<\/span><\/p>\n<ul>\n<li style=\"text-align: justify;\"><span>If you already use password synchronisation, don\u2019t deploy PTA<\/span><\/li>\n<li style=\"text-align: justify;\"><span>PTA takes precedence over password synchronisation<\/span><\/li>\n<li style=\"text-align: justify;\"><span>Turning off PTA requires that the AAD Connect server has internet connectivity \u2013 you can use PowerShell to switch the tenant to use password synchronisation if the on-premises environment goes down<\/span><\/li>\n<li style=\"text-align: justify;\"><span>PTA agent connectivity issues will prevent users from authenticating<\/span><\/li>\n<li style=\"text-align: justify;\"><span>There is no logic in the PTA agents to load balance traffic<\/span><\/li>\n<\/ul>\n<p style=\"text-align: justify;\"><span>Deploy more than one PTA agent \u2013 by default, the first PTA agent deploys on the AAD Connect server<\/span><\/p>\n<h3 style=\"padding-bottom: 15px; margin-bottom: 30px; margin-top: 40px; border-bottom: 1px solid #f16020;\"><span>ADFS<\/span><\/h3>\n<p style=\"text-align: justify;\"><span>In a nutshell, provides users (both internal and external to the network) with single sign-on capabilities, but requires additional hardware and infrastructure on-premises, depending on how in-depth you want to go with redundancy and high availability. I won\u2019t go into too much detail with ADFS but just know that Microsoft has listed this option as the most complex to set up because of the additional configuration and infrastructure required. <\/span><\/p>\n<p style=\"text-align: justify;\"><span>The decision to use ADFS is obviously going to come down to business requirements, however, explore other options, such as password synchronisation or PTA.<\/span><\/p>\n<p style=\"text-align: justify;\"><span>There you have it, folks\u2026a bit of a lengthy blog post this time around and focusing on a completely different topic, but nonetheless, still an important topic to discuss and include in your overall transition to Office 365. <\/span><\/p>\n<p style=\"text-align: justify;\"><span>Until next time, Pure Awesomeness signing off!<\/span><\/p>\n<p style=\"text-align: justify;\"><span>&#8220;<em>You miss 100 percent of the shots you don&#8217;t take.<\/em>&#8221; &#8211; Wayne Gretzky<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Hi folks! Pure Awesomeness back again! Yes, I know it\u2019s been a stupid amount of time since my last blog post but I\u2019m back\u2026back again to pump as much knowledge and wisdom into your cerebrums as one individual with the title of Pure Awesomeness can! So, sit back, relax and begin digesting the content in&hellip; <a class=\"more-link\" href=\"https:\/\/www.insentragroup.com\/au\/insights\/geek-speak\/modern-workplace\/identity-and-authentication-the-boss-of-all-bosses\/\">Continue reading <span class=\"screen-reader-text\">Identity and Authentication &#8211; The Boss of All Bosses<\/span><\/a><\/p>\n","protected":false},"author":52,"featured_media":1346,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"content-type":"","footnotes":""},"categories":[19],"tags":[],"class_list":["post-1345","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-modern-workplace","entry"],"_links":{"self":[{"href":"https:\/\/www.insentragroup.com\/au\/wp-json\/wp\/v2\/posts\/1345","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.insentragroup.com\/au\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.insentragroup.com\/au\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.insentragroup.com\/au\/wp-json\/wp\/v2\/users\/52"}],"replies":[{"embeddable":true,"href":"https:\/\/www.insentragroup.com\/au\/wp-json\/wp\/v2\/comments?post=1345"}],"version-history":[{"count":0,"href":"https:\/\/www.insentragroup.com\/au\/wp-json\/wp\/v2\/posts\/1345\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.insentragroup.com\/au\/wp-json\/wp\/v2\/media\/1346"}],"wp:attachment":[{"href":"https:\/\/www.insentragroup.com\/au\/wp-json\/wp\/v2\/media?parent=1345"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.insentragroup.com\/au\/wp-json\/wp\/v2\/categories?post=1345"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.insentragroup.com\/au\/wp-json\/wp\/v2\/tags?post=1345"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}