Showing posts with label AAD. Show all posts
Showing posts with label AAD. Show all posts

Monday, December 5, 2022

Azure Active Directory

Before we get into understanding of Azure Active Directory (AAD), let us understand what is an Identity.

What is an identity?
An identity is an Object mostly userid with a password that is used for authentication / authorization.

What is Azure Active Directory?
Azure Active Directory (Azure AD) is a cloud-based identity and access management service. This service helps your employees access external resources, such as Microsoft 365, the Azure portal, and thousands of other SaaS applications.

Why do we need identities on Azure i.e., AAD?
Azure AD or Identies on azure are needed for
1)login to portal==>>portal.azure.com 
2)Get access to azure resources (RBAC) 
3)Get access to SaaS (Software as a Service) Applications.

Authentication: 
Authentication is the process of proving that you are who you say you are. This is achieved by verification of the identity of a person or device. It' s sometimes shortened to AuthN. Ex: userid and password.

Authorization:
Authorization is the act of granting an authenticated party permission to do something. It specifies what data you ' re allowed to access and what you can do with that data. Authorization is sometimes shortened to AuthZ. Ex: Accessing resources like fileshares, applications etc with the authenticated credentials.

AADS (Active Directory Domain Services) vs AAD (Azure Active Directory)











Hybrid Identity Environment is where both Onprem Identity Service  (ADDS) and Azure Identity Service ADDS are used.

Hybird identity = Onprem identities (ADDS) + Azure Identity (AAD)

Azure AD Tenant / Directory 

Tenant: 
A dedicated and trusted instance of Azure AD. The tenant is automatically created when your organization signs up for a Microsoft cloud service subscription. These subscriptions include Microsoft Azure, Microsoft Intune, or Microsoft 365. An Azure tenant represents a single organization.

Directory: 
Each Azure tenant has a dedicated and trusted Azure AD directory. The Azure AD directory includes the tenant' s users, groups, and apps and is used to perform identity and access management functions for tenant resources.

Initial Domain Name:
Tenant will get a initial domain name, which is generated based on the email addr you used to signup. Ex:If you are using abc@xyz.com to signup Initial domain name would be abcxyz.onmicrosoft.com. We cannot delete the initial domain name, however you can add you own custom domain(s)



Monday, August 9, 2021

Creation of Azure Active Directory Guest Account

In this lab, you will learn how to create an Azure Active Directory Guest user ids.




Requirements: 

Global Administrator role or any of the limited administrator directory roles such as guest inviter or user administrator that allows guest user creation.

Log in to Azure portal and search for Azure Active Directory.











Navigate to the Users section under Manage in Azure Active Directory.













Sunday, August 8, 2021

Azure Active Directory User(s) Creation using Powershell

Goal: 



In this lab, you will learn how to create an Azure Active Directory user id(s) using Azure Powershell.

Requirements: 

User should be part of Global Administration or User Administration Role.

Create AAD User(s) using Powershell:


Creation of user accounts using PowerShell on your local machine requires the following. However, you can also use Azure Powershell in Cloudshell step 1 is not required.
1) Azure Active Directory PowerShell Modules, here is the command that is required to install AAD PowerShell modules on your machine.
$AzureAdCred = Get-Credential
Connect-AzureAD -Credential $AzureAdCred
Install-Module AzureAD
2)Authentication to Azure Active Directory. Once installation of AAD PS modules is done run the following command for authentication.