Identity in Office 365 - SPS Redmond 2012

34
Identity in Office 365

description

One of the most compelling aspects of Office 365 is how it can be integrated into organization's existing IT infrastructures to provide users with a seamless experience; when implemented properly users shouldn't even realize a difference between on premise platforms and services in the cloud with Office 365. But while this is a situation that can be very simple for end users to work within, establishing and configuring the systems necessary to provide that simple experience can be very complex and confusing. In this session, attendees will be introduced to the numerous ways that existing on premises systems, including Active Directory, Exchange, SharePoint, and Lync, can be seamlessly integrated into Office 365 by organizations of all shapes and sizes. We will walk through the decision process companies will need to follow to determine how to configure their coexistence and integration strategies, as well as provide hands-on examples of common set ups.

Transcript of Identity in Office 365 - SPS Redmond 2012

Page 1: Identity in Office 365  - SPS Redmond 2012

Identity in Office 365

Page 2: Identity in Office 365  - SPS Redmond 2012

Blog: http://www.MyCentralAdmin.com Twitter: @ferringer

Page 3: Identity in Office 365  - SPS Redmond 2012

3 | SharePoint Saturday Redmond 2012

Outline

Office 365 Overview

Changing the Identity Perspective

Authentication vs. Authorization

Who Are You?

What Do You Do Here?

Who’s in Charge Here?

Page 4: Identity in Office 365  - SPS Redmond 2012

4 | SharePoint Saturday Redmond 2012

Email and Calendaring

Websites and Collaboration

IM and Online Meetings

Office Client and Web Apps

Hosted by Microsoft – in the cloud!

Page 5: Identity in Office 365  - SPS Redmond 2012

5 | SharePoint Saturday Redmond 2012

Office 365 Overview

Changing the Identity Perspective

Authentication vs. Authorization

Who Are You?

What Do You Do Here?

Who’s in Charge Here?

Page 6: Identity in Office 365  - SPS Redmond 2012

6 | SharePoint Saturday Redmond 2012

Did Someone say Cloud?

Page 7: Identity in Office 365  - SPS Redmond 2012

7 | SharePoint Saturday Redmond 2012

What’s Your Perspective?

Page 8: Identity in Office 365  - SPS Redmond 2012

8 | SharePoint Saturday Redmond 2012

Identity’s impact on Office 365

End User Experience

Complexity

Scale

Manageability

Investment

Page 9: Identity in Office 365  - SPS Redmond 2012

9 | SharePoint Saturday Redmond 2012

Office 365 Overview

Changing the Identity Perspective

Authentication vs. Authorization

Who Are You?

What Do You Do Here?

Who’s in Charge Here?

Page 10: Identity in Office 365  - SPS Redmond 2012

10 | SharePoint Saturday Redmond 2012

Authentication vs. Authorization

Who gets in?

What can they do?

Page 11: Identity in Office 365  - SPS Redmond 2012

11 | SharePoint Saturday Redmond 2012

Who gets in?

Where do your Office 365 user accounts live?

What is needed to use them?

What can they do?

What are the limitations of the approach?

Page 12: Identity in Office 365  - SPS Redmond 2012

12 | SharePoint Saturday Redmond 2012

Office 365 Overview

Changing the Identity Perspective

Authentication vs. Authorization

Who Are You?

What Do You Do Here?

Who’s in Charge Here?

Page 13: Identity in Office 365  - SPS Redmond 2012

13 | SharePoint Saturday Redmond 2012

Identity Options 1. Microsoft Online (MSO) IDs

2. MSO IDs + Directory Synchronization

3. Single Sign On + Directory Synchronization

Your Environment

AD

MS Online Directory Sync

Identity Services

Provisioning platform

Lync Online

SharePoint Online

Exchange Online

Active Directory Federation Services 2.0

Trust

IdP Directory

Store

Admin Portal/ PowerShell

Authentication platform

Office 365 Desktop Setup

Microsoft Online Services

IdP

Page 14: Identity in Office 365  - SPS Redmond 2012

14 | SharePoint Saturday Redmond 2012

What can they do?

Appropriate for • Smaller orgs without

AD on-premise

Pros • No servers required on-

premise

Cons • No SSO • No 2FA • 2 sets of credentials to

manage with differing password policies

• IDs mastered in the cloud

Appropriate for • Medium/Large orgs with

AD on-premise

Pros • Users and groups

mastered on-premise • Enables co-existence

scenarios Cons • No SSO • No 2FA • 2 sets of credentials to

manage with differing password policies

• Single server deployment

Appropriate for • Larger enterprise orgs

with AD on-premise Pros • SSO with corporate cred • IDs mastered on-premise • Password policy

controlled on-premise • 2FA solutions possible • Enables co-existence

scenarios Cons • High availability server

deployments required

Page 15: Identity in Office 365  - SPS Redmond 2012

15 | SharePoint Saturday Redmond 2012

Sign On Experience *SSO vs. Online IDs Summary

Win7/Vista/XP

SSO IDs (domain joined)

MS Online IDs

Outlook Web Application

SharePoint Web Application

ActiveSync, POP, IMAP, Entourage

Outlook 2007 or 2010

Online ID Online ID Online ID

Win 7/Vista/XP

Office 2010, or Office 2007 SP2

Online ID

Win7/Vista/XP

Lync Online

Online ID

AD credentials AD credentials AD credentials AD credentials AD credentials

SSO IDs (non-domain joined) AD credentials AD credentials AD credentials AD credentials AD credentials

*Requires ADFS 2.0

Page 16: Identity in Office 365  - SPS Redmond 2012

16 | SharePoint Saturday Redmond 2012

Your Environment

AD

MS Online Directory Sync

Identity Services

Lync Online

SharePoint Online

Exchange Online

Active Directory Federation Services 2.0

Trust

IdP Directory

Store

Authentication platform

Office 365 Desktop Setup

Microsoft Online Services

IdP

Active Directory Federation Services (AD FS)

Page 17: Identity in Office 365  - SPS Redmond 2012

17 | SharePoint Saturday Redmond 2012

How does AD FS work?

Claims authentication

Think of it like a passport

Passport Application

Visa Application

Submit for authorization

Allowed access

Page 18: Identity in Office 365  - SPS Redmond 2012

18 | SharePoint Saturday Redmond 2012

AD FS’s Authentication flow

`

Client

(joined to CorpNet)

Authentication platformAD FS 2.0 Server

Exchange Online or

SharePoint Online

Active Directory

Your Environment Microsoft Online Services

Logon (SAML 1.1) Token UPN:[email protected] Source User ID: ABC123

Auth Token UPN:[email protected] Unique ID: 254729

Page 19: Identity in Office 365  - SPS Redmond 2012

19 | SharePoint Saturday Redmond 2012

AD FS 2.0 deployment options 1. Single server configuration

2. AD FS 2.0 server farm and load-balancer

3. AD FS 2.0 proxy server or UAG/TMG (External Users, Active Sync, Outlook)

Enterprise

DMZ

AD FS 2.0 Server Proxy

External user Internal

user

Active Directory

AD FS 2.0 Server

AD FS 2.0 Server

AD FS 2.0 Server Proxy

Page 20: Identity in Office 365  - SPS Redmond 2012

20 | SharePoint Saturday Redmond 2012

ADFS Considerations

Can you afford an outage?

How do you secure it?

It’s complex

Requires specific AD config

UPN formatting

Requires DirSync

Other options available

Shibboleth (added August 2012)

Hat tip: @usher

Page 21: Identity in Office 365  - SPS Redmond 2012

21 | SharePoint Saturday Redmond 2012

Directory Synchronization

One-way copy of accounts to Office 365

Required for SSO/AD FS

But can be used without AD FS

Required for Hybrid scenarios

Think of it as an appliance, always running

Page 22: Identity in Office 365  - SPS Redmond 2012

22 | SharePoint Saturday Redmond 2012

Your Environment

AD

MS Online Directory Sync

Identity Services

Lync Online

SharePoint Online

Exchange Online

Active Directory Federation Services 2.0

Trust

IdP Directory

Store

Authentication platform

Office 365 Desktop Setup

Microsoft Online Services

IdP

How DirSync Fits in

Page 23: Identity in Office 365  - SPS Redmond 2012

23 | SharePoint Saturday Redmond 2012

Getting to know DirSync

It’s actually Forefront Identity Manager

Copies AD accounts into Office 365

But not back down

Doesn’t sync passwords

Filtering now available

Can have sizing issues

Upload sizing

Database sizing

FIM: no touchy! (maybe)

Page 24: Identity in Office 365  - SPS Redmond 2012

24 | SharePoint Saturday Redmond 2012

Office 365 Overview

Changing the Identity Perspective

Authentication vs. Authorization

Who Are You?

What Do You Do Here?

Who’s in Charge Here?

Page 25: Identity in Office 365  - SPS Redmond 2012

25 | SharePoint Saturday Redmond 2012

Who does what around here?

Role-based Administration (RBAC)

External access

Page 26: Identity in Office 365  - SPS Redmond 2012

26 | SharePoint Saturday Redmond 2012

Office 365 user roles

End Users

Service administrators

Exchange Online

SharePoint Online

Lync Online

Office 365 administrators

External users

Page 27: Identity in Office 365  - SPS Redmond 2012

27 | SharePoint Saturday Redmond 2012

Office 365 admin roles

Global administrator

Billing administrator

Password administrator

Services administrator

User management administrator

Delegated administrator

See the Office 365 Support Services Description document for more info:

http://tinyurl.com/o365SvcDescrs

Page 28: Identity in Office 365  - SPS Redmond 2012

28 | SharePoint Saturday Redmond 2012

External access

Allows external users access to SharePoint Online

No USLs required

Not full Extranet

Users can have:

MSO ID

Live ID

EASI ID

It’s a Feature Preview…

Page 29: Identity in Office 365  - SPS Redmond 2012

29 | SharePoint Saturday Redmond 2012

Office 365 Overview

Changing the Identity Perspective

Authentication vs. Authorization

Who Are You?

What Do You Do Here?

Who’s in Charge Here?

Page 30: Identity in Office 365  - SPS Redmond 2012

30 | SharePoint Saturday Redmond 2012

Managing Identity in Office 365

Admin activities do not go away

AD FS is complex

And important!

PowerShell is your friend

How’s your internet connection?

Office 365 is constantly changing

Page 31: Identity in Office 365  - SPS Redmond 2012

31 | SharePoint Saturday Redmond 2012

Troubleshooting Identity

Microsoft Online Diagnostics and Logging tool (MOSDAL)

Microsoft Remote Connectivity Analyzer: HTTP://testexchangeconnectivity.com

Fiddler

WireShark/Netmon

Office 365 Expert Discussion Series: http://tinyurl.com/o365ExptDisc

Page 32: Identity in Office 365  - SPS Redmond 2012

32 | SharePoint Saturday Redmond 2012

Tie IT All Together

Page 33: Identity in Office 365  - SPS Redmond 2012
Page 34: Identity in Office 365  - SPS Redmond 2012

Blog: http://www.MyCentralAdmin.com Twitter: @ferringer