官术网_书友最值得收藏!

Azure Active Directory B2B integration

Azure AD B2B allows any partner to use their own identities and credentials in a collaboration scenario. For the authentication flows and capabilities, we'll take a more in-depth look in Chapter 8, Using the Azure AD App Proxy and the Web Application Proxy and Chapter 10Exploring Azure AD Identity Services. For now, we'll give a quick overview of the synchronization part:

Azure AD B2B local application access scenario

For Azure AD B2B users to use on-premises Kerberos applications, we need to synchronize the guest user accounts back to the On-Premises Active Directory. For this reason, you need to provide your default Azure AD domain suffix in your local AD. In our case, it's inovitcloudlabs.onmicrosoft.com. You will find the option in the AD Domains and Trusts console:

Adding your Azure AD tenant suffix to your local UPN suffixes

The registration of the new UPN suffix is necessary because the Azure AD Application Proxy checks the local AD for the existence of the guest user UserPrincipalName, such as jochen.nickel_inovit.ch#EXT#@inovitcloudlabs.onmicrosoft.com.

Microsoft provides a default solution for synchronizing the guest users back to the local AD; check it out at https://bit.ly/2Bor7xy. The solution contains the needed MIM 2016 configuration or a script to deploy the solution successfully. Don't be worried, we'll do the default configuration and extension later in the book.

主站蜘蛛池模板: 应用必备| 沭阳县| 靖边县| 宜都市| 吐鲁番市| 衢州市| 宜兴市| 合水县| 汽车| 东乡| 西乌珠穆沁旗| 汉中市| 张北县| 股票| 通辽市| 博客| 重庆市| 汉寿县| 洞头县| 庆城县| 金溪县| 沛县| 黄梅县| 横峰县| 九龙城区| 剑川县| 九江县| 刚察县| 卢龙县| 垫江县| 霍州市| 胶南市| 松潘县| 阿尔山市| 政和县| 三台县| 阿克陶县| 多伦县| 锡林郭勒盟| 新蔡县| 凤冈县|