官术网_书友最值得收藏!

Extending Directory Services to Azure

Organizations have leveraged Directory Services and Identity Services for years, and they have manifested in the Azure Active Directory in Azure. The Azure Active Directory (AAD), is important for securing services for Azure-based solutions.  Before we discuss moving existing applications to Azure in Chapter 2, Moving existing apps to Azure, it is a good practice to synchronize directories so that resources can be shared from on-premise to Azure in hybrid scenarios.  A hybrid scenario would be defined as moving your web front-end virtual machines into Azure while your databases' virtual machines remain on-premise.  You can leverage Azure Connect to solve the syncing of your on-premise Active Directory to Azure Active Directory, as shown in the following diagram:

Azure AD Connect

While this book is about Hands-On Solutions with Azure, the configuration of the synchronization to Azure can be complex based on the directory services configured within your organization. You can find Azure Connect in the portal, as shown in the following screenshot.

You can also learn how to set up Azure Active Directory to sync with your organization by using the guide at https://docs.microsoft.com/en-us/azure/active-directory/connect/active-directory-aadconnect, as you can see below in Figure 1.7.

Azure Connect in the portal

No matter how you choose to use Azure, it is important to get the security right upfront.  Now, one of the biggest differences is that the Azure Active Directory has pricing plans based on the type of services you need, and you can review that pricing here: https://azure.microsoft.com/en-us/pricing/details/active-directory/

Make sure to move all of your domains first. You want to use OU filtering to ensure that only the people you want are synchronized.  Moving resources to a non-sync OU will reduce the object's sync, for example, there may be people that have left or services not in use.

Once everything has been completed, your users should be able to change their passwords on both fronts.  You will also have the ability to access and secure resources without having to add them to Azure AD and cut down on your user management.

主站蜘蛛池模板: 阿合奇县| 江安县| 蒙城县| 余干县| 莱州市| 古蔺县| 宜丰县| 望江县| 安图县| 南木林县| 大关县| 凌云县| 建始县| 阿拉善盟| 民勤县| 渝北区| 东丰县| 台中县| 天长市| 忻城县| 潞城市| 综艺| 赤壁市| 高雄市| 新巴尔虎右旗| 甘孜| 丰县| 金寨县| 广昌县| 靖江市| 商城县| 横山县| 彰化县| 碌曲县| 库车县| 滦平县| 疏勒县| 永善县| 阿瓦提县| 铁力市| 海林市|