How MIM and Azure AD Connect enables Hybrid Identity
This is a mind map talking about How MIM and Azure AD Connect enables Hybrid Identity. You can create a mind map like this effortlessly.
Tags:
Similar Mind Maps
Outline


Microsoft cloud capabilities are developing we can see thedestination ever more clearly
Most organizations are still hybrid organizations, and stillneed onpremise AD
MIM is great for organizing onpremises identities, and isan important cloudenable in all but the simplest cases itcan be gradually wound down, but will also persist for sometime
Azure AD Connect is very capable and will be around fromsome time.

HTTP(S) traffice is terminated in the cloud, blocking manyattacks
No incoming connections
Abnormalities detected & reported and autidting byAzure AD
Sign Signon experience from Azure AD to onpremiseapplications

Most organizations are using cloud services (Azure)
Few of them are able to become all cloud. Userstypically have a cloud and an onpremises "persona"(identity)
At leat on ecloud and onepremises persona
Admin: "one" identity to manage, one place.
User: same signon or single signon
Security: consistent and timely identity data
Goverance: knowing what you know about users
Azure AD Connect is to hybrid identity management,what MIM is to onpremises identity management

A free tool which does a lot out of the box
Based on MIM, but it is different and doesmore
Fully supported as an AD/AAD sync engine
Benefits
Objects and attributes synchronized (users, contacts,groups and their memberships, and devices)
Alows (some) cloud secrutiy and governance features
Various authentication options
Consolitating Identities
Managed AuthenticationMethods
Password Hash Sync (PHS) least effort,no real time onpremises dependency,leaked credential protection
PHS
PassThrough Authentication (PTA) ADin control, lightweight agents, onlyoutbound networking
PTA
Federated Authentication
Federation
Seamless SSO
configures Azure AD as a Kerberos service
Hybrid Azure AD join
One of the two possible devicescenarios in Azure AD Connect
Suitably configured AD joined computerscan become Hybrid Azure AD Joined
Certificatebased SSO
Integrating HR

Admin: one identity to manage
User: same signon
Security: consistent and timely identity data across systems
Governance: knowing what you know about users and their entitlements
MIM's ongoing importance

Maintains cloud identities for the same reason that AD maintainsonpremises identities
Protects identity information and makes it available for anycloud service to use for authentication and authorizationpurposes