<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:series="https://publishpress.com/"
	>

<channel>
	<title>SSO Azure AD Archives - Anuj Varma, Hands-On Technology Architect, Clean Air Activist</title>
	<atom:link href="https://www.anujvarma.com/tag/sso-azure-ad/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.anujvarma.com/tag/sso-azure-ad/</link>
	<description>Production Grade Technical Solutions &#124; Data Encryption and Public Cloud Expert</description>
	<lastBuildDate>Wed, 31 May 2017 18:52:32 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.9.4</generator>

<image>
	<url>https://www.anujvarma.com/wp-content/uploads/anujtech.png</url>
	<title>SSO Azure AD Archives - Anuj Varma, Hands-On Technology Architect, Clean Air Activist</title>
	<link>https://www.anujvarma.com/tag/sso-azure-ad/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Azure AD Connect&#8211;Identity in the Cloud, SSO Azure AD</title>
		<link>https://www.anujvarma.com/azure-ad-connect-identity-in-the-cloud/</link>
					<comments>https://www.anujvarma.com/azure-ad-connect-identity-in-the-cloud/#respond</comments>
		
		<dc:creator><![CDATA[Anuj Varma]]></dc:creator>
		<pubDate>Thu, 11 May 2017 20:41:47 +0000</pubDate>
				<category><![CDATA[Azure]]></category>
		<category><![CDATA[Identity in the Cloud]]></category>
		<category><![CDATA[Azure IAM]]></category>
		<category><![CDATA[Azure AD Connect]]></category>
		<category><![CDATA[Seamless SSO Azure]]></category>
		<category><![CDATA[SSO Azure AD]]></category>
		<guid isPermaLink="false">http://www.anujvarma.com/?p=4702</guid>

					<description><![CDATA[<p>The idea is – hundreds (maybe thousands) of applications – but just a SINGLE Identity (that works across all the apps)s. &#160; Three Models for Authentication In all these models, [&#8230;]</p>
<p>The post <a href="https://www.anujvarma.com/azure-ad-connect-identity-in-the-cloud/">Azure AD Connect&ndash;Identity in the Cloud, SSO Azure AD</a> appeared first on <a href="https://www.anujvarma.com">Anuj Varma, Hands-On Technology Architect, Clean Air Activist</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>The idea is – hundreds (maybe thousands) of applications – but just a SINGLE Identity (that works across all the apps)s.</p>
<p>&nbsp;</p>
<p><a href="http://www.anujvarma.com/wp-content/uploads/Identity_Cloud_Single_Identity_MultipleApps.png"><img fetchpriority="high" decoding="async" title="Identity_Cloud_Single_Identity_MultipleApps" style="border-top: 0px; border-right: 0px; background-image: none; border-bottom: 0px; padding-top: 0px; padding-left: 0px; border-left: 0px; display: inline; padding-right: 0px" border="0" alt="Identity_Cloud_Single_Identity_MultipleApps" src="http://www.anujvarma.com/wp-content/uploads/Identity_Cloud_Single_Identity_MultipleApps_thumb.png" width="684" height="457"></a></p>
<h3>Three Models for Authentication</h3>
<p>In all these models, identity between on-prem and Azure AD needs to be synchronized.</p>
<ol>
<li>Authenticate in Azure (Using Azure AD Connect)
<li>Authenticate against On-Prem AD (Windows Server AD) – by passing credentials from Azure to On-Prem using ADFS
<li>Seamless SSO </li>
</ol>
<h3>Seamless SSO</h3>
<p>In order to avoid authenticating already authenticated users, a pass through agent is provided. Essentially, you add in two more infrastructure components – an AD Proxy (on the Azure side) and Connectors (on each of the apps).</p>
<ol>
<li><em>Azure AD app proxy</em> is a cloud service that allows users to access on-premises apps securely.
<li>Users connect to the cloud service that routes traffic to the applications via <em>connectors. </em><em>Connectors</em> are usually deployed inside the corporate network, next to the applications.
<li>Users connect to the cloud service that routes their traffic to application resources via the connectors.</li>
</ol>
<p><em>Note: OWASP Recommendation&nbsp; &#8211; Store the secondary SSO / framework / custom session identifiers in native session object – as opposed to sending as additional headers or cookies.</em></p>
<h3>Authenticate in Azure </h3>
<p><a href="http://www.anujvarma.com/wp-content/uploads/Identity_Cloud.png"><img decoding="async" title="Identity_Cloud" style="border-top: 0px; border-right: 0px; background-image: none; border-bottom: 0px; padding-top: 0px; padding-left: 0px; border-left: 0px; display: inline; padding-right: 0px" border="0" alt="Identity_Cloud" src="http://www.anujvarma.com/wp-content/uploads/Identity_Cloud_thumb.png" width="725" height="506"></a></p>
<p>Authenticate with Azure AD Connect (Service). Between Windows Server AD and Azure AD – perform Identity + Password (Hash) synchronization.</p>
<h3>Summary</h3>
<p>IAM in the cloud is a combination of Windows Server Active Directory, Microsoft’s Identity Manager&nbsp; and Microsoft’s Azure Active Directory. With the combination of an AD in Azure and an AD on-prem, there are a multitude of authentication options available for providing a single point of IAM for multiple apps.&nbsp; </p>
<p>The post <a href="https://www.anujvarma.com/azure-ad-connect-identity-in-the-cloud/">Azure AD Connect&ndash;Identity in the Cloud, SSO Azure AD</a> appeared first on <a href="https://www.anujvarma.com">Anuj Varma, Hands-On Technology Architect, Clean Air Activist</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.anujvarma.com/azure-ad-connect-identity-in-the-cloud/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>

<!--
Performance optimized by W3 Total Cache. Learn more: https://www.boldgrid.com/w3-total-cache/?utm_source=w3tc&utm_medium=footer_comment&utm_campaign=free_plugin

Page Caching using Disk: Enhanced 
Content Delivery Network via N/A
Minified using Disk

Served from: www.anujvarma.com @ 2026-06-07 10:08:23 by W3 Total Cache
-->