Book Image

Mastering Identity and Access Management with Microsoft Azure - Second Edition

By : Jochen Nickel
Book Image

Mastering Identity and Access Management with Microsoft Azure - Second Edition

By: Jochen Nickel

Overview of this book

Microsoft Azure and its Identity and access management are at the heart of Microsoft's software as service products, including Office 365, Dynamics CRM, and Enterprise Mobility Management. It is crucial to master Microsoft Azure in order to be able to work with the Microsoft Cloud effectively. You’ll begin by identifying the benefits of Microsoft Azure in the field of identity and access management. Working through the functionality of identity and access management as a service, you will get a full overview of the Microsoft strategy. Understanding identity synchronization will help you to provide a well-managed identity. Project scenarios and examples will enable you to understand, troubleshoot, and develop on essential authentication protocols and publishing scenarios. Finally, you will acquire a thorough understanding of Microsoft Information protection technologies.
Table of Contents (23 chapters)
Title Page
Copyright and Credits
About Packt
Contributors
Preface
Index

Understanding declarative provisioning and expressions


The easiest way to explain declarative provisioning is as follows: objects are processed from the source connected directory to the target source by evaluating how the objects and the associated attributes should be transformed. This is controlled by inbound rules from the connector space to the metaverse and outbound rules from the metaverse to the connector space. The following diagram gives you an overview of all of the components:

Declarative provisioning options and components overview

Declarative provisioning provides the following capabilities:

  • The only way to configure the sync engine
  • Functions to configure attribute flows
  • Precedence is on SRs (not on Connectors)
  • MV—deletion rules now use declarative provisioning
  • Introduces parameters, such as %Domain.Netbios%
  • Configured through PowerShell

The attribute-flow expression language can be explained as follows:

  • Written in Visual Basic for Applications (VBA)
  • Stricter syntax:
    • Useful errors for...