Book Image

Mastering Identity and Access Management with Microsoft Azure - Second Edition

By : Jochen Nickel
Book Image

Mastering Identity and Access Management with Microsoft Azure - Second Edition

By: Jochen Nickel

Overview of this book

Microsoft Azure and its Identity and access management are at the heart of Microsoft's software as service products, including Office 365, Dynamics CRM, and Enterprise Mobility Management. It is crucial to master Microsoft Azure in order to be able to work with the Microsoft Cloud effectively. You’ll begin by identifying the benefits of Microsoft Azure in the field of identity and access management. Working through the functionality of identity and access management as a service, you will get a full overview of the Microsoft strategy. Understanding identity synchronization will help you to provide a well-managed identity. Project scenarios and examples will enable you to understand, troubleshoot, and develop on essential authentication protocols and publishing scenarios. Finally, you will acquire a thorough understanding of Microsoft Information protection technologies.
Table of Contents (23 chapters)
Title Page
Copyright and Credits
About Packt
Contributors
Preface
Index

Special considerations in advanced synchronization concepts


In this section, we'll start using our knowledge in practical examples. First, we'll explore some essential functions that can be used out of the box. In some environments, you have the requirement that an organization has an organizational unit (OU) filter in place, where all users are included in this OU. But now that you need to filter out, this shouldn't be synchronized to the Azure AD. Furthermore, we'll integrate a second AD forest and use PowerShell to configure the synchronization rules.

Using standard filters to exclude users and groups

In this section, we'll use the standard filtering options to exclude users and groups to be synchronized to the metaverse:

  1. Log in as domain administrator to your YD1ADS01.
  2. Open the Active Directory Users and Computers console (dsa.msc).
  3. Be sure that you are in the advanced features view:

Active Directory Users and Computers—Advanced Features option

  1. Choose one of your users and move to the Attribute...