Optimizing Active Directory to Better Suit a Hybrid Environment Gary Savarino Solution Consultant Active Directory Subject Matter Expert
Gary Savarino Solutions Consultant & Active Directory Subject Matter Expert Dell Software Gary Savarino is a Solutions Consultant and Active Directory Subject Matter Expert at Dell Software, specialising in Dell Software s Microsoft Platforms Management Solutions. Gary has been in the IT Industry for 16 years, having spent the last 5 years with Quest/Dell Software. Gary gained much of his experience in previous roles spending 11 years in the trenches at global companies like Unisys and Vodafone. He understands the complexity of day-to-day IT administration and the way a major project such as migration can impact, and potentially hamper, the business. At Dell Software, he works closely with account teams to oversee sales engagements, influence product direction and architectural documentation, present interactive product demonstrations, and position Dell Software as a leader in the Active Directory and Microsoft Platform Management market space. 2
Agenda AD vs. Azure AD what s the difference? Why Does Office 365 Care? What is Modernizing AD? How do we get there? Normalizing Consolidating Security Provisioning 3
On-premises AD vs. Azure AD On-Premises AD LDAP Interface Kerberos/NTLM Authentication Hierarchical structure (OUs, etc.) Rich schema Integrated management services (e.g. Group Policy) Tight Windows integration Azure AD PowerShell and REST interfaces OAUTH and SAML authentication Flat structure Simple non-extensible schema Management services are add-on Integrated SSO support Client agnostic 4
Azure AD & Office 365 Provides the Directory Service for Office 365 applications Can integrate with on-prem AD users and groups using federation or password sync Office 365 *requires* an Azure AD instance (may be under the covers for smaller organizations) 5
Why companies do organizations looking move to move to the to cloud? the cloud? Economies of scale: When implemented properly, the cloud computing economic model can drastically reduce the cost of IT infrastructures. Speed of deployment: Moving to cloud based applications and SaaS is quick and efficient. Trusted advisors, i.e. Microsoft, Google, Amazon recommend doing so. One unified platform for modern business 6
Why Modernize AD? A migration to Office 365 means a migration to Azure AD, you must have Azure to have O365 For those with on-prem AD, you will synchronize onprem AD to Azure AD It s important to not drag your cruft with you 7
What Does It Mean to Modernize? Normalize AD Domains Clean-up OU Structure Improve Security Solid de/ Provisioning 8
Normalizing AD The principle: the fewer domains/forests you have to synchronize to Azure AD, the better A good time look at your AD domain structure and consolidate/migrate Better to normalize before you have to stuff all that into Azure AD 9
OU Structure Users and groups all over the place? Makes it harder to pick which OUs to synchronize to Azure AD More likely to get objects you don t want/need Eases management once they are in Azure AD 10
Good Security Delegation On-prem AD structures don t translate to Azure AD, but Good secure management and delegation of AD typically translates into better understanding of Azure AD s delegation model A role-based approach to AD security ensures a clean mapping to Azure AD s simple delegation model 11
Solid Provisioning/De-Provisioning Bottom line: If you don t have good control over on-prem identity lifecycle, then it won t be better in Azure AD Ramifications for: Security-people getting access to Office 365 apps and data that shouldn t Licensing-costs for licensing people who no longer exist in your org 12
Modernizing AD Optimizes your Active Directory to gain velocity to the cloud. 13
More than just technology improvements Forrester Consulting Total Economic Impact Study Reduction in AD management labor costs Reduction in cost for identity attestation Reduction in effort preparing audit reports. Reduction in labor needed for user migrations The qualitative benefits include: Laying a foundation for a centralized AD management model Increased user and computer migration speeds Single sign-on for users who work at multiple locations Improved insight into group usage Easy delegation of permissions Reduced help desk labor effort associated with password resets Reduction in footprint needed for AD backup and recovery 14
Optimize AD to gain velocity to the cloud with Dell Most organizations have real and significant challenges around Active Directory that need to be solved to take advantage of cloud services. No other single vendor can offer you a total, collaborative, end-to-end AD modernization solution to optimize your journey to the cloud. Dell helps you better manage, better secure, better comply, better recover AD to better serve your business. 15
Market leadership & Experience 16
Thank you!