Azure Security Service
Case Study
An on-premises Customer wants to Adopt Cloud SaaS Services. organization has on-premesis active Directory and they want to start using Software as a Services,they want to use a single identity for simplify provisioning and deprovisioning and better security. they have users anf groups in their active directory. they actually want to remove any reliance on their on-premises active directory domain services.
- They want use a single identify for simplified provisioning and deprovisioning and better security.
- They want to use Identity Management.
Solution
1.Multi Factor Authentication
The Customer has an on premises Active directory.Now the first Thing That has to happen is to implement Azure Active Directory(AAD). So Azure Active directory(AAD) connect is implemented which is then replicates the users into Azure AD.
if we use Azure AD Premium P1 ,all the users get MFA using their phone
Azure AD Premium P1 :- we can use Azure AD Conditional Access to prompt users for multi-factor authentication during certain scenarios or events to fit your business requirements.
2.Limit Higher Privilages
Azure AD Premium P2:-Provides the strongest security position and improved user experience. Adds risk-based Conditional Access to the Azure AD Premium P1 features that adapts to user's patterns and minimizes multi-factor authentication prompts.
Have a look into below link to know about MFA
Available versions of Azure AD Multi-Factor AuthenticationSteps to implement MFA in Azure AD
- In azure Portal,click on Azure Active Directory
- Click on Users tab. All user list will appear
- Click on Multi-factor authentication at the top. After you click it will take to another website in new window.
- A new window will open for multi-factor authentication.
- At top, there are two section ‘Users’ and ‘Service Settings’. By default, User section will open.
- Click on ‘Service Settings’. Here you can see the available option for verification and modify the options as per your choice and need.
- select the user from User tab for which we need to enable MFA and click ‘Enable’,
- A popup window will appear. Click on ‘enable multi-factor authentication’
- Close the window. we can see that MFA status has been changed to ‘Enabled’ now. Now try to login to Azure Portal with that user login. After entering login and password, another screen will come for MFA. Click Next
- Select the option for verification. we can choose the 'Authentication Phone' or 'Authentication Email'as default option. Select your country name, enter your phone number for Authentication Phone Option and click ‘Next’.
- i.Enter the verification that you will receive on your phone number and click Verify.
ii.Click ‘Done’
iii.Now, the next time when we login to the Azure portal we need to provide extra authorization
if we choose Authentication option
![Multi Factor Authentication In Microsoft Azure Updated](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjPyfvXOYiEAhNy9x1ncZmUj9DfryxPWEtUxck8BjZdC1zPehAWQFIEDW-QBdNNWyWd33FlsaILzGgDNCLpnTbXDAeOUK5ZLyknvNcYMPOEmOQYe6aBSoDtc2KJFF6JBncR4GrHW_MizyhW/s72-c/Screenshot+%2528124%2529_LI.jpg)