Azure AD Premium vs. Azure AD

Many of my customers ask me that, and most of the cases I answer with the following: “If you have an Office 365 subscription, then you already have Azure Active Directory”

In addition to that, if they have Azure AD Connect enabled, will mean that their OnPremises users, passwords and groups are being synchronized to Azure Active Directory.

This is the standard case, but then many of my customers want to enable more features, but many of them are only available on Premium version, and yes it incurs an extra cost

Moreover, nowdays we have different types of Azure Active Directory licensing like:

  • Azure Active Directory Basic
  • Azure Active Directory Premium P1
  • Azure Active Directory Premium P2

But, which features has each one of the licenses?

With Azure Active Directory Basic

  • Manage users & group memberships in the cloud, and assign licensing
  • Sync your on-premises directory using Azure AD Connect
  • Cloud Users can reset their own passwords online
  • Company branding for the SSO access panel, etc.
  • 99.9% uptime SLA

Azure Active Directory Premium P1

  • MFA for cloud and OnPremises
  • Monitor AD synchronization health in the cloud
  • Cloud and OnPremise Users can change their own passwords online
  • Advanced security & usage reports
  • Self-service group & app management (dynamic groups)
  • Run Cloud App Discovery to uncover unmanaged cloud applications running in your environment

Azure Active Directory Premium P2

  • Azure Identity Protection
  • Privileged Identity Management

So, if you want to more about the Azure Active Directory, you can visit the following link, where you can find more info about it.

Till next time!

Advertisements

AzureAD admin is in the new Azure Portal!

Hi there!

Yes, you’re reading well, MS have launch the preview of AzureAD in the new Azure Portal. As you know, when you need to configure something of AzureAD in the new portal, automatically redirects to manage.windowsazure.com.

It was very confusing and it was simply stupid, but from today we can enjoy the new AzurePortal:

azuread.PNG

I hope that MS will be improving the user experience of this new feature, but for this time this are great news 🙂

If you want to hear more info about this, you can visit the following Technet Blog

Cheers!

 

How to connect to O365 using PowerShell

PowerShell is a necessary tool  to connect to O365 administration, more than the 40% of the features of O365 are not visible in the administration panel, so the only way to manage them is via PowerShell code. To the vast majority of users the web portal will be more useful, but if you need to do repetitive tasks or very complex PowerShell is your tool.

So, how do we connect to the several services that offer O365? Let’s being:

Azure Active Directory

$credential = get-credential
Import-Module MsOnline

Connect-MsolService -Credential $credential

Exchange Online

$exchangeSession = New-PSSession -ConfigurationName Microsoft.Exchange -ConnectionUri https://outlook.office365.com/powershell-liveid/ -Credential $credential -Authentication “Basic” -AllowRedirection

Import-PSSession $exchangeSession

SharePoint Online

Import-Module Microsoft.Online.SharePoint.PowerShell

Connect-SPOService -Url https://<NombreDelTenant>-admin.sharepoint.com -credential $credential

Skype for Business

Import-Module LyncOnlineConnector

$lyncSession = New-CsOnlineSession -Credential $credential

Import-PSSession $lyncSession

BONUS: Microsoft Azure

Get-AzurePublishSettingsFile cmdlet

#opens a web page on the Windows Azure Management Portal, from which you can download the subscription information. The information is contained in a .publishsettings file.

Import-AzurePublishSettingsFile “Pathtopublishingfile”

Get-AzureAccount

Get-AzureSubscription
#the previous commands allow to view account and subscription details

Depending of which operations or services we are using, we will be able to connect to the service without problem

Updating DirSync to AAD: Part 2

Hi all, I will continue posting about how to update DirSync in order to get all the advantages of AAD.

If you followed my previous post, and if you have installed all the software requirements in your server, you’re ready to update to AAD. In my case I followed this guide:

http://blogs.msdn.com/b/vilath/archive/2015/05/29/in-place-upgrade-dirsync-to-azure-ad-connect-preview-2.aspx

It was so easy to do, but I had one problem, when I installed AAD and before I configure it, the services of synchronization were stopped, I still don’t know why, but I checked the event viewer and I realized that the account that runs the services does not have the required permissions.

So I needed to put out the server from the Group policy of the domain and put the user the right permissions. In my case it was strange because the user that runs the services was a local user. I didn’t do the original configuration but it seems that is something wrong there, I’m checking if it’s possible to change the user per a domain user, so this would not happen again.

Till the next time!

Updating DirSync to AAD: part 1

Hi all! Today I will start with a serie of posts about how to update DirSync to AAD. For those who don’t know what is AAD, I will tell them that is a new tool from Microsoft that simplifies the synchronization between your on-premises directories with Azure AD, and also to enable single sign-on to Office 365 and other applications.

Azure AD Connect includes all the advances and features of AAD Sync as:

  • Enable your users to perform self-service password reset in the cloud with write-back to on premises AD
  • Enable provisioning from the cloud with user write back to on premises AD
  • Enable write back of “Groups in Office 365” to on premises distribution groups in a forest with Exchange
  • Enable device write back so that your on-premises access control policies enforced by ADFS can recognize devices that registered with Azure AD. This includes the recently announced support for Azure AD Join in Windows 10.
  • Sync custom directory attributes to your Azure Active Directory tenant and consume it from your cloud applications

So, If your question is being: DirSync being replaced by AAD? The answer is yes 🙂

Next thing we have to check before installing nothing is to review the requisites:

Active Directory domain – Windows Server 2003 or higher DC
Machines – The machine on which the wizard is run (and sync will be configured) must be running Windows Server 2008 R2, 2012 or 2012 R2 and must be domain joined
Credentials you will need – To run the wizard, you must be logged in as a domain account, not a local machine account. Windows Server Active Directory enterprise administrator credentials
Azure Active Directory global administrator account – It is helpful to have a test user account created in Active Directory so that you can do a test sign-in upon completion of the configuration
Azure AD –  You will need one Azure AD tenant which you can use for the evaluation of this preview.

Also the following software to update from DirSync to AAD:

Objects in ACTIVE DIRECTORY CPU MEMORY HDD Size
less than 10.000 1,6 GHz 4 GB 70 GB
10.000–50.000 1,6 GHz 4 GB 70 GB
50.000–100.000 1,6 GHz 16 GB 100 GB*
for more than 100.000 objects is required a complete version of SQL Server
100.000–300.000 1,6 GHz 32 GB < 300 GB
300.000–600.000 1,6 GHz 32 GB 450 GB
more than 600.000 1,6 GHz 32 GB 500 GB

To check how many object do we have in AD, we hbave the following Powershell to check it:

Import-module activedirectory

Get-ADObject -Filter {name -like '*'} -SearchBase 'CN=Schema,CN=Configuration,DC=domain,DC=local' -ResultSetSize $null | Measure-Object

In my case it was about 5k objects, so I was able to update withour problems 🙂

If you need more information, you can visit: https://azure.microsoft.com/en-us/documentation/articles/active-directory-aadconnect/

How to restore local databases to Azure Databases

We are in involved in several projects with Azure, and in one of them, we need to create an Azure Database to use with an Application Web and restore some information that we have onPremises on Azure Databases.

So, as you can imagine, is it not possible to restore a OnPremises database to Azure, you have to do additional steps, so the goal of this post is to explain that process:

First, you’ll need to create a SQL Database in Azure:

untitled

Give a name for the database. Once it is created, you will see the servername listed in the dashboard:

untitled1.png

So, we need to start the SQL Server Management Studio and connect to the Azure database, entering the server name and Login credentials:

untitled2.png

In SQL Server Management Studio, will now be listed the database created:

Sin título

Next Step is to connect to the Local SQL server instance and generate the scripts:

Sin título1.png

The script generator will now start. In this instance I have selected to script the entire database

untitled4

Before you create the script, click on the ‘Advanced’ button

untitled5

Under the advanced options, be sure to select to script the database for SQL Azure

untitled6

In my example, I chose to only script the schema but you can script the schema and or data

untitled8

After you are done, create the script

untitled9

Next step is to select Azure database in Management Studio and execute the script file you have previously generated

untitled10

Hit f5…

untitled11

After doing this, the schema will be created in the Azure database

untitled12

Easy, isn’t it?

Microsoft Azure Essentials – 10979

Course Information
https://www.microsoft.com/learning/en-us/course.aspx?id=10979b

Before attending this course, students must have:

  • Professional experience in information technology.
  • An understanding of websites.
  • A basic understanding of Active Directory concepts such as domains, users, and domain controllers.
  • A basic understanding of database concepts, including tables and simple queries.

Module 1

Multi-Factor Authentication
https://msdn.microsoft.com/library/azure/jj713614.aspx

Understand Your Bill
http://azure.microsoft.com/en-us/support/understand-your-bill/

Azure General Price Information Page
http://azure.microsoft.com/en-us/pricing/

Storage Pricing
http://azure.microsoft.com/en-us/pricing/details/storage/

How to Reduce Bills (Save $) For Your Applications Deployed On Windows Azure Virtual Machines
http://blogs.msdn.com/b/cie/archive/2014/03/30/how-to-reduce-bills-save-for-your-applications-deployed-on-windows-azure-virtual-machines.aspx

I’m confused between Azure Cloud Services and Azure VMs?
http://blogs.msdn.com/b/plankytronixx/archive/2014/04/24/i-m-confused-between-azure-cloud-services-and-azure-vms-what-the.aspx

Free Workstation in Minutes
http://blogs.msdn.com/b/plankytronixx/archive/2014/11/21/provision-a-dev-workstation-in-6-minutes-and-0-00.aspx

What is a Cloud?
https://technet.microsoft.com/en-us/magazine/hh509051.aspx

More from the Cloud Engineer
http://thecloudengineer.blogspot.com/2015/04/azure-basic-definitions.html

Module 2

Services by Region Info
http://azure.microsoft.com/en-us/regions/#services
Locations Info
http://azure.microsoft.com/en-us/regions/#overview

Azure VM FAQ
https://msdn.microsoft.com/en-us/library/azure/dn683781.aspx
VM and Cloud Service Sizes for Azure
https://msdn.microsoft.com/library/azure/dn197896.aspx
Azure VM Extensions and Features
https://msdn.microsoft.com/en-us/library/azure/dn606311.aspx

Create a Virtual Machine Running Windows
http://azure.microsoft.com/en-us/documentation/articles/virtual-machines-windows-tutorial/

Host Caching
http://stackoverflow.com/questions/19370693/what-is-the-difference-in-the-host-cache-preference-settings-when-adding-a-dis

About Virtual Machine Disks in Azure
https://msdn.microsoft.com/en-us/library/azure/dn790303.aspx

Community created Linux and FreeBSD VM Images
https://vmdepot.msopentech.com/List/Index

Module 3

WebJobs
http://azure.microsoft.com/en-us/documentation/articles/web-sites-create-web-jobs/

Why Clear DB?
https://www.cleardb.com/developers/help/faq

Module 4

Get started with Azure Websites and ASP.NET
http://azure.microsoft.com/en-us/documentation/articles/web-sites-dotnet-get-started/

Azure Websites, Cloud Services, and Virtual Machines comparison
http://azure.microsoft.com/en-us/documentation/articles/choose-web-site-cloud-service-vm/

Set up staging environments for web apps in Azure App Service
http://azure.microsoft.com/en-us/documentation/articles/web-sites-staged-publishing/

Update an Azure Service
https://msdn.microsoft.com/en-us/library/azure/hh472157.aspx

Configure a Virtual Network in the Management Portal
https://msdn.microsoft.com/library/azure/dn631643.aspx

Configure a Cross-Premises Site-to-Site connection to an Azure Virtual Network
https://msdn.microsoft.com/library/azure/dn133795.aspx

Configure a Point-to-Site VPN connection to an Azure Virtual Network
https://msdn.microsoft.com/library/azure/dn133792.aspx

Configure a VNet to VNet Connection
https://msdn.microsoft.com/library/azure/dn690122.aspx

VNet Configuration Tasks
https://msdn.microsoft.com/library/azure/jj156206.aspx

VNet FAQ
https://msdn.microsoft.com/library/azure/dn133803.aspx

VNet Forums
https://social.msdn.microsoft.com/Forums/en-US/home?forum=WAVirtualMachinesVirtualNetwork

Module 5

Azure Subscription and Service Limits, Quotas, and Constraints

http://azure.microsoft.com/en-us/documentation/articles/azure-subscription-service-limits/#storagelimits

Azure Blog Storage (1st of 7 part article)
http://justazure.com/azure-blob-storage-part-one-introduction/

Windows Azure Storage Explorers (2014) Old List
http://blogs.msdn.com/b/windowsazurestorage/archive/2014/03/11/windows-azure-storage-explorers-2014.aspx

Resize Azure Data Disks
http://blogs.technet.com/b/keithmayer/archive/2015/03/24/resizing-data-disks-in-the-cloud-on-microsoft-azure.aspx

Module 6

Azure SQL Database Guidelines and Limitations
https://msdn.microsoft.com/en-us/library/ff394102.aspx

Module 7

More on Azure AD
Azure Active Directory Editions
Azure Active Directory Service Description
Azure AD Pricing Details

Azure Multi-Factor Authentication
https://msdn.microsoft.com/en-us/library/azure/dn249471.aspx

Assigning administrator roles in Azure AD – Billing, Global, Password, Service, User
https://msdn.microsoft.com/en-us/library/azure/dn468213.aspx

Module 8

Azure Downloads
http://azure.microsoft.com/en-us/downloads/

Appendix

Provision a developer workstation in 6 minutes and $0.00
http://blogs.msdn.com/b/plankytronixx/archive/2014/11/21/provision-a-dev-workstation-in-6-minutes-and-0-00.aspx

Use the Microsoft Azure Import/Export Service to Transfer Data to Blob Storage
http://azure.microsoft.com/en-us/documentation/articles/storage-import-export-service/

Manage Upgrades to the Azure Guest Operating System
https://msdn.microsoft.com/en-us/library/azure/ff729422.aspx
https://msdn.microsoft.com/en-us/library/azure/ff729420.aspx