AZURE ACTIVE DIRECTORY TEAM BLOG
<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
xmlns:content="http://purl.org/rss/1.0/modules/content/"
xmlns:wfw="http://wellformedweb.org/CommentAPI/"
xmlns:dc="http://purl.org/dc/elements/1.1/"
xmlns:atom="http://www.w3.org/2005/Atom"
xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
>
<channel>
<title>Azure Active Directory – Enterprise Mobility and Security Blog</title>
<atom:link href="https://blogs.technet.microsoft.com/enterprisemobility/feed/?product=azure-active-directory" rel="self" type="application/rss+xml" />
<link>https://blogs.technet.microsoft.com/enterprisemobility</link>
<description>The most recent news and updates about Microsoft’s Enterprise Mobility offerings and events for enterprise technology professionals and developers.</description>
<lastBuildDate>Thu, 04 May 2017 22:00:15 +0000</lastBuildDate>
<language>en-US</language>
<sy:updatePeriod>hourly</sy:updatePeriod>
<sy:updateFrequency>1</sy:updateFrequency>
<item>
<title>Azure AD and third-party apps: It’s a bigger deal than you might think!</title>
<link>https://blogs.technet.microsoft.com/enterprisemobility/2017/05/01/azure-ad-and-third-party-apps-its-a-bigger-deal-than-you-might-think/</link>
<comments>https://blogs.technet.microsoft.com/enterprisemobility/2017/05/01/azure-ad-and-third-party-apps-its-a-bigger-deal-than-you-might-think/#comments</comments>
<pubDate>Mon, 01 May 2017 16:00:52 +0000</pubDate>
<dc:creator><![CDATA[Alex_SimonsMS]]></dc:creator>
<category><![CDATA[Uncategorized]]></category>
<category><![CDATA[Apps]]></category>
<category><![CDATA[Cloud]]></category>
<category><![CDATA[SaaS]]></category>
<category><![CDATA[SSO]]></category>
<guid isPermaLink="false">https://blogs.technet.microsoft.com/enterprisemobility/?p=51195</guid>
<description><![CDATA[Howdy folks, Today I’ve got a new batch of data to share that I hope many of you will find interesting and useful. Those of you who follow the blog know that Azure AD works well with a ton of applications and that our app gallery features over 2,800 pre-integrated third-party apps. (Third-party meaning apps <p><a class="read-more" href="https://blogs.technet.microsoft.com/enterprisemobility/2017/05/01/azure-ad-and-third-party-apps-its-a-bigger-deal-than-you-might-think/">Continue reading</a></p>]]></description>
<content:encoded><![CDATA[<p>Howdy folks,</p> <p>Today I’ve got a new batch of data to share that I hope many of you will find interesting and useful.</p> <p>Those of you who follow the blog know that Azure AD works well with a ton of applications and that our app gallery features over 2,800 pre-integrated third-party apps. (Third-party meaning apps that were written by someone other than Microsoft).</p> <p>But did you ever wonder which apps people use the most? Or how many people use Azure AD with third-party apps? Well today your questions will be answered.</p> <p>Let’s start with the top-level numbers.</p> <ul> <li>In April, <strong>6.7 million unique active users</strong> signed into a third-party app using Azure AD. Pretty amazing right? And that number is growing 10-12% every month!</li> <li>Those 6.7 million unique active users signed into more than <strong>190k </strong><strong>third-party apps</strong>! And that number grows by 10k to 20k apps per month. (Yes, this numbers blows my mind too!)</li> </ul> <p>Those are some really big numbers. They give you an idea of just how big the use of Azure AD as a cloud IDaaS service is. Even more exciting for us is how fast usage is growing, both in terms of the number of unique active users and unique active applications. Let’s take a look at the growth in these numbers over the last 12 months:</p> <p style="text-align: left"><img width="957" height="786" class="size-full wp-image-51235 aligncenter" alt="unique-users-vs-apps" src="https://msdnshared.blob.core.windows.net/media/2017/04/unique-users-vs-apps.png" /></p> <p style="text-align: left">The number of Azure AD tenants (a good proxy for customers) that have a user using third-party apps is growing at a similar pace:</p> <p style="text-align: center"><img width="954" height="789" class="alignnone wp-image-51245 size-full" alt="unique-users-vs-tenants" src="https://msdnshared.blob.core.windows.net/media/2017/04/unique-users-vs-tenants.png" /></p> <p style="text-align: left">Now, you might also be wondering: what kinds of apps are these people using?</p> <p>As you would expect, customers use Azure AD with Office 365 and Azure more than anything else, but they also use Azure AD with a boatload of third-party SaaS apps, custom line-of-business apps and on-premises apps. Many of our largest customers have all of these types of apps integrated with Azure AD. One of our customers already has 1,329 unique third-party applications their employees access using Azure AD!</p> <p>You’re probably also curious about which third-party SaaS apps Azure AD users use the most. Here’s a chart with the top 15 third-party SaaS apps by usage month for the last nine months:</p> <p style="text-align: center"><img width="1024" height="537" class="size-large wp-image-51225 aligncenter" alt="top-3rd-party-apps" src="https://msdnshared.blob.core.windows.net/media/2017/04/Top-3rd-party-apps-1024x537.png" /></p> <p style="text-align: left">Pretty cool, right? Who would have guessed that there would be a lot of customers using Azure AD with Google Apps, Workday, or ServiceNow? When we started working on Azure AD Premium five years ago, I hoped this would be the case. It’s exciting to see it’s happening!</p> <p>Hopefully this was interesting information, and you found it useful. If we see a lot of interest, I’ll start publishing this data on a regular basis.</p> <p>And thanks to our customers for betting on us and making this happen. We really appreciate your vote of confidence and we wouldn’t be here without the awesome input and feedback you’ve given us.</p> <p>Best Regards,</p> <p>Alex Simons (Twitter: <a href="https://twitter.com/Alex_A_Simons">@Alex_A_Simons</a>)</p> <p>Director of Program Management</p> <p>Microsoft Identity Division</p> ]]></content:encoded>
<wfw:commentRss>https://blogs.technet.microsoft.com/enterprisemobility/2017/05/01/azure-ad-and-third-party-apps-its-a-bigger-deal-than-you-might-think/feed/</wfw:commentRss>
<slash:comments>2</slash:comments>
</item>
<item>
<title>New Enhancements to the Azure AD Pass Through Authentication Preview are live!</title>
<link>https://blogs.technet.microsoft.com/enterprisemobility/2017/04/27/new-enhancements-to-the-azure-ad-pass-through-authentication-preview-are-live/</link>
<comments>https://blogs.technet.microsoft.com/enterprisemobility/2017/04/27/new-enhancements-to-the-azure-ad-pass-through-authentication-preview-are-live/#comments</comments>
<pubDate>Thu, 27 Apr 2017 16:00:00 +0000</pubDate>
<dc:creator><![CDATA[Alex_SimonsMS]]></dc:creator>
<category><![CDATA[Uncategorized]]></category>
<category><![CDATA[Authentication]]></category>
<category><![CDATA[Cloud]]></category>
<category><![CDATA[Deployment]]></category>
<category><![CDATA[Hybrid]]></category>
<category><![CDATA[Hybrid Cloud]]></category>
<category><![CDATA[SSO]]></category>
<guid isPermaLink="false">https://blogs.technet.microsoft.com/enterprisemobility/?p=51155</guid>
<description><![CDATA[Howdy folks, If you’re a follower of this blog you’ll probably recall that we announced pass-through authentication and seamless single sign-on in Azure AD at the end of last year. These features make it easy and fast to deliver world class end user sign-in experiences with Azure AD. Today I’m excited to announce a few <p><a class="read-more" href="https://blogs.technet.microsoft.com/enterprisemobility/2017/04/27/new-enhancements-to-the-azure-ad-pass-through-authentication-preview-are-live/">Continue reading</a></p>]]></description>
<content:encoded><![CDATA[<p>Howdy folks,</p> <p>If you’re a follower of this blog you’ll probably recall that we <a href="https://blogs.technet.microsoft.com/enterprisemobility/2016/12/07/introducing-azuread-pass-through-authentication-and-seamless-single-sign-on/">announced</a> pass-through authentication and seamless single sign-on in Azure AD at the end of last year. These features make it easy and fast to deliver world class end user sign-in experiences with Azure AD. Today I’m excited to announce a few improvements we’ve made that make these capabilities even more secure, easier to use, and easier to administer.</p> <p><strong>Pass-through authentication<br /> </strong></p> <p>Pass-through authentication lets users sign in to your cloud apps while getting rid of the need to store any user passwords in the cloud or deploy new server infrastructure. Some of the key improvements we’ve just turned on include:</p> <ul> <li><strong>Security</strong>: We’ve improved user sign-on security with public key / private key encryption between Azure AD and on-premises agents. That’s in addition to secure HTTPS, which is always used to transfer usernames and passwords.</li> <li><strong>Usability</strong>: We now support using any attribute, configured as Alternate ID in Azure AD Connect, as the username.</li> <li><strong>Easier deployment</strong>: Now you only need to open two ports to deploy pass-through authenticationthe standard ports 80 and 443.</li> </ul> <p><strong>Seamless single sign-on<br /> </strong></p> <p>Seamless single sign-on gives users on your corporate network the ability to access cloud apps from their domain-joined devices without needing to re-enter their passwords. This feature uses Kerberos authentication instead.</p> <p>We simplified the end user sign-on experience by removing the need for your users to enter their usernames when they access cloud apps with tenant-specific URLs (like outlook.office365.com/owa/contoso.com).</p> <p><strong>Customer adoption<br /> </strong></p> <p>We’ve seen our enterprise customers enthusiastically adopting these new capabilities even before they go GA. Deutsche Post DHL, a global organization with almost 500,000 employees, has been using these features in production and has this to say about their experience:</p> <blockquote><p>“We use pass-through authentication and seamless single sign-on to provide 50,000+ users the ability to sign-in to Yammer and 16 other enterprise applications. What I like most about it is its simplicity – it just works! We plan to migrate all ADFS-based applications to this setup soon.” – <strong>Joe Gasowski</strong>, Head of Identity and Access Management, Deutsche Post DHL</p></blockquote> <p><strong>Learn more!<br /> </strong></p> <p>Dive into our detailed documentation for <a href="https://docs.microsoft.com/en-us/azure/active-directory/connect/active-directory-aadconnect-pass-through-authentication">pass-through authentication </a>and <a href="https://docs.microsoft.com/en-us/azure/active-directory/connect/active-directory-aadconnect-sso">seamless single sign-on</a> and let us know what you think by leaving us a comment below or emailing us at <a href="mailto:aadopauthfeedback@microsoft.com">aadopauthfeedback@microsoft.com</a>. We look forward to hearing from you!</p> <p>Best regards,</p> <p>Alex Simons (Twitter: <a href="https://twitter.com/Alex_A_Simons">@Alex_A_Simons</a>)</p> <p>Director of Program Management</p> <p>Microsoft Identity Division</p> ]]></content:encoded>
<wfw:commentRss>https://blogs.technet.microsoft.com/enterprisemobility/2017/04/27/new-enhancements-to-the-azure-ad-pass-through-authentication-preview-are-live/feed/</wfw:commentRss>
<slash:comments>8</slash:comments>
</item>
<item>
<title>Demonstrating our Growth Mindset & Learning from our Customers: We’re reverting the branding logic on Azure AD login pages</title>
<link>https://blogs.technet.microsoft.com/enterprisemobility/2017/04/25/having-a-growth-mindset-learning-from-our-customers-were-reverting-the-branding-logic-on-azure-ad-login-pages/</link>
<comments>https://blogs.technet.microsoft.com/enterprisemobility/2017/04/25/having-a-growth-mindset-learning-from-our-customers-were-reverting-the-branding-logic-on-azure-ad-login-pages/#respond</comments>
<pubDate>Wed, 26 Apr 2017 00:26:09 +0000</pubDate>
<dc:creator><![CDATA[Alex_SimonsMS]]></dc:creator>
<category><![CDATA[Uncategorized]]></category>
<guid isPermaLink="false">https://blogs.technet.microsoft.com/enterprisemobility/?p=51035</guid>
<description><![CDATA[Howdy folks, Back on April 7th we announced changes to the branding logic for Azure AD login pages. In the 18 days since then we’ve learned a ton from you, our customers, including the fact that many of you are not thrilled with these changes. Additionally, we learned that we took many you by surprise <p><a class="read-more" href="https://blogs.technet.microsoft.com/enterprisemobility/2017/04/25/having-a-growth-mindset-learning-from-our-customers-were-reverting-the-branding-logic-on-azure-ad-login-pages/">Continue reading</a></p>]]></description>
<content:encoded><![CDATA[<p>Howdy folks,</p> <p>Back on April 7<sup>th </sup><a href="https://blogs.technet.microsoft.com/enterprisemobility/2017/04/07/improving-the-branding-logic-of-azure-ad-login-pages/">we announced changes to the branding logic for Azure AD login pages</a>. In the 18 days since then we’ve learned a ton from you, our customers, including the fact that many of you are not thrilled with these changes. Additionally, we learned that we took many you by surprise and did not give you enough time to alert and train your employees about the change.</p> <p>So today we get to demonstrate our Growth Mindset! We’ve learned from your feedback and we’ve decided to roll back these changes (they are being reverted as I type). We’re going to revisit the overall here plan and take steps to better socialize and communicate future end-user facing UX changes. Ariel Gordon the PM for these features has the details below.</p> <p>Thanks to all of you who shared your feedback with us about these changes. We learned a lot from you and we’ll use these lessons to improve going forward.</p> <p>Best regards,</p> <p>Alex Simons (Twitter: <a href="https://twitter.com/Alex_A_Simons">@Alex_A_Simons</a>)</p> <p>Director or Program Management</p> <p>Microsoft Identity Division</p> <p>———————–</p> <p>Hi everyone,</p> <p>Earlier this month we changed the logic that controls app vs. company branding on Azure AD login pages. These changes had two key motivations: provide better brand awareness to customers using B2B flows, and reconcile the branding logic between Azure AD and Microsoft accounts, as a prerequisite to merging the two login experiences later this year.</p> <p>And while we tested and validated the new logic with many customers, we underestimated the impact of these changes to the broader community. You’ve also told us that these changes had disrupted your business because we failed to provide advanced notice.</p> <p>We’re heard you loud and clear. We’ve therefore decided to rollback these changes, effective immediately. We’re also making changes to our engineering and communication process to ensure this doesn’t happen again. Specifically, our team is making the following commitments:</p> <ol> <li>Future login UX change that affect business customers will be announced ahead of time</li> <li>Changes will be tested via flighting, and incorporate a Preview period that allows us to gather broader feedback from you</li> <li>For most disruptive design changes, we’ll introduce an opt-in period of at least 30 days, giving everyone a chance to update their support and training materials</li> </ol> <p>Best regards,</p> <p>Ariel Gordon, Principal Program Manager, Identity Division <a href="https://twitter.com/askariel">(@askariel</a>)</p> ]]></content:encoded>
<wfw:commentRss>https://blogs.technet.microsoft.com/enterprisemobility/2017/04/25/having-a-growth-mindset-learning-from-our-customers-were-reverting-the-branding-logic-on-azure-ad-login-pages/feed/</wfw:commentRss>
<slash:comments>0</slash:comments>
</item>
<item>
<title>#AzureAD Mailbag: Azure AD App Proxy, Round 2</title>
<link>https://blogs.technet.microsoft.com/enterprisemobility/2017/04/21/azuread-mailbag-azure-ad-app-proxy-round-2/</link>
<comments>https://blogs.technet.microsoft.com/enterprisemobility/2017/04/21/azuread-mailbag-azure-ad-app-proxy-round-2/#respond</comments>
<pubDate>Fri, 21 Apr 2017 16:00:22 +0000</pubDate>
<dc:creator><![CDATA[Mark Morowczynski [MSFT]]]></dc:creator>
<category><![CDATA[Uncategorized]]></category>
<category><![CDATA[Mailbag]]></category>
<category><![CDATA[SaaS]]></category>
<guid isPermaLink="false">https://blogs.technet.microsoft.com/enterprisemobility/?p=50057</guid>
<description><![CDATA[Hey everyone, Ian Parramore here. Long time no post for us on these mailbags. You might be wondering what happened and why we didnt have a post for almost 2 months. I can tell you who is to blame, Mark. Now that we got that out of the way. Today were going to dive in <p><a class="read-more" href="https://blogs.technet.microsoft.com/enterprisemobility/2017/04/21/azuread-mailbag-azure-ad-app-proxy-round-2/">Continue reading</a></p>]]></description>
<content:encoded><![CDATA[<p>Hey everyone, Ian Parramore here. Long time no post for us on these mailbags. You might be wondering what happened and why we didnt have a post for almost 2 months. I can tell you who is to blame, <a href="https://twitter.com/markmorow">Mark</a>. Now that we got that out of the way. Today were going to dive in a little bit on some of the most common questions weve seen around the Azure AD Application Proxy. For those of you not familiar with this awesome feature, Application Proxy provides single sign-on (SSO) and secure remote access for web applications hosted on-premises. These on-premises web applications can now be integrated with Azure AD, allowing your end users to access your on-premises applications the same way they access O365 and other SaaS apps integrated with Azure AD. You don’t even need to change the network infrastructure or require a VPN to provide this solution for your users. To learn more about Application Proxy and how to get started, see our <a href="https://docs.microsoft.com/en-us/azure/active-directory/active-directory-application-proxy-get-started">documentation</a>. Now lets dig into some of your questions.</p> <p> </p> <p><b>Question 1:</b></p> <p>Im trying to setup Kerberos constrained delegation as discussed in <a href="https://azure.microsoft.com/en-us/documentation/articles/active-directory-application-proxy-sso-using-kcd/">this article</a> but am struggling to understand the PrincipalsAllowedToDelegateToAccount method. Do you have some more insights you can share on this?</p> <p> </p> <p><b>Answer 1:</b></p> <p>PrincipalsAllowedToDelegateToAccount is specifically used where the Connector servers are in a different domain to the web application service account and requires the use of Resource-based Constrained Delegation.</p> <p> </p> <p>If the Connector servers and the web application service account are in the same domain then you can use the Active Directory Users and Computers to configure the delegation settings on each of the Connector machine accounts to allow them to delegate to the target SPN.</p> <p> </p> <p>If the Connector servers and the web application service account are in different domains then we need to use Resource based delegation where the delegation permissions are configured on the target web server / web application service account.</p> <p>This is a relatively new method of Constrained Delegation introduced in Windows Server 2012 which supports cross-domain delegation by allowing the resource (web service) owner to control which machine/service accounts are allowed to delegate to it. There is no UI to assist with this configuration so we need to use PowerShell.</p> <p> </p> <p>Each Azure AD Application Proxy Connector machine account needs to be granted permissions to delegate to the web application service account.</p> <p>When validating your configuration you can check the PrincipalsAllowedToDelegateToAccount setting using the following PowerShell:-</p> <p>Get-ADUser -Identity sharepointserviceaccount -Properties “PrincipalsAllowedToDelegateToAccount”</p> <p> </p> <p>The following output shows 2 machine accounts with permissions to delegate to the sharepointserviceaccount corresponding to our 2 Connector servers:</p> <p> </p> <p><a href="https://msdnshared.blob.core.windows.net/media/2017/03/image812.png"><img width="2702" height="128" title="image" style="padding-top: 0px;padding-left: 0px;padding-right: 0px;border: 0px" alt="image" src="https://msdnshared.blob.core.windows.net/media/2017/03/image_thumb760.png" border="0" /></a></p> <p> </p> <p>If one or more of your Connector servers do not have permissions to delegate to the target web application service account then you will see errors similar to the following:</p> <p><a href="https://msdnshared.blob.core.windows.net/media/2017/03/image813.png"><img width="1147" height="1056" title="image" style="padding-top: 0px;padding-left: 0px;padding-right: 0px;border: 0px" alt="image" src="https://msdnshared.blob.core.windows.net/media/2017/03/image_thumb761.png" border="0" /></a></p> <p> </p> <p>In the article you’ll see the following sample PowerShell commands:</p> <p>$connector= Get-ADComputer -Identity <span style="background-color: #ffff00">connectormachineaccount</span> -server dc.connectordomain.com</p> <p>Set-ADUser -Identity sharepointserviceaccount -PrincipalsAllowedToDelegateToAccount $connector</p> <p> </p> <p>This is fine but will only set one Connector with delegation rights to the sharepointserviceaccount.</p> <p>If you only specify one of two Azure AD App Proxy connectors, access to the app will only succeed if traffic is routing through that connector.</p> <p> </p> <p>Where you have more than one Connector the first command would ideally look something like this:</p> <p>$connectors = Get-ADComputer <span style="background-color: #ffff00">-filter {name – like “*<i>appproxyname</i>*”}</span> -server dc.connectordomain.com</p> <p> </p> <p>This command assumes the connectors have a similar name and that the wildcards will return more than one computer account. For example, in my environment I have two connectors, MSFTPM-AAP1 and MSFTPM-AAP2. So I would run:</p> <p>$connectors = Get-ADComputer <span style="background-color: #ffff00">-filter {name – like “*<i>aap</i>*”}</span> -server dc.connectordomain.com</p> <p> </p> <p>This returns both servers and sets them in the $connectors variable. I can then run the second command to set the attribute appropriately on my resource server:</p> <p>Set-ADUser -Identity sharepointserviceaccount -PrincipalsAllowedToDelegateToAccount $connectors</p> <p> </p> <p>We can then use the following PowerShell to re-validate the setting:</p> <p>Get-ADUser -Identity sharepointserviceaccount -Properties “PrincipalsAllowedToDelegateToAccount”</p> <p>Note the above examples are using Set-AdUser/Get-AdUser when getting/setting the PrincipalsAllowedToDelegateToAccount attribute. This is because the web application is running under a service account.</p> <p> </p> <p>If the web application was running under a machine context we would need to use Set-AdComputer/Get-AdComputer. This may be relevant in a test environment with only a single web server but in a load balanced web server deployment we would expect the services to be running under a common service account.</p> <p> </p> <p>When populating the $connectors variable we will always use Get-AdComputer as we are specifically interested in the Connector machine accounts.</p> <p> </p> <p>For further information about Kerberos Constrained Delegation and Resource-based Constrained Delegation please see the following whitepaper <a href="http://aka.ms/kcdpaper">http://aka.ms/kcdpaper</a></p> <p> </p> <p><b>Question 2:</b></p> <p>Should I create a dedicated account to register the connector with the Azure AD Application Proxy?</p> <p> </p> <p><b>Answer 2:</b></p> <p>There’s no reason to. Any global admin account will work fine. The credentials entered during installation are not used after the registration process. Instead, a certificate is issued to the connector which will be used for authentication from that point forward. You can see this certificate in the personal store of the computer account:</p> <p><a href="https://msdnshared.blob.core.windows.net/media/2017/03/image814.png"><img width="1392" height="154" title="image" style="padding-top: 0px;padding-left: 0px;padding-right: 0px;border: 0px" alt="image" src="https://msdnshared.blob.core.windows.net/media/2017/03/image_thumb762.png" border="0" /></a></p> <p><b></b></p> <p><b>Question 3: </b></p> <p>How can I monitor the performance of the Azure AD Application Proxy connector?</p> <p><b></b></p> <p><b>Answer 3: </b></p> <p>There are Performance Monitor counters that are installed along with the connector. To view them do the following:</p> <p>1. Start -> Type “Perfmon” -> Enter</p> <p>2. Select Performance Monitor and click the green “+” icon:</p> <p><a href="https://msdnshared.blob.core.windows.net/media/2017/03/image815.png"><img width="1202" height="244" title="image" style="padding-top: 0px;padding-left: 0px;padding-right: 0px;border: 0px" alt="image" src="https://msdnshared.blob.core.windows.net/media/2017/03/image_thumb763.png" border="0" /></a></p> <p>3. Select and add the Microsoft AAD App Proxy Connector counters:</p> <p><a href="https://msdnshared.blob.core.windows.net/media/2017/03/image816.png"><img width="1281" height="882" title="image" style="padding-top: 0px;padding-left: 0px;padding-right: 0px;border: 0px" alt="image" src="https://msdnshared.blob.core.windows.net/media/2017/03/image_thumb764.png" border="0" /></a></p> <p> </p> <p><b>Question 4: </b></p> <p>Can only IIS-based apps be published? What about web apps running on non-Windows web servers? Does the connector have to be installed on a server with IIS installed?</p> <p> </p> <p><b>Answer 4: </b></p> <p>Woah, this is a 3 for 1!</p> <p> No there is no IIS requirement for apps that are published.</p> <p> Yes you can publish web apps running on servers other than Windows Server. Having said that, you may or may not be able to use pre-authentication with a non-Windows Server depending on if the web server supports Negotiate (Kerberos authentication).</p> <p>The server the connector is installed on does not have to have IIS installed.</p> <p> </p> <p><b>Question 5: </b></p> <p>Does the Azure AD App Proxy connector have to be on the same subnet as the resource?</p> <p> </p> <p><b>Answer 5:</b></p> <p>There is no requirement for the connector to be on the same subnet. It does however need name resolution to the resource as well as the necessary network connectivity (routing to the resource, ports open on the resource, etc.). If you want a more detailed discussion on connector location, please see <a href="https://blogs.technet.microsoft.com/applicationproxyblog/2016/08/16/network-topology-considerations-when-using-azure-ad-application-proxy/">our blog</a>.</p> <p> </p> <p><b>Question 6: </b></p> <p>Ive published the App Proxy application, and Im able to log in, but the application is not displaying as expected. Why isnt it working?</p> <p> </p> <p><b>Answer 6: </b>If youre able to login and the application isnt displaying properly, there are two common possible causes.</p> <p>Please verify that all the pages referenced by the application are in the path you published. For example, we see many cases where the published path is contoso/myapp/register/, but the web page has references to resource under different paths e.g. conotoso/myapp/style.css. Because the path containing the style page has not been published, the application is unable to find it when loading.</p> <p>One way to check if this may be the problem is to look at a Fiddler trace or use the Network tab in the F12 Developer tools in Internet Explorer or Edge browsers to get an overview of the request/response pairs and associated HTTP status codes as you load a web page. You can use the output to identify if you are getting any 404 errors, and if so, whether the resources with the 404 errors are in the published path.</p> <p> </p> <p>In the above example, publishing contoso/myapp/ instead of contoso/myapp/register/ would solve the problem.</p> <p> </p> <p>Also, make sure to check if your application uses hard-coded internal links to either other applications or unpublished sites or, for its own internal namespace.</p> <p> </p> <p>This can be problematic where the internal and external FQDNs in use are different and the web server generates links based on its internal name. Our general recommendation is to use the same internal and external FQDN and protocol (validate that both are the same https is preferred, http is allowed) where possible to reduce the chance of any problems.</p> <p> </p> <p>For sites that contain links to other internal sites or applications, you would need to identify these and then ensure the relevant applications and sites are also published and available externally through Application Proxy. If these links are fully qualified, please use the <a href="https://docs.microsoft.com/en-us/azure/active-directory/active-directory-application-proxy-custom-domains">custom domains feature</a> to make sure these links will work. If not, look for an upcoming announcement in the coming months on some new Application Proxy capabilities in this area.! Please check the <a href="https://blogs.technet.microsoft.com/enterprisemobility/">Enterprise Mobilty and Security blog</a> for announcements.</p> <p> </p> <p>You can use a tool such as Fiddler to review the traffic and identify request failures with a 404 status. You can also use the Network tab in the F12 Developer tools in Internet Explorer or Edge browsers to get an overview of the request/response pairs and associated HTTP status codes as you load a web page.</p> <p> </p> <p>Thanks for reading.</p> <p> </p> <p>For any questions you can reach us at<br /> <a>AskAzureADBlog@microsoft.com</a>, the <a href="https://social.msdn.microsoft.com/Forums/azure/en-US/home?forum=WindowsAzureAD">Microsoft Forums</a> and on Twitter <a href="https://twitter.com/AzureAD">@AzureAD</a>, <a href="https://twitter.com/markmorow">@MarkMorow</a> and <a href="https://twitter.com/Alex_A_Simons">@Alex_A_Simons</a></p> <p> </p> <p>-Ian Parramore, Harshini Jayaram, and Mark Morowczynski</p> ]]></content:encoded>
<wfw:commentRss>https://blogs.technet.microsoft.com/enterprisemobility/2017/04/21/azuread-mailbag-azure-ad-app-proxy-round-2/feed/</wfw:commentRss>
<slash:comments>0</slash:comments>
</item>
<item>
<title>Extend cloud identity and access management to your customer and partner relationships</title>
<link>https://blogs.technet.microsoft.com/enterprisemobility/2017/04/12/extend-cloud-identity-and-access-management-to-your-customer-and-partner-relationships-2/</link>
<pubDate>Wed, 12 Apr 2017 16:00:59 +0000</pubDate>
<dc:creator><![CDATA[Andrew Conway]]></dc:creator>
<category><![CDATA[Uncategorized]]></category>
<guid isPermaLink="false">https://blogs.technet.microsoft.com/enterprisemobility/?p=50525</guid>
<description><![CDATA[Organizations are transforming how they operate in a digital world. This means seizing new opportunities quickly, reinventing business processes, and delivering greater value to customers.]]></description>
<content:encoded><![CDATA[<p>Organizations are transforming how they operate in a digital world. This means seizing new opportunities quickly, reinventing business processes, and delivering greater value to customers. More important than ever are the strong and trusted relationships with the whole ecosystem in which an organization operates. This includes business partners, contractors, and of course customers. While business-to-business (B2B) and business-to-consumer (B2C) interactions may be different, sustaining both requires information security combined with intuitive user experiences.</p> <p>As your network of B2B and B2C connections grows online, securing them across on-premises, cloud, and hybrid scenarios becomes more of a challenge. A secure identity platform is critical to support this growth and to enable digital business securely. With this goal in mind, today we announce two important extensions in the capability of Microsoft Azure Active Directory.</p> <h2>Azure Active Directory B2B collaboration now generally available</h2> <p>Businesses are increasingly dispersed, mobile, and collaborative, relying on wide range of vendors, partners, and contractors to stay nimble and capitalize on changing markets. Azure Active Directory (AD) is the foundation of our identity-driven approach to security and extends beyond your own employees to secure the identities of external collaboratorspartners, contractors, and vendors. Our goal is to make it easy and secure to collaborate with the employees of any organization. Azure AD B2B collaboration is generally available today and is part of Microsoft Enterprise Mobility + Security (EMS).</p> <p>B2B collaboration provides external user accounts with secure access to documents, resources, and applicationswhile maintaining control over internal data. Theres no need to add external users to your directory, sync them, or manage their lifecycle; IT can invite collaborators to use any email addressOffice 365, on-premises Microsoft Exchange, or even a personal address (Outlook.com, Gmail, Yahoo!, etc.)and even set up conditional access policies, including multi-factor authentication. Your developers can use the Azure AD B2B APIs to write applications that bring together different organizations in a secure wayand deliver a seamless and intuitive end user experience.</p> <p>Millions of users from thousands of businesses have already been using Azure AD B2B collaboration capabilities available through public preview.</p> <blockquote><p>As early adopters of Azure AD B2B collaboration, we used this service to provide a simple and secure way for partners, large and small, to use their own credentials to access Kodak Alaris systems. The latest enhancements are interesting, and we plan to use the invitation manager API in our Partner Relationship Management portal for a more customized guest onboarding/provisioning experience. The Azure AD team has been an incredible partner in our re-creation of a more agile and cost-effective hybrid cloud IT infrastructure. Steve Braunschweiger, Chief Enterprise IT Architect Kodak Alaris</p></blockquote> <h3>Heres how you can get started with Azure Active Directory B2B collaboration:</h3> <ul> <li>Watch this <a href="https://aka.ms/b2bmechanics">Mechanics Video</a> to see the benefits of cloud-based B2B identity and access management</li> <li>Read more details from the <a href="https://aka.ms/b2bcollabblog">Azure AD B2B team blog</a></li> <li>Get started with <a href="https://docs.microsoft.com/en-us/azure/active-directory/active-directory-b2b-admin-add-users">Azure Active Directory B2B collaboration</a></li> </ul> <h2>Azure Active Directory B2C now available in Europe</h2> <p>Another important audience within most enterprise ecosystems are the customers who trust your business with their own sensitive personal and financial information. Azure Active Directory B2C enables organizations to securely connect with their customers at scale. Today, Azure AD B2C is generally available in Europe. Azure AD B2C is a highly available, global identity and access management service for your consumer-facing applications. It scales to hundreds of millions of protected identities, integrates easily with nearly any platform on any device, and includes optional multi-factor authentication for additional protection. Your consumers will be able to use existing social media accounts or create new credentials for single sign-on access to your applications through a fully customizable experience.</p> <p>Organizations now have the option to use Azure AD B2C tenants that operate and store data only in European datacenters. For all other regions, Azure AD B2C is available through the North American or European datacenters.</p> <h3>Heres how you can get started with Azure Active Directory B2C:</h3> <ul> <li>Watch <a href="https://youtu.be/ASC7CG4XMq8">this video</a> to see the benefits of cloud-based consumer identity and access management</li> <li>Read more details from the <a href="https://aka.ms/azureadb2ceu">Azure AD B2C team blog</a></li> <li>Get started with <a href="http://azure.microsoft.com/trial/get-started-aad-b2c/">Azure AD B2C</a> in your consumer app</li> </ul> <p>As companies adopt a cloud-first position to take advantage of increased agility and faster innovation, like B2B and B2C, we recognize that cloud-first doesnt mean cloud-only. <a href="https://blogs.technet.microsoft.com/hybridcloud/2017/04/12/consistency-is-the-cure-for-hybrid-cloud-complexity/">As we announced today</a>, we make it easy for customers to maximize their existing investments to adopt cloud. A hybrid approach is a strategic plan for businesses financially, for security, and for their identities and applications.</p> ]]></content:encoded>
</item>
<item>
<title>Azure AD B2B Collaboration is Generally Available!</title>
<link>https://blogs.technet.microsoft.com/enterprisemobility/2017/04/12/azure-ad-b2b-collaboration-is-generally-available/</link>
<pubDate>Wed, 12 Apr 2017 16:00:57 +0000</pubDate>
<dc:creator><![CDATA[Alex_SimonsMS]]></dc:creator>
<category><![CDATA[Uncategorized]]></category>
<category><![CDATA[B2B]]></category>
<category><![CDATA[Cloud]]></category>
<category><![CDATA[Conditional Access]]></category>
<category><![CDATA[SaaS]]></category>
<guid isPermaLink="false">https://blogs.technet.microsoft.com/enterprisemobility/?p=50485</guid>
<description><![CDATA[Howdy folks, This is a blog post I’ve been as eager to publish as I suspect you’ve been eager to read it. I’m excited to let you know that Azure AD business-to-business (B2B) collaboration is generally available worldwide! Azure AD B2B collaboration capabilities enable any organization using Azure AD to work safely and securely with <p><a class="read-more" href="https://blogs.technet.microsoft.com/enterprisemobility/2017/04/12/azure-ad-b2b-collaboration-is-generally-available/">Continue reading</a></p>]]></description>
<content:encoded><![CDATA[<p><span style="color: black;font-family: Segoe UI;font-size: 11pt">Howdy folks,<br /> </span></p> <p><span style="color: black;font-family: Segoe UI;font-size: 11pt">This is a blog post I’ve been as eager to publish as I suspect you’ve been eager to read it. I’m excited to let you know that Azure AD business-to-business (B2B) collaboration is generally available worldwide!<br /> </span></p> <p><span style="color: black;font-family: Segoe UI;font-size: 11pt">Azure AD B2B collaboration capabilities enable any organization using Azure AD to work safely and securely with users from any other organization, small or large, with or without Azure AD, & with or without an IT organization.<br /> </span></p> <p><span style="color: black;font-family: Segoe UI;font-size: 11pt">Organizations using Azure AD can provide their B2B partners access to documents, resources, and applications while maintaining control over corporate data. Developers can use the Azure AD B2B APIs to write applications that bring two organizations together in a secure way that is also seamless and intuitive for end users to navigate.<br /> </span></p> <p><span style="color: black;font-family: Segoe UI;font-size: 11pt">Customer demand for these capabilities is sky high! Already during the public preview, customers have invited 2.6M guest users using these new capabilities. <img class="aligncenter" alt="" src="https://msdnshared.blob.core.windows.net/media/2017/04/041117_0246_AzureADB2BC1.png" /><br /> </span></p> <p style="text-align: justify"><span style="color: black;font-family: Segoe UI;font-size: 11pt">And more than 20% of Azure AD Tenants with >10 users are now using Azure AD B2B!:<br /> </span></p> <p style="text-align: justify"><span style="color: black;font-family: Segoe UI;font-size: 11pt"><br /> <img class="aligncenter" alt="" src="https://msdnshared.blob.core.windows.net/media/2017/04/041117_0246_AzureADB2BC2.png" /><br /> </span></p> <p><span style="color: black;font-family: Segoe UI;font-size: 11pt">We have spent thousands and thousands of hours with these customers diving into how we can best serve their needs with Azure AD B2B.<br /> </span></p> <p><span style="color: black;font-family: Segoe UI;font-size: 11pt">I’d like to thank all of you who spent time with us providing feedback and suggestions. We would not have reached this point without your partnership.<br /> </span></p> <p><span style="color: black;font-family: Segoe UI;font-size: 11pt">Now you can dive in and use Azure AD B2B in your organization! Here are a few of highlights of the things you can do now:<br /> </span></p> <p><span style="color: black;font-family: Segoe UI;font-size: 11pt"><strong>Easily add B2B users to your organization:<br /> </strong></span></p> <p><img class="aligncenter" alt="" src="https://msdnshared.blob.core.windows.net/media/2017/04/041117_0246_AzureADB2BC3.png" /><span style="color: black;font-family: Segoe UI;font-size: 11pt"><br /> </span></p> <p><span style="color: black;font-family: Segoe UI;font-size: 11pt"><strong>Enable your collaborators to bring their own identity to work with you:<br /> </strong></span></p> <p><img class="aligncenter" alt="" src="https://msdnshared.blob.core.windows.net/media/2017/04/041117_0246_AzureADB2BC4.png" /><span style="color: black;font-family: Segoe UI;font-size: 11pt"><br /> </span></p> <p><span style="color: black;font-family: Segoe UI;font-size: 11pt"><strong>Delegate to application and group owners so they can add B2B users directly to any of the thousands of apps that work with Azure AD:<br /> </strong></span></p> <p><img class="aligncenter" alt="" src="https://msdnshared.blob.core.windows.net/media/2017/04/041117_0246_AzureADB2BC5.png" /><span style="color: black;font-family: Segoe UI;font-size: 11pt"><br /> </span></p> <p><img class="aligncenter" alt="" src="https://msdnshared.blob.core.windows.net/media/2017/04/041117_0246_AzureADB2BC6.png" /><span style="color: black;font-family: Segoe UI;font-size: 11pt"><br /> </span></p> <p><span style="color: black;font-family: Segoe UI;font-size: 11pt"><strong>Have consistent authorization policies protecting your corporate content across your employees and partners:<br /> </strong></span></p> <p><img class="aligncenter" alt="" src="https://msdnshared.blob.core.windows.net/media/2017/04/041117_0246_AzureADB2BC7.png" /><span style="color: black;font-family: Segoe UI;font-size: 11pt"><br /> </span></p> <p><span style="color: black;font-family: Segoe UI;font-size: 11pt"><strong>Use our APIs and sample code to easily build applications to onboard your external partners in ways customized to your organization’s needs:<br /> </strong></span></p> <p><img class="aligncenter" alt="" src="https://msdnshared.blob.core.windows.net/media/2017/04/041117_0246_AzureADB2BC8.png" /><span style="color: black;font-family: Segoe UI;font-size: 11pt"><br /> </span></p> <p><span style="color: black;font-family: Segoe UI;font-size: 11pt">With Azure AD B2B collaboration, you can get the full power of Azure AD to protect your partner relationships in a way that end users find easy and intuitive.<br /> </span></p> <p><span style="color: #0070c0;font-family: Segoe UI;font-size: 11pt"><strong>Work with any user from any partner<br /> </strong></span></p> <ul> <li><span style="color: black;font-family: Segoe UI;font-size: 11pt">Partners use their own credentials<br /> </span></li> <li><span style="color: black;font-family: Segoe UI;font-size: 11pt">No requirement for partners to use Azure AD<br /> </span></li> <li><span style="color: black;font-family: Segoe UI;font-size: 11pt">No external directories or complex set-up required<br /> </span></li> </ul> <p><span style="color: #0070c0;font-family: Segoe UI;font-size: 11pt"><strong>Simple and secure collaboration<br /> </strong></span></p> <ul> <li><span style="color: black;font-family: Segoe UI;font-size: 11pt">Provide access to any corporate application or resource<br /> </span></li> <li><span style="color: black;font-family: Segoe UI;font-size: 11pt">Seamless user experiences<br /> </span></li> <li><span style="color: black;font-family: Segoe UI;font-size: 11pt">Enterprise-grade security for applications and data<br /> </span></li> </ul> <p><span style="color: #0070c0;font-family: Segoe UI;font-size: 11pt"><strong>No management overhead<br /> </strong></span></p> <ul> <li><span style="color: black;font-family: Segoe UI;font-size: 11pt">No external account or password management<br /> </span></li> <li><span style="color: black;font-family: Segoe UI;font-size: 11pt">No sync or manual account lifecycle management<br /> </span></li> <li><span style="color: black;font-family: Segoe UI;font-size: 11pt">No external administrative overhead<br /> </span></li> </ul> <p><span style="color: black;font-family: Segoe UI;font-size: 11pt">Get started today on <a href="https://portal.azure.com/">the Azure portal</a>.<br /> </span></p> <p><span style="color: #1f1f1f;font-family: Segoe UI;font-size: 21pt">Learn More<br /> </span></p> <p><span style="color: #41424e;font-family: Segoe UI;font-size: 11pt">There’s far more detail about the new Azure AD B2B Collaboration features in our <a href="https://docs.microsoft.com/en-us/azure/active-directory/active-directory-b2b-what-is-azure-ad-b2b"><span style="color: #0078d7;text-decoration: underline">updated documentation</span></a>, so take a look and let us know if you have any questions! <span style="color: black">And if you haven’t seen it yet, check out (below) the latest short video about Azure AD B2B<span style="color: #41424e"> we put together, too.<br /> </span></span></span></p> <p><iframe width="560" height="315" src="https://www.youtube.com/embed/AhwrweCBdsc" frameborder="0" allowfullscreen></iframe> </p> <p><span style="color: #41424e;font-family: Segoe UI;font-size: 11pt">As always, connect with us for any feedback, discussions and suggestions through our <a target="_blank" href="https://techcommunity.microsoft.com/t5/Azure-Active-Directory-B2B/bd-p/AzureAD_B2b"><span style="color: #0078d7;text-decoration: underline"><strong>Microsoft Tech Community</strong></span></a>. You know we’re listening!<br /> </span></p> <p><span style="color: #41424e;font-family: Segoe UI;font-size: 11pt">Best Regards,<br /> Alex Simons (@Twitter:<a href="https://twitter.com/Alex_A_Simons"><span style="color: #0078d7;text-decoration: underline"><strong>@Alex_A_Simons</strong></span></a>)<br /> Director of Program Management<br /> Microsoft Identity Division</span></p> ]]></content:encoded>
</item>
<item>
<title>End of support for DirSync and Azure AD Sync is rapidly approaching. Time to upgrade to Azure AD Connect!</title>
<link>https://blogs.technet.microsoft.com/enterprisemobility/2017/04/10/end-of-support-for-dirsync-and-azure-ad-sync-is-rapidly-approaching-time-to-upgrade-to-aad-connect/</link>
<comments>https://blogs.technet.microsoft.com/enterprisemobility/2017/04/10/end-of-support-for-dirsync-and-azure-ad-sync-is-rapidly-approaching-time-to-upgrade-to-aad-connect/#comments</comments>
<pubDate>Mon, 10 Apr 2017 16:00:41 +0000</pubDate>
<dc:creator><![CDATA[Alex_SimonsMS]]></dc:creator>
<category><![CDATA[Uncategorized]]></category>
<category><![CDATA[Hybrid]]></category>
<guid isPermaLink="false">https://blogs.technet.microsoft.com/enterprisemobility/?p=50106</guid>
<description><![CDATA[Howdy folks, On April 13 of last year, we announced the deprecation of “Windows Azure Active Directory Sync (DirSync)” and “Azure Active Directory Sync (Azure AD Sync)” and that it was time to start planning to upgrade to Azure AD Connect. We also announced at the time that DirSync & Azure AD Sync will reach <p><a class="read-more" href="https://blogs.technet.microsoft.com/enterprisemobility/2017/04/10/end-of-support-for-dirsync-and-azure-ad-sync-is-rapidly-approaching-time-to-upgrade-to-aad-connect/">Continue reading</a></p>]]></description>
<content:encoded><![CDATA[<p><span style="font-family: Segoe UI">Howdy folks,<br /> </span></p> <p><span style="font-family: Segoe UI">On April 13 of last year, we announced the deprecation of “Windows Azure Active Directory Sync (DirSync)” and “Azure Active Directory Sync (Azure AD Sync)” and that it was time to start planning to upgrade to Azure AD Connect. We also announced at the time that DirSync & Azure AD Sync will reach <strong>end of Support on April 13, 2017</strong>. Since then, 35,000 customers have successfully upgraded from these deprecated tools to Azure AD Connect that’s what we like to see!<br /> </span></p> <p><span style="font-family: Segoe UI">Today, we are confirming that DirSync and Azure AD Sync will reach end of Support as planned on April 13, 2017.<br /> </span></p> <p><span style="font-family: Segoe UI">I would <span style="text-decoration: underline"><strong><em>highly</em></strong></span> recommend that if you haven’t upgraded to Azure AD Connect, you should do so VERY soon to avoid service disruptions. Azure AD will stop accepting connections from DirSync and Azure AD Sync after <strong>December 31, 2017</strong>.<br /> </span></p> <p><span style="font-family: Segoe UI">For more information about the DirSync and AAD Sync upgrade, please see the <a href="https://docs.microsoft.com/en-us/azure/active-directory/connect/active-directory-aadconnect-dirsync-deprecated">DirSync and Azure AD Sync deprecation documentation</a>.<br /> </span></p> <p><span style="font-family: Segoe UI">If you have any questions or feedback about this change, we’re all ears. Please leave us a comment below or reach on Twitter using the #AzureAD hashtag.<br /> </span></p> <p><span style="font-family: Segoe UI">Best regards,<br /> </span></p> <p><span style="font-family: Segoe UI">Alex Simons (Twitter: <a href="https://twitter.com/Alex_A_Simons">@Alex_A_Simons</a>)<br /> </span></p> <p><span style="font-family: Segoe UI">Director of Program Management<br /> </span></p> <p><span style="font-family: Segoe UI">Microsoft Identity Division<br /> </span></p> ]]></content:encoded>
<wfw:commentRss>https://blogs.technet.microsoft.com/enterprisemobility/2017/04/10/end-of-support-for-dirsync-and-azure-ad-sync-is-rapidly-approaching-time-to-upgrade-to-aad-connect/feed/</wfw:commentRss>
<slash:comments>1</slash:comments>
</item>
<item>
<title>We’ve added 21 new 3rd party apps to the Azure AD App Gallery!</title>
<link>https://blogs.technet.microsoft.com/enterprisemobility/2017/03/29/weve-added-21-new-3rd-party-apps-to-the-azure-ad-app-gallery/</link>
<pubDate>Wed, 29 Mar 2017 14:38:10 +0000</pubDate>
<dc:creator><![CDATA[Alex_SimonsMS]]></dc:creator>
<category><![CDATA[Uncategorized]]></category>
<category><![CDATA[Apps]]></category>
<category><![CDATA[Modern Apps]]></category>
<category><![CDATA[SaaS]]></category>
<category><![CDATA[SSO]]></category>
<guid isPermaLink="false">https://blogs.technet.microsoft.com/enterprisemobility/?p=49896</guid>
<description><![CDATA[Howdy folks, Many of you probably associate Azure AD with Office 365 & Microsoft Azure. That makes a lot of sense. Those are the cloud services our customers use the most with Azure AD. But you might be surprised to learn that customers use Azure AD with a TON of applications built by 3rd party <p><a class="read-more" href="https://blogs.technet.microsoft.com/enterprisemobility/2017/03/29/weve-added-21-new-3rd-party-apps-to-the-azure-ad-app-gallery/">Continue reading</a></p>]]></description>
<content:encoded><![CDATA[<p>Howdy folks,</p> <p>Many of you probably associate Azure AD with Office 365 & Microsoft Azure. That makes a lot of sense. Those are the cloud services our customers use the most with Azure AD.</p> <p>But you might be surprised to learn that customers use Azure AD with a TON of applications built by 3<sup>rd</sup> party developers. This is one of our most popular and fastest growing capabilities. This month alone our customers used Azure AD with more than 170,000 3<sup>rd</sup> party applications!</p> <p>Given how popular this capability is, I’m excited to announce that working with our ISV partners, we’ve just added 22 new 3<sup>rd</sup> party apps to the Azure AD app gallery! Let’s take a quick tour of the apps we added.</p> <p style="text-align: center"><img alt="" src="https://msdnshared.blob.core.windows.net/media/2017/03/032917_1431_Wevejustadd3.png" /></p> <p><strong>HR apps</strong>:</p> <p style="margin-left: 36pt"><a href="https://azuremarketplace.microsoft.com/en-us/marketplace/apps/aad.firmplay?tab=Overview"><span style="color: #0563c1;text-decoration: underline"><strong>FirmPlay: Employee Advocacy for Recruiting</strong></span></a>manages your employee Advocacy program with powerful software that lets you curate, collect, create, and share employee generated content with prospective talent. <a href="https://www.firmplay.com/"><span style="color: #0563c1;text-decoration: underline">FirmPlay</span></a> app allows you to easily collect employee insights and turn them into engaging, shareable recruiting content the kind that resonates with top talent.</p> <p style="margin-left: 36pt"><a href="https://azuremarketplace.microsoft.com/en-us/marketplace/apps/aad.patheercoach?tab=Overview"><span style="color: #0563c1;text-decoration: underline"><strong>Patheer Coach</strong></span></a><strong> </strong>provides the tools for employees to continually grow and develop skills, it also empowers leaders to drive performance. The <a href="https://patheer.com/"><span style="color: #0563c1;text-decoration: underline">Patheer Coach</span></a> app allows leaders to capture and analyze their talent landscape, such as identifying high-performing employees, forecasting talent and skill capability gaps to build a strong talent pipeline.</p> <p style="margin-left: 36pt"><a href="https://azuremarketplace.microsoft.com/en-us/marketplace/apps/aad.pingboard?tab=Overview"><span style="color: #0563c1;text-decoration: underline"><strong>Pingboard</strong></span></a><span style="color: black">is the place for everything you need to know about the people you work with. You can quickly build your org chart and share it with your team. Everyone will always know who’s who and who does what. <a href="https://pingboard.com/?utm_source=MSN_SE_NW_US_BRNDED&utm_medium=cpc&utm_campaign=search__-__nw__-__branded&utm_term=ping_board_exm&c1=MSN_SE_NW&source=US_BRNDED&cr2=search__-__nw__-__branded&kw=ping_board_exm&cr5=76347355658954&cr7=c"><span style="color: #0563c1;text-decoration: underline">Pingboard</span></a> is the employee directory, org chart and out of office calendar.<br /> </span></p> <p style="margin-left: 36pt"><a href="https://azuremarketplace.microsoft.com/en-us/marketplace/apps/aad.planmyleave?tab=Overview"><span style="color: #0563c1;text-decoration: underline"><strong>PlanMyLeave</strong></span></a><span style="color: black"> is an HRIS and online leave management system designed to scale easily from small to medium businesses to large enterprises. <a href="https://www.bing.com/search?q=PlanMyLeave&qs=n&form=QBLH&pc=BBMU&sp=-1&pq=planmyleave&sc=5-11&sk=&cvid=7448230F89044762BC90C3FD9F336CB0"><span style="color: #0563c1;text-decoration: underline">PlanMyLeave</span></a> helps you customize leave types and set up complex leave policies for any country.</span><span style="font-size: 10pt"><br /> </span></p> <p><span style="color: black"><strong>Business Management apps<span style="color: #505050">:<br /> </span></strong></span></p> <p style="margin-left: 36pt"><a href="https://azuremarketplace.microsoft.com/en-us/marketplace/apps/aad.cflow?tab=Overview"><span style="color: #0563c1;text-decoration: underline">Cavintek’s Cflow</span></a><span style="color: black"><strong> </strong>is a cloud-basedbusiness process management app that helps streamline and automate business process in SMBs. <a href="http://www.cavintek.com/"><span style="color: #0563c1;text-decoration: underline">Cflow</span></a> moves organization from emails and spreadsheets to using business apps and secures all communication.<br /> </span></p> <p style="margin-left: 36pt"><a href="https://azuremarketplace.microsoft.com/en-us/marketplace/apps/aad.contractrebates?tab=Overview"><span style="color: #0563c1;text-decoration: underline"><strong>Contract Rebates</strong></span></a><span style="color: black"><strong> by Xen Computers Limited </strong>managescontractual pricing agreements between indirect customers and wholesalers, providing validataion and payment of rebates together with financial control and reporting capabilities.<br /> </span></p> <p style="margin-left: 36pt"><a href="https://azuremarketplace.microsoft.com/en-us/marketplace/apps/aad.lecorpio?tab=Overview"><span style="color: #0563c1;text-decoration: underline"><strong>Lecorpio</strong></span></a><span style="color: black"><strong> Intellectual Property Management </strong>provides a secure, web-based portal that centrally manages the entire IP lifecycle from the submission of disclosures all the way through to the payment of annuities, and ongoing opposition filings, enforcement actions, arbitration, litigation, contracts, license agreements and more. <a href="http://www.lecorpio.com/company/"><span style="color: #0563c1;text-decoration: underline">Lecorpio</span></a> is trusted by the world’s most innovative companies.<br /> </span></p> <p><strong>Collaboration apps</strong>:<span style="color: #505050;font-family: Segoe UI"><br /> </span></p> <p style="margin-left: 36pt"><a href="https://azuremarketplace.microsoft.com/en-us/marketplace/apps/aad.fuze?tab=Overview"><span style="color: #0563c1;text-decoration: underline"><strong>Fuze</strong></span></a><span style="color: #505050">offers unified communication service that enables efficient collaboration at work. <a href="https://www.fuze.com/fuze-reimagined"><span style="color: #0563c1;text-decoration: underline">Fuze</span></a> combines voice, video, messaging, and content sharing in a single app with great user experience.<br /> </span></p> <p style="margin-left: 36pt"><a href="https://azuremarketplace.microsoft.com/en-us/marketplace/apps/aad.maxxpoint?tab=Overview"><span style="color: #0563c1;text-decoration: underline"><strong>MaxxPoint</strong></span></a><span style="color: #505050"> brings together your unified communication apps from West UC with a secure and easy-to-use interface. MaxxPoint app gives you the visibility across your enterprise and the tools to manage your UC services.<br /> </span></p> <p style="margin-left: 36pt"><a href="https://azuremarketplace.microsoft.com/en-us/marketplace/apps/aad.teamwork?tab=Overview"><span style="color: #0563c1;text-decoration: underline"><strong>Teamwork Projects</strong></span></a><span style="color: #505050">is acollaborative project managementapp designed to streamline processes and connect your team. The <a href="https://www.teamwork.com/project-management-software"><span style="color: #0563c1;text-decoration: underline"><strong>Teamwork Projects app</strong></span></a> keeps all your team’s tasks in one place, so your team can collaborate in real time for great results.<br /> </span></p> <p style="margin-left: 36pt"><a href="https://azuremarketplace.microsoft.com/en-us/marketplace/apps/aad.worksmobile?tab=Overview"><span style="color: #0563c1;text-decoration: underline"><strong>Works Mobile Chat Service</strong></span></a><span style="color: #505050">offers business messenger service for users to talk with their contact list freely. Users can easily send photos and videos while talking and can also share contact and location information. <a href="https://line.worksmobile.com/jp/home/talk"><span style="color: #0563c1;text-decoration: underline">Works Mobile</span></a> is the only business chat to connect with LINE. LINE Works also contacts customers and business partners for easy communication.<br /> </span></p> <p><strong>Content Management apps:<br /> </strong></p> <p style="margin-left: 36pt"><a href="https://azuremarketplace.microsoft.com/en-us/marketplace/apps/aad.azuredockit?tab=Overview"><span style="color: #0563c1;text-decoration: underline">Azure DockIt</span></a><span style="color: black">is a SaaS solution that automatically generates technical documentation of your Azure environment. <a href="https://www.azuredockit.com/"><span style="color: #0563c1;text-decoration: underline">Azure DockIt</span></a> can generate a complete documentation of your Microsoft Azure Subscrtipion in less than 5 minutes.<br /> </span></p> <p style="margin-left: 36pt"><a href="https://azuremarketplace.microsoft.com/en-us/marketplace/apps/aad.evernote?tab=Overview"><span style="color: #0563c1;text-decoration: underline"><strong>Evernote</strong></span></a><span style="color: black">allows you to capture information in any environment using whatever device or platform you find most convenient, and makes this information accessible and searchable at any time from any devices. <a href="https://evernote.com/"><span style="color: #0563c1;text-decoration: underline">Evernote</span></a> helps users collaborate in a single workspace.<strong><br /> </strong></span></p> <p style="margin-left: 36pt"><a href="https://azuremarketplace.microsoft.com/en-us/marketplace/apps/aad.inkling?tab=Overview"><span style="color: #0563c1;text-decoration: underline">Inkling</span></a><span style="color: black"> offers a mobile platform that brings policies and procedures to life for deskless worker. The <a href="https://www.inkling.com/product/collaborative-authoring/"><span style="color: #0563c1;text-decoration: underline">Inkling</span></a> collaborative authoring tools let users select content types, drag and drop widgets, automate import of old files, and allow multiple authors edit the content simultaneously.<br /> </span></p> <p><span style="color: black"><strong>Developer Services apps:<br /> </strong></span></p> <p style="margin-left: 36pt"><a href="https://azuremarketplace.microsoft.com/en-us/marketplace/apps/aad.githubcom?tab=Overview"><span style="color: #0563c1;text-decoration: underline"><strong>GitHub</strong></span></a><span style="color: black">is a development platform inspired by the way developers work. GitHub hosts code, manages projects, and builds software alongside millions of developers. <a href="https://github.com/"><span style="color: #0563c1;text-decoration: underline">GitHub</span></a> brings teams together to work through problems, move ideas forward, and learn from each other along the way.<br /> </span></p> <p><strong>Facility Management apps:<br /> </strong></p> <p style="margin-left: 36pt"><a href="https://azuremarketplace.microsoft.com/en-us/marketplace/apps/aad.servicechannel?tab=Overview"><span style="color: #0563c1;text-decoration: underline"><strong>ServiceChannel</strong></span></a><span style="color: black">provides facilities and contractor management platform that enables complete service automation and repair and maintenance management at all locations. <a href="http://servicechannel.info/service-automation/"><span style="color: #0563c1;text-decoration: underline">ServiceChannel</span></a> isin the process of transforming the Facilities Management industry and assisting companies to be better in running their operations.</span><span style="font-size: 10pt"><br /> </span></p> <p><strong>Finance apps:<br /> </strong></p> <p style="margin-left: 36pt"><a href="https://azuremarketplace.microsoft.com/en-us/marketplace/apps/aad.landgorillaclient?tab=Overview"><span style="color: #0563c1;text-decoration: underline"><strong>Land Gorilla Client app</strong></span></a>provides the construction loan software and lending solutions that streamline post-closing construction administration services, so customers can easily scale and control their pipeline as they increase loan volume. Construction lenders trust <a href="https://www.landgorilla.com/"><span style="color: #0563c1;text-decoration: underline">Land Gorilla</span></a>.<strong><br /> </strong></p> <p><strong>Healthcare apps:<br /> </strong></p> <p style="margin-left: 36pt"><a href="https://azuremarketplace.microsoft.com/en-us/marketplace/apps/aad.cernercentral?tab=Overview"><span style="color: #0563c1;text-decoration: underline"><strong>Cerner Central</strong></span></a>is a web portal for client IT administrators to manage identity federation, access management, and auditing capabilities for Cerner’s cloud platforms: Healthe Intent and Millennium. <a href="https://cernercentral.com/"><span style="color: #0563c1;text-decoration: underline">Cerner Central</span></a> is the hub that securely connects your enterprise to the Cerner Cloud for app access, authentication token management, audit reports, device access, user accounts and more.</p> <p style="margin-left: 36pt"><a href="https://azuremarketplace.microsoft.com/en-us/marketplace/apps/aad.deskyogi?tab=Overview"><span style="color: #0563c1;text-decoration: underline"><strong>Desk Yogi</strong></span></a>offers a wellnesssolution and provides fitness, yoga, nutrition and stress reduction right at your desk. <a href="https://www.desk-yogi.com/"><span style="color: #0563c1;text-decoration: underline">Desk Yogi</span></a> helps you improve<strong><br /> </strong>your health and happiness with 3 to 10-minute video lessons taught by expert teachers.</p> <p><span style="color: black"><strong>Productivity apps:<br /> </strong></span></p> <p style="margin-left: 36pt"><a href="https://azuremarketplace.microsoft.com/en-us/marketplace/apps/aad.adobecreativecloud?tab=Overview"><span style="color: #0563c1;text-decoration: underline">Adobe Creative Cloud</span></a><span style="color: black">gives you everything that you need to turn your brightest ideas into your best work across your desktop and mobile devices and share it with the world. <a href="https://www.adobe.com/creativecloud.html"><span style="color: #0563c1;text-decoration: underline">Creative Cloud</span></a> provides the essential tools like Photoshop to innovative new tools like Adobe DX. You also get build-in templates to jump-start your designs and step-by-step tutorials to help you get up to speed quickly and sharpen your skills. It is your entire creative world, all in one place.<br /> </span></p> <p><span style="color: black"><strong>Project Management apps:<br /> </strong></span></p> <p style="margin-left: 36pt"><a href="https://azuremarketplace.microsoft.com/en-us/marketplace/apps/aad.p2wareppmonline?tab=Overview"><span style="color: #0563c1;text-decoration: underline">P2ware PPM </span></a><span style="color: black">solution combines leading project portfolio management techniques with 7*24 cloud availability. <a href="https://p2ware.com/en/project-management-tools/project-manager/7"><span style="color: #0563c1;text-decoration: underline">P2ware Project Manager</span></a> is a project manage app that embraces all aspects of real world project management from planning to execution.<br /> </span></p> <p><strong>Security apps:<br /> </strong></p> <p style="margin-left: 36pt"><a href="https://azuremarketplace.microsoft.com/en-us/marketplace/apps/aad.zscalerprivateaccess?tab=Overview"><span style="color: #0563c1;text-decoration: underline"><strong>Zscaler Private Access (ZPA)</strong></span></a><strong><br /> </strong>delivers policy-based, secure access to applications and assets without the hassle or security risks of a VPN. The <a href="https://www.zscaler.com/products/zscaler-private-access"><span style="color: #0563c1;text-decoration: underline">Zscaler</span></a> approach is more secure than VPN because it reduces the potential attack surface and doesn’t require hardware infrastructure.</p> <p>If you want to suggest a new SaaS app, please submit your request using the <a href="http://aka.ms/aadapprequest"><span style="color: #0563c1;text-decoration: underline">Azure AD Application Request forum</span></a>. We are actively reviewing the requests and working to release new SaaS app.</p> <p>Best Regards,</p> <p>Alex Simons (Twitter: <a href="https://twitter.com/Alex_A_Simons"><span style="color: #0563c1;text-decoration: underline">@Alex_A_Simons</span></a>)</p> <p>Director of Program Management</p> <p>Microsoft Identity Division</p> ]]></content:encoded>
</item>
<item>
<title>PingAccess for Azure AD: The public preview is being deployed!</title>
<link>https://blogs.technet.microsoft.com/enterprisemobility/2017/03/22/pingaccess-for-azure-ad-the-public-preview-is-being-deployed/</link>
<pubDate>Wed, 22 Mar 2017 16:00:52 +0000</pubDate>
<dc:creator><![CDATA[Alex_SimonsMS]]></dc:creator>
<category><![CDATA[Uncategorized]]></category>
<category><![CDATA[Apps]]></category>
<category><![CDATA[Authentication]]></category>
<category><![CDATA[Hybrid]]></category>
<category><![CDATA[Hybrid Cloud]]></category>
<category><![CDATA[Identity-driven Security]]></category>
<category><![CDATA[On-Prem]]></category>
<category><![CDATA[SSO]]></category>
<guid isPermaLink="false">https://blogs.technet.microsoft.com/enterprisemobility/?p=49215</guid>
<description><![CDATA[Howdy folks, Back in September, I blogged about our exciting partnership with Ping Identity. Since then, Microsoft and Ping Identity have worked closely together to extend the capabilities of Azure AD Application Proxy to support new kinds of on-premises applications using Ping Access. I’m happy to announce today that PingAccess for Azure AD is now <p><a class="read-more" href="https://blogs.technet.microsoft.com/enterprisemobility/2017/03/22/pingaccess-for-azure-ad-the-public-preview-is-being-deployed/">Continue reading</a></p>]]></description>
<content:encoded><![CDATA[<p>Howdy folks,</p> <p>Back in September, I blogged about <a href="https://blogs.technet.microsoft.com/enterprisemobility/2016/09/14/azuread-and-pingaccess-partnering-to-bring-you-secure-remote-access-to-even-more-on-premises-web-apps/">our exciting partnership with Ping Identity</a>.</p> <p>Since then, Microsoft and Ping Identity have worked closely together to extend the capabilities of Azure AD Application Proxy to support new kinds of on-premises applications using Ping Access.</p> <p>I’m happy to announce today that PingAccess for Azure AD is now ready for Public Preview and is currently being deployed across Azure AD data centers around the world. Many of you in North America will see it turn on today and it should be available to everyone by the end of the day Friday, 3/24/2017.</p> <p>I’ve invited one of the program managers on our team, Harshini Jayaram, to share more details in a blog, which you’ll find below. We hope you try it out and look forward to hearing what you think!</p> <p>Best regards,</p> <p>Alex Simons (Twitter: <a href="http://www.twitter.com/alex_a_simons">@Alex_A_Simons</a>)</p> <p>Director of Program Management</p> <p>Microsoft Identity Division</p> <p>—-</p> <p>Hi all,</p> <p>We’ve already have many customers use Application Proxy to provide single sign-on (SSO) and secure remote access for web applications hosted on-premises. Many of them use this product for applications such as local SharePoint sites, Outlook Web Access for local Exchange servers, and other business web applications. It is a simple, secure, and cost-effective solution:</p> <ul> <li><strong>Simple:</strong> You don’t need to change the network infrastructure, put anything in a DMZ, or use VPN.</li> <li><strong>Secure:</strong> Application Proxy only uses outbound connections, giving you a more secure solution. It also works with other security features you’ve seen in Azure such as two-step verification, conditional access, and risk analysis. Learn more about this in <a href="https://docs.microsoft.com/en-us/azure/active-directory/application-proxy-security-considerations">Security considerations for Azure AD Application Proxy</a>.</li> <li><strong>Cost-Effective:</strong> Application Proxy is a service that we maintain in the cloud, so you can save time and money.</li> </ul> <p>Right now, all those benefits of Application Proxy are available for many different types of applications, including:</p> <ul> <li>Web applications using Integrated Windows Authentication</li> <li>Web applications using form-based access</li> <li>Web APIs that you want to expose to rich applications on different devices</li> <li>Applications hosted behind a Remote Desktop Gateway</li> </ul> <p>If you want more details, you can check out our <a href="https://go.microsoft.com/fwlink/?linkid=844804">Application Proxy documentation</a>. For this blog, I want to focus more on how we’re adding header-based applications with this new public preview!</p> <h2>PingAccess for Azure AD enables more apps!</h2> <p>Our customers have consistently asked for Application Proxy to also support apps that use headers for authentication, such as Peoplesoft, Netweaver Portal, and WebCenter. To enable this capability for our Azure AD Premium customers, we have partnered with Ping Identity. Ping Identity’s PingAccess now allows Application Proxy to support apps that use header-based authentication.</p> <p>PingAccess is installed on-premises. For apps that use header-based authentication, Application Proxy connectors route traffic through PingAccess. Existing App Proxy applications are not impacted and use the current flow with no changes. An overview of this flow is shown below, and you can always check out our <a href="https://docs.microsoft.com/en-us/azure/active-directory/active-directory-application-proxy-get-started">overview documentation</a> for more on App Proxy flows.</p> <p style="text-align: center"><img alt="" src="https://msdnshared.blob.core.windows.net/media/2017/03/032217_0025_PingAccessf1.jpg" /></p> <p style="text-align: center"><strong>Figure 1</strong>: Application Proxy + PingAccess Infrastructure Overview</p> <p>PingAccess is a separately licensed feature, but your Azure Premium licenses now include a free license to configure up to 20 applications with this flow. If you have more apps, you’ll need to get a license through Ping Identity.</p> <h2>Joining the Preview</h2> <p>We are excited to have you join our preview! To get started you need to:</p> <ol> <li>Configure Application Proxy Connectors</li> <li>Create an Azure AD Application Proxy Application</li> <li>Download & Configure PingAccess</li> <li>Configure Applications in PingAccess</li> </ol> <p>Just head to our <a href="https://docs.microsoft.com/en-us/azure/active-directory/application-proxy-ping-access">Application Proxy + PingAccess documentation</a> for a walkthrough of each of these steps.</p> <p>We hope you enjoy trying this preview! As always, we’d love to hear from you with any questions, comments, or feedback, so please leave us a <span style="font-family: Times New Roman">comment</span> or reach out to us directly at <a href="mailto:aadapfeedback@microsoft.com">aadapfeedback@microsoft.com</a>.</p> <p>Thanks,</p> <p>Harshini Jayaram</p> ]]></content:encoded>
</item>
<item>
<title>First ever #AzureAD AMA results</title>
<link>https://blogs.technet.microsoft.com/enterprisemobility/2017/03/21/first-ever-azuread-ama-results/</link>
<pubDate>Tue, 21 Mar 2017 16:00:25 +0000</pubDate>
<dc:creator><![CDATA[Alex_SimonsMS]]></dc:creator>
<category><![CDATA[Uncategorized]]></category>
<guid isPermaLink="false">https://blogs.technet.microsoft.com/enterprisemobility/?p=49165</guid>
<description><![CDATA[Howdy folks, On March 9th, the Azure AD team hosted its first “Ask Me Anything” (AMA) on Reddit. A bunch of us gathered in a big conference room, and even more of the team joined on a Skype call (sadly, the Skypers didn’t get any of the snacks or pizza).And so many of you asked <p><a class="read-more" href="https://blogs.technet.microsoft.com/enterprisemobility/2017/03/21/first-ever-azuread-ama-results/">Continue reading</a></p>]]></description>
<content:encoded><![CDATA[<p>Howdy folks,</p> <p>On March 9<sup>th</sup>, the Azure AD team hosted its first “Ask Me Anything” (AMA) on Reddit. A bunch of us gathered in a big conference room, and even more of the team joined on a Skype call (sadly, the Skypers didn’t get any of the snacks or pizza).And so many of you asked such great questions that we learned a lot ourselves. Thank you for participating!</p> <p>If you haven’t had a chance to go through the thread yet, I recommend you <a href="http://aka.ms/azuread-reddit-ama">take a look</a>.There’s a lot of interesting and valuable information there.</p> <p style="text-align: center"><img alt="" src="https://msdnshared.blob.core.windows.net/media/2017/03/032117_0547_FirsteverAz1.jpg" /></p> <p style="text-align: center"><em>Just about to start!<br /> </em></p> <p style="text-align: center"><img alt="" src="https://msdnshared.blob.core.windows.net/media/2017/03/032117_0547_FirsteverAz2.jpg" /></p> <p style="text-align: center"><em>Everyone hard at work AMAing<br /> </em></p> <p>So how did it go? Pretty awesome! Some quick stats:</p> <ul> <li>More than <strong>50 people</strong> from our team participated, and some of our wonderful MVPs and representatives from our Microsoft partner teams joined, as well</li> <li>We had <strong>102 top-level questions</strong> (29 per hour) and <strong>449 total</strong> comments (128 per hour)</li> <li>Our post was upvoted by <strong>96% of people</strong> with a total of <strong>72 points. </strong>This compares with: <ul> <li><strong>25</strong> – average number of points for of all other /r/Azure AMAs (a <strong>284% increase</strong>!)</li> <li><strong>89%</strong> – average upvote percentage for all other /r/Azure AMAs (a <strong>7.8% increase</strong>!)</li> </ul> </li> <li>We answered <strong>99% of questions during the event</strong></li> <li>The <a href="http://aka.ms/azuread-reddit-ama">Azure AD AMA page</a> had <strong>2,586 hits</strong> in the five days surrounding the event, and is <strong>still getting 60-100 hits</strong> per day</li> </ul> <p>For questions per hour, total comment count, and response rate, we’re the new AMA champions at Microsoft.The SQL team has us beat for total number of questions, though, so we’ll definitely host another AMA in the future and try to knock them off the top. We’re looking forward to it and hope you’ll join us!</p> <p>Best regards,</p> <p>Alex Simons (Twitter: <a href="https://twitter.com/Alex_A_Simons">@Alex_A_Simons</a>)</p> <p>Director of Program Management</p> <p>Microsoft Identity Division</p> ]]></content:encoded>
</item>
</channel>
</rss>