May 2019
Intermediate to advanced
620 pages
21h 41m
English
In on-premises networks, access is typically governed by group memberships; when you authenticate on a domain-joined system, the groups an account is a member of dictate the level of access. Dynamic Access Control and Authentication Policies, introduced in Windows Server 2012, showed the possibilities of attribute-based access control with claims in Kerberos.
For cloud applications, services, and systems, a more granular form of access control is needed. Microsoft introduced the controls organizations need with Conditional Access. Access can be allowed or denied, per Azure AD account and/or group, and per Azure AD-integrated applications, including on-premises claims-based applications and applications that are published through ...