Chapter 4. Identity and Access Management
In this chapter, you will learn how Microsoft Azure handles identity and access management. We cover both how and why you can provide or prevent access to resources. We also explore Azure Active Directory (Azure AD) and how it relates to your existing Microsoft Active Directory with a look at different support tiers and the associated features available for your organization as a result.
Access Control and Authorization
There are two critical security functions in any IT environment:
- Authentication
-
Who are you?
- Authorization
-
Are you permitted to perform a specific task?
Granting and restricting access to your resources within the Azure environment is a critical operational process. The use of authentication and authorization will affect who has access to resources and how they access them. Identity and access management are different than the network security groups and application security groups discussed in the next chapter.
Microsoft uses Microsoft Active Directory for identity and access management within Azure. This makes adapting to the identity management on Azure much easier for those familiar with the concept of Active Directory on-premises.
Azure AD domain services and on-premises Active Directory are different technical platforms, despite having shared technology roots. Certain features are not available in Azure AD and some features require more effort to design and maintain using Active Directory.
For more information ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access