Skip to content

Commit 4962f4d

Browse files
authored
Merge pull request #164955 from NishthaBabith-V/CloudAuth
Cloud authentication deployment plan
2 parents 3af28d8 + e80d96f commit 4962f4d

19 files changed

+443
-956
lines changed

.openpublishing.redirection.json

Lines changed: 10 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -41474,6 +41474,16 @@
4147441474
"redirect_url": "/azure/active-directory/authentication/tutorial-enable-azure-mfa",
4147541475
"redirect_document_id": true
4147641476
},
41477+
{
41478+
"source_path_from_root": "/articles/active-directory/hybrid/plan-migrate-adfs-pass-through-authentication.md",
41479+
"redirect_url": "/azure/active-directory/hybrid/migrate-from-federation-to-cloud-authentication",
41480+
"redirect_document_id": false
41481+
},
41482+
{
41483+
"source_path_from_root": "/articles/active-directory/hybrid/plan-migrate-adfs-password-hash-sync.md",
41484+
"redirect_url": "/azure/active-directory/hybrid/migrate-from-federation-to-cloud-authentication",
41485+
"redirect_document_id": true
41486+
},
4147741487
{
4147841488
"source_path_from_root": "/articles/active-directory/conditional-access/app-based-mfa.md",
4147941489
"redirect_url": "/azure/active-directory/authentication/tutorial-enable-azure-mfa",

articles/active-directory/fundamentals/active-directory-deployment-plans.md

Lines changed: 11 additions & 13 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
11
---
22
title: Deployment plans - Azure Active Directory | Microsoft Docs
3-
description: End-to-end guidance about how to deploy many Azure Active Directory capabilities.
3+
description: Guidance about how to deploy many Azure Active Directory capabilities.
44
services: active-directory
55
author: BarbaraSelden
66
manager: daveba
@@ -16,7 +16,7 @@ ms.collection: M365-identity-device-management
1616
---
1717

1818
# Azure Active Directory deployment plans
19-
Looking for end-to-end guidance on deploying Azure Active Directory (Azure AD) capabilities? Azure AD deployment plans walk you through the business value, planning considerations, and operational procedures needed to successfully deploy common Azure AD capabilities.
19+
Looking for complete guidance on deploying Azure Active Directory (Azure AD) capabilities? Azure AD deployment plans walk you through the business value, planning considerations, and operational procedures needed to successfully deploy common Azure AD capabilities.
2020

2121
From any of the plan pages, use your browser's Print to PDF capability to create an up-to-date offline version of the documentation.
2222

@@ -25,16 +25,16 @@ From any of the plan pages, use your browser's Print to PDF capability to create
2525

2626
| Capability | Description|
2727
| -| -|
28-
| [Multi-Factor Authentication](../authentication/howto-mfa-getstarted.md)| Azure AD Multi-Factor Authentication (MFA) is Microsoft's two-step verification solution. Using admin-approved authentication methods, Azure AD MFA helps safeguard access to your data and applications while meeting the demand for a simple sign-in process. Watch this video on [How to configure and enforce multi-factor authentication in your tenant](https://www.youtube.com/watch?v=qNndxl7gqVM)|
28+
| [Azure AD multifactor authentication](../authentication/howto-mfa-getstarted.md)| Azure AD Multi-Factor Authentication (MFA) is Microsoft's two-step verification solution. Using admin-approved authentication methods, Azure AD MFA helps safeguard access to your data and applications while meeting the demand for a simple sign in process. Watch this video on [How to configure and enforce multi-factor authentication in your tenant](https://www.youtube.com/watch?v=qNndxl7gqVM)|
2929
| [Conditional Access](../conditional-access/plan-conditional-access.md)| With Conditional Access, you can implement automated access control decisions for who can access your cloud apps, based on conditions. |
3030
| [Self-service password reset](../authentication/howto-sspr-deployment.md)| Self-service password reset helps your users reset their passwords without administrator intervention, when and where they need to. |
31-
| [Passwordless](../authentication/howto-authentication-passwordless-deployment.md) | Implement passwordless authentication using the the Microsoft Authenticator app or FIDO2 Security keys in your organization |
31+
| [Passwordless](../authentication/howto-authentication-passwordless-deployment.md) | Implement passwordless authentication using the Microsoft Authenticator app or FIDO2 Security keys in your organization |
3232

3333
## Deploy application and device management
3434

3535
| Capability | Description|
3636
| -| - |
37-
| [Single sign-on](../manage-apps/plan-sso-deployment.md)| Single sign-on helps your users access the apps and resources they need to do business while signing in only once. After they've signed in, they can go from Microsoft Office to SalesForce to Box to internal applications without being required to enter credentials a second time. |
37+
| [Single sign-on](../manage-apps/plan-sso-deployment.md)| Single sign-on helps your users' access the apps and resources they need to do business while signing in only once. After they've signed in, they can go from Microsoft Office to SalesForce to Box to internal applications without being required to enter credentials a second time. |
3838
| [My Apps](../manage-apps/my-apps-deployment-plan.md)| Offer your users a simple hub to discover and access all their applications. Enable them to be more productive with self-service capabilities, like requesting access to apps and groups, or managing access to resources on behalf of others. |
3939
| [Devices](../devices/plan-device-deployment.md) | This article helps you evaluate the methods to integrate your device with Azure AD, choose the implementation plan, and provides key links to supported device management tools. |
4040

@@ -43,10 +43,9 @@ From any of the plan pages, use your browser's Print to PDF capability to create
4343

4444
| Capability | Description|
4545
| -| -|
46-
| [ADFS to Password Hash Sync](../hybrid/plan-migrate-adfs-password-hash-sync.md)| With Password Hash Synchronization, hashes of user passwords are synchronized from on-premises Active Directory to Azure AD, letting Azure AD authenticate users with no interaction with the on-premises Active Directory |
47-
| [ADFS to Pass Through Authentication](../hybrid/plan-migrate-adfs-pass-through-authentication.md)| Azure AD Pass-through Authentication helps your users sign in to both on-premises and cloud-based applications using the same passwords. This feature provides users with a better experience - one less password to remember - and reduces IT helpdesk costs because users are less likely to forget how to sign in. When people sign in using Azure AD, this feature validates users' passwords directly against your on-premises Active Directory. |
46+
| [AD FS to cloud user authentication](/hybrid/migrate-from-federation-to-cloud-authentication.md)| Learn to migrate your user authentication from federation to cloud authentication with either pass through authentication or password hash sync.
4847
| [Azure AD Application Proxy](../app-proxy/application-proxy-deployment-plan.md) |Employees today want to be productive at any place, at any time, and from any device. They need to access SaaS apps in the cloud and corporate apps on-premises. Azure AD Application proxy enables this robust access without costly and complex virtual private networks (VPNs) or demilitarized zones (DMZs). |
49-
| [Seamless SSO](../hybrid/how-to-connect-sso-quick-start.md)| Azure Active Directory Seamless Single Sign-On (Azure AD Seamless SSO) automatically signs users in when they are on their corporate devices connected to your corporate network. With this feature, users won't need to type in their passwords to sign in to Azure AD and usually won't need to enter their usernames. This feature provides authorized users with easy access to your cloud-based applications without needing any additional on-premises components. |
48+
| [Seamless SSO](../hybrid/how-to-connect-sso-quick-start.md)| Azure Active Directory Seamless Single Sign-On (Azure AD Seamless SSO) automatically signs users in when they are on their corporate devices connected to your corporate network. With this feature, users won't need to type in their passwords to sign in to Azure AD and usually won't need to enter their usernames. This feature provides authorized users with easy access to your cloud-based applications without needing any extra on-premises components. |
5049

5150
## Deploy user provisioning
5251

@@ -74,8 +73,8 @@ Roles might include the following
7473
|End-user|A representative group of users for which the capability will be implemented. Often previews the changes in a pilot program.
7574
|IT Support Manager|IT support organization representative who can provide input on the supportability of this change from a helpdesk perspective. 
7675
|Identity Architect or Azure Global Administrator|Identity management team representative in charge of defining how this change is aligned with the core identity management infrastructure in your organization.|
77-
|Application Business Owner |The overall business owner of the affected application(s), which may include managing access.  May also provide input on the user experience and usefulness of this change from an end-user's perspective.
78-
|Security Owner|A representative from the security team that can sign off that the plan will meet the security requirements of your organization.|
76+
|Application Business Owner |The overall business owner of the affected application(s), which may include managing access.  May also provide input on the user experience and usefulness of this change from an end user's perspective.
77+
|Security Owner|A representative from the security team that can sign out that the plan will meet the security requirements of your organization.|
7978
|Compliance Manager|The person within your organization responsible for ensuring compliance with corporate, industry, or governmental requirements.|
8079

8180
**Levels of involvement might include:**
@@ -88,10 +87,9 @@ Roles might include the following
8887

8988
- **I**nformed of project plan and outcome
9089

91-
9290
## Best practices for a pilot
93-
A pilot allows you to test with a small group before turning a capability on for everyone. Ensure that as part of your testing, each use case within your organization is thoroughly tested. It's best to target a specific group of pilot users before rolling this out to your organization as a whole.
91+
A pilot allows you to test with a small group before turning on a capability for everyone. Ensure that as part of your testing, each use case within your organization is thoroughly tested. It's best to target a specific group of pilot users before rolling this deployment out to your organization as a whole.
9492

95-
In your first wave, target IT, usability, and other appropriate users who can test and provide feedback. This feedback should be used to further develop the communications and instructions you send to your users, and to give insights into the types of issues your support staff may see.
93+
In your first wave, target IT, usability, and other appropriate users who can test and provide feedback. Use this feedback to further develop the communications and instructions you send to your users, and to give insights into the types of issues your support staff may see.
9694

9795
Widening the rollout to larger groups of users should be carried out by increasing the scope of the group(s) targeted. This can be done through [dynamic group membership](../enterprise-users/groups-dynamic-membership.md), or by manually adding users to the targeted group(s).

articles/active-directory/hybrid/TOC.yml

Lines changed: 3 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -153,10 +153,8 @@
153153
href: reference-connect-instances.md
154154
- name: Migration
155155
items:
156-
- name: Migrate from federation to PHS
157-
href: plan-migrate-adfs-password-hash-sync.md
158-
- name: Migrate from federation to PTA
159-
href: plan-migrate-adfs-pass-through-authentication.md
156+
- name: Migrate from federation to cloud authentication
157+
href: migrate-from-federation-to-cloud-authentication.md
160158
- name: Move groups from one forest to another
161159
href: how-to-connect-migrate-groups.md
162160
- name: Migrate to cloud authentication using staged rollout
@@ -264,7 +262,7 @@
264262
href: how-to-connect-health-adfs.md
265263
- name: Risky IP report for Azure AD Connect Health with AD FS
266264
href: how-to-connect-health-adfs-risky-ip.md
267-
- name: AD FS Sign-Ins in Azure AD with Connect Health
265+
- name: AD FS sign-ins in Azure AD with Connect Health
268266
href: how-to-connect-health-ad-fs-sign-in.md
269267
- name: Use Azure AD Connect Health for sync
270268
href: how-to-connect-health-sync.md
155 KB
Loading
Loading
Loading
119 KB
Loading
224 KB
Loading
Loading
224 KB
Loading

0 commit comments

Comments
 (0)