title | description | keywords | services | author | manager | ms.assetid | ms.service | ms.workload | ms.topic | ms.date | ms.subservice | ms.author | ms.collection |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
What is hybrid identity with Azure Active Directory? |
Hybrid identity is having a common user identity for authentication and authorization both on-premises and in the cloud. |
introduction to Azure AD Connect, Azure AD Connect overview, what is Azure AD Connect, install active directory |
active-directory |
billmath |
daveba |
59bd209e-30d7-4a89-ae7a-e415969825ea |
active-directory |
identity |
overview |
05/17/2019 |
hybrid |
billmath |
M365-identity-device-management |
Today, businesses, and corporations are becoming more and more a mixture of on-premises and cloud applications. Users require access to those applications both on-premises and in the cloud. Managing users both on-premises and in the cloud poses challenging scenarios.
Microsoft’s identity solutions span on-premises and cloud-based capabilities. These solutions create a common user identity for authentication and authorization to all resources, regardless of location. We call this hybrid identity.
With hybrid identity to Azure AD and hybrid identity management these scenarios become possible.
To achieve hybrid identity with Azure AD, one of three authentication methods can be used, depending on your scenarios. The three methods are:
These authentication methods also provide single-sign on capabilities. Single-sign on automatically signs your users in when they are on their corporate devices, connected to your corporate network.
For additional information, see Choose the right authentication method for your Azure Active Directory hybrid identity solution.
Here are some common hybrid identity and access management scenarios with recommendations as to which hybrid identity option (or options) might be appropriate for each.
1 Password hash synchronization with single sign-on.
2 Pass-through authentication and single sign-on.
3 Federated single sign-on with AD FS.
4 AD FS can be integrated with your enterprise PKI to allow sign-in using certificates. These certificates can be soft-certificates deployed via trusted provisioning channels such as MDM or GPO or smartcard certificates (including PIV/CAC cards) or Hello for Business (cert-trust). For more information about smartcard authentication support, see this blog.
[!INCLUDE active-directory-free-license.md]