Identity Foundation
Cloud First Strategy
Identity and access management for Commercial and Government organizations has decisively shifted to the cloud. While some scenarios require air-gapped networks (unpatchable systems, combat systems, nuclear reactors, submarines), the vast majority of scenarios benefit from the security, productivity, and return on investment provided by cloud-based IAM. Microsoft Entra is the cloud-based IAM that underpins Microsoft 365. Windows for Hello Business Cloud Kerberos Trust is the most modern Windows Hello for Business deployment model.
Cloud-First Advantages
Security
On-prem Active Directory is under attack with modern tools and no longer defensible with legacy tools. Microsoft Entra provides:
-
Conditional Access to integrate and automate
- MFA and Password-less credentials
- Better signals to measure risk, based on Artificial Intelligence
- Modern password management
-
Access Governance to ensure the right access, to the right resources, for the right people, for the right duration
-
Blast-radius reduction to contain risk of on-prem components to compromise the cloud environment
These three articles recommend the move to Microsoft Entra:
-
NSA Security Advisory (Dec 2020) recommends Azure Active Directory as the Authoritative Identity Provider.
-
https://aka.ms/protectm365 recommends against identity federation (in response to SolarWinds).
-
https://aka.ms/ad2azuread provides information on moving from AD to fully cloud based IAM.
Productivity
Microsoft Entra automates and simplifies low latency, anywhere, anytime access across the expanding digital estate:
-
Single Sign On across any user and any app
-
Better experience through self-service
-
Automated lifecycle management for workforce and external accounts
-
Improved performance through globally distributed, infinitely elastic cloud infrastructure
Return on Investment
Microsoft Entra reduces costs through infrastructure simplification and vendor consolidation:
-
Reduction of complex and costly 3rd party products and integration
-
Reduction of the cost of procuring and maintaining aging infrastructure
-
Short time to value
📩 Don't Miss the Next Solution
Join the list to see the real-time solutions I'm delivering to my GCC High clients.