2016-02-25

Microsoft's Azure Active Directory: A new paradigm for Authentication

Looked at some introductory videos for Azure Active Directory ("AAD") Developers. Wow!

MS is reinventing itself with a whole new paradigm for AuthN / IDaaS out in the cloud.

Wrote a quick report summarizing video content. You can find it here.

TL;DR summary:


  • AAD and AD become a single logical entity. On-premise AD driven from cloud-based AAD.
  • Strategic AuthN protocols are:
    • OpenID Connect (MS extension of OpenID)
    • OAuth
    • WS-Federation / SAML are *not* strategic. Neither is Windows Identity Foundation.
  • Apps (public or corporate) must be registered to AAD. After that federation is easy.
  • ADAL is MS multi-platform open-source SDK to do AuthN, also Xamarin, Apache Cordova
  • Win10 will have new AuthN flows integrated at OS level: “WebAccountManager” API
  • Whole effort is serious MS “catch-up”; work in progress, rough around edges, incomplete at times
    • Eg.Kludgy support of single-page web apps with Javascript calling multiple background Web APIs.
  • Major MS paradigm shift / change in fundamental architectural direction.


6 comments:

bestessays said...

Even there are many advancements in dealing with cyber security but the threats are also increasing and i believe there is a time to look into further possibilities for securities

Logo Design Services London said...

Assuring a powerful visual identity that stands out and appeals to your target audience, Professional logo design services London offer carefully created, distinctive logos that successfully reflect your brand.

missaf said...

A Yangdong generator is a dependable power source that delivers effective energy solutions to households and businesses. yangdong generator in Pakistan are well-known for their longevity, allowing them to operate continuously even under demanding power situations.

Arthur Kane said...

Microsoft's Azure Active Directory is truly a game-changer when it comes to authentication. It brings a new level of security and flexibility for managing user identities and access. This shift can be especially beneficial for educational institutions, where online class help services can integrate seamlessly with Azure AD to streamline access to resources. With single sign-on and multi-factor authentication, students and teachers can enjoy a more secure and efficient learning environment. Embracing this technology could significantly improve the way institutions manage online learning platforms and protect sensitive data.

ansha rehman said...

Join forces with a top social media marketing agency that produces outcomes! Our specialty is developing creative ideas that increase sales, engage your audience, and strengthen your brand. Are you prepared to advance your social media presence? Let's get it done!

affordable fence system said...

Azure Active Directory from Microsoft transforms authentication with smooth access control and cutting-edge security. Similar to this, top Electric Fence services use state-of-the-art technology to improve perimeter security for dependable defense.