Azure Active Directory Password Protection- Adoption Kit

Azure Active Directory Password Protection- Adoption Kit

Version: 1.0 For the latest version, please check

Contents

Azure Active Directory Password Protection- Adoption Kit................................................................................................................................. 1 Awareness ................................................................................................................................................................................................................................ 3

Business Overview............................................................................................................................................................................................................ 3 Pricing and Licensing Requirements......................................................................................................................................................................... 4 Key Benefits ........................................................................................................................................................................................................................ 4 Customer Stories/Case Studies................................................................................................................................................................................... 4 Announcements/Blogs ................................................................................................................................................................................................... 4 Training/Learning Resources ............................................................................................................................................................................................ 4 Level 100 Knowledge/Concepts ................................................................................................................................................................................. 4 Role-Based Guidance...................................................................................................................................................................................................... 5

IT Administrator Staff ................................................................................................................................................................................................. 5 Help Desk Staff ............................................................................................................................................................................................................. 5 Training................................................................................................................................................................................................................................. 6 On-Demand Webinars............................................................................................................................................................................................... 6 Videos............................................................................................................................................................................................................................... 6 Online Courses.............................................................................................................................................................................................................. 6 Books ................................................................................................................................................................................................................................ 6 Tutorial ............................................................................................................................................................................................................................. 6 Whitepaper..................................................................................................................................................................................................................... 6 FAQ.................................................................................................................................................................................................................................... 6 End-user Readiness and Communication ................................................................................................................................................................... 7 Planning and Change Management.............................................................................................................................................................................. 7 Deployment Plan .............................................................................................................................................................................................................. 7 Architecture Plan/Topology ......................................................................................................................................................................................... 8 Testing ....................................................................................................................................................................................................................................... 9 Deployment............................................................................................................................................................................................................................. 9 Deployment ........................................................................................................................................................................................................................ 9 Operations ............................................................................................................................................................................................................................... 9 Operations........................................................................................................................................................................................................................... 9 Monitoring .......................................................................................................................................................................................................................... 9

Troubleshooting................................................................................................................................................................................................................ 9 References ........................................................................................................................................................................................................................... 9 Support and Feedback ...................................................................................................................................................................................................... 10

Awareness

This section helps you to analyze the benefits of Azure Active Directory (Azure AD) Password Protection. You will learn about the ease of use, pricing and licensing model, as well as customer stories about how it helped improve their business. You will also receive up-to-date announcements and access to blogs that discuss ongoing improvements.

Business Overview

Your organization's protected assets should be available to only those who have authorized access. Unfortunately, poor password choices expose you to the risk of corporate data breaches. You need a password system that prevents users from setting up easily guessed passwords when they select or change their passwords.

Most users think if they have chosen a password that meets a complexity requirement, something like P@$$w0rd1! they are safe. Attackers know how users create passwords, and there are three methods they use to be aware of:

? They know to account for character substitutions like "$" for "s". ? They also know that if there are complexity rules, most people will apply them in the same way, by starting a

word with a capital letter and ending the password with a digit or punctuation. ? They know that requiring users to change their passwords periodically leads to other predictable patterns. For

instance, if users must change their password every quarter, they often pick passwords based on sports teams, months or seasons and combine them with the current year.

To defend your organization from a password spray attack, it is integral for all users to have passwords that are hard to guess. However, it is often difficult for users to know how to create hard-to-guess passwords.

Azure AD Password Protection allows you to eliminate easily guessed passwords and customize lockout settings for your environment., the feature lets you:

? Protect accounts in Azure AD and Windows Server Active Directory by preventing users from using passwords from a list of more than 500 of the most commonly used passwords, plus over 1-million-character substitution variations of those passwords.

? Manage password protection for Azure AD and on-premises Windows Server Active Directory from a unified admin experience in the Azure portal.

? Customize Azure AD smart lockout settings and specify a list of added company specific passwords to block.

For more information, refer to the links below:

? Watch this video: Ensure all your users have strong passwords with Azure Active Directory Password Protection

? Learn how to: Eliminate bad passwords in your organization ? Follow: Azure AD Password Protection on-premises - Frequently asked questions.

Pricing and Licensing Requirements

Refer to Azure AD Password Protection License requirements for cloud as well as on-premises users. Additional licensing information, including costs, can be found on the Azure Active Directory pricing page.

Key Benefits

The key benefits with Azure AD Password Protection are:

Improved Security You can eliminate the easily guessed passwords and lower the risk of compromise by a password spray attack with access to the Microsoft Global banned password list of compromised passwords.

Exercise Control You can also customize your Azure AD smart lockout settings and specify a list of company specific passwords to block.

Unified Admin Experience You can manage password protection for Azure AD and on-premises Windows Server Active Directory from a unified admin experience in the Azure portal.

Customer Stories/Case Studies

To learn more about customer and partner experiences with Azure AD Password Protection, visit - See the amazing things people are doing with Azure.

Announcements/Blogs

Azure AD receives improvements on an ongoing basis. To stay up to date with the most recent developments, see What's new in Azure Active Directory?

Blogs by the Tech Community and Microsoft Identity Division:

? April 02, 2019, Azure AD Password Protection is now generally available! ? October 14, 2018, Email Phishing Protection Guide ? Part 15: Implement the Microsoft Azure AD Password

Protection Service (for On-Premises too!)

Training/Learning Resources

The section provides concepts, role-based guidance, and lists the various training resources available for Azure AD Password Protection.

Level 100 Knowledge/Concepts

Refer to the following links:

? Watch this video: Ensure all your users have strong passwords with Azure Active Directory Password Protection

? Learn how to Eliminate bad passwords in your organization. Understand the following concepts: o What is a Global banned password list? o What is a Custom banned password list? o What are the On-premises hybrid scenarios for Azure AD Password Protection? o Understand How are passwords evaluated o Azure AD Password Protection License requirements o What do users see when they try to reset with a banned password.

? Learn how to Enforce Azure AD password protection for Windows Server Active Directory. This includes: o What are the Azure AD Password Protection Design principles? o How Azure AD Password Protection supports Incremental deployment? o What is the Architectural diagram for Azure AD Password Protection? o How password protection works o What is the Forest/tenant binding for password protection? o How do you Download the installers for Azure AD Password Protection?

? Understand Configuring the custom banned password list ? What are Azure Active Directory smart lockout settings? ? What are the Azure AD Password Protection on-premises - Frequently asked questions?

Role-Based Guidance

IT Administrator Staff

Learn how you can manage password protection on Azure AD and on-premises Windows Server Active Directory from a unified admin experience in the Azure portal. Here are some useful links to help you get started:

? Learn the Security baseline (FINAL) for Windows 10 v1903 and Windows Server v1903 ? Watch this video- Ensure all your users have strong passwords with Azure Active Directory Password

Protection ? How to Eliminate bad passwords in your organization. ? How to Enforce Azure AD password protection for Windows Server Active Directory. ? What are Azure Active Directory smart lockout settings? ? Understand Configuring the custom banned password list ? What are Azure AD Password Protection on-premises - Frequently asked questions? ? How do you do Azure AD Password Protection troubleshooting? ? What is Azure AD Password Protection agent version history?

Help Desk Staff

? Refer to Azure AD Password Protection on-premises - Frequently asked questions ? For additional questions, you can also view the MSDN forum. ? If you cannot find the answer to a problem, our support teams are always available to help you- Contact

Microsoft support

................
................

In order to avoid copyright disputes, this page is only a partial summary.

Google Online Preview   Download