Hybrid IAM with O365 and AWS

%3CLINGO-SUB%20id%3D%22lingo-sub-2546567%22%20slang%3D%22en-US%22%3EHybrid%20IAM%20with%20O365%20and%20AWS%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2546567%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20Team%2C%3C%2FP%3E%3CP%3EI%20have%20a%20below%20scenario%20to%20discuss%20and%20looking%20for%20a%20single%20IAM%20solution.%3C%2FP%3E%3CP%3E-%20Business%20units%20(%203%20%3A(%3C%2Fimg%3E%3CBR%20%2F%3E-%20A%2C%20B%20%26amp%3B%20C%3C%2FP%3E%3CP%3E-%20200%20employees%20in%20each%20business%20unit%20i.e%20around%20600%20users%3C%2FP%3E%3CP%3E-%20Users%20email%20accounts%20are%20Microsoft%20O365%20accounts%3C%2FP%3E%3CP%3E-%20No%20local%20AD%20currently%20and%20no%20ADFC%20in%20place%3C%2FP%3E%3CP%3E-%203%20different%20tenants%20on%200365.%201%20for%20each%20business%20unit%20i.e%20A%2C%20B%20%26amp%3B%20C%3C%2FP%3E%3CP%3E-%20users%20machines%20are%20in%20a%20workgroup%3C%2FP%3E%3CP%3E-%20Business%20Applications%20are%20hosted%20in%20AWS%20(SaaS%20services%20mostly)%3C%2FP%3E%3CP%3E%3CBR%20%2F%3E**Solution%20required%3A**%3C%2FP%3E%3CP%3E-%20Single%20IAM%20solution%20for%20the%20company%20as%20its%20difficult%20to%20manage%20and%20control%20the%20distributed%20IDs%20all%20over%20the%20place%3CBR%20%2F%3E-%20Machines%2Flaptops%20need%20to%20be%20domain%20joined%20and%20local%20workgroup%20profiles%20need%20to%20me%20migrated%20to%20target%20domain%3C%2FP%3E%3CP%3E%3CBR%20%2F%3E**My%20thought%20process%3A**%3CBR%20%2F%3E-%20Setup%20local%20AD%20from%20A%20domain%2Fbusiness%20unit%20(Have%20separate%20OU%20to%20manage%20other%20business%20units).%20Local%20AD%20will%20become%20single%20source%20of%20Identities%20and%20can%20be%20managed%20centrally%3CBR%20%2F%3E-%20Make%20it%20hybrid%20using%20Azure%20AD%20Connect.%20Sync%20IDs%20to%20O365%20Azure%20AD%20tenenats%20with%20UPN%3CBR%20%2F%3E-%20Setup%20SSO%20using%20federation%20between%20AWS%20SaaS%20applications%20with%20local%20AD.%3CBR%20%2F%3E-%20Bring%20workgroup%20machines%20into%20the%20domain%20and%20migrate%20local%20profiles%20to%20domain%20profiles%20on%20the%20machines%20using%203rd%20party%20tools%3C%2FP%3E%3CP%3E**Challenges%3A**%3CBR%20%2F%3E-%20Is%20it%20possible%20to%20sync%20single%20AD%20source%20through%20Azure%20AD%20connect%20to%20multiple%20O365%20Azure%20AD%20tenants%20(as%20we%20have%203%20in%20the%20scenario)%3F%20And%20with%20UPN%3CBR%20%2F%3E-%20If%20I%20create%20new%20IDs%20in%20local%20AD%20and%20sync%20them%2C%20what%20will%20actually%20happen%20to%20the%20existing%20O365%20IDs%20for%20users%20in%20Azure%20AD%3F%20and%20how%20these%20IDs%20will%20be%20merged%20as%20users%20already%20have%20an%20email%20account%20with%20emails%2C%20calendar%2C%20etc.%3F%3CBR%20%2F%3E-%20Is%20it%20possible%20to%20set%20up%20a%20Federation%20between%20AWS%20SaaS%20Services%20and%20local%20AD%20using%20ADFS%20or%20is%20there%20any%20way%20to%20probably%20create%20a%20Federation%20between%20Azure%20AD%20and%20AWS%20Saas%20application%3F%3C%2FP%3E%3CP%3E%3CBR%20%2F%3EAny%20pointers%20will%20be%20helpful%20to%20achieve%20IAM%20for%20the%20above%20scenario%3C%2FP%3E%3CP%3EThanks%20in%20advance%3C%2FP%3E%3CP%3ERegards%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E
Occasional Contributor

Hi Team,

I have a below scenario to discuss and looking for a single IAM solution.

- Business units ( 3 :(
- A, B & C

- 200 employees in each business unit i.e around 600 users

- Users email accounts are Microsoft O365 accounts

- No local AD currently and no ADFC in place

- 3 different tenants on 0365. 1 for each business unit i.e A, B & C

- users machines are in a workgroup

- Business Applications are hosted in AWS (SaaS services mostly)


**Solution required:**

- Single IAM solution for the company as its difficult to manage and control the distributed IDs all over the place
- Machines/laptops need to be domain joined and local workgroup profiles need to me migrated to target domain


**My thought process:**
- Setup local AD from A domain/business unit (Have separate OU to manage other business units). Local AD will become single source of Identities and can be managed centrally
- Make it hybrid using Azure AD Connect. Sync IDs to O365 Azure AD tenenats with UPN
- Setup SSO using federation between AWS SaaS applications with local AD.
- Bring workgroup machines into the domain and migrate local profiles to domain profiles on the machines using 3rd party tools

**Challenges:**
- Is it possible to sync single AD source through Azure AD connect to multiple O365 Azure AD tenants (as we have 3 in the scenario)? And with UPN
- If I create new IDs in local AD and sync them, what will actually happen to the existing O365 IDs for users in Azure AD? and how these IDs will be merged as users already have an email account with emails, calendar, etc.?
- Is it possible to set up a Federation between AWS SaaS Services and local AD using ADFS or is there any way to probably create a Federation between Azure AD and AWS Saas application?


Any pointers will be helpful to achieve IAM for the above scenario

Thanks in advance

Regards,

 

 

0 Replies