ADFS works with both cloud-based and on-premises deployments. It is a self-managed solution that can be deployed on-premises or in Azure VMs. ADFS can operate without Azure identity management services. It creates endpoints with unique IDs for authentication, which can work across a hybrid environment.
Azure Active Directory is a centralized, cloud-based identity as a service (IDaaS) solution which creates multiple directories for each directory service. It can operate purely on the cloud without an on-premises deployment. Azure AD creates users, groups, and other entities.
A key difference between the two technologies is that Azure AD creates a Security Token Service (STS) instance that binds every Azure Active Directory to its users. An endpoint provided by Microsoft decides how to route requests between Azure Active Directory instances—this process is known as home realm discovery. The multi-tenancy of Azure AD makes it a more popular solution.
The main advantage of Azure AD vs ADFS is that it works to connect company-hosted resources to Azure AD, even when those on-premises infrastructures cannot access the cloud at all.
Currently, the main use cases for using ADFS with Office 365 and Azure AD are:
Related content: Read our guide to Azure AD SSO
ADFS works better with Azure for several reasons:
Microsoft provides an alternative SSO solution called Seamless SSO, which is part of Azure AD Connect (explained in more detail below). This solution automatically logs users in when they use a corporate device connected to the corporate network. When Seamless SSO is enabled, users can log in to Azure AD without entering a password. Sometimes users can even log in without a username.
Read how Pathlock’s integration with Microsoft Azure Active Directory provides enterprises with an identity governance solution SOX, SoD, & others.
Azure AD Connect provides a connection between on-prem identity systems and Azure AD. It allows you to manage identities using a hybrid public cloud and on-premise infrastructure. When you integrate the on-premise directories with Azure AD, the service offers features that help you manage identity more easily, allowing the users of your on-premise systems to access cloud resources.
Azure AD Connect provides the following features:
One advantage of integrating on-premises directories with Azure AD is its contribution to productivity. Integration ensures that users have a common identity to access cloud and on-premise resources. For example, it makes it easier for users to access cloud services like Microsoft 365.
Azure AD Connect allows you to leverage the latest capabilities for your hybrid environment. It replaces older identity integration solutions like Azure AD Sync and DirSync.
Azure AD Connect uses the following architecture to integrate between on-premise AD forests and Azure AD:
Forests are the largest units in Active Directory, containing one or more AD trees. The Azure AD Connect provisioning engine establishes a connection between Azure AD on one end and the forests on the other. It then imports (i.e., reads) the information from the directories. Exports initiate updates to the provisioning engine. Sync operations evaluate the rules governing how objects travel through the engine.
Azure AD Connect enables synchronization between Azure AD and the on-premise Active Directory using several rules, processes, and staging areas:
Learn more in our detailed guide to Azure AD connect
Pathlock is the leader in Access Governance for business-critical applications. Staying compliant with Sarbanes-Oxley is a critical business requirement, and Pathlock Control helps to automate the compliance process. As a MISA member, Pathlock can bring these capabilities to users of Azure Active Directory, with tight integration between the solutions.
Customers rely on Pathlock to streamline critical processes like fine-grained provisioning, separation of duties, and detailed user access reviews. With Pathlock’s out-of-the-box integration to Azure Active Directory, customers can enjoy the best of both worlds, including:
Interested to learn more about the winning combination of Pathlock and Azure Active Directory? Request a demo today to see the solution in action!
Share