Azure AD Custom Security Attributes

Поделиться
HTML-код
  • Опубликовано: 3 дек 2024
  • НаукаНаука

Комментарии • 34

  • @NTFAQGuy
    @NTFAQGuy  2 года назад +8

    Adding your own custom attributes to Azure AD to store info and control access to other resources! Please make sure to read the description for the chapters and key information about this video and others.
    ⚠ P L E A S E N O T E ⚠
    🔎 If you are looking for content on a particular topic search the channel. If I have something it will be there!
    🕰 I don't discuss future content nor take requests for future content so please don't ask 😇
    Thanks for watching!
    ☁🤙💪

  • @lltagged
    @lltagged 2 года назад +1

    So for the first 40ish minutes, I was like 'why on earth would I need this in my tenant?'.
    Now I just want to get started on tagging everything. Thanks for another great vid!

  • @IulianSandulache
    @IulianSandulache 2 года назад +1

    Great video, i just had a client posing me questions regarding custom security attributes. Things are clear now and i can help him.
    Thanks John.

  • @christianibiri
    @christianibiri 2 года назад +2

    This is a great great video, at the beginning was hard to understand, but I had watched 2 times and now it is crystal clear for me! a huge thanks!!!

  • @CloudContext
    @CloudContext 2 года назад +1

    Awesome, can definitely think of a few clients who will want this.

  • @dosto-evsky
    @dosto-evsky 2 года назад

    Thank you Sir, awesome video, took almost all day to consume, much appreciated, looks very powerful.

  • @alwehliye
    @alwehliye 2 года назад

    Massive thanks John! Your content are always awesome.

  • @mattblaker1127
    @mattblaker1127 2 года назад +1

    once again another great video!

    • @NTFAQGuy
      @NTFAQGuy  2 года назад

      Glad you enjoyed it!

  • @simonkeen9776
    @simonkeen9776 2 года назад +1

    Awesome content thanks John!
    Hope you don't mind if I go ahead and start using this in production😅

  • @monsterpuss
    @monsterpuss 2 года назад

    thanks for explaining this so clearly in your own inimitable way. I have 2 questions:
    1) If I had an app that allowed emplyees of grade c and above to perform some kind of activity (changing stock levels for example), whereas people of grade d and below could only read stock levels, could that all be handled by assigning the app a managed identity and then allowing that managed identity to read the relevant attributes from the attribute set?
    2) What happens to custom/extended attributes in ADDS (on-prem). If I understand things correctly at present, those attributes don't transefer across to cloud identities? Does this change with AAD custome attributes? Is there some way in AD Connect to map fields across?

    • @NTFAQGuy
      @NTFAQGuy  2 года назад +1

      Apps could view the values and act accordingly including mi. Don’t sync from on prem today and you should look at Aad connect config as there are attributes today that sync from ad

  • @ZATennisFan
    @ZATennisFan 2 года назад

    Another great video.....

  • @jeremyahagan
    @jeremyahagan 2 года назад

    Would be useful in conjunction with sensitivity labels

  • @prasantchettri133
    @prasantchettri133 2 года назад

    I wish this could be used for device account

  • @samuraialbany
    @samuraialbany 2 года назад

    Hi John, thanks for another wonderful video! I have a scenario where I would love to use a custom attribute for users that would allow me to assign tp dynamic use groups. Existing attributes won’t work. Could I use this or is their another approach?

    • @NTFAQGuy
      @NTFAQGuy  2 года назад +1

      Aad already has dynamic groups that can be based off attributes.

  • @kauffmann101
    @kauffmann101 2 года назад

    John , there should be a wrong spelling on some topics in the content list , it should be RBAC instead of ABAC. Great contents as usual !

    • @NTFAQGuy
      @NTFAQGuy  2 года назад +4

      No its ABAC. That is the point.

  • @10010110101
    @10010110101 2 года назад +2

    Can these be used to pass to a saml token with an SSO application tied to AAD?

    • @NTFAQGuy
      @NTFAQGuy  2 года назад +1

      Not yet

    • @ppguitars
      @ppguitars 2 года назад +1

      This would be very useful!

  • @dejvoch
    @dejvoch 2 года назад

    Hi John,
    Thank you for the video.
    I really like that Global Admin by default don't see everything, so attributes could be used for sensitive data and only particular users could access it. So ti could be use for HR data as well.
    From technical perspective, if I want to drive permissions using these Security attributes, what I understood, these are mainly useful for Azure resources permissions - VM, Blob, whatever. However it is meant not to be for driving permissions for User / groups objects in Azure AD, correct?
    Scenario: I have a country admin, let's say "admin.germany" and I want him to fully manage AAD objects (mainly Users, Groups) which belongs to Germany, I was wondering whether this can be used for such case?
    For now I use the Administrative Units, however I don't like it much because the list (members of AU) has to be maintained manually.
    Thanks for tips.
    Also, another question - could those security attributes be used for Exchange RBAC scoping?

    • @NTFAQGuy
      @NTFAQGuy  2 года назад +1

      Recommend post to reddit. Sadly I can't read and help with questions of this length. Just don't have time. Sorry.

  • @hope42
    @hope42 2 года назад

    Hi John, was wonder if you got my post or should I try posting again?

    • @NTFAQGuy
      @NTFAQGuy  2 года назад

      There are lots of posts every day, I really don’t track and just try to respond where possible.

    • @hope42
      @hope42 2 года назад

      I posted again, saw it, but it looks like it was removed. @@NTFAQGuy

    • @hope42
      @hope42 2 года назад

      RUclips says they marked my comment as possible spam and you have to release it in the RUclips Studio Comments/Held for review. I gave you kudos for your best video yet. Not sure why they marked it as Spam.

    • @NTFAQGuy
      @NTFAQGuy  2 года назад

      @@hope42 don’t know but don’t see anything but appreciate you liking the videos. 🤙

  • @imperionllc
    @imperionllc 2 года назад

    Do any of these attributes sync back on prem?

    • @NTFAQGuy
      @NTFAQGuy  2 года назад

      No

    • @dejvoch
      @dejvoch 2 года назад

      @@NTFAQGuy I wish the answer to be "not yet" rather than No.

    • @NTFAQGuy
      @NTFAQGuy  2 года назад

      @@dejvoch The flow is nearly always AD to AAD with AD source of truth. Very few things every flow AAD to AD. Also I cannot speak to future.