Exploring the Real Relationship Between Azure AD and Azure Subscriptions

Поделиться
HTML-код
  • Опубликовано: 22 июл 2024
  • In this video I walk through the relationship between Azure AD and Azure subscriptions exploring common concerns, questions and identifying what is real and what we can do.
  • НаукаНаука

Комментарии • 90

  • @dudeus
    @dudeus 3 года назад +6

    Please don’t stop doing videos. You have no idea how much these help us. Thank you so much.🙏

  • @henriquealexandreh
    @henriquealexandreh Год назад

    Short but precious video. Thanks again John!

  • @eamonsalimi5660
    @eamonsalimi5660 3 года назад +1

    WoW, this is by far the best explanation on this matter, keep it up 👍

  • @pakhong9986
    @pakhong9986 2 года назад

    You are awesome man, thanks a lot for clarifying the concepts ! !

  • @laxminarayanarora4670
    @laxminarayanarora4670 4 года назад +6

    I really admire love like... your videos the most :) . Your presentation skills and depth of knowldge is unique.

    • @NTFAQGuy
      @NTFAQGuy  4 года назад

      Very kind, thank you!

  • @sylviawylie9218
    @sylviawylie9218 2 месяца назад

    Generic comment to show my appreciation. Keep winning John!

  • @laxminarayanarora4670
    @laxminarayanarora4670 4 года назад +1

    We underprivileged and don't have good resources generally and cant manage good learning stuff frequently nether can enroll in good courses to learn AZURE, your channel is only HOPE for us.
    Long Live you and your channel !

    • @NTFAQGuy
      @NTFAQGuy  4 года назад

      Good luck and remember there are free Azure trials and certain services that are always free to help you learn at no cost.

  • @vinodhkumar2156
    @vinodhkumar2156 3 года назад

    Like your way of presentation on the topics you deliver. subscribed

    • @NTFAQGuy
      @NTFAQGuy  3 года назад

      Thanks and welcome

  • @Dechkaon
    @Dechkaon 4 года назад +1

    Liked and subscribed. Good work there John

  • @kenrq63
    @kenrq63 4 года назад +1

    Another concise and useful video John, thank you very much.

    • @NTFAQGuy
      @NTFAQGuy  4 года назад

      Thanks!

    • @NTFAQGuy
      @NTFAQGuy  4 года назад

      Did your coin arrive yet? :)

    • @kenrq63
      @kenrq63 4 года назад

      @@NTFAQGuy Not yet John. I will let you know when it arrives :-)

    • @kenrq63
      @kenrq63 3 года назад

      @@NTFAQGuy Yes, my coin arrived today, thank you very much. It is very cool :-)

    • @NTFAQGuy
      @NTFAQGuy  3 года назад +1

      Ken RQ great to hear, sorry it took so long! Crazy!

  • @matrixman20101
    @matrixman20101 4 года назад +1

    Thank you , May I ask you if you can also sometimes share the work experience , in terms to the issues during the migration to the cloud and risks and concerns , and even integration with 3rd party tools , I think it'll be also more informative , real case scenarios :), thank you in advance ! cheers

  • @ibrahimabdeltawab6418
    @ibrahimabdeltawab6418 2 года назад

    So informative! Thanks so much ❤️

    • @NTFAQGuy
      @NTFAQGuy  2 года назад +1

      Glad it was helpful!

  • @madhurbhardwaj7284
    @madhurbhardwaj7284 3 года назад

    once again as usual excellent video....

  • @DAngotti22
    @DAngotti22 Год назад

    Helpful! Thanks John!

  • @ronaldvanackooij5139
    @ronaldvanackooij5139 4 года назад

    Hi John, great video (again) ;).
    I would like you to address some time on this topic related to CSP Azure plans and subscriptions, as it is enormous important that the customer understands that the CSP is by default owner of that subscription. You can remove that inherited security principal that resembles a group in the CSP AAD tenant, which for a lot of organization I would definitely advise to look at, or request (at least) the procedures they have in-place to allow their staff to have access to their customer's resources.

    • @NTFAQGuy
      @NTFAQGuy  4 года назад +1

      Thanks. I'll think about that. Honestly I don't deal with CSP so have little experience with them or their impact. I'll have to dig into it.

    • @jochenjuelke265
      @jochenjuelke265 3 года назад

      @ronald Yes cap model brings some more aspects to subscriptions ;) you can technically remove the cup providerˋs permission (aobo, admin on behalf of;, a special service principal) BUT from commercial site the csp then gets no more discount from ms billing)

  • @anandchandrashekhar2933
    @anandchandrashekhar2933 2 года назад

    The video series is better than Pluralsight content. Thank you John

    • @NTFAQGuy
      @NTFAQGuy  2 года назад

      Glad you enjoy it

  • @sreekanth5009
    @sreekanth5009 2 года назад

    Awesome 👌 👏

  • @elanshudnow
    @elanshudnow 4 года назад

    Great video. I think the only thing I would have liked to see discussed is when using Management Groups, a Global Administrator in AAD can add themselves to User Access Administrator which then allows them access to the Subscriptions underneath.

    • @NTFAQGuy
      @NTFAQGuy  4 года назад +1

      management groups are really separate from this (in fact I cover this on my last Azure update on this channel :-) ). You don't need management groups for GA to get user access administrator and get sub access. management groups are great for governance on the azure resources (including RBAC) but not much to do with AAD relationship with subs.

    • @elanshudnow
      @elanshudnow 4 года назад

      John Savill Very good point. Thank you. You ever run into customers that have a huge problem with Global Admins being able to gain access to Azure Subscriptions so easily via User Access Administrator?

    • @NTFAQGuy
      @NTFAQGuy  4 года назад +1

      Sometimes however generally should really limit who has ga. Most trusted :) use pim etc

  • @Carlesgl81
    @Carlesgl81 4 года назад +1

    Great video again John! Any amazing shirt 👕 this time but in any case, the content and the explanation deserves to be shared on LinkedIn. Quick question, as far as I understood, as owner/admin, you are able to create as many AADs as you want, right? Like for example, one for test, one for dev and one for prod correct? Thanks!

    • @NTFAQGuy
      @NTFAQGuy  4 года назад +1

      Anyone can create as many aads as they want. That is the point. They are not related to subscription rights.

  • @cnchandroo
    @cnchandroo 4 года назад

    Thanks John for this wonderful video. Is it possible for you to take a video on Azure AD B2B? I am sure you already did this, but just want to know any additional features in Azure AD B2B and what is the different between this and SPO external sharing, etc.,
    Thanks once again.

    • @NTFAQGuy
      @NTFAQGuy  4 года назад +1

      I already did a pretty deep dive on b2b. It’s on this channel. Thanks.

  • @ahmadabdalla90
    @ahmadabdalla90 4 года назад

    Great as usual! Where I see this a bit concerning, is let’s say an organisation is using PIM to grant temporary permissions as ‘Owner’ for specific use cases (i.e Locks management), if they become rogue, and move a subscription, the entire RBAC model falls apart including PIM since it’s tied to the home AAD tenant. And even rolling back this action is a nightmare because SPNs, managed identities, users and groups will need to be reassigned 😂

    • @NTFAQGuy
      @NTFAQGuy  4 года назад +2

      Yes, owner is super powerful and really careful consideration should be used for its use. Some companies don’t have anyone with owner and use processes for any owner type operations. Whenever you move a sub all rbac is ripped out.

    • @ahmadabdalla90
      @ahmadabdalla90 4 года назад

      Agreed, and in the end even if it’s a ‘zero trust’ model, You would still have some level of trust with users possessing such roles or even smaller roles. Btw the Load balancer video was awesome, would be great to have one covering all load balancing technologies side by side compared deep dive ☺️☺️

    • @elvirkaric1449
      @elvirkaric1449 4 года назад

      @@NTFAQGuy - yes "Owner" is powerful but I think that is in the case of "pay as you go" model. With CSP you will have "service account" that is owner for all of your subscriptions and only that account can transfer subscription out of your AAD (all this is done in different portal then portal.azure.com). P.S. I like your explanations of Azure topics.

    • @NTFAQGuy
      @NTFAQGuy  4 года назад

      Elvir Karic interesting, thanks. I don’t have much interaction with CSP. Note owner also applies to ea enrollments, not just pay as you go.

    • @renes34
      @renes34 3 года назад

      @@NTFAQGuy My MSDN based subscription has an "Account Admin" role (unique, attached to the account that set the subscription up) it is the only one that can transfer subscriptions. Nobody with "Owner" rights can. Just like the "service account" story from Elvir I guess. "Owners" can't also access Payment Methods under Subscriptions, they will get a pop-up telling them that only "Account Admins" can access this info.
      Maybe a little too soon, but my conclusion is that the "Owner" role is not the absolute owner of a subscription".
      Indeed GREAT videos, many many thanks.

  • @gauravsharma8220
    @gauravsharma8220 2 года назад

    your are always great👍

  • @daothman
    @daothman 3 года назад +1

    Nice video, Any resources on how to integrate Azure from different companies during a company acquisition ?

    • @NTFAQGuy
      @NTFAQGuy  3 года назад

      I have videos on things like b2b and migrate technologies. Different aspects to consider

  • @taylorfusion
    @taylorfusion 4 года назад

    I’ve just begun watching your channel. I enjoy the whiteboard and then tenant demonstrations. I would like, however to request that when you sketch names that you take better care in writing them so that they are easily viewable. Many of your acronyms are inconsistent and hard to read and they dilute your message beyond the time you’re speaking them. Thanks for the channel!

    • @NTFAQGuy
      @NTFAQGuy  4 года назад +2

      I’ll try and keep that in mind. It’s often a trade off between neatness and keeping the flow going. Appreciate the feedback.

  • @amolpandit7865
    @amolpandit7865 2 года назад

    Great video. For Subscriptions that get created automatically under the tenant (e.g. Visual Studio Sub), do they possess any risk to other subscriptions ?

    • @NTFAQGuy
      @NTFAQGuy  2 года назад +1

      There is no inherent connection between them or permission.

  • @vernondunbar5846
    @vernondunbar5846 4 года назад

    Thank you!

  • @markymarkymarky1974
    @markymarkymarky1974 3 года назад

    John, If I have 2 tenants (tenant 1 is the o365 tenant and tenant 2 is the infrastructure workload tenant), the issue is i need two log logins! what is best practice here? move subscription?

    • @NTFAQGuy
      @NTFAQGuy  3 года назад

      you can add an account as a guest (b2b) to the other.

  • @monsterpuss
    @monsterpuss 4 года назад

    Would it be possible to extend the explanation to include Enterprise Enrollments?

    • @NTFAQGuy
      @NTFAQGuy  4 года назад +1

      Enterprise enrollments don't change anything about relationship between Azure AD and subscriptions. The enterprise enrollment will trust a certain Azure AD for its RBAC/account/dept owners etc. (the first AAD login of the enrollment) The subscriptions will trust the AAD of the subscription creator (since you could have dept/account admins from other tenants). HTH

  • @LarsEllerhorst
    @LarsEllerhorst 4 года назад +2

    Hi John, the video is quite interesting but I would prefer more analogies with the Active Directory on premise. Since a lot of admins are moving from the classical AD on prem and supposing they know that system it would be easier to highlight similarities and differences here. As I understand Azure AD it is just a specialized AD for the cloud. Basically the forest root is onmicrosoft.com and each tenant is a subdomain. Relationships between the domains can be umderstood as the old trusted relationships of NT4 domains; they are not trusted until explicid configured to do so, e.g. B2B relations. In this sense I would compare a subscription object like an email account, which can be migrated on premise from one domain to another; you keep the emails but the server location, group memberships, login & password etc. may change. If I'm wrong let me know.

    • @NTFAQGuy
      @NTFAQGuy  4 года назад

      No, that is not correct, they are completely different. You should watch my Azure AD overview. Azure AD is nothing like AD so that may be why you think I should talk about AD. The reality is AD has really nothing to do with this particular conversion. Check out my other videos should help clear up the confusion. Marketing use the Azure AD name but there is no AD in it really ;-) B2B is not relationship between AAD tenants, its a single guest with no relationship between tenants and can even be from gmail, msa or an email with OTP. onmicrosoft.com is just part of the default name of domains, e.g. savilltech.onmicrosoft.com but then I can give custom name. There is no onmicrosoft.com domain, its just part of the DNS name. There is no root onmicrosoft.com domain because there is no AD here. No trusts, no forest, no tree etc. No kerberos (normally) :-)

    • @LarsEllerhorst
      @LarsEllerhorst 4 года назад

      @@NTFAQGuy Thanks for the clarification. To me it always seemed to be quite similar.

    • @NTFAQGuy
      @NTFAQGuy  4 года назад

      @@LarsEllerhorst yeah, the names make it confusing but really they are completely different with different goals. In the next couple of weeks I'll be posting an identity video where I'll go into detail on Azure AD which will help a lot and also how AD relates to AAD.

    • @LarsEllerhorst
      @LarsEllerhorst 4 года назад

      @@NTFAQGuy Thanks, looking forward to it. I always thought, regarding AD Connect or ADFS, both are quite similar, just Azure AD a different flavour to accommodate to the needs being hosted in a cloud environment. So much parts seems to be equal, user objects, computer objects, the hierarchy, ACLs etc.

    • @NTFAQGuy
      @NTFAQGuy  4 года назад

      @@LarsEllerhorst right AAD Connect replicates objects from AD to Azure AD. ADFS can be used to federate the authentication from AAD to use AD. They have same type of objects like users and groups (but so do most systems with identities :-) ) but fulfil different use cases. I think the video will fill in the gaps. But things like hierarchy, there is no hierarchy, ACLs are a common component across nearly any system but once again different with AD and AAD. Look for video in couple of weeks but hopefully for now at least understand Azure AD is not AD in the cloud :-)

  • @orlandokelly5011
    @orlandokelly5011 3 года назад

    We have been discussing this very topic at my organisation, my worry is that someone adds a subscription to our AAD, they build an app and let people have the ability access to that application that has not been verified for corporate standards, governance, dpio etc. Maybe that app is asking for personal information, maybe the data is stored in a region that violates our data protection rules. Maybe the app is unsecured and data is exposed publicly. It seems strange any user can spin up a subscription, add users and then maybe use that membership from a corporate level without any oversight. Is this the case, or am I missing something around this. Look forward to your thoughts around this.

    • @NTFAQGuy
      @NTFAQGuy  3 года назад

      If you worried about an app then that is what governance will provide. Have the root mg in place and you’ll know if subscriptions are added can apply policy and rbac. On the user info side that is really about guest access and there are ways to restrict permissions of guests to a certain level.

  • @dheerajkumarsolanki5716
    @dheerajkumarsolanki5716 3 года назад

    How Azure Tenant related to AAD and Azure Subscription?

    • @NTFAQGuy
      @NTFAQGuy  3 года назад

      Azure tenant is an AAD instance.

  • @Timmy-Hi5
    @Timmy-Hi5 3 года назад +1

    Hey John, at the 11th minute , what would be then the best practices of Subscription owners. For example we do not want to give this to humans, but automate it. If we automate how to protect it. No worries don't need full A-Z tutorials 😁 🙈 just some pointers 🍺💪🇬🇧

    • @NTFAQGuy
      @NTFAQGuy  3 года назад +1

      Some companies would only have pipelines with that kind of permission and the pipelines would be controlled as to what they are doing. Many companies are not super concerned, there is a level of trust to people you make subscription owners and worse case you can take ownership and move back.

    • @Timmy-Hi5
      @Timmy-Hi5 3 года назад

      @@NTFAQGuy 🇬🇧💪 thanks 👍

  • @tilikumtim5562
    @tilikumtim5562 4 года назад

    Is it generally best practice to create a management group, even if you only have 1 subscription?
    Oh and your videos are great, you explain things really clearly.

    • @NTFAQGuy
      @NTFAQGuy  4 года назад

      The nice thing about management groups is you can turn them on and move things around at any time. If you just have one subscription you really don’t need to yet. Use them when you want to use rbac/policy/budget at a higher level.

    • @tilikumtim5562
      @tilikumtim5562 4 года назад

      @@NTFAQGuy Thanks for the explanation!

  • @WafaPRO
    @WafaPRO 3 года назад +1

    GREEEEEEAT

  • @cloudstrife7083
    @cloudstrife7083 4 года назад

    Do you have a path for study for Azure ? I mean once your good with Windows Server and creating Active Directory Users share files and all that offline what's the path to learn Azure correctly ? I am asking this because like I told you in the past I study Linux and Windows Server together
    Do you feel like going back to programming at times ? Learning web development or C# and have a great career well paid doing remote work ?

    • @NTFAQGuy
      @NTFAQGuy  4 года назад

      I’m about to release my azure master class which will be a good starting point for people. Good luck!

    • @cloudstrife7083
      @cloudstrife7083 4 года назад

      @@NTFAQGuy How expensive it will be ? How good are you with Linux now ?

    • @NTFAQGuy
      @NTFAQGuy  4 года назад +1

      Masterclass will be free and no adverts etc like all my other RUclips videos.

    • @cloudstrife7083
      @cloudstrife7083 4 года назад

      @@NTFAQGuy ok thank you thought it was a bundle on a paying site like udemy and the others etc
      Have you studied Linux and Cisco a little ? What do you think of programming ?

    • @NTFAQGuy
      @NTFAQGuy  4 года назад

      I've created content for Pluralsight and they have a high standard. I've never looked at Udemy. I would focus more on the instructor but first exhaust the free materials. Having at least a basic knowledge of programming I think is useful for scripting etc. I have never dabbled with Cisco. You have to decide what path you want to take. Jack of all trades, master of none :-)

  • @denkozlov4220
    @denkozlov4220 2 года назад

    Emmm as a newbie in Azure I felt even more confused watching this vid. Maybe i'll come back to it later when I grasp more idea about the Azure.

    • @NTFAQGuy
      @NTFAQGuy  2 года назад

      This is not a beginner video. Start with the getting started with azure playlist

  • @haidaraltaiar
    @haidaraltaiar Год назад

    Great video thank you