Exploring the Real Relationship Between Azure AD and Azure Subscriptions

  Рет қаралды 32,418

John Savill's Technical Training

John Savill's Technical Training

Күн бұрын

Пікірлер: 88
@dudeus
@dudeus 3 жыл бұрын
Please don’t stop doing videos. You have no idea how much these help us. Thank you so much.🙏
@laxminarayanarora4670
@laxminarayanarora4670 4 жыл бұрын
We underprivileged and don't have good resources generally and cant manage good learning stuff frequently nether can enroll in good courses to learn AZURE, your channel is only HOPE for us. Long Live you and your channel !
@NTFAQGuy
@NTFAQGuy 4 жыл бұрын
Good luck and remember there are free Azure trials and certain services that are always free to help you learn at no cost.
@henriquealexandreh
@henriquealexandreh 2 жыл бұрын
Short but precious video. Thanks again John!
@laxminarayanarora4670
@laxminarayanarora4670 4 жыл бұрын
I really admire love like... your videos the most :) . Your presentation skills and depth of knowldge is unique.
@NTFAQGuy
@NTFAQGuy 4 жыл бұрын
Very kind, thank you!
@eamonsalimi5660
@eamonsalimi5660 4 жыл бұрын
WoW, this is by far the best explanation on this matter, keep it up 👍
@NTFAQGuy
@NTFAQGuy 4 жыл бұрын
Thanks a lot!
@kenrq63
@kenrq63 4 жыл бұрын
Another concise and useful video John, thank you very much.
@NTFAQGuy
@NTFAQGuy 4 жыл бұрын
Thanks!
@NTFAQGuy
@NTFAQGuy 4 жыл бұрын
Did your coin arrive yet? :)
@kenrq63
@kenrq63 4 жыл бұрын
@@NTFAQGuy Not yet John. I will let you know when it arrives :-)
@kenrq63
@kenrq63 4 жыл бұрын
@@NTFAQGuy Yes, my coin arrived today, thank you very much. It is very cool :-)
@NTFAQGuy
@NTFAQGuy 4 жыл бұрын
Ken RQ great to hear, sorry it took so long! Crazy!
@anandchandrashekhar2933
@anandchandrashekhar2933 3 жыл бұрын
The video series is better than Pluralsight content. Thank you John
@NTFAQGuy
@NTFAQGuy 3 жыл бұрын
Glad you enjoy it
@pakhong9986
@pakhong9986 3 жыл бұрын
You are awesome man, thanks a lot for clarifying the concepts ! !
@daothman
@daothman 4 жыл бұрын
Nice video, Any resources on how to integrate Azure from different companies during a company acquisition ?
@NTFAQGuy
@NTFAQGuy 4 жыл бұрын
I have videos on things like b2b and migrate technologies. Different aspects to consider
@sylviawylie9218
@sylviawylie9218 8 ай бұрын
Generic comment to show my appreciation. Keep winning John!
@vinodhkumar2156
@vinodhkumar2156 4 жыл бұрын
Like your way of presentation on the topics you deliver. subscribed
@NTFAQGuy
@NTFAQGuy 4 жыл бұрын
Thanks and welcome
@Dechkaon
@Dechkaon 4 жыл бұрын
Liked and subscribed. Good work there John
@NTFAQGuy
@NTFAQGuy 4 жыл бұрын
Thank you!
@elanshudnow
@elanshudnow 4 жыл бұрын
Great video. I think the only thing I would have liked to see discussed is when using Management Groups, a Global Administrator in AAD can add themselves to User Access Administrator which then allows them access to the Subscriptions underneath.
@NTFAQGuy
@NTFAQGuy 4 жыл бұрын
management groups are really separate from this (in fact I cover this on my last Azure update on this channel :-) ). You don't need management groups for GA to get user access administrator and get sub access. management groups are great for governance on the azure resources (including RBAC) but not much to do with AAD relationship with subs.
@elanshudnow
@elanshudnow 4 жыл бұрын
John Savill Very good point. Thank you. You ever run into customers that have a huge problem with Global Admins being able to gain access to Azure Subscriptions so easily via User Access Administrator?
@NTFAQGuy
@NTFAQGuy 4 жыл бұрын
Sometimes however generally should really limit who has ga. Most trusted :) use pim etc
@madhurbhardwaj7284
@madhurbhardwaj7284 3 жыл бұрын
once again as usual excellent video....
@NTFAQGuy
@NTFAQGuy 3 жыл бұрын
Thank you!
@ronaldvanackooij5139
@ronaldvanackooij5139 4 жыл бұрын
Hi John, great video (again) ;). I would like you to address some time on this topic related to CSP Azure plans and subscriptions, as it is enormous important that the customer understands that the CSP is by default owner of that subscription. You can remove that inherited security principal that resembles a group in the CSP AAD tenant, which for a lot of organization I would definitely advise to look at, or request (at least) the procedures they have in-place to allow their staff to have access to their customer's resources.
@NTFAQGuy
@NTFAQGuy 4 жыл бұрын
Thanks. I'll think about that. Honestly I don't deal with CSP so have little experience with them or their impact. I'll have to dig into it.
@jochenjuelke265
@jochenjuelke265 3 жыл бұрын
@ronald Yes cap model brings some more aspects to subscriptions ;) you can technically remove the cup providerˋs permission (aobo, admin on behalf of;, a special service principal) BUT from commercial site the csp then gets no more discount from ms billing)
@matrixman20101
@matrixman20101 4 жыл бұрын
Thank you , May I ask you if you can also sometimes share the work experience , in terms to the issues during the migration to the cloud and risks and concerns , and even integration with 3rd party tools , I think it'll be also more informative , real case scenarios :), thank you in advance ! cheers
@monsterpuss
@monsterpuss 4 жыл бұрын
Would it be possible to extend the explanation to include Enterprise Enrollments?
@NTFAQGuy
@NTFAQGuy 4 жыл бұрын
Enterprise enrollments don't change anything about relationship between Azure AD and subscriptions. The enterprise enrollment will trust a certain Azure AD for its RBAC/account/dept owners etc. (the first AAD login of the enrollment) The subscriptions will trust the AAD of the subscription creator (since you could have dept/account admins from other tenants). HTH
@DAngotti22
@DAngotti22 2 жыл бұрын
Helpful! Thanks John!
@NTFAQGuy
@NTFAQGuy 2 жыл бұрын
You're welcome!
@ibrahimabdeltawab6418
@ibrahimabdeltawab6418 2 жыл бұрын
So informative! Thanks so much ❤️
@NTFAQGuy
@NTFAQGuy 2 жыл бұрын
Glad it was helpful!
@LarsEllerhorst
@LarsEllerhorst 4 жыл бұрын
Hi John, the video is quite interesting but I would prefer more analogies with the Active Directory on premise. Since a lot of admins are moving from the classical AD on prem and supposing they know that system it would be easier to highlight similarities and differences here. As I understand Azure AD it is just a specialized AD for the cloud. Basically the forest root is onmicrosoft.com and each tenant is a subdomain. Relationships between the domains can be umderstood as the old trusted relationships of NT4 domains; they are not trusted until explicid configured to do so, e.g. B2B relations. In this sense I would compare a subscription object like an email account, which can be migrated on premise from one domain to another; you keep the emails but the server location, group memberships, login & password etc. may change. If I'm wrong let me know.
@NTFAQGuy
@NTFAQGuy 4 жыл бұрын
No, that is not correct, they are completely different. You should watch my Azure AD overview. Azure AD is nothing like AD so that may be why you think I should talk about AD. The reality is AD has really nothing to do with this particular conversion. Check out my other videos should help clear up the confusion. Marketing use the Azure AD name but there is no AD in it really ;-) B2B is not relationship between AAD tenants, its a single guest with no relationship between tenants and can even be from gmail, msa or an email with OTP. onmicrosoft.com is just part of the default name of domains, e.g. savilltech.onmicrosoft.com but then I can give custom name. There is no onmicrosoft.com domain, its just part of the DNS name. There is no root onmicrosoft.com domain because there is no AD here. No trusts, no forest, no tree etc. No kerberos (normally) :-)
@LarsEllerhorst
@LarsEllerhorst 4 жыл бұрын
@@NTFAQGuy Thanks for the clarification. To me it always seemed to be quite similar.
@NTFAQGuy
@NTFAQGuy 4 жыл бұрын
@@LarsEllerhorst yeah, the names make it confusing but really they are completely different with different goals. In the next couple of weeks I'll be posting an identity video where I'll go into detail on Azure AD which will help a lot and also how AD relates to AAD.
@LarsEllerhorst
@LarsEllerhorst 4 жыл бұрын
@@NTFAQGuy Thanks, looking forward to it. I always thought, regarding AD Connect or ADFS, both are quite similar, just Azure AD a different flavour to accommodate to the needs being hosted in a cloud environment. So much parts seems to be equal, user objects, computer objects, the hierarchy, ACLs etc.
@NTFAQGuy
@NTFAQGuy 4 жыл бұрын
@@LarsEllerhorst right AAD Connect replicates objects from AD to Azure AD. ADFS can be used to federate the authentication from AAD to use AD. They have same type of objects like users and groups (but so do most systems with identities :-) ) but fulfil different use cases. I think the video will fill in the gaps. But things like hierarchy, there is no hierarchy, ACLs are a common component across nearly any system but once again different with AD and AAD. Look for video in couple of weeks but hopefully for now at least understand Azure AD is not AD in the cloud :-)
@markymarkymarky1974
@markymarkymarky1974 3 жыл бұрын
John, If I have 2 tenants (tenant 1 is the o365 tenant and tenant 2 is the infrastructure workload tenant), the issue is i need two log logins! what is best practice here? move subscription?
@NTFAQGuy
@NTFAQGuy 3 жыл бұрын
you can add an account as a guest (b2b) to the other.
@dheerajkumar.solanki
@dheerajkumar.solanki 3 жыл бұрын
How Azure Tenant related to AAD and Azure Subscription?
@NTFAQGuy
@NTFAQGuy 3 жыл бұрын
Azure tenant is an AAD instance.
@orlandokelly5011
@orlandokelly5011 4 жыл бұрын
We have been discussing this very topic at my organisation, my worry is that someone adds a subscription to our AAD, they build an app and let people have the ability access to that application that has not been verified for corporate standards, governance, dpio etc. Maybe that app is asking for personal information, maybe the data is stored in a region that violates our data protection rules. Maybe the app is unsecured and data is exposed publicly. It seems strange any user can spin up a subscription, add users and then maybe use that membership from a corporate level without any oversight. Is this the case, or am I missing something around this. Look forward to your thoughts around this.
@NTFAQGuy
@NTFAQGuy 4 жыл бұрын
If you worried about an app then that is what governance will provide. Have the root mg in place and you’ll know if subscriptions are added can apply policy and rbac. On the user info side that is really about guest access and there are ways to restrict permissions of guests to a certain level.
@cnchandroo
@cnchandroo 4 жыл бұрын
Thanks John for this wonderful video. Is it possible for you to take a video on Azure AD B2B? I am sure you already did this, but just want to know any additional features in Azure AD B2B and what is the different between this and SPO external sharing, etc., Thanks once again.
@NTFAQGuy
@NTFAQGuy 4 жыл бұрын
I already did a pretty deep dive on b2b. It’s on this channel. Thanks.
@Timmy-Hi5
@Timmy-Hi5 4 жыл бұрын
Hey John, at the 11th minute , what would be then the best practices of Subscription owners. For example we do not want to give this to humans, but automate it. If we automate how to protect it. No worries don't need full A-Z tutorials 😁 🙈 just some pointers 🍺💪🇬🇧
@NTFAQGuy
@NTFAQGuy 4 жыл бұрын
Some companies would only have pipelines with that kind of permission and the pipelines would be controlled as to what they are doing. Many companies are not super concerned, there is a level of trust to people you make subscription owners and worse case you can take ownership and move back.
@Timmy-Hi5
@Timmy-Hi5 4 жыл бұрын
@@NTFAQGuy 🇬🇧💪 thanks 👍
@ahmadabdalla90
@ahmadabdalla90 4 жыл бұрын
Great as usual! Where I see this a bit concerning, is let’s say an organisation is using PIM to grant temporary permissions as ‘Owner’ for specific use cases (i.e Locks management), if they become rogue, and move a subscription, the entire RBAC model falls apart including PIM since it’s tied to the home AAD tenant. And even rolling back this action is a nightmare because SPNs, managed identities, users and groups will need to be reassigned 😂
@NTFAQGuy
@NTFAQGuy 4 жыл бұрын
Yes, owner is super powerful and really careful consideration should be used for its use. Some companies don’t have anyone with owner and use processes for any owner type operations. Whenever you move a sub all rbac is ripped out.
@ahmadabdalla90
@ahmadabdalla90 4 жыл бұрын
Agreed, and in the end even if it’s a ‘zero trust’ model, You would still have some level of trust with users possessing such roles or even smaller roles. Btw the Load balancer video was awesome, would be great to have one covering all load balancing technologies side by side compared deep dive ☺️☺️
@elvirkaric1449
@elvirkaric1449 4 жыл бұрын
@@NTFAQGuy - yes "Owner" is powerful but I think that is in the case of "pay as you go" model. With CSP you will have "service account" that is owner for all of your subscriptions and only that account can transfer subscription out of your AAD (all this is done in different portal then portal.azure.com). P.S. I like your explanations of Azure topics.
@NTFAQGuy
@NTFAQGuy 4 жыл бұрын
Elvir Karic interesting, thanks. I don’t have much interaction with CSP. Note owner also applies to ea enrollments, not just pay as you go.
@renes34
@renes34 4 жыл бұрын
@@NTFAQGuy My MSDN based subscription has an "Account Admin" role (unique, attached to the account that set the subscription up) it is the only one that can transfer subscriptions. Nobody with "Owner" rights can. Just like the "service account" story from Elvir I guess. "Owners" can't also access Payment Methods under Subscriptions, they will get a pop-up telling them that only "Account Admins" can access this info. Maybe a little too soon, but my conclusion is that the "Owner" role is not the absolute owner of a subscription". Indeed GREAT videos, many many thanks.
@amolpandit7865
@amolpandit7865 2 жыл бұрын
Great video. For Subscriptions that get created automatically under the tenant (e.g. Visual Studio Sub), do they possess any risk to other subscriptions ?
@NTFAQGuy
@NTFAQGuy 2 жыл бұрын
There is no inherent connection between them or permission.
@Carlesgl81
@Carlesgl81 4 жыл бұрын
Great video again John! Any amazing shirt 👕 this time but in any case, the content and the explanation deserves to be shared on LinkedIn. Quick question, as far as I understood, as owner/admin, you are able to create as many AADs as you want, right? Like for example, one for test, one for dev and one for prod correct? Thanks!
@NTFAQGuy
@NTFAQGuy 4 жыл бұрын
Anyone can create as many aads as they want. That is the point. They are not related to subscription rights.
@sreekanth5009
@sreekanth5009 2 жыл бұрын
Awesome 👌 👏
@gauravsharma8220
@gauravsharma8220 3 жыл бұрын
your are always great👍
@NTFAQGuy
@NTFAQGuy 3 жыл бұрын
Thank you!
@tilikumtim5562
@tilikumtim5562 4 жыл бұрын
Is it generally best practice to create a management group, even if you only have 1 subscription? Oh and your videos are great, you explain things really clearly.
@NTFAQGuy
@NTFAQGuy 4 жыл бұрын
The nice thing about management groups is you can turn them on and move things around at any time. If you just have one subscription you really don’t need to yet. Use them when you want to use rbac/policy/budget at a higher level.
@tilikumtim5562
@tilikumtim5562 4 жыл бұрын
@@NTFAQGuy Thanks for the explanation!
@vernondunbar5846
@vernondunbar5846 4 жыл бұрын
Thank you!
@NTFAQGuy
@NTFAQGuy 4 жыл бұрын
My pleasure!
@cloudstrife7083
@cloudstrife7083 4 жыл бұрын
Do you have a path for study for Azure ? I mean once your good with Windows Server and creating Active Directory Users share files and all that offline what's the path to learn Azure correctly ? I am asking this because like I told you in the past I study Linux and Windows Server together Do you feel like going back to programming at times ? Learning web development or C# and have a great career well paid doing remote work ?
@NTFAQGuy
@NTFAQGuy 4 жыл бұрын
I’m about to release my azure master class which will be a good starting point for people. Good luck!
@cloudstrife7083
@cloudstrife7083 4 жыл бұрын
@@NTFAQGuy How expensive it will be ? How good are you with Linux now ?
@NTFAQGuy
@NTFAQGuy 4 жыл бұрын
Masterclass will be free and no adverts etc like all my other KZbin videos.
@cloudstrife7083
@cloudstrife7083 4 жыл бұрын
@@NTFAQGuy ok thank you thought it was a bundle on a paying site like udemy and the others etc Have you studied Linux and Cisco a little ? What do you think of programming ?
@NTFAQGuy
@NTFAQGuy 4 жыл бұрын
I've created content for Pluralsight and they have a high standard. I've never looked at Udemy. I would focus more on the instructor but first exhaust the free materials. Having at least a basic knowledge of programming I think is useful for scripting etc. I have never dabbled with Cisco. You have to decide what path you want to take. Jack of all trades, master of none :-)
@haidaraltaiar
@haidaraltaiar 2 жыл бұрын
Great video thank you
@denkozlov4220
@denkozlov4220 3 жыл бұрын
Emmm as a newbie in Azure I felt even more confused watching this vid. Maybe i'll come back to it later when I grasp more idea about the Azure.
@NTFAQGuy
@NTFAQGuy 3 жыл бұрын
This is not a beginner video. Start with the getting started with azure playlist
@WafaPRO
@WafaPRO 4 жыл бұрын
GREEEEEEAT
The Line Between AD and Azure AD!
49:52
John Savill's Technical Training
Рет қаралды 84 М.
Как Ходили родители в ШКОЛУ!
0:49
Family Box
Рет қаралды 2,3 МЛН
진짜✅ 아님 가짜❌???
0:21
승비니 Seungbini
Рет қаралды 10 МЛН
Understanding DNS in Azure
26:59
John Savill's Technical Training
Рет қаралды 126 М.
The Reality Of AI
7:01
ThePrimeagenClips
Рет қаралды 16 М.
Simon Sinek's Advice Will Leave You SPEECHLESS 2.0 (MUST WATCH)
20:43
Alpha Leaders
Рет қаралды 2,7 МЛН
Azure AD Overview
46:21
John Savill's Technical Training
Рет қаралды 130 М.
Azure AD Administrative Units Overview
12:02
John Savill's Technical Training
Рет қаралды 39 М.
Proxy vs Reverse Proxy vs Load Balancer | Simply Explained
13:19
TechWorld with Nana
Рет қаралды 278 М.
Understanding Azure Subscriptions
5:56
CloudStrategist
Рет қаралды 9 М.
Azure AD App Registrations, Enterprise Apps and Service Principals
33:44
John Savill's Technical Training
Рет қаралды 244 М.