When evaluating your organization’s technology choices, there are a few different angles to took at it from:
Usefulness – Do the pieces of tech that make up your stack accomplish what you need them to in the most efficient way possible?
Total cost of ownership – Is your TCO where you want it to be, or can it be improved with different tools?
User experience – Is your chosen tech easy to use? Does it save or suck IT’s time?
Employee experience – How does your technology affect the employee experience at your company? Is it promoting productivity and happiness or frustrating and holding up end users?
This article focuses on the employee experience aspect of your tech evaluation process.
Consider this:69% of employees are more likely to remain at your company for 3 years if they have a positive onboarding experience. Though onboarding is just one small piece of the employee experience puzzle, it’s an important one, and your technology is the foundation of your onboarding processes.
This is important because if your tech isn’t up to par, then your workflows become disconnected and inefficient, and HR and IT will either have to work harder to make up for that, or your onboarding and identity lifecycle management tasks will be substandard. This leads to IT and HR frustration and burnout, decreased productivity on the end user’s part, and unsatisfied employees, which all negatively affects your bottom line.
A good starting point when evaluating your IT tech stack from the angle of how your tech impacts the employee experience is to survey employees with tech- and IT-specific questions. Here are a handful to get you started:
10 Tech Stack and Employee Experience Questions
Onboarding
1.Rate your onboarding experience in the following areas:
a. Device setup (1-5 scale)
b. Access setup (1-5 scale)
c. Technical orientation (1-5 scale)
2. Did you have access to everything technology-wise that you needed on day 1 of your employment? (Yes/No)
Role and/or Access Changes
3.Have you changed roles or responsibilities since joining the organization? (Yes/No)
a. If yes, rate your role change experience (1-5 scale)
b. If yes, did you have to reach out to IT or HR to fix anything after your role change, or was it all handled correctly behind the scenes? (Had to reach out./Everything was handled appropriately.)
If they answer that they had to reach out, you can provide a box for them to further explain the issue.
4. Have your access needs changed over time for any other reason? (Yes/No)
a. If yes, rate how efficiently this was handled (i.e., Did your privileges change in a timely manner to allow you to be productive?) (1-5 scale)
b. If yes, rate how effectively this was handled (i.e., When your privileges were changed, did you have everything you needed to be productive?) (1-5 scale)
Remote/In-Office Work
5.At any point with our organization, did you switch between in-office and remote work? (Yes/No)
a. If yes, when switching from in-office to remote work, did IT and HR ensure that you were set up to be productive from the moment you changed your work style? (Yes/No)
6. When working from a new location, was your technical experience impacted in a negative way? (i.e., Were you able to access everything you needed with the appropriate security measures in place?) (Yes/No/NA)
Specific Tools
7. How satisfied are you with the apps, software, and other tools you use on a daily basis? (1-5 scale)
Credentials
8. How satisfied are you with the efficiency and ease of daily login processes? (1-5 scale)
9. How satisfied are you with our password management tool? (1-5 scale)
General Pulse Check
10.How satisfied are you with the preparedness of the IT department based on past interactions you’ve had? (1-5 scale)
Creating Your Survey
All of the questions listed here are general suggestions to get you started with evaluating your tech stack vs your employees’ experiences. Modify or remove them as you see fit – feel free to make them more specific or allow employees to write in open-ended answers, to give you a better picture of how your tech truly impacts each person’s day-to-day responsibilities.
If you’re looking to improve the employee experience at your organization, it’s important to find and employ technology that connects seamlessly and reduces any current tech disruptions that your end users face. A good place to start is by ensuring that IT’s directory service and HR’s tool of choice connect well. Employee experience and security issues often begin when these two tools don’t work well together, leading to even bigger issues down the line.
About Version 2 Digital
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.
Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.
About JumpCloud At JumpCloud, our mission is to build a world-class cloud directory. Not just the evolution of Active Directory to the cloud, but a reinvention of how modern IT teams get work done. The JumpCloud Directory Platform is a directory for your users, their IT resources, your fleet of devices, and the secure connections between them with full control, security, and visibility.
Until recently, Windows was the de facto platform of choice in the working world as businesses set up their networks on the Microsoft operating system.
They used Word for word processing, Excel for spreadsheet work, PowerPoint for presentations, and Active Directory for domain management. However, the old paradigm has been shifting for some time now.
While Windows-based PCs and laptops are still the market leaders for large and small-to-medium-sized enterprises (SMEs), many organizations have begun to adopt Mac, Linux, and Android devices. Improved usability, convenience, and affordability are commonly cited reasons for switching.
Translation: administrators must manage and control access to their Azure Active Directory from different types of devices and operating systems.
So, can you bind a Mac to Azure Active Directory?
Let’s find out.
Mac and Azure AD: Unwilling Bedfellows
The short answer is yes — you can bind Mac to Azure. But as you can imagine, it is far from straightforward.
Competitors hardly find incentives to make life easy for each other. Think of Pepsi and Coke’s cola wars or Nike and Adidas’ sportswear battles; they’ve been at it for decades. Apple and Microsoft are no different.
With Microsoft’s Azure being a leading access management solution, many IT managers have found themselves being the grass that suffers the pinch between the giant boots of these two tech giants.
Since its release in 2000, Active Directory (AD) has been a staple for Windows networks. It provides users and IT admins with identity management, access control, and policy enforcement for Windows servers, desktops, and laptops.
Azure Active Directory (AAD) is Microsoft’s cloud-based version of its traditional on-premise Active Directory service. It allows businesses to securely access their applications and resources from anywhere on their windows device.
However, the problem arises when it comes to Apple’s Macs. While Microsoft has done an excellent job of making Windows computers compatible with AAD, the same cannot be said for Mac users.
The Challenge of Binding Macs to Azure AD
The challenge of binding Macs to Azure Active Directory is twofold:
No thanks to the Apple-Microsoft rivalry, there is no native integration between Macs and AAD.
Even when workaround solutions exist, ensuring a seamless user experience can also take time and effort.
For example, some admins have taken a cobbled approach of creating a domain within Azure using the Azure AD Domain Services (AD DS) before setting up a VPN connection between their Macs and the Azure domain. The problem, however, is that this solution is complicated and even discouraged by Microsoft.
Others, which already utilize Active Directory, can choose to implement an on-prem directory extension. However, this presents a new set of challenges, from extra costs to more infrastructure to manage.
In addition, this doesn’t enable direct Mac integration into Azure AD. Instead, admins are left with a non-future-proof method of managing endpoints.
The Solution: Step Out of Platforms And Into Identity
A better approach that IT admins take to resolve this problem is to think away from platforms and into identity.
Rather than relying on a cobbled solution that requires managing multiple directories or on-prem extensions, cloud identity management solutions such as the JumpCloud Directory Platform provide a single-user directory that can manage all users’ access to the network and other applications from one central platform.
This solution enables admins to bind not only Macs but also Windows, Linux, and other devices to Azure Active Directory in an intuitive and hassle-free manner. With JumpCloud, admins can securely manage users’ AAD access, regardless of their device or platform.
Also, IT teams that leverage other cloud-computing platforms, such as Amazon’s AWS, or Google Workspace, needn’t worry about managing different identities.
Users can access every network or resource with a single identity, such as Wi-Fi, VPN, web applications, legacy LDAP application, and on-prem or cloud-based file storage solutions. This configuration creates a true single sign-on (SSO) experience for users, making it more convenient and secure.
Manage Identity with the JumpCloud Directory Platform
JumpCloud provides an all-in-one solution for IT admins to bind Macs to Azure Active Directory without any of the earlier-mentioned problems. It’s an identity provider that delivers secure, cloud-based access services to users regardless of their devices.
The platform streamlines user experiences with SSO while unifying admin tools for mobile device management (MDM), multi-factor authentication (MFA), and compliance controls behind one pane of glass. Want to get a better handle on your heterogeneous environment? Watch our demo video and sign up for a free trial today.
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.
Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.
About JumpCloud At JumpCloud, our mission is to build a world-class cloud directory. Not just the evolution of Active Directory to the cloud, but a reinvention of how modern IT teams get work done. The JumpCloud Directory Platform is a directory for your users, their IT resources, your fleet of devices, and the secure connections between them with full control, security, and visibility.
Microsoft Intune is a cloud-based enterprise mobility and security (EMS) management solution that enables organizations to manage mobile devices. It integrates with other components of Microsoft’s EMS platform, including Azure Active Directory (AAD) and Azure Information Protection (AIP), allowing IT teams to enforce security policies and manage how endpoints are used in the organization.
Intune allows organizations to achieve a productive mobile workforce without worrying about corporate data security. For example, IT teams can set rules and configure security policies for various devices, whether those devices are corporate-owned or personal. This helps organizations implement bring your own device (BYOD) policies while mitigating security concerns.
However, despite these benefits, Intune has only traditionally supported devices running Windows, macOS, iOS, and Android operating systems (OSs). This left out Linux-based devices that many companies use to maintain workloads out of the picture for a long time. Toward the end of 2022 however, Microsoft finally added Linux workstation support to Intune — starting with Ubuntu.
Does Intune Support Linux?
The short answer is yes. In October 2022, Microsoft announced that Microsoft Endpoint Manager (MEM) added Linux-based devices to its unified endpoint management solution, with general availability for Ubuntu LTS.
However, Microsoft has yet to release support for other distros which means IT teams are either leaving other types of Linux workstations unmanaged or using other third-party mobile application management (MAM) and mobile device management (MDM) tools.
What’s Been Discussed?
Companies need to ensure that all endpoints are secure and compliant. In this regard, IT teams need to ensure that they mitigate compliance issues by deploying software and patches to all device types, including Linux endpoints. Effective Linux MDM is particularly challenging due to the many flavors of Linux distributions.
With Linux support added to Intune, IT teams can theoretically use a unified console to manage devices and apply the same protection policies and configurations for Linux workstations. Whether Microsoft is able to accomplish that for more distros after Ubuntu remains to be seen.
Having cross-platform support in an MDM is essential because the integration of multiple operating systems into one tool streamlines:
Cloud-Based Management
If IT teams are able to combine all the applications and device controls in one cloud-based endpoint management system, they can then apply policies and endpoint configurations in the same way across a heterogenous IT environment for added security and compliance.
In addition, a unified MDM allows organizations to move their employees closer to Zero Trust security architecture and cover their entire IT infrastructure. For example, IT teams can apply management controls such as password policies, Wi-Fi profiles, and certificates in a standard way across all cloud-managed endpoints.
Compliance
Adding Linux support to an existing MDM enables companies to more easily enforce compliance policies and standards. For example, IT teams can create rules and configuration settings such as the minimum RHEL version that devices need to meet to be considered compliant.
IT teams can also create application policies that provide an extra layer of protection, allowing employees to access them on personal devices securely. Most importantly, IT teams can also take actions for non-compliance, like sending notifications to the user.
Conditional Access Policies
Determining if the device is compliant is one of the outcomes of cloud management. In a Microsoft-specific ecosystem, MEM allows organizations to assess the device’s posture while sending signals to AAD. If MEM finds that the device is compliant, it applies conditional access configurations. These configurations combine device compliance signals with other signals such as user identity risks to secure access to enterprise resources through adaptive policies.
With Intune, Microsoft’s goal is to allow IT teams to set AAD Conditional Access policies for Linux devices, as it does for Windows, macOS, iOS, and Android endpoints. This would ensure that only compliant Linux devices can access enterprise resources such as Microsoft 365 applications.
However, note that the current release only provides conditional access policies protecting web applications via Microsoft Edge. This is an example of Microsoft attempting to lock admins and users further into the Microsoft ecosystem, without allowing for the flexibility of choice in IT tools.
The Good News? A Linux Device Management Alternative Already Exists
Even if Microsoft succeeds with its Intune Linux management framework, the approach will still face some challenges. This is because of the differences between Microsoft’s approach to identity and access management (IAM) and other open source solutions.
For example, while Microsoft’s approach is to create segmented solutions that seamlessly integrate with Azure, the same cannot be said about non-Windows platforms like Linux-based OSs. Additionally, it is those very same segmented solutions that force users into Microsoft products and add additional complexity and cost for IT admins.
If you’d prefer to have a cloud-based MDM that provides the openness you need to choose the best tools and IT resources for your stack, while still resolving compliance and security issues in a heterogeneous environment, then you should consider JumpCloud® as an alternative cloud directory service.
As an open directory platform and unified MDM, JumpCloud centralizes identity and system management, irrespective of OS. It can overcome the common “admin black hole” associated with managing Linux devices, and help you reduce the number of IT tools your organization has to pay for and manage to fully secure its IT environment.
Whether you need patch management, encryption and lock-screen policies, MFA, or other capabilities applied to the Linux devices in your fleet, JumpCloud supports the following distros:
Amazon Linux 2 on x86_64 and ARM64 processors
Amazon Linux 2022 (AL2022) on x86_64 and ARM64 processors
CentOS 7, 8
Debian 10, 11 on x86_64 and ARM64 processors
Fedora 35, and 36
Mint 19, 20, 21 Cinnamon on x86_64 and ARM64 processors
RHEL 8, 9 on x86_64 and ARM64 processors
Rocky Linux 8, 9 on x86_86 and ARM64 processors
Ubuntu 18.04 (64 bit), 20.04, and 21.04, and 22.04 on x86_64 and ARM64 processors
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.
Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.
About JumpCloud At JumpCloud, our mission is to build a world-class cloud directory. Not just the evolution of Active Directory to the cloud, but a reinvention of how modern IT teams get work done. The JumpCloud Directory Platform is a directory for your users, their IT resources, your fleet of devices, and the secure connections between them with full control, security, and visibility.
Editor’s Note: Given the fast-paced nature of technology, it is possible that some of the information presented in this article is out-of-date, or incomplete, in some fashion. The author periodically reviews and revises this article to ensure information contained within is as accurate as possible.
Microsoft® Azure® is an umbrella for a variety of cloud services, including Azure Active Directory (AAD). On its face, Azure AD might seem like a replacement for on-prem Active Directory (AD) or a cloud-based solution for organizations in need of a directory service, but more factors come into play for IT admins making purchasing decisions, including complicated SKUs and licensing. This article examines the total cost of ownership (TCO) of AAD for the type of configuration that a small and medium-sized enterprise (SME) would require for its identity management lifecycle.
AAD was created to extend on-prem AD identities to Azure in order to provide user management for Microsoft Office applications, and now single sign-on (SSO) for service providers (SP). It’s available as a standalone product, but is also bundled with Microsoft 365 (M365) subscriptions. Microsoft has positioned AAD as the connective tissue within a broader identity and access management (IAM) ecosystem. That extends from users and devices to its security portfolio. Add-ons and integrations are almost inescapable, because AAD is very interwoven with those products. It’s not even possible to implement Microsoft’s best practices for AAD without paying more.
A Codependent Approach
Significantly, Microsoft manages endpoints separately from identities even though experts recommend making identity the new perimeter in cybersecurity. Device management (outside of AD) is only bundled with some of its premium M365 SKUs, but not AAD. Organizations that aren’t using M365 will have to purchase a separate subscription to manage their devices.
Microsoft’s reference architecture suggests an array of Microsoft-based tools to fully leverage AAD, so even Microsoft-heavy IT shops will encounter more IT infrastructure and maintenance costs. You’ll have limited administrative capabilities if you use AAD without on-prem AD, or aren’t subscribed to premium tiers and add-on services. For example, you won’t be able to employ the suite of group policy objects (GPOs) to on-prem Windows devices, and you’ll struggle with authenticating local IT resources such as applications and file servers.
AAD is also not an open directory, so working with external identities from other identity providers (IP) and connecting users to IT resources (RADIUS, LDAP) requires even more solutions. Some are cloud-based, but others expand its footprint on-premise, and are reliant on AD.
Costs of Azure Active Directory
To fully assess the TCO of Azure AD, it’s necessary to account for tangential, but necessary, costs. Fortunately, we’ve developed an equation to help you understand the TCO of AAD:
Costs of Azure Active Directory = Azure AD Premium Package + Add-Ons for device management + External Identities + Azure AD DS + Active Directory + LDAP Server + RADIUS Server + Integration/Management Time for your implements
Let’s begin by assessing AAD’s pricing and then branch outward to the other components.
Standalone Azure AD and M365
Standalone AAD has three SKUs:
AAD Free – AAD Free provides SSO to Microsoft apps and federation to other SAML/OIDC services. This version is feature-limited with no group management, limited MFA configurations, limits on directory objects per user, and various other restrictions.
Premium 1 (P1) – P1 introduces SSO sign-in page customizations, conditional access rules, role-based group assignments to applications, end-user self-service for passwords and MFA, additional cloud security, and options for authenticating users into local Windows apps.
Premium 2 (P2) – P2 adds risk-based identity protection, more self-service capabilities, as well as identity governance and compliance such as privileged access and entitlements management. Logging and reporting is also more comprehensive.
Image credit: learn.microsoft.com
M365 subscriptions also bundle AAD. It’s not even possible to use M365 without AAD, which serves as its substrate for managing your users. Some admins encounter AAD through Office.
Its directory features are gated off into multiple tiers:
M365 Business Premium – This includes device management and security services to protect identities.
M365 E1 – Device management isn’t included and AAD is limited.
M365 E3 – This edition includes device management and AAD P1.
M365 E5 – This edition includes device management and AAD P2.
M365 F3 – This edition includes device management and AAD P1.
Enterprise Mobility + Security (EMS) E3 – This edition includes device management and AAD P1.
EMS E5 – This edition includes device management and AAD P2.
Image credit: Microsoft
Device Management
AAD sounds a lot like AD, but it doesn’t perform the same role; for example, it won’t manage your devices. Microsoft established its Intune product lineup to manage Android/Chrome, Apple, Linux, and Windows endpoints. It uses AAD to manage identities, Configuration Manager (formerly SCCM), in addition to Windows Defender for security and Autopilot for onboarding Windows devices. Intune may be bundled with M365, depending upon your subscription level. However, Intune is not included with AAD P1 or P2, and that omission will increase your monthly costs per user.
Intune includes enterprise-grade features and can be a useful tool for compliance and managing non-Windows devices for organizations that have many remote workers. However, it also has documented downsides. SMEs that are accustomed to AD may be unfamiliar with its quirks:
Unpredictable time spent importing the provisioning of devices, assigning profiles, and deploying apps.
Simple mistakes can cause actions to fail, such as a Registry key requirement rule filtering out devices.
Problems with assigning available licenses to new users.
Configuration changes taking a long time to go into effect.
Loss of internet connectivity causing Windows Autopilot to fail.
The cost of learning, implementing, and supporting Intune is another TCO consideration.
Azure Active Directory Domain Services
Intune is not the only option for Microsoft shops. Azure Active Directory Domain Services (Azure AD DS) is billed as a domain controller-as-a-service for virtual machines and legacy applications. It’s charged for the hour, and the price is based on the number of directory objects.
Per Microsoft, “Azure AD DS provides a managed domain for your users, applications, and services to consume. This approach changes some of the available management tasks you can do, and what privileges you have within the managed domain.”
Azure AD DS differs from on-prem AD in a number of ways, including its lack of domain or enterprise administrator privileges. You also cannot add on-prem domain controllers to the managed domain.
If you use AAD and Azure AD DS in conjunction with on-prem AD — which is necessary if you want full AD capabilities — you’ll have to factor in the associated costs for that as well.
Managing External Identities
Microsoft Entra is necessary to manage external (non-Microsoft) identities and devices. There’s a charge for every single MFA authentication for non-Microsoft identities such as Google Workspace. In addition, AAD P1 or P2 licenses are necessary to work with external identities.
Complex Licensing
If you think that AAD is the right solution for your organization, you’ll have to dig through the pricing and SKUs outlined above. It goes without saying that the pricing model is complicated, and non-system access needs may also obligate you to purchase more CALs. You should begin by understanding your current situation. If you have a Microsoft Enterprise Agreement, Open Volume agreement, or are part of the Cloud Solutions Program, you will have a right to certain functionality (Basic and Premium depending upon your specific agreement).
If your IT organization isn’t a part of any of those programs, yet you’ve purchased Azure or M365, you can purchase the right Premium Azure AD services. It’s possible for SMEs to overspend on AAD or be upsold by a Microsoft partner due to the complexity of its licensing, so it’s important to take the time to understand your requirements versus what you’re paying for.
Image credit: Reddit
Complicated Setup and Migrations
The breadth of potential configurations, critical need to understand security best practices, and overall complexity can make adopting AAD a major initiative. Most SMEs aren’t experts in Microsoft licensing and seek assistance for their implementations. For instance, AAD’s default settings can place your users at risk of phishing attacks that can even bypass MFA. IT teams that are migrating from products such as AD FS or have multiple domains in a forest will face some technical considerations that may be unclear and unfamiliar. Microsoft’s guidance states:
“If you have multiple on-premises domains in a forest, we recommend storing and synchronizing information for the entire forest to a single Azure AD tenant. Filter information for identities that occur in more than one domain, so that each identity appears only once in Azure AD, rather than being duplicated. Duplication can lead to inconsistencies when data is synchronized. For more information, see the Topology section below.”
That can be significant work for an SME.
The realization that adopting AAD can be very cumbersome has given rise to a cottage industry of consultants, and many organizations purchase blocks of hours to support their deployments. In-house resources may not be enough. Factor implement costs into your TCO calculations.
Cost of Active Directory
Active Directory represents a number of costs for organizations, including servers, software, and licensing. SMEs will also have to maintain a server room, which can add significant costs.
Servers: Domain Controllers
If you use Azure AD with on-prem AD, servers are an obvious cost. You either need to maintain a server room or spin up AD in a virtual environment, both of which must factor into the TCO of Azure AD. You need to budget for the costs of redundant servers, too, in case your primary domain controller (DC) fails. High availability (HA) is automatic whenever there’s more than one DC. That makes it possible to shut down a server for maintenance without impacting your end users.
A task from an IT department’s project to set up high availability
Objects are automatically replicated throughout the server cluster and administration is more complex: e.g., add-on apps must be installed and updated on each DC. Adding additional servers to achieve HA may increase licensing, management, and other infrastructure costs.
Software: Windows Server
Beyond the cost of the servers themselves, you’ll need to purchase the software to be installed on them. Since 2016, Windows Server licensing has been on a per CPU core pricing structure, rather than the previous per socketed CPU structure. Admins can purchase those licenses in 2- or 16-packs. You may need to stand up multiple servers for all of the required server roles.
An example of new CALs being required without Software Assurance volume licensing
Hardening AD for Security
It can take more than a work week to secure AD to recommended best practices. Maintaining AD alongside AAD could dramatically increase IT overhead and administrative costs.
A statement of work to harden a domain controller — the total cost was $6,485.95
Advanced Identity Lifecycle Management
AD isn’t Zero Trust and identity lifecycle management is a manual process unless SMEs develop automations or use third-party solutions. That increases the risk that users may be over or under-provisioned, or that inactive accounts remain in use. Managing users in AD can be a disjointed, error-prone process. The risk of data exfiltration is higher with manual processes, which creates a financial risk as laws and regulations are treating violations more seriously. AAD’s advanced identity management policies can extend AD and improve upon it, but only with P1, P2 subscriptions. Azure AD Connect is required to sync identities between AD and AAD.
Server Rooms
An accumulation of hardware, servers, and network equipment means you’ll be spending more for your server room. Eventually, you’ll require a more powerful core switch or better firewall. “Better” translates to more expensive and potentially unplanned downtime on your network as well as new annual support costs, change management, and backups of your configurations.
Support renewal costs for upgraded firewalls at a manufacturing company
Then, you’ll have to establish physical security controls and ideally, fire suppression. An inert gas system requires sealing a room and having dedicated HVAC. Other solutions for special hazards, including in-rack fire suppression, are also costly. See here for an example:
Part of a quote for a server room’s fire suppression upgrade
Microsoft promises consolidation, but its solutions can be a wellspring of added administration.
This next section explores non-systems requirements and challenges AAD creates for SSO.
LDAP Server
AAD and AD lack SSO to everything, especially the core protocols that network devices or Wi-Fi networks use. This can lead to identity silos and duplicate authentication flows. Microsoft promises consolidation, but its solutions can be a wellspring of added administration.
If you aren’t hosting all your server infrastructure in Azure, you’ll also need to manage the associated identity management costs to manage user access to other cloud infrastructure providers such as AWS® and GCP. Some of these platforms offer their own managed Active Directory services, so you can potentially leverage those managed AD services, but you’ll need to make sure that they can connect back to your other AD infrastructure and/or with Azure. None of this work is easy, and it can add a great deal of fragility to your IAM environment.
Azure AD doesn’t come with cloud LDAP functionality, so you’ll need to maintain an LDAP server, as well as service on-prem LDAP applications and MFA solution, if required. Azure AD DS is also required to sync passwords and group memberships from Active Directory. Azure AD DS allows organizations to migrate legacy applications to Azure entirely, but that service represents an additional cost as well as the work around the migration of applications which is not an easy task in most instances.
Image credit: Microsoft
RADIUS Server
Azure AD does not come with cloud RADIUS functionality either. Instead, you’ll need to spin up a RADIUS server, use the NPS server role or another cloud service to have the capability of managing Wi-Fi and VPN access. You’ll also require a secondary authentication method. JumpCloud makes it possible to leverage AAD credentials for delegated authentication. Many network devices use RADIUS for authentication, and the lack of support makes initiatives such as compliances more difficult. Auditors often want devices, down to switches, protected by MFA.
Vendor Lock-In
This level of platform integration may be beneficial for “all Microsoft and Azure” organizations. However, the lack of interoperability through an open directory and continued reliance on AD adds costs, complexity, and administrative overhead. That level of monoculture and high dependence on a single vendor makes it more difficult to adopt “best-of-breed” solutions.
With the changing IT landscape, the good news is that IT organizations are leveraging a wider range of platforms. This requires a different set of IT management tools, and specifically, it involves the core identity provider. Using Azure AD encourages the use of Azure throughout your entire environment. AAD, like AD, obligates the use of Microsoft infrastructure and services/applications. This strategy has been successful for Microsoft in the past, and the company is employing it again to work to lock-in customers into Microsoft platforms.
Microsoft’s promotion of IT consolidation has been successful from a sales perspective, but it doubles down on vendor lock-in. In contrast, an open directory platform provides value lock-in.
Evaluating Azure Active Directory
Azure AD might be the solution for a Microsoft shop that already has AD established and needs to extend their IT resource management to the cloud. However, organizations should assess their existing stack and whether Azure AD will address all their needs before making the purchase. Beyond Azure AD, organizations will likely need to purchase Intune for device management. Azure AD DS is also necessary to maintain Azure AD Connect (along with their on-prem AD instance), as well as RADIUS and LDAP instances and other add-ons. These all represent cost centers. Azure AD is not an all-in-one solution, but does meet certain use cases.
Resource to Calculate TCO
JumpCloud released a TCO Guide and TCO Calculator to help IT admins understand the complete costs of different solutions used in their environment. We also invite you to try JumpCloud, which is free and full-featured for 10 uses and devices. It may help extend AD in the way that your organization needs to adapt to change or meet compliance requirements without hassle. JumpCloud is
JumpCloud’s open directory platform delivers select features found in AAD, Entra, and Intune with an emphasis on what’s best for SMEs. Those capabilities are available without gated licensing, tethering your team to legacy systems, or complicated workarounds. It’s priced to enable workflows, versus charging more for advanced identity lifecycle management. JumpCloud enables IT unification, as opposed to consolidating with a single vendor.
Software renewals come out of the capital expenditures (CAPEX) budget, which is a major long-term expenditure versus operating expenses (OPEX), the day-to-day operational budget. Accounting makes a distinction between software and services. Using services helps your organization to lower its income taxes and free up cash. Services may make it easier to budget when you already know what the ongoing costs will be.
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.
Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.
About JumpCloud At JumpCloud, our mission is to build a world-class cloud directory. Not just the evolution of Active Directory to the cloud, but a reinvention of how modern IT teams get work done. The JumpCloud Directory Platform is a directory for your users, their IT resources, your fleet of devices, and the secure connections between them with full control, security, and visibility.
MariaDB is an open source and community-developed fork of MySQL. It is a widely used relational database management system (RDMS) used to store data both in production and for personal and experimental projects. It was designed by the original developers of the MySQL database server, with the objective of remaining open source under the GNU GPL license.
Some of the advantages of using MariaDB over MySQL include:
Strong security thanks to additional security features such as user roles, PAM and LDAP authentication, data encryption, and role-based access control (RBAC).
High performance thanks to more and better storage engines such as Aria and XtraDB. The former replaces MyISAM in MySQL and offers better caching. XtraDB replaces InnoDB and improves performance.
Galera clustering which ensures scalability, high availability, and zero loss of data through replication.
Integrated monitoring using microsecond precision and extended user statistics.
In this guide, we will demonstrate how to install and secure MariaDB on RHEL 9.
Step 1: Upgrade Software Packages
To get started, log into your server as a sudo user via SSH. Next, upgrade all the packages and refresh the repositories as follows:
$ sudo dnf update
The MariaDB Server package is provided by the official AppStream repositories. You can confirm this by searching for the package on the repositories as shown:
$ sudo dnf search mariadb-server
The following output confirms that MariaDB is hosted on the default repositories.
Step 2: Install MariaDB Server on RHEL 9
The next step is to install the MariaDB Server. To do so, run the following command:
$ sudo dnf install mariadb-server -y
The command installs the MariaDB server alongside other dependencies and additional packages required by the database server.
Once the installation is complete, confirm that MariaDB is installed using the following command:
$ rpm -qi mariadb-server
Running this command displays comprehensive details about the MariaDB Server package including the name, version, architecture, installation date, and installed size to name a few.
Step 3: Start and Enable MariaDB Server
Up to this point, we have successfully installed the MariaDB Server. By default, the MariaDB service does not start automatically. As such you need to start it by running the following command:
$ sudo systemctl start mariadb
In addition, set it to start automatically on system startup.
$ sudo systemctl enable mariadb
To verify that MariaDB is up and running, run the command:
$ sudo systemctl status mariadb
MariaDB listens on TCP port 3306. You can confirm this using the command:
$ sudo ss -pnltu | grep mariadb
Step 4: Secure MariaDB Server
The default settings for the MariaDB database server are considered weak and not robust in the face of a breach or intrusion. As such, you need to go an extra step and secure the database server. To do this, run the mysql_secure_installation script as shown:
$ sudo mysql_secure_installation
Running the script will present you with a series of prompts.
First, you will be required to provide the root password. Next, switch to unix_socket authentication which allows the user to use operating system credentials when connecting to the MariaDB database server.
You can then decide to change the root user or let it remain exactly the way it is.
For the remaining prompts, press “Y” in order to secure MariaDB to the recommended standards. This does the following:
Removes anonymous users from the database server. This prevents the risk of having anyone log into MariaDB without having a user account.
Disallows remote root login. This ensures that only the root user is allowed to connect from ‘localhost’ or the server on which MariaDB is installed. This prevents brute-force attacks using the root user password.
Removes a test database called test which can be accessed by anyone and is only used for testing. Its removal is recommended before transitioning to a producing environment.
Reloads the privilege tables. Hence, saves all the changes made.
MariaDB is now secured using the recommended security standards after installation.
Step 5: Log Into MariaDB Server
To log in to the MariaDB database server, run the command:
$ sudo mysql -u root -p
Provide the root password for MariaDB and press ENTER. This ushers you to the MariaDB shell.
To check the version of MariaDB installed, run the command:
SELECT VERSION();
From the output, you can see that we are running MariaDB 10.5.16.
To list all the databases, run the command:
SHOW DATABASES;
Step 6: Create Database and Database User (Optional)
This step illustrates how to create a database and a database user.
To create a database in the MariaDB Server, run the following command where test_db is the database name:
CREATE DATABASE test_db;
Next, create a database user on the system with a password. Here, test_user is the name of the database user and P@ssword321@ is the user’s password. Be sure to provide a stronger password for your user.
CREATE USER 'test_user'@'localhost' IDENTIFIED BY 'Password321@';
Next, grant privileges to the database user on the database. This determines the rights that the user has on the database, e.g., ALTER, CREATE, DELETE, DROP, SELECT, UPDATE, etc. This command will grant user rights to the database.
GRANT ALL ON test_db.* TO 'test_user'@'localhost' WITH GRANT OPTION;
Lastly, reload the grant tables in order to save the changes made as follows:
FLUSH PRIVILEGES
To confirm the creation of the database, again, run the following SQL query:
SHOW DATABASES;
This time around, an additional database named test_db appears on the list.
To view a list of all the users in the database server, run the following query:
SELECT User, Host FROM mysql.user;
Conclusion
In this guide, you learned how to install and secure the MariaDB database server on RHEL 9. For more information about MariaDB, check out the official documentation.
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.
Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.
About JumpCloud At JumpCloud, our mission is to build a world-class cloud directory. Not just the evolution of Active Directory to the cloud, but a reinvention of how modern IT teams get work done. The JumpCloud Directory Platform is a directory for your users, their IT resources, your fleet of devices, and the secure connections between them with full control, security, and visibility.