{"id":59538,"date":"2022-11-07T17:04:53","date_gmt":"2022-11-07T09:04:53","guid":{"rendered":"https:\/\/version-2.com.sg\/?p=59538"},"modified":"2022-12-02T18:13:33","modified_gmt":"2022-12-02T10:13:33","slug":"azure-ad-best-practices","status":"publish","type":"post","link":"https:\/\/version-2.com\/zh\/2022\/11\/azure-ad-best-practices\/","title":{"rendered":"Azure AD Best Practices"},"content":{"rendered":"\t\t<div data-elementor-type=\"wp-post\" data-elementor-id=\"59538\" class=\"elementor elementor-59538\">\n\t\t\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-35fe5dd post-content elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"35fe5dd\" data-element_type=\"section\" data-e-type=\"section\" data-settings=\"{&quot;jet_parallax_layout_list&quot;:[{&quot;jet_parallax_layout_image&quot;:{&quot;url&quot;:&quot;&quot;,&quot;id&quot;:&quot;&quot;,&quot;size&quot;:&quot;&quot;},&quot;_id&quot;:&quot;cef08c3&quot;,&quot;jet_parallax_layout_image_tablet&quot;:{&quot;url&quot;:&quot;&quot;,&quot;id&quot;:&quot;&quot;,&quot;size&quot;:&quot;&quot;},&quot;jet_parallax_layout_image_mobile&quot;:{&quot;url&quot;:&quot;&quot;,&quot;id&quot;:&quot;&quot;,&quot;size&quot;:&quot;&quot;},&quot;jet_parallax_layout_speed&quot;:{&quot;unit&quot;:&quot;%&quot;,&quot;size&quot;:50,&quot;sizes&quot;:[]},&quot;jet_parallax_layout_type&quot;:&quot;scroll&quot;,&quot;jet_parallax_layout_direction&quot;:&quot;1&quot;,&quot;jet_parallax_layout_fx_direction&quot;:null,&quot;jet_parallax_layout_z_index&quot;:&quot;&quot;,&quot;jet_parallax_layout_bg_x&quot;:50,&quot;jet_parallax_layout_bg_x_tablet&quot;:&quot;&quot;,&quot;jet_parallax_layout_bg_x_mobile&quot;:&quot;&quot;,&quot;jet_parallax_layout_bg_y&quot;:50,&quot;jet_parallax_layout_bg_y_tablet&quot;:&quot;&quot;,&quot;jet_parallax_layout_bg_y_mobile&quot;:&quot;&quot;,&quot;jet_parallax_layout_bg_size&quot;:&quot;auto&quot;,&quot;jet_parallax_layout_bg_size_tablet&quot;:&quot;&quot;,&quot;jet_parallax_layout_bg_size_mobile&quot;:&quot;&quot;,&quot;jet_parallax_layout_animation_prop&quot;:&quot;transform&quot;,&quot;jet_parallax_layout_on&quot;:[&quot;desktop&quot;,&quot;tablet&quot;]}]}\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-409a2e9a\" data-id=\"409a2e9a\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-5a8be8f elementor-widget elementor-widget-text-editor\" data-id=\"5a8be8f\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<article class=\"is-type-body-default is-important\"><p>Identity is the <a href=\"https:\/\/jumpcloud.com\/blog\/2022-fal-con-event-recap\">new perimeter<\/a>. Cyberattacks are becoming more advanced and cloud-focused. Identity providers (IdP) have responded by offering security controls that make it possible for small and medium-sized enterprises (SMEs) to be proactive and mitigate these threats. Many SMEs use Microsoft\u2019s Azure Active Directory (AAD), which has <a href=\"https:\/\/learn.microsoft.com\/en-us\/azure\/security\/fundamentals\/identity-management-best-practices\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">prescribed best practices<\/a> to secure identities. Microsoft reserves several features for its most premium subscriptions levels. IT administrators must determine which <a href=\"https:\/\/learn.microsoft.com\/en-us\/azure\/active-directory\/authentication\/concept-mfa-licensing#available-versions-of-azure-ad-multi-factor-authentication\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">subscription tiers<\/a>, or mixture of supplemental services from an open directory, are most appropriate for their unique security requirements.\u00a0<\/p><p>This article outlines the fundamentals of securing identities in AAD with emphasis on understanding what options are available and tailoring security controls to your organization. Provisioning and identity and access management (IAM) is the starting point, followed by centralizing the identity management lifecycle, adding appropriate controls, and auditing.<\/p><h2 id=\"heading1\">Identity and Access Control<\/h2><p>There are three main paths for provisioning in AAD:\u00a0<\/p><ul><li>HR-driven onboarding.<\/li><li>Federating identity from AAD to cloud apps.<\/li><li>Inter-directory such as between the <a href=\"https:\/\/jumpcloud.com\/blog\/ad-ds\">Active Directory Domain Services<\/a> (AD DS) server role to access resources from your on-prem Active Directory domains.<\/li><\/ul><figure class=\"wp-block-image size-full\"><img fetchpriority=\"high\" decoding=\"async\" class=\"wp-image-71349\" src=\"https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2022\/11\/1-1.png\" sizes=\"(max-width: 512px) 100vw, 512px\" srcset=\"https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2022\/11\/1-1.png 512w, https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2022\/11\/1-1-300x166.png 300w\" alt=\"\" width=\"512\" height=\"283\" \/><figcaption>Image credit: Microsoft<\/figcaption><\/figure><h3>Provision, Manage, and Deprovision Access\u00a0<\/h3><figure class=\"wp-block-image size-full\"><img decoding=\"async\" class=\"wp-image-71350\" src=\"https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2022\/11\/2-1.png\" sizes=\"(max-width: 512px) 100vw, 512px\" srcset=\"https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2022\/11\/2-1.png 512w, https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2022\/11\/2-1-300x178.png 300w\" alt=\"\" width=\"512\" height=\"303\" \/><\/figure><p>Most Microsoft shops have Active Directory (AD). A sync tool called Azure AD Connect syncs users with AAD. Microsoft also accepts non-Microsoft identities for access control, but additional costs may be assessed. Some organizations may have deployed <a href=\"https:\/\/jumpcloud.com\/blog\/what-is-adfs\">Active Directory Federation Services<\/a> (AD FS) prior to the advent of AAD.\u00a0<\/p><p>There\u2019s a significant potential for disruptions to system availability when identities are migrated from AD FS to AAD without deliberate planning. Avoid impulsive decision-making when you\u2019re migrating users. Organizations that opt for a hybrid approach should harden Active Directory. This <a href=\"https:\/\/jumpcloud.com\/blog\/active-directory-faq\">detailed guide<\/a> offers recommendations about how AD should be managed and maintained for optimal security. Always limit administrative privileges in AD and avoid running day-to-day as a domain administrator.<\/p><figure class=\"wp-block-image size-full\"><img decoding=\"async\" class=\"wp-image-71351\" src=\"https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2022\/11\/3-1.png\" sizes=\"(max-width: 512px) 100vw, 512px\" srcset=\"https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2022\/11\/3-1.png 512w, https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2022\/11\/3-1-300x129.png 300w\" alt=\"\" width=\"512\" height=\"221\" \/><\/figure><p>Familiarize yourself with \u201cjoin, move, and leave\u201d planning processes and Microsoft\u2019s concepts for <a href=\"https:\/\/learn.microsoft.com\/en-us\/azure\/active-directory\/governance\/what-is-identity-lifecycle-management\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">identity governance<\/a>. Automation is possible, but it\u2019s designed for mid-size to large organizations. There\u2019s no default auditing to avoid over-provisioning users or for when individuals leave. Due diligence is necessary to avoid security and compliance issues.<\/p><h3 id=\"heading2\">Critically Important AAD Best Practices<\/h3><p>Verify that you\u2019ve completed these steps before moving on.<\/p><h4>Role-Based Access Control<\/h4><figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-71352\" src=\"https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2022\/11\/4-1.png\" sizes=\"(max-width: 512px) 100vw, 512px\" srcset=\"https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2022\/11\/4-1.png 512w, https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2022\/11\/4-1-300x192.png 300w\" alt=\"\" width=\"512\" height=\"328\" \/><\/figure><p>AAD has built-in and custom user roles, and role-based access control (RBAC) is standard across all subscription tiers. This permits IT to follow the concept of least privilege and helps to establish a <a href=\"https:\/\/jumpcloud.com\/solutions\/zero-trust\" target=\"_blank\" rel=\"noreferrer noopener\">Zero Trust<\/a> security approach, but it relies heavily on manual input and maintenance.<\/p><p>Ensure that you:<\/p><ul><li>Minimize the number of privileged accounts.<ul><li>Plan to manage, control, and monitor access.<\/li><li>Limit global administrator accounts and make use of other roles such as billing administrator, global reader, helpdesk administrator, and license administrator.<\/li><\/ul><\/li><li>Limit global administrators and never sync high privilege accounts from AD.<\/li><li>Pay careful attention to external collaboration settings and consider restricting external users from being able to invite guests to shared files; third-party storage; as well as review and adjust global sharing settings for SharePoint Online and OneDrive. These changes impact end users, but make it easier to recognize the \u201cofficial\u201d channels.<\/li><\/ul><p>Using security groups for users assists with application security and lowers administrative overhead. Microsoft limits this capability to AAD Premium 1 (P1) and Premium 2 (P2) accounts. However, always try to avoid assigning resources directly to users and use identity protection. Please note that Microsoft has <a href=\"https:\/\/learn.microsoft.com\/en-us\/azure\/active-directory\/hybrid\/concept-azure-ad-connect-sync-user-and-contacts\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">documented multiple limitations<\/a> to syncing AD groups with ADD groups.\u00a0 For example, AD primary group memberships will not sync over to AAD.<\/p><h4>Multi-Factor Authentication<\/h4><figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-71386\" src=\"https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2022\/11\/5-3.png\" sizes=\"(max-width: 512px) 100vw, 512px\" srcset=\"https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2022\/11\/5-3.png 512w, https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2022\/11\/5-3-300x115.png 300w\" alt=\"\" width=\"512\" height=\"196\" \/><\/figure><p>Multi-factor authentication (MFA) is vital for identity protection. AAD\u2019s free tier only permits the use of the Microsoft Authenticator application. Admins have the option of only protecting the Azure AD Global Administrator versus all accounts, but it\u2019s highly advisable to set up MFA for all users. Protect against MFA self-enrollment attacks by using a Temporary Access Pass (TAP) to secure the initial registration. Avoid mixing per-user MFA with Security Defaults and other settings.<\/p><p>Your budget may impact what\u2019s possible. Microsoft assesses fees for all MFA verifications that happen with non-Microsoft identities and capabilities vary depending upon <a href=\"https:\/\/learn.microsoft.com\/en-us\/azure\/active-directory\/authentication\/concept-mfa-licensing#available-versions-of-azure-ad-multi-factor-authentication\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">licensing levels<\/a>.\u00a0<\/p><p>Consider using additional context and \u201cnumber matching\u201d in Authenticator notifications to include the application name and geographic location in Push MFA prompts. This practice safeguards against \u201cMFA bombing,\u201d where attackers send repeated requests to exploit MFA fatigue. Attackers successfully hijacked Microsoft users\u2019 sign-in sessions to bypass <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/microsoft-phishing-bypassed-mfa-in-attacks-against-10-000-orgs\/\" target=\"_blank\" rel=\"noreferrer noopener\">MFA at 10,000 organizations<\/a> by using advanced phishing toolkits. Microsoft\u2019s mitigation is to use certificate-based authentication and Fast ID Online (FIDO) v2.0 MFA implementations.\u00a0<\/p><p>MFA through FIDO 2 devices and Windows Hello requires AAD P1 and P2. Additional hardware costs may apply. Some additional security controls include conditional access (CA).<\/p><h4>Conditional Access<\/h4><p>Microsoft recommends that all accounts deploy CA, but it\u2019s also an extra cost and only available through P1, P2, or the E3 and E5 tiers for Microsoft 365 (M365) users. The standard M365 tier doesn\u2019t include it. The overall licensing scheme is changing and can be bewildering.\u00a0<\/p><p>There\u2019s more than one CA implementation:<\/p><ul><li>P1 enforces MFA in certain scenarios<\/li><li>P2 is risk based, learning user behavior to minimize MFA prompts<\/li><\/ul><p>There are additional steps to consider for password management before we move on.<\/p><h4>Configure Password Management<\/h4><figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-71354\" src=\"https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2022\/11\/6.png\" sizes=\"(max-width: 512px) 100vw, 512px\" srcset=\"https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2022\/11\/6.png 512w, https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2022\/11\/6-300x63.png 300w\" alt=\"\" width=\"512\" height=\"108\" \/><\/figure><p>Microsoft has revised its password policy guidance to no longer expire passwords. It\u2019s important to understand that SMEs that are regulated or don\u2019t have MFA and CA configured shouldn\u2019t do that. You may also consider changing passwords if you suspect an ID has been hijacked. CrowdStrike found that <a href=\"https:\/\/jumpcloud.com\/blog\/2022-fal-con-event-recap\">71% of attacks are now malware-less<\/a> and targeting cloud IDs. 75% of cloud breaches are due to compromised identities. A Zero Trust posture isn\u2019t optional. Consider deploying <a href=\"https:\/\/www.crowdstrike.com\/cybersecurity-101\/what-is-xdr\/\" target=\"_blank\" rel=\"noreferrer noopener\">Extended Detection and Response<\/a> (XDR) from a vendor of your choosing or paying extra for Microsoft Identity Protection if you prefer the Microsoft stack.<\/p><p>Other best practices are:<\/p><ul><li>Set up self-service password reset (SSPR) with two authentication methods. Note that using security questions might be risky, because attackers gather intelligence on employees that\u2019s \u201copen source\u201d from the web or obtain information from third-party breaches elsewhere. Microsoft charges extra for on-premises write-back.<\/li><li>Use the same password policies everywhere (on-prem and cloud-based). Microsoft maintains <a href=\"https:\/\/learn.microsoft.com\/en-us\/azure\/active-directory\/authentication\/concept-password-ban-bad-on-premises\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">extensive documentation<\/a> on an agent-based approach to enforce AAD password protection on AD DS without exposing your domain controller to the web or forcing networking changes. Note that you have to be proficient in modifying AD settings.<\/li><\/ul><h4>Prepare for the Worst<\/h4><figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-71355\" src=\"https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2022\/11\/7.png\" sizes=\"(max-width: 512px) 100vw, 512px\" srcset=\"https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2022\/11\/7.png 512w, https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2022\/11\/7-300x140.png 300w\" alt=\"\" width=\"512\" height=\"239\" \/><\/figure><p>Create an <a href=\"https:\/\/learn.microsoft.com\/en-us\/azure\/active-directory\/roles\/security-emergency-access\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">emergency access<\/a> Global Admin account for when it\u2019s necessary to \u201cbreak the glass\u201d during network outages and periods of system downtime. This account is excluded from CA and MFA. Always store these credentials appropriately and use a highly complex password.<\/p><p>Following the steps outlined above provides a strong foundation with the appropriate entitlements, attributes, and processes to prepare AAD for application provisioning.<\/p><h2 id=\"heading3\">Manage Connected Applications<\/h2><p>Application provisioning is on a per user basis by default with group assignment to applications being reserved for P1, P2, or equivalent AAD subscribers. Ensure that applications don\u2019t provision high access through RBAC. There are multiple options, and automation is available for application provisioning. The initial provisioning cycle populates users, followed by programmatic incremental updates that handle updates made through Microsoft Graph or AD.<\/p><p>Microsoft provides several options for attribute mapping from identities that originate from the \u201cthree paths\u201d mentioned above via <a href=\"https:\/\/jumpcloud.com\/blog\/scim-provisioning-defined\">SCIM<\/a> endpoints to cloud resources or the <a href=\"https:\/\/learn.microsoft.com\/en-us\/azure\/active-directory\/app-provisioning\/on-premises-scim-provisioning\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Azure AD Provisioning agent<\/a>. The latter must run on the same server as your SCIM application. Microsoft also has options for one-way connections from AAD to LDAP or SQL database user stores, but those have several <a href=\"https:\/\/learn.microsoft.com\/en-us\/azure\/active-directory\/app-provisioning\/on-premises-ldap-connector-configure\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">on-premise prerequisites<\/a>. Provisioning users into AD DS isn\u2019t supported.<\/p><p>Siloed identities complicate existing identity practices and infrastructure as well as increase technical overhead and the attack surface area. Enable single sign-on (SSO) to centralize identity management either through AAD or a system or service that integrates with it.\u00a0<\/p><h3>Enable Single Sign-On<\/h3><figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-71356\" src=\"https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2022\/11\/8.png\" sizes=\"(max-width: 512px) 100vw, 512px\" srcset=\"https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2022\/11\/8.png 512w, https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2022\/11\/8-300x243.png 300w\" alt=\"\" width=\"512\" height=\"415\" \/><\/figure><p>SSO will improve security through modern authentication protocols, make life easier for your users, and reduce management overhead. Microsoft has imposed restrictions on the number of SSO applications per user on its free tier, but that policy may be changing. AAD provides pre-built integrations through the Azure AD application gallery in addition to <a href=\"https:\/\/jumpcloud.com\/blog\/what-is-saml\">SAML<\/a> and <a href=\"https:\/\/jumpcloud.com\/blog\/saml-oauth\">OAuth 2.0<\/a> SSO protocols for manual settings. Microsoft doesn\u2019t support the AAA protocol <a href=\"https:\/\/jumpcloud.com\/blog\/what-is-the-radius-protocol\">RADIUS<\/a>, which many network appliances use for access control, so its SSO doesn\u2019t access all of your resources. Consider using <a href=\"https:\/\/jumpcloud.com\/platform\/cloud-radius\" target=\"_blank\" rel=\"noreferrer noopener\">cloud RADIUS<\/a> or install and configure the <a href=\"https:\/\/jumpcloud.com\/blog\/microsoft-server-core-licensing-costs-more\">Microsoft NPS server role<\/a>.<\/p><p>It\u2019s possible for all AAD tiers to access native Windows apps via Kerberos, NTLM, LDAP, RDP, and SSH authentication in a hybrid deployment. However, identity protection features such as CA are limited to P1 and P2 products including <a href=\"https:\/\/go.microsoft.com\/fwlink\/p\/?linkid=2126406\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Azure AD Application Proxy<\/a> or <a href=\"https:\/\/go.microsoft.com\/fwlink\/p\/?linkid=2123157\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">secure hybrid partnerships integrations<\/a>. These services will extend modern security to legacy apps.<\/p><figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-71357\" src=\"https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2022\/11\/9.png\" sizes=\"(max-width: 512px) 100vw, 512px\" srcset=\"https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2022\/11\/9.png 512w, https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2022\/11\/9-300x89.png 300w\" alt=\"\" width=\"512\" height=\"152\" \/><\/figure><h4>Phishing Considerations<\/h4><figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-71358\" src=\"https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2022\/11\/10.png\" sizes=\"(max-width: 400px) 100vw, 400px\" srcset=\"https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2022\/11\/10.png 400w, https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2022\/11\/10-300x260.png 300w\" alt=\"\" width=\"400\" height=\"347\" \/><\/figure><p>Microsoft\u2019s default settings permit all users to access the AAD admin portal and register custom SSO applets. Attackers are wise to this workflow and exploit OAuth in phishing exploits, which may bypass MFA. The principle of least privilege mandates that users who don\u2019t need access shouldn\u2019t receive it. Strongly consider restricting user-driven application consent and setting <a href=\"https:\/\/learn.microsoft.com\/en-us\/azure\/active-directory\/develop\/v2-permissions-and-consent\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">permissions classifications<\/a> to \u201clow impact.\u201d This also applies to group owners. Compliance boundaries are murkier and should be carefully assessed outside of the Microsoft ecosystem.<\/p><figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-71359\" src=\"https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2022\/11\/11.png\" sizes=\"(max-width: 512px) 100vw, 512px\" srcset=\"https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2022\/11\/11.png 512w, https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2022\/11\/11-300x118.png 300w\" alt=\"\" width=\"512\" height=\"201\" \/><\/figure><p>AAD can be complex and Microsoft has amassed <a href=\"https:\/\/azure.microsoft.com\/en-us\/partners\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Azure partners<\/a> for advanced specialization. Blocks of time with consultants should be a budgeting consideration for any AAD project. This writer, a former IT director, needed consultants even when projects appeared straightforward.<\/p><p>AAD is capable of alerting you to suspicious OAuth authorization requests, but that requires an additional subscription to Microsoft Cloud App security, either standalone or through M365 E5. Other solutions such as <a href=\"https:\/\/www.crowdstrike.com\/resources\/videos\/how-to-detect-and-prevent-suspicious-activities-with-falcon-identity-protection\/\" target=\"_blank\" rel=\"noreferrer noopener\">CrowdStrike Falcon Identity Protection<\/a> have this capability. JumpCloud is a CrowdStrike partner and integrates with its solutions through the <a href=\"https:\/\/store.crowdstrike.com\/apps\/jumpcloud-secure-device-management\" target=\"_blank\" rel=\"noreferrer noopener\">CrowdStrike Store<\/a>.<\/p><p>Now that you\u2019re familiar with configuring users, groups, and applications, let\u2019s review reporting.\u00a0<\/p><h2 id=\"heading4\">Audit Your Security Regularly<\/h2><figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-71360\" src=\"https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2022\/11\/12.png\" alt=\"\" width=\"254\" height=\"290\" \/><\/figure><p>You should always look for ways to improve in-house security and processes. If you can\u2019t stop it, you should at least monitor it. Regularly audit your entitlements, users, and review activity reports. Taking this extra step helps make security a process as opposed to relying solely on products and services.\u00a0<\/p><p>Ideally, you\u2019ll be monitoring all privilege changes, suspicious activity, and signs of known attacks. AAD will provide you with several reports:<\/p><ul><li>Basic security and usage reports are included among all subscription tiers<\/li><li>Advanced reporting is restricted to P1 and P2<\/li><li>SIEM reporting and Identity Protection require P2 (or equivalent) subscriptions<\/li><\/ul><p>Some security capabilities may be more accessible and easier to deploy via JumpCloud, which integrates with AD, AAD\/M365, <a href=\"https:\/\/support.jumpcloud.com\/s\/article\/g-suite-user-import-provisioning-and-sync1\" target=\"_blank\" rel=\"noreferrer noopener\">Google Workspace<\/a>, and <a href=\"https:\/\/jumpcloud.com\/blog\/azure-ad-okta\">Okta<\/a>, or can function as a standalone directory. JumpCloud is focused on managing identities, in all places, as your security perimeter.<\/p><h2 id=\"heading5\">How JumpCloud Improves Upon Azure AD Best Practices<\/h2><figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-71361\" src=\"https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2022\/11\/13.png\" sizes=\"(max-width: 512px) 100vw, 512px\" srcset=\"https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2022\/11\/13.png 512w, https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2022\/11\/13-300x162.png 300w\" alt=\"\" width=\"512\" height=\"277\" \/><\/figure><p>JumpCloud is an open directory platform that manages identities, access control, and devices. Devices are a method of granting access to an identity or application, so device management is included by default. That makes it possible to assemble high visibility telemetry data for reporting.<\/p><p>As previously noted, Microsoft requires its users to purchase additional subscriptions (<a href=\"https:\/\/www.microsoft.com\/en-us\/security\/business\/microsoft-entra\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Entra<\/a>, M365 E3\/5, AAD P1\/2, and Intune for device management) to meet its recommendations for best practices. Standard AAD deployments fall short of Microsoft\u2019s guidance, but some of its premium offerings may sell SMEs more features than they require or even want to purchase.<\/p><p>JumpCloud can help to fill in some of those gaps, and is easy to deploy, with deepening integrations for exporting AAD user groups. It\u2019s designed for SMEs, so IT teams may benefit from having more control over what they\u2019re buying (as opposed to not using what they pay for). The next section explores the specifics of how JumpCloud can improve AAD and help your organization to build the stack of its choosing out of best-of-breed apps and services.<\/p><h3>IAM and SSO<\/h3><figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-71362\" src=\"https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2022\/11\/14.png\" sizes=\"(max-width: 512px) 100vw, 512px\" srcset=\"https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2022\/11\/14.png 512w, https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2022\/11\/14-300x193.png 300w\" alt=\"\" width=\"512\" height=\"330\" \/><\/figure><p>Identities flow into JumpCloud from other directories, <a href=\"https:\/\/jumpcloud.com\/blog\/how-jumpclouds-hris-integration-works\">HRIS systems<\/a>, or JumpCloud\u2019s <a href=\"https:\/\/jumpcloud.com\/platform\/ldap\" target=\"_blank\" rel=\"noreferrer noopener\">Cloud LDAP<\/a>. Attributes, such as where users are located, who their supervisor is, or what team they belong to, simplify provisioning user access to IT resources such as applications and networks.\u00a0<\/p><figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-71363\" src=\"https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2022\/11\/15.png\" sizes=\"(max-width: 512px) 100vw, 512px\" srcset=\"https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2022\/11\/15.png 512w, https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2022\/11\/15-300x248.png 300w\" alt=\"\" width=\"512\" height=\"424\" \/><\/figure><p>Group management is provided at no additional cost and leverages <a href=\"https:\/\/jumpcloud.com\/blog\/the-immediate-advantages-of-attribute-based-access-control\">attribute-based access control<\/a> (ABAC), enabling the system to continuously audit entitlements for Zero Trust access control. JumpCloud is introducing the ability to automate and apply membership suggestions to groups. RBAC is more of a manual process, which can lead to mistakes that over or under provision users. Group members can access resources through SSO protocols and more:<\/p><ul><li>SAML<\/li><li>OAuth 2.0<\/li><li>OIDC<\/li><li>RADIUS<\/li><li>LDAP<\/li><\/ul><p>JumpCloud provides <a href=\"https:\/\/jumpcloud.com\/blog\/feature-bulletin-radius-auth-azure-ad#:~:text=Delegated%20authentication%20removes%20the%20need,end%20user%20productivity%20and%20satisfaction.\">delegated authentication<\/a> that leverages AAD credentials and password policies for RADIUS. This capability extends Azure SSO to network resources such as Wi-Fi networks and VPNs while also reducing technical overhead and eliminating siloed identities. SSO applets launch from within the JumpCloud user console as a security control for phishing.<\/p><h4>Environment-Wide MFA<\/h4><p>JumpCloud Protect\u2122, an integrated authenticator app for MFA, is designed to be frictionless. It provides application-based Push MFA and TOTP in addition to WebAuthn and U2F keys. More options for biometric authentication and <a href=\"https:\/\/jumpcloud.com\/blog\/q4-2022-roadmap-webinar-recap#heading2\">passwordless log-in experiences<\/a> are being added to the platform.\u00a0<\/p><p>MFA can be configured for most SSO, LDAP, and RADIUS logins. It\u2019s also integrated with CA.<\/p><figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-71364\" src=\"https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2022\/11\/16.png\" sizes=\"(max-width: 512px) 100vw, 512px\" srcset=\"https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2022\/11\/16.png 512w, https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2022\/11\/16-300x188.png 300w\" alt=\"\" width=\"512\" height=\"320\" \/><\/figure><h4>Conditional Access<\/h4><p>AAD identities can be protected by conditional access through JumpCloud as an add-on without purchasing P1 or P2 from Microsoft. Pre-built rules are available to enforce MFA for privileged user groups, restrict logins to specific locations, and to require device trust. Meaning, any identity + device that isn\u2019t managed by JumpCloud won\u2019t be able to access cloud apps. More granular conditions such as OS version and device encryption status are coming soon.<\/p><figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-71365\" src=\"https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2022\/11\/17.png\" sizes=\"(max-width: 512px) 100vw, 512px\" srcset=\"https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2022\/11\/17.png 512w, https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2022\/11\/17-300x104.png 300w\" alt=\"\" width=\"512\" height=\"177\" \/><\/figure><h4>Password Management<\/h4><p>A decentralized <a href=\"https:\/\/jumpcloud.com\/platform\/password-manager\" target=\"_blank\" rel=\"noreferrer noopener\">password manager and vault<\/a> is available as an add-on through browser plug-ins and mobile apps to help SMEs implement complex passphrases for users. This feature assists with provisioning and revoking user access to reduce the risk of data breaches. Centralized password management also increases visibility for compliance peace of mind.<\/p><figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-71366\" src=\"https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2022\/11\/18.png\" sizes=\"(max-width: 237px) 100vw, 237px\" srcset=\"https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2022\/11\/18.png 237w, https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2022\/11\/18-139x300.png 139w\" alt=\"\" width=\"237\" height=\"512\" \/><\/figure><h3>Device Management<\/h3><figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-71367\" src=\"https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2022\/11\/19.png\" sizes=\"(max-width: 512px) 100vw, 512px\" srcset=\"https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2022\/11\/19.png 512w, https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2022\/11\/19-300x186.png 300w\" alt=\"\" width=\"512\" height=\"318\" \/><\/figure><p>JumpCloud is cross-OS, supporting:<\/p><ul><li><strong>Android:<\/strong> Support for policies and application distribution is <a href=\"https:\/\/jumpcloud.com\/blog\/q4-2022-roadmap-webinar-recap\">coming<\/a> in late 2022 and beyond.<\/li><li><strong>Apple products: <\/strong><a href=\"https:\/\/jumpcloud.com\/platform\/mdm\" target=\"_blank\" rel=\"noreferrer noopener\">Mobile Device Management<\/a> (MDM) is available for macOS and iOS devices, providing for application distribution, policies, and commands with the option for Zero Trust deployment. Policies are timely and in-touch with the needs of Mac admins, including addressing \u201cDay 0\u201d OS upgrade controls.\u00a0<\/li><li><strong>Linux: <\/strong>JumpCloud supports <a href=\"https:\/\/support.jumpcloud.com\/support\/s\/article\/jumpcloud-agent-compatibility-system-requirements-and-impacts1#linux\" target=\"_blank\" rel=\"noreferrer noopener\">multiple Linux distros<\/a> with multiple deployment options. It provides pre-built policies, including full disk encryption (FDE), and Sudo access for commands (with pre-built security commands through the Admin Console). IAM capabilities aren\u2019t restricted to certain browsers; Microsoft mandates Edge for Intune device enrollment. Intune is an additional subscription beyond standalone AAD.<strong>\u00a0<\/strong><\/li><li><strong>Windows: <\/strong>Anything an admin wishes to do is possible through security commands and a PowerShell module. Commands function through a queue. JumpCloud providespre-built <a href=\"https:\/\/jumpcloud.com\/blog\/limitations-with-azure-policies\">GPO-like policies<\/a> including fine-grained control over BitLocker, as well as a GUI for custom policies. There\u2019s also software distribution, and more, with Windows Out of Box Experience (OOBE) coming soon to streamline onboarding remote workers.<\/li><\/ul><figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-71368\" src=\"https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2022\/11\/20.png\" sizes=\"(max-width: 512px) 100vw, 512px\" srcset=\"https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2022\/11\/20.png 512w, https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2022\/11\/20-300x127.png 300w\" alt=\"\" width=\"512\" height=\"217\" \/><\/figure><h4>Patch Management<\/h4><figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-71369\" src=\"https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2022\/11\/21.png\" sizes=\"(max-width: 512px) 100vw, 512px\" srcset=\"https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2022\/11\/21.png 512w, https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2022\/11\/21-300x127.png 300w\" alt=\"\" width=\"512\" height=\"216\" \/><\/figure><p>JumpCloud offers <a href=\"https:\/\/jumpcloud.com\/blog\/jumpcloud-patch-management\">cross-OS patching<\/a> as an add-on. Patching is an important activity to mitigate the risk of security breaches that leverage 0-Day attacks with a healthy device state. Centralizing patch management helps to reduce costs versus purchasing a third-party patch management solution for Windows and all other operating systems. Browser patch management is arriving in Q4, 2022, and it will extend to reporting for management status.<\/p><figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-71370\" src=\"https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2022\/11\/22.png\" sizes=\"(max-width: 512px) 100vw, 512px\" srcset=\"https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2022\/11\/22.png 512w, https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2022\/11\/22-300x171.png 300w\" alt=\"\" width=\"512\" height=\"291\" \/><\/figure><h4>Remote Assist<\/h4><p>IT teams can extend opt-in remote support to users with <a href=\"https:\/\/support.jumpcloud.com\/s\/article\/Remote-Assist-Review-Guide\" target=\"_blank\" rel=\"noreferrer noopener\">Remote Assist<\/a>. It\u2019s free and works cross-OS. The only configuration that\u2019s required is to have JumpCloud agents running on a device that\u2019s bound to an identity from the open directory. It\u2019s possible to:<\/p><ul><li>Copy and paste between devices<\/li><li>Work in multi-monitor systems<\/li><li>Turn on audit logging<\/li><\/ul><figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-71371\" src=\"https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2022\/11\/23.png\" sizes=\"(max-width: 512px) 100vw, 512px\" srcset=\"https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2022\/11\/23.png 512w, https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2022\/11\/23-300x197.png 300w\" alt=\"\" width=\"512\" height=\"336\" \/><\/figure><h3>Reporting<\/h3><p>JumpCloud\u2019s emphasis on making identity the new perimeter is reflected in the telemetry that\u2019s available from built-in reporting tools including Device Insights and Directory Insights. There\u2019s a growing selection of pre-made reports, stored for analysis. SIEM integration is also possible.<\/p><p>Some of those include:<\/p><ul><li>User to Devices<\/li><li>User to RADIUS Server<\/li><li>User to LDAP<\/li><li>User to Directories<\/li><li>User to SSO Applications<\/li><li>OS Patch Management Policy<\/li><\/ul><p>Cloud Insights is an add-on to monitor Amazon Web Services (AWS) events and user actions. This makes compliance and data forensics easier for SMEs and helps to enforce least privilege in cloud infrastructure. Support for Google Cloud (GCP) will be introduced next for a multi-cloud strategy.<\/p><figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-71372\" src=\"https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2022\/11\/24.png\" sizes=\"(max-width: 512px) 100vw, 512px\" srcset=\"https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2022\/11\/24.png 512w, https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2022\/11\/24-300x138.png 300w\" alt=\"\" width=\"512\" height=\"236\" \/><\/figure><h2>Avoid Vendor Lock-In and Do More with JumpCloud<\/h2><p>JumpCloud is <a href=\"https:\/\/console.jumpcloud.com\/signup?email=&amp;first_touch=Non-Paid&amp;first_touch_timestamp=2022-09-05T06:42:17.230Z&amp;jcsgmtuuid=3e98afb0-b055-44b0-b943-254a1f55d8f7\" target=\"_blank\" rel=\"noreferrer noopener\">available to try<\/a> with full functionality for 10 users and devices, and with 10 days of complementary chat support before charges are accessed. AAD users benefit from more freedom of choice, simpler deployment workflows, access to more sources, and lower costs.<\/p><p>Sometimes self-service doesn\u2019t get you everything you need. If that\u2019s how you\u2019re feeling, <a href=\"https:\/\/calendly.com\/jc-implementation\/free-one-time-30-min-consult\" target=\"_blank\" rel=\"noreferrer noopener\">schedule a 30-minute consultation<\/a> to discuss options for implementation assistance, migration services, custom scripting, and more.<\/p><figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-71373\" src=\"https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2022\/11\/25.png\" sizes=\"(max-width: 512px) 100vw, 512px\" srcset=\"https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2022\/11\/25.png 512w, https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2022\/11\/25-300x168.png 300w\" alt=\"\" width=\"512\" height=\"286\" \/><\/figure><p>Similarly, managed service providers (MSPs) receive 10 free user accounts within the first organization that they create in the <a href=\"https:\/\/jumpcloud.com\/blog\/customizable-multi-tenant-portal-for-msps\">multi-tenant portal<\/a>, JumpCloud\u2019s dedicated MSP solution.<\/p><div class=\"blog-post-tags m-t-2\"><ul class=\"blog-post-topics-list\"><li class=\"blog-post-topics-list-item\"><a class=\"blog-post-topics-list-link is-type-body-default is-important is-type-weight-semi-bold has-text-navy\" href=\"\/blog?topics=best-practices\">Best Practices<\/a><\/li><\/ul><ul class=\"blog-post-collections-list\"><li class=\"blog-post-collections-list-item\"><a class=\"blog-post-collections-list-link is-type-body-tiny is-type-weight-semi-bold is-important directory-services\" href=\"\/blog?collections=directory-services\">Directory Services<\/a><\/li><li class=\"blog-post-collections-list-item\"><a class=\"blog-post-collections-list-link is-type-body-tiny is-type-weight-semi-bold is-important security\" href=\"\/blog?collections=security\">Security<\/a><\/li><\/ul><\/div><\/article>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-2004c86 elementor-widget elementor-widget-shortcode\" data-id=\"2004c86\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"shortcode.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<div class=\"elementor-shortcode\">\t\t<div data-elementor-type=\"page\" data-elementor-id=\"18103\" class=\"elementor elementor-18103\">\n\t\t\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-748947f elementor-section-full_width elementor-section-height-default elementor-section-height-default\" data-id=\"748947f\" data-element_type=\"section\" data-e-type=\"section\" data-settings=\"{&quot;jet_parallax_layout_list&quot;:[{&quot;jet_parallax_layout_image&quot;:{&quot;url&quot;:&quot;&quot;,&quot;id&quot;:&quot;&quot;,&quot;size&quot;:&quot;&quot;},&quot;_id&quot;:&quot;c4f773e&quot;,&quot;jet_parallax_layout_image_tablet&quot;:{&quot;url&quot;:&quot;&quot;,&quot;id&quot;:&quot;&quot;,&quot;size&quot;:&quot;&quot;},&quot;jet_parallax_layout_image_mobile&quot;:{&quot;url&quot;:&quot;&quot;,&quot;id&quot;:&quot;&quot;,&quot;size&quot;:&quot;&quot;},&quot;jet_parallax_layout_speed&quot;:{&quot;unit&quot;:&quot;%&quot;,&quot;size&quot;:50,&quot;sizes&quot;:[]},&quot;jet_parallax_layout_type&quot;:&quot;scroll&quot;,&quot;jet_parallax_layout_direction&quot;:&quot;1&quot;,&quot;jet_parallax_layout_fx_direction&quot;:null,&quot;jet_parallax_layout_z_index&quot;:&quot;&quot;,&quot;jet_parallax_layout_bg_x&quot;:50,&quot;jet_parallax_layout_bg_x_tablet&quot;:&quot;&quot;,&quot;jet_parallax_layout_bg_x_mobile&quot;:&quot;&quot;,&quot;jet_parallax_layout_bg_y&quot;:50,&quot;jet_parallax_layout_bg_y_tablet&quot;:&quot;&quot;,&quot;jet_parallax_layout_bg_y_mobile&quot;:&quot;&quot;,&quot;jet_parallax_layout_bg_size&quot;:&quot;auto&quot;,&quot;jet_parallax_layout_bg_size_tablet&quot;:&quot;&quot;,&quot;jet_parallax_layout_bg_size_mobile&quot;:&quot;&quot;,&quot;jet_parallax_layout_animation_prop&quot;:&quot;transform&quot;,&quot;jet_parallax_layout_on&quot;:[&quot;desktop&quot;,&quot;tablet&quot;]}]}\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-7995c19\" data-id=\"7995c19\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-a437045 elementor-widget elementor-widget-image-box\" data-id=\"a437045\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image-box.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<div class=\"elementor-image-box-wrapper\"><div class=\"elementor-image-box-content\"><h3 class=\"elementor-image-box-title\">About Version 2 Digital<\/h3><p class=\"elementor-image-box-description\">Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.\n<br><br>\nThrough an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.<\/p><\/div><\/div>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<\/div>\n\t\t\n\t\t<div data-elementor-type=\"page\" data-elementor-id=\"57539\" class=\"elementor elementor-57539\">\n\t\t\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-6b25dc0d elementor-section-full_width elementor-section-height-default elementor-section-height-default\" data-id=\"6b25dc0d\" data-element_type=\"section\" data-e-type=\"section\" data-settings=\"{&quot;jet_parallax_layout_list&quot;:[{&quot;_id&quot;:&quot;c4f773e&quot;,&quot;jet_parallax_layout_image&quot;:{&quot;url&quot;:&quot;&quot;,&quot;id&quot;:&quot;&quot;,&quot;size&quot;:&quot;&quot;},&quot;jet_parallax_layout_image_tablet&quot;:{&quot;url&quot;:&quot;&quot;,&quot;id&quot;:&quot;&quot;,&quot;size&quot;:&quot;&quot;},&quot;jet_parallax_layout_image_mobile&quot;:{&quot;url&quot;:&quot;&quot;,&quot;id&quot;:&quot;&quot;,&quot;size&quot;:&quot;&quot;},&quot;jet_parallax_layout_speed&quot;:{&quot;unit&quot;:&quot;%&quot;,&quot;size&quot;:50,&quot;sizes&quot;:[]},&quot;jet_parallax_layout_type&quot;:&quot;scroll&quot;,&quot;jet_parallax_layout_direction&quot;:&quot;1&quot;,&quot;jet_parallax_layout_fx_direction&quot;:null,&quot;jet_parallax_layout_z_index&quot;:&quot;&quot;,&quot;jet_parallax_layout_bg_x&quot;:50,&quot;jet_parallax_layout_bg_x_tablet&quot;:&quot;&quot;,&quot;jet_parallax_layout_bg_x_mobile&quot;:&quot;&quot;,&quot;jet_parallax_layout_bg_y&quot;:50,&quot;jet_parallax_layout_bg_y_tablet&quot;:&quot;&quot;,&quot;jet_parallax_layout_bg_y_mobile&quot;:&quot;&quot;,&quot;jet_parallax_layout_bg_size&quot;:&quot;auto&quot;,&quot;jet_parallax_layout_bg_size_tablet&quot;:&quot;&quot;,&quot;jet_parallax_layout_bg_size_mobile&quot;:&quot;&quot;,&quot;jet_parallax_layout_animation_prop&quot;:&quot;transform&quot;,&quot;jet_parallax_layout_on&quot;:[&quot;desktop&quot;,&quot;tablet&quot;]}]}\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-3cc1b37d\" data-id=\"3cc1b37d\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-52c4a230 elementor-widget elementor-widget-text-editor\" data-id=\"52c4a230\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><strong>About JumpCloud<\/strong><br \/>At JumpCloud, our mission is to build a world-class cloud directory. Not just the evolution of Active Directory to the cloud, but a reinvention of how modern IT teams get work done. The JumpCloud Directory Platform is a directory for your users, their IT resources, your fleet of devices, and the secure connections between them with full control, security, and visibility.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<\/div>\n\t\t","protected":false},"excerpt":{"rendered":"<p>Identity is the new perimeter. Cyberattacks are becomin [&hellip;]<\/p>\n","protected":false},"author":143524195,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_wpcom_ai_launchpad_first_post":false,"_jetpack_feature_clip_id":0,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_post_was_ever_published":false},"categories":[488,1016,61],"tags":[489,1017],"class_list":["post-59538","post","type-post","status-publish","format-standard","hentry","category-488","category-jumpcloud","category-press-release","tag-489","tag-jumpcloud"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.4 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Azure AD Best Practices - Version 2<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/jumpcloud.com\/blog\/azure-ad-best-practices\" \/>\n<meta property=\"og:locale\" content=\"zh_HK\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Azure AD Best Practices - Version 2\" \/>\n<meta property=\"og:description\" content=\"Identity is the new perimeter. Cyberattacks are becomin [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/jumpcloud.com\/blog\/azure-ad-best-practices\" \/>\n<meta property=\"og:site_name\" content=\"Version 2\" \/>\n<meta property=\"article:published_time\" content=\"2022-11-07T09:04:53+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2022-12-02T10:13:33+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2022\/11\/1-1.png\" \/>\n<meta name=\"author\" content=\"version2hk\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"\u4f5c\u8005\" \/>\n\t<meta name=\"twitter:data1\" content=\"version2hk\" \/>\n\t<meta name=\"twitter:label2\" content=\"\u9810\u8a08\u95b1\u8b80\u6642\u9593\" \/>\n\t<meta name=\"twitter:data2\" content=\"20 \u5206\u9418\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/jumpcloud.com\\\/blog\\\/azure-ad-best-practices#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/version-2.com\\\/2022\\\/11\\\/azure-ad-best-practices\\\/\"},\"author\":{\"name\":\"version2hk\",\"@id\":\"https:\\\/\\\/version-2.com\\\/zh\\\/#\\\/schema\\\/person\\\/d14d2d3cd77ffdb618b9f1330fe084db\"},\"headline\":\"Azure AD Best Practices\",\"datePublished\":\"2022-11-07T09:04:53+00:00\",\"dateModified\":\"2022-12-02T10:13:33+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/version-2.com\\\/2022\\\/11\\\/azure-ad-best-practices\\\/\"},\"wordCount\":2913,\"publisher\":{\"@id\":\"https:\\\/\\\/version-2.com\\\/zh\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/jumpcloud.com\\\/blog\\\/azure-ad-best-practices#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/jumpcloud.com\\\/\\\/wp-content\\\/uploads\\\/2022\\\/11\\\/1-1.png\",\"keywords\":[\"2022\",\"JumpCloud\"],\"articleSection\":[\"2022\",\"JumpCloud\",\"Press Release\"],\"inLanguage\":\"zh-HK\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/version-2.com\\\/2022\\\/11\\\/azure-ad-best-practices\\\/\",\"url\":\"https:\\\/\\\/jumpcloud.com\\\/blog\\\/azure-ad-best-practices\",\"name\":\"Azure AD Best Practices - Version 2\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/version-2.com\\\/zh\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/jumpcloud.com\\\/blog\\\/azure-ad-best-practices#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/jumpcloud.com\\\/blog\\\/azure-ad-best-practices#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/jumpcloud.com\\\/\\\/wp-content\\\/uploads\\\/2022\\\/11\\\/1-1.png\",\"datePublished\":\"2022-11-07T09:04:53+00:00\",\"dateModified\":\"2022-12-02T10:13:33+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/jumpcloud.com\\\/blog\\\/azure-ad-best-practices#breadcrumb\"},\"inLanguage\":\"zh-HK\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/jumpcloud.com\\\/blog\\\/azure-ad-best-practices\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"zh-HK\",\"@id\":\"https:\\\/\\\/jumpcloud.com\\\/blog\\\/azure-ad-best-practices#primaryimage\",\"url\":\"https:\\\/\\\/jumpcloud.com\\\/\\\/wp-content\\\/uploads\\\/2022\\\/11\\\/1-1.png\",\"contentUrl\":\"https:\\\/\\\/jumpcloud.com\\\/\\\/wp-content\\\/uploads\\\/2022\\\/11\\\/1-1.png\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/jumpcloud.com\\\/blog\\\/azure-ad-best-practices#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"\u9996\u9801\",\"item\":\"https:\\\/\\\/version-2.com\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Azure AD Best Practices\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/version-2.com\\\/zh\\\/#website\",\"url\":\"https:\\\/\\\/version-2.com\\\/zh\\\/\",\"name\":\"Version 2\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\\\/\\\/version-2.com\\\/zh\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/version-2.com\\\/zh\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"zh-HK\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/version-2.com\\\/zh\\\/#organization\",\"name\":\"Version 2\",\"url\":\"https:\\\/\\\/version-2.com\\\/zh\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"zh-HK\",\"@id\":\"https:\\\/\\\/version-2.com\\\/zh\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/i0.wp.com\\\/version-2.com\\\/wp-content\\\/uploads\\\/2020\\\/08\\\/v2-hk-hor-4.png?fit=1795%2C335&ssl=1\",\"contentUrl\":\"https:\\\/\\\/i0.wp.com\\\/version-2.com\\\/wp-content\\\/uploads\\\/2020\\\/08\\\/v2-hk-hor-4.png?fit=1795%2C335&ssl=1\",\"width\":1795,\"height\":335,\"caption\":\"Version 2\"},\"image\":{\"@id\":\"https:\\\/\\\/version-2.com\\\/zh\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/version-2.com\\\/zh\\\/#\\\/schema\\\/person\\\/d14d2d3cd77ffdb618b9f1330fe084db\",\"name\":\"version2hk\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"zh-HK\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/d280627252b42d7489de74dd88aa04043a495f25e258575000dc767e287bf94c?s=96&d=identicon&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/d280627252b42d7489de74dd88aa04043a495f25e258575000dc767e287bf94c?s=96&d=identicon&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/d280627252b42d7489de74dd88aa04043a495f25e258575000dc767e287bf94c?s=96&d=identicon&r=g\",\"caption\":\"version2hk\"},\"sameAs\":[\"http:\\\/\\\/version2xfortcom.wordpress.com\"],\"url\":\"https:\\\/\\\/version-2.com\\\/zh\\\/author\\\/version2hk\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Azure AD Best Practices - Version 2","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/jumpcloud.com\/blog\/azure-ad-best-practices","og_locale":"zh_HK","og_type":"article","og_title":"Azure AD Best Practices - Version 2","og_description":"Identity is the new perimeter. Cyberattacks are becomin [&hellip;]","og_url":"https:\/\/jumpcloud.com\/blog\/azure-ad-best-practices","og_site_name":"Version 2","article_published_time":"2022-11-07T09:04:53+00:00","article_modified_time":"2022-12-02T10:13:33+00:00","og_image":[{"url":"https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2022\/11\/1-1.png","type":"","width":"","height":""}],"author":"version2hk","twitter_card":"summary_large_image","twitter_misc":{"\u4f5c\u8005":"version2hk","\u9810\u8a08\u95b1\u8b80\u6642\u9593":"20 \u5206\u9418"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/jumpcloud.com\/blog\/azure-ad-best-practices#article","isPartOf":{"@id":"https:\/\/version-2.com\/2022\/11\/azure-ad-best-practices\/"},"author":{"name":"version2hk","@id":"https:\/\/version-2.com\/zh\/#\/schema\/person\/d14d2d3cd77ffdb618b9f1330fe084db"},"headline":"Azure AD Best Practices","datePublished":"2022-11-07T09:04:53+00:00","dateModified":"2022-12-02T10:13:33+00:00","mainEntityOfPage":{"@id":"https:\/\/version-2.com\/2022\/11\/azure-ad-best-practices\/"},"wordCount":2913,"publisher":{"@id":"https:\/\/version-2.com\/zh\/#organization"},"image":{"@id":"https:\/\/jumpcloud.com\/blog\/azure-ad-best-practices#primaryimage"},"thumbnailUrl":"https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2022\/11\/1-1.png","keywords":["2022","JumpCloud"],"articleSection":["2022","JumpCloud","Press Release"],"inLanguage":"zh-HK"},{"@type":"WebPage","@id":"https:\/\/version-2.com\/2022\/11\/azure-ad-best-practices\/","url":"https:\/\/jumpcloud.com\/blog\/azure-ad-best-practices","name":"Azure AD Best Practices - Version 2","isPartOf":{"@id":"https:\/\/version-2.com\/zh\/#website"},"primaryImageOfPage":{"@id":"https:\/\/jumpcloud.com\/blog\/azure-ad-best-practices#primaryimage"},"image":{"@id":"https:\/\/jumpcloud.com\/blog\/azure-ad-best-practices#primaryimage"},"thumbnailUrl":"https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2022\/11\/1-1.png","datePublished":"2022-11-07T09:04:53+00:00","dateModified":"2022-12-02T10:13:33+00:00","breadcrumb":{"@id":"https:\/\/jumpcloud.com\/blog\/azure-ad-best-practices#breadcrumb"},"inLanguage":"zh-HK","potentialAction":[{"@type":"ReadAction","target":["https:\/\/jumpcloud.com\/blog\/azure-ad-best-practices"]}]},{"@type":"ImageObject","inLanguage":"zh-HK","@id":"https:\/\/jumpcloud.com\/blog\/azure-ad-best-practices#primaryimage","url":"https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2022\/11\/1-1.png","contentUrl":"https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2022\/11\/1-1.png"},{"@type":"BreadcrumbList","@id":"https:\/\/jumpcloud.com\/blog\/azure-ad-best-practices#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"\u9996\u9801","item":"https:\/\/version-2.com\/"},{"@type":"ListItem","position":2,"name":"Azure AD Best Practices"}]},{"@type":"WebSite","@id":"https:\/\/version-2.com\/zh\/#website","url":"https:\/\/version-2.com\/zh\/","name":"Version 2","description":"","publisher":{"@id":"https:\/\/version-2.com\/zh\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/version-2.com\/zh\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"zh-HK"},{"@type":"Organization","@id":"https:\/\/version-2.com\/zh\/#organization","name":"Version 2","url":"https:\/\/version-2.com\/zh\/","logo":{"@type":"ImageObject","inLanguage":"zh-HK","@id":"https:\/\/version-2.com\/zh\/#\/schema\/logo\/image\/","url":"https:\/\/i0.wp.com\/version-2.com\/wp-content\/uploads\/2020\/08\/v2-hk-hor-4.png?fit=1795%2C335&ssl=1","contentUrl":"https:\/\/i0.wp.com\/version-2.com\/wp-content\/uploads\/2020\/08\/v2-hk-hor-4.png?fit=1795%2C335&ssl=1","width":1795,"height":335,"caption":"Version 2"},"image":{"@id":"https:\/\/version-2.com\/zh\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/version-2.com\/zh\/#\/schema\/person\/d14d2d3cd77ffdb618b9f1330fe084db","name":"version2hk","image":{"@type":"ImageObject","inLanguage":"zh-HK","@id":"https:\/\/secure.gravatar.com\/avatar\/d280627252b42d7489de74dd88aa04043a495f25e258575000dc767e287bf94c?s=96&d=identicon&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/d280627252b42d7489de74dd88aa04043a495f25e258575000dc767e287bf94c?s=96&d=identicon&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/d280627252b42d7489de74dd88aa04043a495f25e258575000dc767e287bf94c?s=96&d=identicon&r=g","caption":"version2hk"},"sameAs":["http:\/\/version2xfortcom.wordpress.com"],"url":"https:\/\/version-2.com\/zh\/author\/version2hk\/"}]}},"jetpack_sharing_enabled":true,"jetpack_shortlink":"https:\/\/wp.me\/pbQRKm-fui","jetpack_featured_media_url":"","post_mailing_queue_ids":[],"_links":{"self":[{"href":"https:\/\/version-2.com\/zh\/wp-json\/wp\/v2\/posts\/59538","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/version-2.com\/zh\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/version-2.com\/zh\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/version-2.com\/zh\/wp-json\/wp\/v2\/users\/143524195"}],"replies":[{"embeddable":true,"href":"https:\/\/version-2.com\/zh\/wp-json\/wp\/v2\/comments?post=59538"}],"version-history":[{"count":3,"href":"https:\/\/version-2.com\/zh\/wp-json\/wp\/v2\/posts\/59538\/revisions"}],"predecessor-version":[{"id":59645,"href":"https:\/\/version-2.com\/zh\/wp-json\/wp\/v2\/posts\/59538\/revisions\/59645"}],"wp:attachment":[{"href":"https:\/\/version-2.com\/zh\/wp-json\/wp\/v2\/media?parent=59538"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/version-2.com\/zh\/wp-json\/wp\/v2\/categories?post=59538"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/version-2.com\/zh\/wp-json\/wp\/v2\/tags?post=59538"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}