Azure Active Directory
Welcome to the Azure Active Directory Forum.
-
Merge office365 and live accounts that use the same email address
I use both Azure/msdn and office 365
I already had an msdn account [email protected] ( Windows Live account) and our company recently migrated to Office 365 which resulted in a [email protected] Office365 account.Wich is causing a lot of grieve when switching between asure web portal / msdn web portal / office 365 web portal
Even when I have no portals open, I cant switch accounts. I need to explicity open the portal that I last logged in to. Log out, and then I can switch accounts.
And having both office 365 portal and Azure portal open at the same…
769 votesOur team owns the Microsoft account and Azure AD sign-in/sign-up experiences. We know that some experiences are confusing for some of you and we’re working hard to simplify them.
More specifically:
1) We know a number of users have multiple accounts with Microsoft, some they created themselves and others they got from their work or school. Today, using multiple accounts in Office 365, Azure.com or VisualStudio.com requires you sign out of one account and sign in to another. To address this we’re building the ability to be signed in with more than one account at the same time, in the same browser. This should start showing up on Microsoft web properties later this year.
2) There’s a small number of Microsoft business services that only support “Live ID” accounts, and not organizational accounts that are used for other business services like Office 365. Examples include MSDN and Volume Licensing. We’re…
-
Update the Azure Active Directory PowerShell Module to allow MFA
According to MS Support [1] you cannot use an account with MFA to connect to AAD via PowerShell. This is a problem, because most activities done with PS require Admin rights, and we want Admin accounts to have MFA.
I did some digging and I believe this limitation comes from the fact that the AAD PowerShell module still uses the Microsoft Online Services Sign-In Assistant [2] for authentication.
It looks like MS is updating Office applications to use ADAL instead of the MSOL Sign-in Assistant to "enable new authentication flows, including support for Multi-Factor Authentication (MFA)." [3]
I propose making…
151 votesIn Public Preview version of the PowerShell Module:
/ Brjann Brekkan
-
Update UserType from portal
Be able to see and change the userType from the portal.
(This is only available in Powershell : example: change from Guest -> member, in order to see the directory as an external user.)Set-MsolUser -UserPrincipalName xxxhotmail.com#EXT#@xxxhotmail.onmicrosoft.com -UserType Member
138 votes -
Add Azure Active Directory to portal.azure.com
As more services become only available for management in portal.azure.com (such as API Apps), it's annoying to have to go back to the "old" portal.
119 votesNew features are starting to show up in the new portal so we are making progress but the whole migration is not complete yet.
You have Privileged Identity Management and Azure AD ID Protection in the new portal.
When you go to the Application Panel you will also see preview of the new look and feel of that as a preview.
Will get back to this thread asap when I have more to share on the full migration.
- Brjann Brekkan
Program Manager Customer Success Team -
Enable legacy Windows Server Active Directory functionality for compute services
I want use this Windows Azure Active Directory services to standard compute services to remove complecation.
for example, we need Active Directory for building failover cluster services IaaS. I don't want to make DC only for that...111 votesDomain Services is available in preview: https://azure.microsoft.com/en-us/services/active-directory-ds/
/Brjann -
Remove requirement for onprem Exchange when using DirSync
as per : http://tinyurl.com/kqgjvqx
Currently for a small business who want password sync, but make the move to 365. they have to keep Exchange running on premise simply to be able to edit user attributes related to Exchange. - an active directory DLL, standalone app or simply support in the 365 portal would solve this for so many customers.
104 votesThe Azure Active Directory PM responsible for Sync has received this feedback and is reviewing. / Brjann Brekkan
-
Enable Self Service Password Reset from Windows 10 Sign In Screen
Azure AD self service password reset works great. The issue being if a user cannot log on they haven't a browser to access the portal easily.
Can the reset portal be integrated with a "Forgotten my password" link on the Sign In screen. Azure AD join integrates with web based services such as MFA so it hopefully the foundations are there.
87 votesThanks for the feedback! This is something we’re actively looking at supporting.
-
Get user membership groups in the claims with AD B2C
As it's possible in the standard AD by changing the API application manifest option "groupMembershipClaims" to "SecurityGroup", is it possible to return user membership group in the claims with AD B2C?
Now, we can have only the default and custom attributes by adding a signin policy, but it's impossible to get user membership groups.
78 votesWe will add this to our backlog. For now, you could query using Graph – not the desired method but it would work.
/Brjann Brekkan
-
Fix Error AADSTS50020 when logged in user doesn't have permissions to selected Application.
Currently if the logged in users doesnt exist in the Tenant Directory for a given application. The user is shown a very unhelpful page with the following:
Sorry, but we’re having trouble signing you in.
We received a bad request.The debug error is :
AADSTS50020: User account 'some email address' from external identity provider 'https://sts.windows.net/someguid/'; is not supported for application 'https://someappurl'. The account needs to be added as an external user in the tenant. Please sign out and sign in again with an Azure Active Directory user account.78 votes -
AADB2C: Send email invitation for new user to sign up
I would like the ability to trigger an email invitation be sent to new users for our web application that I want to authenticate with AADB2C. In our multi-tenant design, each tenant will be responsible for adding their own users to their tenant. I would like the admin of the tenant to be able to send an email invitation to the new user and then that user can complete the sign-up process.
70 votesThank you for the feedback. We are strongly considering this for the future. Today we are focusing on customer facing apps with open self-service signup. /Jose Rojas
-
Sync Azure Active Directory Down to On-Premises AD
It would be great to be able to sync Azure AD down to On-premise AD. I want to centrally manage my users, passwords, and groups from Azure AD. That way the on-premise server just acts as a medium for the local environment.
Here: http://msdn.microsoft.com/en-us/library/azure/dn798669.aspx
It says "coming soon" for cloud to on premise sync. It was last updated on September 5th 2014. I cant find any new information on if this is out.
65 votesWrite-back from Azure AD to on premises AD is being worked on and will start to show up in next few months initially supporting password write back and then groups, Additional features for enabling write back for user object and devices is also on our roadmap.
http://technet.microsoft.com/en-us/library/dn757582.aspx
- Brjann Brekkan
-
AADB2C: add an Azure AD provider
AADB2C is great, but why not adding an Azure AD provider? We're developing an application where we can have customers with social identities as well as Azure AD identities, it would be great in the AADB2C login page to have an option like "Organization Account". In this way we can code against one single API and not be forced to use two different entry points.
65 votesWe recognize this is an important use case! We are currently looking for developers to test this and similar features under preview. / Jose Rojas
-
Add Multifactor Authentication (MFA) support for DirectAccess remote technology
One Time Password access to the DirectAccess user tunnel using MFA
59 votesPlease provide more details. DirectAccess is an on-premises technology and as such may not fall into Azure Active Directory.
-
Graph API: Single query way to expand property of children
Impossible to get members of Azure AD group with expanded 'manager' property in one request.
for example:
https://graph.windows.net/<tenant_id>/directoryObjects/<group_id>/members/?api-version=1.6&$expand=managerwe gets the following response:
{"code":"Request_UnsupportedQuery","message":{"lang":"en","value":"An unsupported query was observed. Please ensure you query does not navigate across multiple reference-properties."}I suppose reason of such response is clear. and current workaround is the following:
1) Get group members
2) for each five members(using OData batch) get manager
But this way make us do a lot of requests to Azure AD and we expect performance degradation here.We develop multi tenant application which access Azure AD of all our customers and it's…
52 votesThanks for the feedback! We’re looking into this and will provide an update once we’ve determined the best path forward.
-
Device-level authentication as primary authentication like ADFS 4.0 (Windows 2016) in Azure AD
It would be AWESOME, if Azure Active Directory would provide device-level authentication as primary authentication like ADFS 4.0 (Windows 2016)
We need this please!
47 votesThanks for your suggestion. This is under review and in our backlog but initially you will see this capability show up in AD FS in Windows Server 2016.
/ Brjann Brekkan
-
Add Custom Identity Provider feature to Azure AD
We have a custom IDp on old ACS and use ADAL v1 to auth a desktop app. We need to use new thinks of ADAL v2 or newer versions.
We already have this app in production so we realy need a way to use Azure b2c with our custom identity provider. In fact we want the feature of custom Idp in Azure AD in order to substitute ACS.
43 votesThanks for your idea – this is under review.
/ Brjann Brekkan
-
SSO / Sign in to Azure via Google Apps IDP
We'd like to enable our users for lots of Azure services (incrementally), starting with some RemoteApp services. We do *not* want to move user authentication to Azure AD (users have lots of complex Google Apps logins, with 2-Factor and U2F Keys).
Is there an easy way for us to enable Google Apps as an IdP in Azure AD?
Like, can we copy user profiles from Google Apps -> Azure, and on login attempt, redirect to the Google Apps sign in screen?
43 votesWe are reviewing this capability for all up Azure AD but initially you will see the ability to support Google ID for users in our B2C release.
/Brjann Brekkan
-
Azure AD Application Proxy – add ability to publish on-prem Remote Desktop Web Access.
Now we use MS TMG (with RSA SecurID 2-factor authentication) to publish RDWeb and RD Gateway to Internet. We need a replacement for MS TMG and RSA 2-factor authentication.
We want to publish our on-prem RDWeb sever to Internet via Azure AD Application Proxy. This solution should support Azure Multifactor authentication and RD Gateway.39 votesWe are working on methods to publish rich clients in a highly secure ways. Hopefully, this would also include Remote Desktop. The current UAG and TMG RDWeb based authentication and SSO is not necessarily the only option to achieve that.
-
AADB2C: skip email verification
When registering "local account", can email verification be optional? I'd like to have the user stay on our app during registration and start using it right away. Thanks.
38 votesThis feature is currently in preview. Will ship in the next 2 weeks! thank you. /Jose Rojas
-
B2C Fully Customizable Sign-In Page
Create a Sign In Policy by which we can provide our own template for the sign in page. It could work the same way as the Sign Up policy does.
38 votesWe’ve shipped the sign-up/signin policy which allows complete customization. Does this satisfy your needs, or do you need a separate fully customizable sign-in (only) experience?
thank you. /Jose Rojas
- Don't see your idea?
