{"id":19785,"date":"2022-01-18T08:30:59","date_gmt":"2022-01-18T13:30:59","guid":{"rendered":"https:\/\/www.eginnovations.com\/blog\/?p=19785"},"modified":"2025-05-16T01:26:07","modified_gmt":"2025-05-16T05:26:07","slug":"what-is-azure-active-directory","status":"publish","type":"post","link":"https:\/\/www.eginnovations.com\/blog\/what-is-azure-active-directory\/","title":{"rendered":"What is Azure Active Directory (Azure AD)?"},"content":{"rendered":"<div class=\"inner_content\">\n<p>This is a multi-part series that covers monitoring <a href=\"https:\/\/www.eginnovations.com\/supported-technologies\/azure-active-directory-monitoring-tools\">Microsoft Azure Active Directory (Azure AD)<\/a>. In this blog post, which is part 1 of the series, you will learn about and understand Microsoft Azure Active Directory (Azure AD) and how it is different from an on-premises Active Directory (AD).<\/p>\n<p>As technology keeps evolving, companies increasingly look to technologies like Cloud Computing to expand, modernize and stay competitive, and in doing so companies can expose themselves to risks. Data has become the most crucial element for businesses. With more data, hackers are breaching clouds and organizations these days and organizations must adhere to increased regulatory standards protecting customer assets and data.<\/p>\n<p>Medium and large organizations struggle to understand how they can protect and secure their data, their customers, and their very existence before moving to the cloud. They are always looking for tools that can prevent data breaches and lower the complexity of identity and access management issues. Microsoft Azure Active Directory (Azure AD) is one such tool that helps you manage identities and access capabilities with ease.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"What_is_Azure_Active_Directory\"><\/span>What is Azure Active Directory?<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-19854 alignright\" src=\"https:\/\/www.eginnovations.com\/blog\/wp-content\/uploads\/2021\/12\/azure-active-directory.jpg\" alt=\"Azure Active Directory logo\" width=\"350\" height=\"130\" border=\"0\" srcset=\"https:\/\/www.eginnovations.com\/blog\/wp-content\/uploads\/2021\/12\/azure-active-directory.jpg 350w, https:\/\/www.eginnovations.com\/blog\/wp-content\/uploads\/2021\/12\/azure-active-directory-300x111.jpg 300w, https:\/\/www.eginnovations.com\/blog\/wp-content\/uploads\/2021\/12\/azure-active-directory-310x115.jpg 310w, https:\/\/www.eginnovations.com\/blog\/wp-content\/uploads\/2021\/12\/azure-active-directory-140x52.jpg 140w\" sizes=\"auto, (max-width: 350px) 100vw, 350px\" \/>Azure Active Directory (Azure AD) is Microsoft\u2019s multi-tenant, cloud-based Identity and Access Management (IAM) service. It takes care of authentication and authorization of user and application identities. It\u2019s the digital infrastructure that allows your employees to sign in and access external resources, such as those held in Microsoft 365 service, an ever-growing list of other SaaS applications, as well as those held on corporate networks.<\/p>\n<p>When you sign up for any services offered by Microsoft Azure cloud, Microsoft automatically assigns a default directory, which is an instance of Azure AD. This directory holds the users and groups that will have access to each of the services the company has signed up for. This default directory is sometimes referred to as a tenant. For more information about creating a tenant for your organization, <a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/active-directory\/fundamentals\/active-directory-access-create-new-tenant\" target=\"blank\" rel=\"noopener noreferrer\">see Quickstart: Create a new tenant in Azure Active Directory.<\/a> The Azure Active Directory tenant represents your organization. Each tenant might have 1 to N Azure Subscriptions. Azure Subscription is a group of cloud services that are billed together.<\/p>\n<p>An Azure AD user account might be single-tenant (has access to resources of a single organization) or multi-tenant (two or more organizations). Every user, who needs access to Azure resources, needs an Azure user account. A user account contains all the information needed to authenticate the user during the sign-in process. Once authenticated, Azure AD builds an access token to authorize the user and determine what resources they can access and what they can do with those resources.<\/p>\n<p style=\"margin-bottom: 15px;\">Typically, Azure AD defines users in three ways:<\/p>\n<ol>\n<li><strong>Cloud identities \u2013<\/strong> These users exist only in Azure AD. Examples are administrator accounts and users that you manage yourself.<\/li>\n<li><strong>Directory-synchronized identities \u2013<\/strong> These users exist in an on-premises Active Directory. A synchronization activity that occurs via Azure AD Connect software brings these users into Azure.<\/li>\n<li><strong>Guest users \u2013 <\/strong>These users exist outside Azure. Examples are accounts from other cloud providers and Microsoft accounts, such as an Xbox LIVE account. Their source is Invited User. This type of account is useful when external vendors or contractors need access to your Azure resources.<\/li>\n<\/ol>\n<h2><span class=\"ez-toc-section\" id=\"What_is_the_difference_between_AD_Active_Directory_and_Azure_AD\"><\/span>What is the difference between AD (Active Directory) and Azure AD?<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>You may be familiar with <a href=\"https:\/\/www.eginnovations.com\/supported-technologies\/active-directory-monitoring\">on-premises Active Directory<\/a> concepts. On-Premises Active Directory is on servers called Domain Controllers (DC). Each DC contains a catalog of users and computers that are authorized to access resources on the network. Users authenticate to DCs via Kerberos or the NTLM protocol. <strong>Azure AD<\/strong> and <strong>On-Premises AD<\/strong> are both created by Microsoft, and they are both IAM systems, but that\u2019s pretty much where the comparisons stop. The following table outlines the differences and similarities between Active Directory concepts and Azure Active Directory:<\/p>\n<table class=\"table_design numbers\" style=\"width: 100%;\">\n<tbody>\n<tr class=\"head_table\">\n<td><strong>Concept<\/strong><\/td>\n<td><strong>Active Directory (AD)<\/strong><\/td>\n<td><strong>Azure Active Directory<\/strong><\/td>\n<\/tr>\n<tr style=\"background: #f7f7f7;\">\n<td style=\"text-align: center;\" colspan=\"3\" data-th=\"Section 1\"><strong>Users<\/strong><\/td>\n<\/tr>\n<tr>\n<td>Provisioning &#8211; users<\/td>\n<td>Organizations create internal users manually or use an in-house or automated provisioning system, such as the Microsoft Identity Manager to integrate with an HR system.<\/td>\n<td>Existing AD organizations use Azure AD Connect to sync identities to the cloud.<br \/>\nAzure AD adds support to automatically create users from cloud HR systems.<br \/>\nAzure AD can provision identities in SCIM-enabled SaaS apps to automatically provide apps with the necessary details to allow access for users.<\/td>\n<\/tr>\n<tr>\n<td>Provisioning &#8211; external identities<\/td>\n<td>Organizations create external users manually as regular users in a dedicated external AD forest, resulting in administration overhead to manage the lifecycle of external identities (guest users).<\/td>\n<td>Azure AD provides a special class of identity to support external identities. Azure AD B2B will manage the link to the external user identity to make sure they are valid.<\/td>\n<\/tr>\n<tr>\n<td>Entitlement management and groups<\/td>\n<td>Administrators make users members of groups. App and resource owners then provide these groups with access to apps or resources.<\/td>\n<td>Groups are also available in Azure AD and administrators can also use groups to grant permissions to resources. In Azure AD, administrators can assign membership to groups manually or use a query to dynamically include users to a group.<br \/>\nAdministrators can use Entitlement management in Azure AD to provide users with access to a collection of apps and resources using workflows and, if necessary, time-based criteria.<\/td>\n<\/tr>\n<tr>\n<td>Admin management<\/td>\n<td>Organizations will use a combination of domains, organizational units, and groups in AD to delegate administrative rights to manage the directory and resources it controls.<\/td>\n<td>Azure AD provides built-in roles with its Azure AD role-based access control (Azure AD RBAC) system, with limited support for creating custom roles to delegate privileged access to the identity system, the apps, and resources it controls.<br \/>\nManaging roles can be enhanced with Privileged Identity Management (PIM) to provide just-in-time, time-restricted, or workflow-based access to privileged roles.<\/td>\n<\/tr>\n<tr>\n<td>Credential management<\/td>\n<td>Credentials in Active Directory are based on passwords, certificate authentication, and smartcard authentication.<br \/>\nPasswords are managed using password policies that are based on password length, expiry, and complexity.<\/td>\n<td>Azure AD uses intelligent password protection for cloud and on-premises. Protection includes smart lockout plus blocking common and custom password phrases and substitutions.<br \/>\nAzure AD significantly boosts security through multi-factor authentication and passwordless technologies, like FIDO2.<br \/>\nAzure AD reduces support costs by providing users a self-service password reset system.<\/td>\n<\/tr>\n<tr style=\"background: #f7f7f7;\">\n<td style=\"text-align: center;\" colspan=\"3\" data-th=\"Section 2\"><strong>Applications<\/strong><\/td>\n<\/tr>\n<tr>\n<td>Infrastructure applications<\/td>\n<td>Active Directory forms the basis for many on-premises infrastructure components, for example, DNS, DHCP, IPSec, WiFi, NPS, and VPN access.<\/td>\n<td>In a new cloud world, Azure AD is the new control plane for accessing apps versus relying on networking controls. When users authenticate, Conditional Access (CA) will control which users will have access to which apps under required conditions.<\/td>\n<\/tr>\n<tr>\n<td>Traditional and legacy applications<\/td>\n<td>Most on-premises applications use LDAP, Windows-Integrated Authentication (NTLM and Kerberos), or Header-based authentication to control access to users.<\/td>\n<td>Azure AD can provide access to these types of on-premises apps using Azure AD application proxy agents running on-premises. Using this method, Azure AD can authenticate Active Directory users on-premises using Kerberos while you migrate or need to coexist with legacy apps.<\/td>\n<\/tr>\n<tr>\n<td>SaaS applications<\/td>\n<td>Active Directory doesn&#8217;t support SaaS applications natively and requires a federation system, such as AD FS.<\/td>\n<td>SaaS apps supporting OAuth2, SAML, and WS-* authentication can be integrated to use Azure AD for authentication.<\/td>\n<\/tr>\n<tr>\n<td>Line of business (LoB) applications with modern authentication<\/td>\n<td>Organizations can use AD FS with Active Directory to support LoB applications requiring modern authentication.<\/td>\n<td data-th=\"Azure Active Directory\">LoB applications requiring modern authentication can be configured to use Azure AD for authentication.<\/td>\n<\/tr>\n<tr>\n<td data-th=\"Concept\">Mid-tier\/Daemon services<\/td>\n<td data-th=\"Active Directory (AD)\">Services running in on-premises environments normally use AD service accounts or group Managed Service Accounts (gMSA) to run. These apps will then inherit the permissions of the service account.<\/td>\n<td data-th=\"Azure Active Directory\">Azure AD provides managed identities to run other workloads in the cloud. The lifecycle of these identities is managed by Azure AD and is tied to the resource provider can\u2019t be used for other purposes to gain backdoor access.<\/td>\n<\/tr>\n<tr style=\"background: #f7f7f7;\">\n<td style=\"text-align: center;\" colspan=\"3\" data-th=\"Section 3\"><strong>Devices<\/strong><\/td>\n<\/tr>\n<tr>\n<td>Mobile<\/td>\n<td>Active Directory doesn\u2019t natively support mobile devices without third-party solutions.<\/td>\n<td>Microsoft\u2019s mobile device management solution, Microsoft Intune, is integrated with Azure AD. Microsoft Intune provides device state information to the identity system to evaluate during authentication.<\/td>\n<\/tr>\n<tr>\n<td>Windows desktops<\/td>\n<td>Active Directory provides the ability to domain join Windows devices to manage them using Group Policy, System Center Configuration Manager, or other third-party solutions.<\/td>\n<td>Windows devices can be joined to Azure AD. Conditional access can check whether a device is Azure AD, joined as part of the authentication process.<br \/>\nWindows devices can also be managed with Microsoft Intune. In this case, conditional access will consider whether a device is compliant (for example, up-to-date security patches and virus signatures) before allowing access to the apps.<\/td>\n<\/tr>\n<tr>\n<td>Windows servers<\/td>\n<td>Active Directory provides strong management capabilities for on-premises Windows servers using Group Policy or other management solutions.<\/td>\n<td>Windows servers virtual machines in Azure can be managed with Azure AD Domain Services. Managed identities can be used when VMs need access to the identity system directory or resources.<\/td>\n<\/tr>\n<tr>\n<td>Linux\/Unix workloads<\/td>\n<td>Active Directory doesn&#8217;t natively support non-Windows without third-party solutions, although Linux machines can be configured to authenticate with Active Directory as a Kerberos realm.<\/td>\n<td>Linux\/Unix VMs can use managed identities to access the identity system or resources. Some organizations migrate these workloads to cloud container technologies, which can also use managed identities.<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><a href=\"https:\/\/www.eginnovations.com\/supported-technologies\/azure-virtual-desktop-monitoring-avd\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-19872\" src=\"https:\/\/www.eginnovations.com\/blog\/wp-content\/uploads\/2021\/12\/azure-banner.jpg\" alt=\"\" width=\"850\" height=\"170\" border=\"0\" srcset=\"https:\/\/www.eginnovations.com\/blog\/wp-content\/uploads\/2021\/12\/azure-banner.jpg 850w, https:\/\/www.eginnovations.com\/blog\/wp-content\/uploads\/2021\/12\/azure-banner-300x60.jpg 300w, https:\/\/www.eginnovations.com\/blog\/wp-content\/uploads\/2021\/12\/azure-banner-768x154.jpg 768w, https:\/\/www.eginnovations.com\/blog\/wp-content\/uploads\/2021\/12\/azure-banner-800x160.jpg 800w, https:\/\/www.eginnovations.com\/blog\/wp-content\/uploads\/2021\/12\/azure-banner-310x62.jpg 310w, https:\/\/www.eginnovations.com\/blog\/wp-content\/uploads\/2021\/12\/azure-banner-140x28.jpg 140w\" sizes=\"auto, (max-width: 850px) 100vw, 850px\" \/><\/a><\/p>\n<h2><span class=\"ez-toc-section\" id=\"Monitoring_Azure_Active_Directory\"><\/span>Monitoring Azure Active Directory<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p style=\"margin-bottom: 15px;\">When monitoring Azure AD, you will need tools that monitor logs, events, metrics, and traces both continually and historically to identify potential issues. In future blog posts, I\u2019ll go into details on how to audit AD but to give an idea of what is possible, here are a few examples of what <a href=\"https:\/\/www.eginnovations.com\/product\" rel=\"noopener noreferrer\">eG Enterprise<\/a> covers:<\/p>\n<ul>\n<li>Monitor app registrations; track certificate errors<\/li>\n<\/ul>\n<p><a href=\"https:\/\/www.eginnovations.com\/blog\/wp-content\/uploads\/2021\/12\/azure-certificate-errors-view.jpg\" data-rel=\"lightbox-image-0\" data-rl_title=\"\" data-rl_caption=\"\" title=\"\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-19857 size-full\" src=\"https:\/\/www.eginnovations.com\/blog\/wp-content\/uploads\/2021\/12\/azure-certificate-errors.jpg\" alt=\"Azure Certificate errors\" width=\"750\" height=\"402\" border=\"0\" srcset=\"https:\/\/www.eginnovations.com\/blog\/wp-content\/uploads\/2021\/12\/azure-certificate-errors.jpg 750w, https:\/\/www.eginnovations.com\/blog\/wp-content\/uploads\/2021\/12\/azure-certificate-errors-300x161.jpg 300w, https:\/\/www.eginnovations.com\/blog\/wp-content\/uploads\/2021\/12\/azure-certificate-errors-310x166.jpg 310w, https:\/\/www.eginnovations.com\/blog\/wp-content\/uploads\/2021\/12\/azure-certificate-errors-140x75.jpg 140w\" sizes=\"auto, (max-width: 750px) 100vw, 750px\" \/><\/a><\/p>\n<ul>\n<li>Audit activities \u2013 add\/delete\/modify users, applications, service principals, groups, policies, members, etc.<\/li>\n<\/ul>\n<p><a href=\"https:\/\/www.eginnovations.com\/blog\/wp-content\/uploads\/2021\/12\/azure-sign-in-logs-view.jpg\" data-rel=\"lightbox-image-1\" data-rl_title=\"\" data-rl_caption=\"\" title=\"\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-19858 size-full\" src=\"https:\/\/www.eginnovations.com\/blog\/wp-content\/uploads\/2021\/12\/azure-sign-in-logs.jpg\" alt=\"Azure Active Directory activity monitoring\" width=\"750\" height=\"400\" border=\"0\" srcset=\"https:\/\/www.eginnovations.com\/blog\/wp-content\/uploads\/2021\/12\/azure-sign-in-logs.jpg 750w, https:\/\/www.eginnovations.com\/blog\/wp-content\/uploads\/2021\/12\/azure-sign-in-logs-300x160.jpg 300w, https:\/\/www.eginnovations.com\/blog\/wp-content\/uploads\/2021\/12\/azure-sign-in-logs-310x165.jpg 310w, https:\/\/www.eginnovations.com\/blog\/wp-content\/uploads\/2021\/12\/azure-sign-in-logs-140x75.jpg 140w\" sizes=\"auto, (max-width: 750px) 100vw, 750px\" \/><\/a><\/p>\n<ul>\n<li>Monitor and audit different sign-in logs<\/li>\n<\/ul>\n<p><a href=\"https:\/\/www.eginnovations.com\/blog\/wp-content\/uploads\/2021\/12\/key-log-info-popup.jpg\" data-rel=\"lightbox-image-2\" data-rl_title=\"\" data-rl_caption=\"\" title=\"\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-19859 size-full\" src=\"https:\/\/www.eginnovations.com\/blog\/wp-content\/uploads\/2021\/12\/key-log-info.jpg\" alt=\"Monitoring Azure Active Directory Sign-in logs\" width=\"750\" height=\"424\" border=\"0\" srcset=\"https:\/\/www.eginnovations.com\/blog\/wp-content\/uploads\/2021\/12\/key-log-info.jpg 750w, https:\/\/www.eginnovations.com\/blog\/wp-content\/uploads\/2021\/12\/key-log-info-300x170.jpg 300w, https:\/\/www.eginnovations.com\/blog\/wp-content\/uploads\/2021\/12\/key-log-info-310x175.jpg 310w, https:\/\/www.eginnovations.com\/blog\/wp-content\/uploads\/2021\/12\/key-log-info-140x79.jpg 140w\" sizes=\"auto, (max-width: 750px) 100vw, 750px\" \/><\/a><\/p>\n<h2><span class=\"ez-toc-section\" id=\"What_is_Azure_AD_Connect\"><\/span>What is Azure AD Connect?<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p><a href=\"https:\/\/learn.microsoft.com\/en-us\/azure\/active-directory\/hybrid\/whatis-azure-ad-connect\">Azure AD Connect<\/a> is the Microsoft tool designed to be a bridge solution between On-premises Active Directory and Azure AD.<\/p>\n<p>It enables IT admins to federate on-premises user identities to the Azure platform so that users can use the same credentials to access both on-premises applications and cloud services, such as Microsoft 365.<\/p>\n<p>It is included for free with your Azure subscription. It offers multiple features, including <a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/active-directory\/hybrid\/how-to-connect-sync-whatis\" target=\"blank\" rel=\"noopener noreferrer\">synchronization,<\/a> <a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/active-directory\/hybrid\/how-to-connect-fed-whatis\" target=\"blank\" rel=\"noopener noreferrer\">federation integration<\/a> and <a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/active-directory\/hybrid\/whatis-azure-ad-connect#what-is-azure-ad-connect-health\" target=\"blank\" rel=\"noopener noreferrer\">health monitoring.<\/a><\/p>\n<p>By default, the sync is one way: from on-premises AD to Azure AD. However, you can configure the writeback function to sync changes from Azure AD back to your on-premises AD. That way, for instance, if a user changes their password using the Azure AD self-service password management function, the password will be updated in the on-premises AD.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-19861 size-full\" src=\"https:\/\/www.eginnovations.com\/blog\/wp-content\/uploads\/2021\/12\/azure-ad-connect.jpg\" alt=\"Azure Active Directory works\" width=\"750\" height=\"440\" border=\"0\" srcset=\"https:\/\/www.eginnovations.com\/blog\/wp-content\/uploads\/2021\/12\/azure-ad-connect.jpg 750w, https:\/\/www.eginnovations.com\/blog\/wp-content\/uploads\/2021\/12\/azure-ad-connect-300x176.jpg 300w, https:\/\/www.eginnovations.com\/blog\/wp-content\/uploads\/2021\/12\/azure-ad-connect-310x182.jpg 310w, https:\/\/www.eginnovations.com\/blog\/wp-content\/uploads\/2021\/12\/azure-ad-connect-140x82.jpg 140w\" sizes=\"auto, (max-width: 750px) 100vw, 750px\" \/><\/p>\n<p>Azure AD Connect can synchronize the user accounts, groups, and credential hashes in your on-premises AD by a scheduler. Most attributes of the user accounts, such as the User Principal Name (UPN) and security identifier (SID), are synchronized.<\/p>\n<p style=\"margin-bottom: 15px;\">However, the following objects and attributes are NOT synchronized:<\/p>\n<ul>\n<li>Any objects and attributes you specifically exclude from the sync<\/li>\n<li>SidHistory attributes for users and groups<\/li>\n<li>Group Policy objects (GPOs)<\/li>\n<li>The contents of the Sysvol folder<\/li>\n<li>Computer objects for computers joined to the on-premises AD environment<\/li>\n<li>Organization unit (OU) structures<\/li>\n<\/ul>\n<p style=\"margin-bottom: 15px;\">By default, a sync task runs every 30 minutes. If the sync task is not running correctly, you may experience issues like:<\/p>\n<ul>\n<li><strong>Sync account issues \u2013<\/strong> If you change the password for a user in On-premises AD, it does not sync on Azure AD, and thereby, the user is unable to access the resources.<\/li>\n<li><strong>Connectivity issues \u2013<\/strong> Microsoft has a <a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/active-directory\/hybrid\/tshoot-connect-connectivity\" target=\"blank\" rel=\"noopener noreferrer\">Azure AD Connectivity URL,<\/a> which shows the list of URLs that need to work between AD Connect and Azure AD.<\/li>\n<\/ul>\n<p>So, it is important to monitor the Azure AD Connect performance. <a href=\"https:\/\/www.eginnovations.com\/product\" rel=\"noopener noreferrer\">eG Enterprise<\/a> captures and reports the following metrics for Azure AD Connect:<\/p>\n<p><a href=\"https:\/\/www.eginnovations.com\/blog\/wp-content\/uploads\/2021\/12\/azure-ad-connect-status-view.jpg\" data-rel=\"lightbox-image-3\" data-rl_title=\"\" data-rl_caption=\"\" title=\"\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-19862 size-full\" src=\"https:\/\/www.eginnovations.com\/blog\/wp-content\/uploads\/2021\/12\/azure-ad-connect-status.jpg\" alt=\"Azure AD Connect Status screen\" width=\"750\" height=\"306\" border=\"0\" srcset=\"https:\/\/www.eginnovations.com\/blog\/wp-content\/uploads\/2021\/12\/azure-ad-connect-status.jpg 750w, https:\/\/www.eginnovations.com\/blog\/wp-content\/uploads\/2021\/12\/azure-ad-connect-status-300x122.jpg 300w, https:\/\/www.eginnovations.com\/blog\/wp-content\/uploads\/2021\/12\/azure-ad-connect-status-310x126.jpg 310w, https:\/\/www.eginnovations.com\/blog\/wp-content\/uploads\/2021\/12\/azure-ad-connect-status-140x57.jpg 140w\" sizes=\"auto, (max-width: 750px) 100vw, 750px\" \/><\/a><\/p>\n<p>It is very common for those with hybrid infrastructure mixing on-premises technologies, such as RDSH farms, Citrix, or VMware with cloud-hosted technologies, such as AVD Hostpools to be using both Azure AD and Active Directory and also Azure AD Connect.<\/p>\n<p><a href=\"https:\/\/www.eginnovations.com\/blog\/wp-content\/uploads\/2021\/12\/Azure-ad-sequence-view.jpg\" data-rel=\"lightbox-image-4\" data-rl_title=\"\" data-rl_caption=\"\" title=\"\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-19863 size-full\" src=\"https:\/\/www.eginnovations.com\/blog\/wp-content\/uploads\/2021\/12\/Azure-ad-sequence.jpg\" alt=\"Azure Active Directory as part of an application topology map\" width=\"750\" height=\"257\" border=\"0\" \/><\/a><\/p>\n<h3><span class=\"ez-toc-section\" id=\"Azure_AD_-_Pricing_and_Licensing\"><\/span>Azure AD \u2013 Pricing and Licensing<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p style=\"margin-bottom: 15px;\">Azure Active Directory comes in four editions:<\/p>\n<ul>\n<li>Free<\/li>\n<li>Office 365 apps<\/li>\n<li>Premium P1<\/li>\n<li>Premium P2<\/li>\n<\/ul>\n<p>The Free edition is included with a subscription of a commercial online service e.g. Azure, Dynamics 365, Intune, and Power Platform.<\/p>\n<p>Office 365 subscriptions include the Free edition, but Office 365 E1, E3, E5, F1, and F3 subscriptions also include additional features, see <a href=\"https:\/\/azure.microsoft.com\/en-gb\/pricing\/details\/active-directory\/\" target=\"blank\" rel=\"noopener noreferrer\">Microsoft\u2019s pricing page for details.<\/a><\/p>\n<h3><span class=\"ez-toc-section\" id=\"SLA_for_Azure_Active_Directory\"><\/span>SLA for Azure Active Directory<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p style=\"margin-bottom: 15px;\">At the time of drafting this blog post, <a href=\"https:\/\/azure.microsoft.com\/en-in\/support\/legal\/sla\/summary\/\">Microsoft guarantees<\/a> 99.99% availability of the Azure Active Directory Basic and Premium services. The services are considered available in the following scenarios:<\/p>\n<ul>\n<li>Users are able to login to the Azure Active Directory service.<\/li>\n<li>Azure Active Directory successfully emits the authentication and authorization tokens required for users to log into applications connected to the service.<\/li>\n<\/ul>\n<p>No SLA is offered for the Free edition of Azure Active Directory, and this should be a serious consideration within most enterprises when evaluating whether to migrate critical identity and access management.<\/p>\n<p>Using Azure AD Connect is free and included in your Azure subscription. However, using Azure AD Connect Health requires an Azure AD Premium P1 license. To find the right license for your requirements, see <a href=\"https:\/\/azure.microsoft.com\/pricing\/details\/active-directory\/\" target=\"blank\" rel=\"noopener noreferrer\">Comparing generally available features of the Free, Basic, and Premium editions.<\/a><\/p>\n<h3><span class=\"ez-toc-section\" id=\"Useful_Links\"><\/span>Useful Links:<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<ul>\n<li>Microsoft Documentation &#8211; <a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/active-directory\/fundamentals\/active-directory-whatis\" target=\"blank\" rel=\"noopener noreferrer\">What is Azure Active Directory? &#8211; Azure Active Directory | Microsoft Docs<\/a><\/li>\n<li>Using Azure AD in conjunction with Citrix technologies; currently in preview is Azure Active Directory Group-Based Support, read more: <a href=\"https:\/\/www.citrix.com\/blogs\/2021\/09\/28\/citrix-virtual-apps-and-desktops-innovations\/\" target=\"blank\" rel=\"noopener noreferrer\">Citrix innovations to power your hybrid-cloud migration | Citrix Blogs<\/a><\/li>\n<li><a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/vmware-cloudsimple\/azure-ad\" target=\"blank\" rel=\"noopener noreferrer\">Azure VMware Solution by CloudSimple &#8211; Use Azure AD as identity source on Private Cloud | Microsoft Docs<\/a><\/li>\n<li>Tutorial: <a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/active-directory\/saas-apps\/vmware-horizon-unified-access-gateway-tutorial\" target=\"blank\" rel=\"noopener noreferrer\">Azure Active Directory single sign-on (SSO) integration with Omnissa Horizon &#8211; Unified Access Gateway | Microsoft Docs<\/a><\/li>\n<li>Microsoft has a fantastic resource center for Azure AD, packed with documentation, tutorials, and guides, see: <a href=\"https:\/\/docs.microsoft.com\/en-gb\/azure\/active-directory\/\" target=\"blank\" rel=\"noopener noreferrer\">Azure Active Directory documentation | Microsoft Docs<\/a><\/li>\n<li><a href=\"https:\/\/docs.microsoft.com\/en-us\/troubleshoot\/azure\/active-directory\/welcome-azure-ad\" target=\"blank\" rel=\"noopener noreferrer\">Troubleshoot Azure Active Directory issues | Microsoft Docs<\/a><\/li>\n<li>Azure AD is just one of a number of components critical to ensure monitoring of AVD deployments is truly end to end and comprehensive; the AVD Broker is another key component, read more: <a href=\"https:\/\/www.eginnovations.com\/blog\/reverse-connect-azure-avd\/\" rel=\"noopener noreferrer\">Reverse Connect for Azure Virtual Desktops (AVD) | eG Innovations<\/a><\/li>\n<\/ul>\n<p><a href=\"https:\/\/www.eginnovations.com\/product\/application-performance-monitoring\/free-trial\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-20830\" src=\"https:\/\/www.eginnovations.com\/blog\/wp-content\/uploads\/2022\/01\/Azure-AD-trial-banner.jpg\" alt=\"\" width=\"850\" height=\"180\" border=\"0\" srcset=\"https:\/\/www.eginnovations.com\/blog\/wp-content\/uploads\/2022\/01\/Azure-AD-trial-banner.jpg 850w, https:\/\/www.eginnovations.com\/blog\/wp-content\/uploads\/2022\/01\/Azure-AD-trial-banner-300x64.jpg 300w, https:\/\/www.eginnovations.com\/blog\/wp-content\/uploads\/2022\/01\/Azure-AD-trial-banner-768x163.jpg 768w, https:\/\/www.eginnovations.com\/blog\/wp-content\/uploads\/2022\/01\/Azure-AD-trial-banner-800x169.jpg 800w, https:\/\/www.eginnovations.com\/blog\/wp-content\/uploads\/2022\/01\/Azure-AD-trial-banner-310x66.jpg 310w, https:\/\/www.eginnovations.com\/blog\/wp-content\/uploads\/2022\/01\/Azure-AD-trial-banner-140x30.jpg 140w\" sizes=\"auto, (max-width: 850px) 100vw, 850px\" \/><\/a><\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>This is a multi-part series that covers monitoring Microsoft Azure Active Directory (Azure AD). In this blog post, which is part 1 of the series, you will learn about and understand Microsoft Azure Active Directory (Azure AD) and how it is different from an on-premises Active Directory (AD). As technology keeps evolving, companies increasingly look [&hellip;]<\/p>\n","protected":false},"author":4,"featured_media":20478,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"inline_featured_image":false,"_lmt_disableupdate":"no","_lmt_disable":"","footnotes":""},"categories":[404],"tags":[405,560,637,558,832,834,833,831,830,415,829],"class_list":["post-19785","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-azure-monitoring","tag-azure","tag-azure-active-directory","tag-azure-active-directory-monitoring","tag-azure-ad","tag-azure-ad-connect","tag-azure-ad-connect-health","tag-azure-ad-health","tag-azure-ad-vs-active-directory","tag-azure-ad-vs-ad","tag-azure-monitoring","tag-microsoft-azure-ad"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v24.5 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>What is Azure Active Directory | eG Innovations<\/title>\n<meta name=\"description\" content=\"What is Azure AD? Learn all about Azure Active Directory, how it differs from an on-premise Active Directory, and how to monitor Azure Active Directory.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.eginnovations.com\/blog\/what-is-azure-active-directory\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"What is Azure Active Directory | eG Innovations\" \/>\n<meta property=\"og:description\" content=\"Learn what Microsoft Azure Active Directory (Azure AD) is and how it is different from an on-premises Active Directory (AD). From eG Innovations \u2013 the world\u2019s leader in IT Monitoring.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.eginnovations.com\/blog\/what-is-azure-active-directory\/\" \/>\n<meta property=\"og:site_name\" content=\"eG Innovations\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/eGInnovations\" \/>\n<meta property=\"article:published_time\" content=\"2022-01-18T13:30:59+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2025-05-16T05:26:07+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.eginnovations.com\/blog\/wp-content\/uploads\/2022\/01\/AzurePart1-Social-Banner.jpg\" \/>\n<meta name=\"author\" content=\"Babu Sundaram\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:title\" content=\"What is Azure Active Directory | eG Innovations\" \/>\n<meta name=\"twitter:description\" content=\"Learn what Microsoft Azure Active Directory (Azure AD) is and how it is different from an on-premises Active Directory (AD). From eG Innovations \u2013 the world\u2019s leader in IT Monitoring.\" \/>\n<meta name=\"twitter:image\" content=\"https:\/\/www.eginnovations.com\/blog\/wp-content\/uploads\/2022\/01\/AzurePart1-Social-Banner.jpg\" \/>\n<meta name=\"twitter:creator\" content=\"@https:\/\/twitter.com\/virtualinfra76?lang=en\" \/>\n<meta name=\"twitter:site\" content=\"@eginnovations\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Babu Sundaram\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"13 minutes\" \/>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"What is Azure Active Directory | eG Innovations","description":"What is Azure AD? Learn all about Azure Active Directory, how it differs from an on-premise Active Directory, and how to monitor Azure Active Directory.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.eginnovations.com\/blog\/what-is-azure-active-directory\/","og_locale":"en_US","og_type":"article","og_title":"What is Azure Active Directory | eG Innovations","og_description":"Learn what Microsoft Azure Active Directory (Azure AD) is and how it is different from an on-premises Active Directory (AD). From eG Innovations \u2013 the world\u2019s leader in IT Monitoring.","og_url":"https:\/\/www.eginnovations.com\/blog\/what-is-azure-active-directory\/","og_site_name":"eG Innovations","article_publisher":"https:\/\/www.facebook.com\/eGInnovations","article_published_time":"2022-01-18T13:30:59+00:00","article_modified_time":"2025-05-16T05:26:07+00:00","og_image":[{"url":"https:\/\/www.eginnovations.com\/blog\/wp-content\/uploads\/2022\/01\/AzurePart1-Social-Banner.jpg","type":"","width":"","height":""}],"author":"Babu Sundaram","twitter_card":"summary_large_image","twitter_title":"What is Azure Active Directory | eG Innovations","twitter_description":"Learn what Microsoft Azure Active Directory (Azure AD) is and how it is different from an on-premises Active Directory (AD). From eG Innovations \u2013 the world\u2019s leader in IT Monitoring.","twitter_image":"https:\/\/www.eginnovations.com\/blog\/wp-content\/uploads\/2022\/01\/AzurePart1-Social-Banner.jpg","twitter_creator":"@https:\/\/twitter.com\/virtualinfra76?lang=en","twitter_site":"@eginnovations","twitter_misc":{"Written by":"Babu Sundaram","Est. reading time":"13 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.eginnovations.com\/blog\/what-is-azure-active-directory\/#article","isPartOf":{"@id":"https:\/\/www.eginnovations.com\/blog\/what-is-azure-active-directory\/"},"author":{"name":"Babu Sundaram","@id":"https:\/\/www.eginnovations.com\/blog\/#\/schema\/person\/5f7590f77be55ecf13f1b8d915ac39df"},"headline":"What is Azure Active Directory (Azure AD)?","datePublished":"2022-01-18T13:30:59+00:00","dateModified":"2025-05-16T05:26:07+00:00","mainEntityOfPage":{"@id":"https:\/\/www.eginnovations.com\/blog\/what-is-azure-active-directory\/"},"wordCount":2336,"commentCount":0,"publisher":{"@id":"https:\/\/www.eginnovations.com\/blog\/#organization"},"image":{"@id":"https:\/\/www.eginnovations.com\/blog\/what-is-azure-active-directory\/#primaryimage"},"thumbnailUrl":"https:\/\/www.eginnovations.com\/blog\/wp-content\/uploads\/2021\/12\/AzurePart1-Thumbnail.jpg","keywords":["Azure","Azure Active Directory","Azure Active Directory Monitoring","Azure AD","Azure AD connect","Azure AD Connect health","Azure AD health","Azure AD vs Active Directory","Azure AD vs. AD","Azure Monitoring","Microsoft Azure AD"],"articleSection":["Azure Monitoring"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.eginnovations.com\/blog\/what-is-azure-active-directory\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.eginnovations.com\/blog\/what-is-azure-active-directory\/","url":"https:\/\/www.eginnovations.com\/blog\/what-is-azure-active-directory\/","name":"What is Azure Active Directory | eG Innovations","isPartOf":{"@id":"https:\/\/www.eginnovations.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.eginnovations.com\/blog\/what-is-azure-active-directory\/#primaryimage"},"image":{"@id":"https:\/\/www.eginnovations.com\/blog\/what-is-azure-active-directory\/#primaryimage"},"thumbnailUrl":"https:\/\/www.eginnovations.com\/blog\/wp-content\/uploads\/2021\/12\/AzurePart1-Thumbnail.jpg","datePublished":"2022-01-18T13:30:59+00:00","dateModified":"2025-05-16T05:26:07+00:00","description":"What is Azure AD? Learn all about Azure Active Directory, how it differs from an on-premise Active Directory, and how to monitor Azure Active Directory.","breadcrumb":{"@id":"https:\/\/www.eginnovations.com\/blog\/what-is-azure-active-directory\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.eginnovations.com\/blog\/what-is-azure-active-directory\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.eginnovations.com\/blog\/what-is-azure-active-directory\/#primaryimage","url":"https:\/\/www.eginnovations.com\/blog\/wp-content\/uploads\/2021\/12\/AzurePart1-Thumbnail.jpg","contentUrl":"https:\/\/www.eginnovations.com\/blog\/wp-content\/uploads\/2021\/12\/AzurePart1-Thumbnail.jpg","width":362,"height":235},{"@type":"BreadcrumbList","@id":"https:\/\/www.eginnovations.com\/blog\/what-is-azure-active-directory\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.eginnovations.com\/blog\/"},{"@type":"ListItem","position":2,"name":"What is Azure Active Directory (Azure AD)?"}]},{"@type":"WebSite","@id":"https:\/\/www.eginnovations.com\/blog\/#website","url":"https:\/\/www.eginnovations.com\/blog\/","name":"eG Innovations","description":"IT Performance Monitoring Insights","publisher":{"@id":"https:\/\/www.eginnovations.com\/blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.eginnovations.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.eginnovations.com\/blog\/#organization","name":"eG Innovations","alternateName":"eg innovations","url":"https:\/\/www.eginnovations.com\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.eginnovations.com\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.eginnovations.com\/blog\/wp-content\/uploads\/2014\/07\/eg-logo-dark-gray1_new.jpg","contentUrl":"https:\/\/www.eginnovations.com\/blog\/wp-content\/uploads\/2014\/07\/eg-logo-dark-gray1_new.jpg","width":362,"height":235,"caption":"eG Innovations"},"image":{"@id":"https:\/\/www.eginnovations.com\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/eGInnovations","https:\/\/x.com\/eginnovations"]},{"@type":"Person","@id":"https:\/\/www.eginnovations.com\/blog\/#\/schema\/person\/5f7590f77be55ecf13f1b8d915ac39df","name":"Babu Sundaram","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.eginnovations.com\/blog\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/d28fef01834f3b388d7d825216013937?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/d28fef01834f3b388d7d825216013937?s=96&d=mm&r=g","caption":"Babu Sundaram"},"sameAs":["https:\/\/x.com\/https:\/\/twitter.com\/virtualinfra76?lang=en"],"url":"https:\/\/www.eginnovations.com\/blog\/author\/babusundaram\/"}]}},"modified_by":"eG Innovations","_links":{"self":[{"href":"https:\/\/www.eginnovations.com\/blog\/wp-json\/wp\/v2\/posts\/19785","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.eginnovations.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.eginnovations.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.eginnovations.com\/blog\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.eginnovations.com\/blog\/wp-json\/wp\/v2\/comments?post=19785"}],"version-history":[{"count":0,"href":"https:\/\/www.eginnovations.com\/blog\/wp-json\/wp\/v2\/posts\/19785\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.eginnovations.com\/blog\/wp-json\/wp\/v2\/media\/20478"}],"wp:attachment":[{"href":"https:\/\/www.eginnovations.com\/blog\/wp-json\/wp\/v2\/media?parent=19785"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.eginnovations.com\/blog\/wp-json\/wp\/v2\/categories?post=19785"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.eginnovations.com\/blog\/wp-json\/wp\/v2\/tags?post=19785"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}