Live data from Hacker News

Does Company ‘X’ have an Azure Active Directory Tenant?

shawntabrizi.com

111–120 of 197 posts

Re: Does Company ‘X’ have an Azure Active Directory Tenant?

#111

Earlier quoted context omitted.

So in that case are the following “illegal” - Apple One - Microsoft Office - Amazon Prime - Google GSuite - Adobe Creative Cloud - Salesforce bundling SFDC with Concur

Honestly, I think the regulators should look at basically all of those things. Here in Europe scrutiny is building and a lot of those organisations do party hard and play loose with the rules. Microsoft is famously anticompetitive, but Adobe, Google and Apple can't be far behind in their respective areas.

Really? So you really think companies shouldn’t be able to sell software that works together bundled together? Why stop there? Phones and computers shouldn’t be “bundled” with operating systems? Computers shouldn’t be “bundled” with sound hardware? Where does it stop?

Re: Does Company ‘X’ have an Azure Active Directory Tenant?

#112

What I can’t understand is why Azure AD doesn’t have a stronger position in the consumer space. Authentication via Google, Apple, and even still Facebook are nearly always supported on customer-facing logins. I rarely see an option for Microsoft. They have a commanding position in the enterprise. What’s keeping them from crossing those enterprise boundaries?

They were an early mover in this area twenty years ago with the original Hailstorm / .Net Passport which was skeptically received and wasn’t helped by some spectacular outages. Google and Facebook leveraged their apps and especially GMail - Apple had the leverage from their App Store to force everyone that mattered to at their service too.

Re: Does Company ‘X’ have an Azure Active Directory Tenant?

#115

Earlier quoted context omitted.

The service is good, but really expensive and the sales tactics are sleazy. They want you paying $40/mo/head.

Azure AD Premium is $480/year per user???? What in the world do you get for that price point?

It’s not. Azure Ad P1 is $6/user/month, P2 is $9/user/month. Cheaper than Okta.

OP was probably thinking of Microsoft 365 E3 which does cost $36/user/month. That however includes a bunch of other stuff besides Azure AD P1.

Re: Does Company ‘X’ have an Azure Active Directory Tenant?

#116
post #97

Earlier quoted context omitted.

It's even worse if you have personal and business accounts tied to the same email address - you never know which one you're using, or which you need.

> It's even worse if you have personal and business accounts tied to the same email address - you never know which one you're using, or which you need I have a friend who managed to do get into this mess, and he's still not sure how he did it. firstname.lastname@companybizname.TLD is apparently linked to two separate identities at Microsoft, one is a business account, one is a "personal" account. Every time he experi…

This is a legacy setup that can no longer be created. Microsoft removed the option to use a custom domain for Microsoft accounts many years ago, but hasn't forced people to change.

However, your friend can get out of this scenario by following the instructions on this site:

https://support.microsoft.com/en-us/account-billing/change-t...

They'll end up with @outlook.com for their Microsoft account. When using Org services via a browser, you'll automatically use your Org account. When using consumer services, you'll automatically use your Microsoft account (assuming you've selected stay sign-in for both).

Re: Does Company ‘X’ have an Azure Active Directory Tenant?

#117
post #97

Earlier quoted context omitted.

It's even worse if you have personal and business accounts tied to the same email address - you never know which one you're using, or which you need.

Indeed. I've never understood this distinction. Either it's a business account, or it's a personal account. It's bad enough that people use their business mail to sign up for personal stuff, we don't need Microsoft to make it even worse.

> we don't need Microsoft to make it even worse.

Microsoft made it better by preventing the scenario from occurring beginning 3 - 5 years ago.

Re: Does Company ‘X’ have an Azure Active Directory Tenant?

#118
post #9
post #6

I thought it would be 100%; everyone switched to AD after Novell. What are the 16.6% using is the interesting part?

Good question. I’ve worked at apple and google and both like to cook their own implementation. It was AD there.

Where?

Re: Does Company ‘X’ have an Azure Active Directory Tenant?

#119
post #21

Earlier quoted context omitted.

NetIQ eDirectory tends to be the other big one. Although I am seeing a rise in companies not having an SSO solution recently at all. In fact some of the SMEs I've seen recently are running most of their stuff entirely via basic Microsoft O365 accounts or iCloud.

I wouldn't think SSO is the primary use for AD. Definitely one big use, though!

What do you think the primary use is?

Re: Does Company ‘X’ have an Azure Active Directory Tenant?

#120
post #92

Earlier quoted context omitted.

Having Azure AD does not prevent clients from also having Okta or any other 2FA provider for 2 factor authentication. In fact, I have worked with at least 10 clients in the last 2 years that used Azure AD for authentication but then something else for 2-factor depending on the type of apps. Sometimes even within one company, there are multiple 2FA protocols, e.g. using Oracle single sign on for ERP apps but Okta for…

Okta is a single sign on provider though. Clearly, authenticating via Azure and also Okta would not be single sign on.

I've actually created this setup (in order to ditch Okta as it is far more expensive than AAD P1 if you want MFA).

You federate AAD and Okta. Sign in to Okta and it's smooth sailing into AAD-based resources like M365.

Okta puts on a good dog and pony show for execs. From a technical perspective, they're no better for corps (at least in first party auth or B2B -- I don't get into the B2C space). We found, for the apps we used, AAD as of ~4 years ago had better SCIM support (!) than Okta.

On top of getting O365 E5 + Ent Sec (I think they're just now called M365 E5) which gave us AAD P2 licenses, overall it was much cheaper than Okta. The goal was to just get MFA, which Microsoft gives away for free (with limited toggles) or in P1 licenses (with more toggles) where-as Okta wanted $6/user/month _just for_ MFA.

Microsoft puts on a terrible sales pitch, though. We were fortunate enough to have an _awesome_ Principal Program Manager spend days with us in-person answering all of our questions and explaining AAD to our IT management.

Post reply on HN