Venu
]]>Hello, Chris,
I can’t tell you much about it, as far as I know, there’s an on-premise integration.
Maybe this article will help you:
https://docs.microsoft.com/en-us/azure/active-directory/authentication/concept-sspr-howitworks
Hello, Gilles,
good question, I hope I got it right.
If you have external or on-premise applications, you can set them up (per tenant) with the Azure Application Proxy.
Take a look at this link:
https://docs.microsoft.com/en-us/azure/active-directory/manage-apps/application-proxy
I hope this helps you?
]]>Hello, PS,
In general, Exchange only allows the combination of one environment (on-premise and EXO). If you have other third party tools in use, you can try to create them instead of MAPI as IMAP accounts on your EXO.
So you can create your users of the child on-premise domain on the EXO of Tenant 1.
Here are some infos about IMAP with EXO:
https://docs.microsoft.com/en-us/exchange/clients-and-mobile-in-exchange-online/pop3-and-imap4/pop3-and-imap4
Regarding your second point: W10 Device Registrations, Group & Device write-back, etc. this was well described by the Microsoft link, that you have posted.
How this affects your multi-tenant planning I can’t describe so quickly now, but this question would be worth an article.
So my organization is looking to have a more robust SSPR capability and we are thinking about taking advantage of our current Azure ADFS environment. It looks as if this can easily be done for users that are say off-site to change locked passwords, but what about users on-site and only have the workstation login screen/credential provider? Is there a design where users can reset their passwords from their logon screen on-premise using Azure SSPR? Does there need to be an updated Credential Provider installed on the workstation?
]]>First of all, fantastic article, and thanks for the tips.
I have one question though when it comes to SSO across SaaS application.
When setting up SSO with third party application, on the SaaS application side, I usually can point only one IDP. If I have a SaaS application that need to allow both IDPs ( Tenant 1 and Tenant 2 ), what would be the best approach to this?
Thanks,
]]>Hi Alex, sure, I will try to deliver the images in a better size.
]]>