{"id":45924,"date":"2020-04-26T09:00:00","date_gmt":"2020-04-26T15:00:00","guid":{"rendered":"https:\/\/jumpcloud.com\/?p=45924"},"modified":"2024-12-20T14:47:34","modified_gmt":"2024-12-20T19:47:34","slug":"use-aad-authentication","status":"publish","type":"post","link":"https:\/\/jumpcloud.com\/blog\/use-aad-authentication","title":{"rendered":"Can I Use Azure AD for Authentication?"},"content":{"rendered":"\n

With more organizations looking to move their IT infrastructure to the cloud, admins are asking: Can I use Azure\u00ae<\/sup> Active Directory\u00ae<\/sup> for authentication? The short answer is yes, but it depends on what you need to authenticate to.<\/p>\n\n\n\n

Authentication<\/a> confirms that a user is actually who they say they are, and protects internal resources against unauthorized access. It\u2019s essential for securing IT infrastructure, and with cybercrime on the rise, IT teams are evaluating the best option for secure authentication in the cloud.<\/p>\n\n\n\n

Below we\u2019ll discuss what resources Azure AD can natively authenticate users to and what resources it struggles with, as well as options for IT teams looking to troubleshoot gaps in AAD\u2019s authentication coverage.<\/p>\n\n\n\n

What is Azure AD?<\/h2>\n\n\n\n

Azure AD is a user management platform offered by Microsoft\u00ae<\/sup> that manages access to Azure infrastructure, Office 365\u2122 (O365), and a selection of web applications. AAD is mainly meant to be used in conjunction with an existing on-prem Active Directory instance, though it can be used on its own.<\/p>\n\n\n\n

By itself, it functions as a substrate identity and access management (IAM) solution with specific administrative capabilities. When used with Active Directory, Azure AD Connect federates AD credentials to Azure AD, ensuring that users can authenticate to web-based apps and Azure using their existing on-prem credentials. <\/p>\n\n\n\n

Azure AD\u2019s Native Authentication Capabilities<\/h3>\n\n\n\n

Natively, AAD authenticates user credentials to Windows\u00ae<\/sup> 10 Pro devices and select web apps. In conjunction with Azure AD Domain Services, it can create a login process for a domain of servers and applications hosted at Azure. Alone, however, AAD doesn\u2019t authenticate to:<\/p>\n\n\n\n