Azure Active Directory and Office 365 Security

Seventy percent of Fortune 500 companies purchased Office 365 in a recent 12-month window. Microsoft calls Office 365 its fastest-growing commercial product ever. However, on-premises Active Directory (AD) still plays the main role in being the authoritative source for authentication and authorization requests to Office 365. System administrators in the vast majority of organizations use one-way Azure AD synchronization in this hybrid directory environment: They synchronize their authoritative, on-premises AD users, groups, attributes and passwords up to the cloud for authentication and authorization to Azure AD and Office 365. That means that if the on-premises Active Directory is not secure, Azure AD and Office 365 will not be secure.

This paper describes a security methodology for governing a hybrid, on-premises/Azure Active Directory environment. System administrators will find detailed explanations and checklists for improving their security posture and keeping their on-premises AD from becoming the Achilles’ heel of their Azure AD and Office 365 security.

