IT:AD:Azure:Account
Summary
An Azure Account can be associated to two types of IdP Accounts
Notes
IdP Account Types
An Azure Account can be associated to two types of IdP Accounts
These two configurations are referred to as:
- Personal Accounts
- Organisation Accounts
Subscriptions
An IdP Account can be associated to zero or more Subscriptions (IT:AD:Azure, IT:AD:Office 365 (O365), IT:AD:InTune etc.).
Zero or more of these Subscriptions can be Azure Subscriptions).
Notes
Types of Accounts
As stated above, there are two types of Accounts: * Personal Accounts * Organisation Accounts.
Their primary characteristics are described below.
Personal Account
Personal Accounts:
- are personal, consumer accounts, created by individuals themselves (as oppossed to an Org's admin) and stored at https://live.com
- services authenticate by redirecting users to sign in via https://signin.live.com
- are currently called Microsoft Accounts (Passport Accounts became Live Accounts, which became Microsoft Accounts)
- Can access services registered in the Azure ADs to which the user has been invited.
- Note: Azure AD has a federation trust relationship with https://live.com. Hence Azure AD can authenticate “native” org accounts, as well as “guest” consumer Microsoft Accounts.
- Considerations:
- There is no API for provisioning Microsoft Accounts, and therefore cannot currently fulfill Organisational (Business/School) provisioning/management/deprovisioning requirements.
Organisation Accounts
Organisation Accounts: * are created by Organisations using Azure AD, or their IT:AD:Office 365 (O365) Subscription's Azure AD. * are Accounts managed in an Organisation's Subscription's Azure AD (either by Cloud Identities, Synchronized Identities, Federated Identities) * services authenticate by redirecting users to sign in via https://signin.live.com * can access services registered in the Azure ADs to which the user belongs (his own org), or has been invited.
Account Management
You can manage your Account from various locations (this makes it a little confusing).
You can manage your Account in one of the following locations: * https://live.com ← core Account Information * https://account.windowsazure.com ← Azure specific Account information (Name can be different than Core for some reason)
Accounts and Subscriptions (in General)
An Account (whether a Personal Microsoft Account or Organisation Account) can be associated to n Subscriptions:
- etc.
Subscriptions can be managed as follows: * Azure:
* O365:
* Visual Studio Team Services:
- (todo)
Account and Azure Subscriptions
As stated elsewhere, an Account can be related to 0-* Subscriptions.
But a Subscription always has at least one IT:AD:Azure:Account associated to it as its IT:AD:Azure:Security:Role:BuiltIn Roles:Owner (and its Service Administrator (SA)).
Accounts and Roles
An Account can have several Administration Roles1) per service2). The Service can be Azure in general, or a Service within Azure (eg Azure AD).
- Azure Subscription Administration Roles:
- Account Administrator (AA) (should maybe have been called Subscription Administrator, but hey…)
- Service Administrator (SA) (same as Owner, but cannot change Service Administrator)
- Service Co-Administrator (CA) (same as Service Administrator but cannot add/remove other Service Administrators)
- Azure Active Directory Roles:
- Global Administrator
- Billing Administrator
- Service Administrator
- User Administrator
- Password Administrator