it:ad:azure:account:home

IT:AD:Azure:Account

Summary

An Azure Account can be associated to two types of IdP Accounts

An Azure Account can be associated to two types of IdP Accounts

These two configurations are referred to as:

  • Personal Accounts
  • Organisation Accounts

AzureIdP IdentityAzure ADMicrosoft LiveAccountAccount infoaccessible viahttps://login.live.com Personal AccountMicrosoft AccountOrganisation AccountAzure AD AccountAccount infoaccessible viahttps://account.windowsazure.com/

An IdP Account can be associated to zero or more Subscriptions (IT:AD:Azure, IT:AD:Office 365 (O365), IT:AD:InTune etc.).

Zero or more of these Subscriptions can be Azure Subscriptions).

AccountSubscriptionAzure Subscription0-*

As stated above, there are two types of Accounts: * Personal Accounts * Organisation Accounts.

Their primary characteristics are described below.

Personal Account

Personal Accounts:

  • are personal, consumer accounts, created by individuals themselves (as oppossed to an Org's admin) and stored at https://live.com
  • services authenticate by redirecting users to sign in via https://signin.live.com
  • are currently called Microsoft Accounts (Passport Accounts became Live Accounts, which became Microsoft Accounts)
  • Can access services registered in the Azure ADs to which the user has been invited.
    • Note: Azure AD has a federation trust relationship with https://live.com. Hence Azure AD can authenticate “native” org accounts, as well as “guest” consumer Microsoft Accounts.
  • Considerations:
    • There is no API for provisioning Microsoft Accounts, and therefore cannot currently fulfill Organisational (Business/School) provisioning/management/deprovisioning requirements.

Organisation Accounts

Organisation Accounts: * are created by Organisations using Azure AD, or their IT:AD:Office 365 (O365) Subscription's Azure AD. * are Accounts managed in an Organisation's Subscription's Azure AD (either by Cloud Identities, Synchronized Identities, Federated Identities) * services authenticate by redirecting users to sign in via https://signin.live.com * can access services registered in the Azure ADs to which the user belongs (his own org), or has been invited.

You can manage your Account from various locations (this makes it a little confusing).

You can manage your Account in one of the following locations: * https://live.com ← core Account Information * https://account.windowsazure.com ← Azure specific Account information (Name can be different than Core for some reason)

An Account (whether a Personal Microsoft Account or Organisation Account) can be associated to n Subscriptions:

AccountSubscriptionsSubscriptions tovarious services suchas Azure, O365, MSDN,VS Team Services, etc.0-*

Subscriptions can be managed as follows: * Azure:

* O365:

* Visual Studio Team Services:

  • (todo)

As stated elsewhere, an Account can be related to 0-* Subscriptions.

AccountSubscriptions0-*

But a Subscription always has at least one IT:AD:Azure:Account associated to it as its IT:AD:Azure:Security:Role:BuiltIn Roles:Owner (and its Service Administrator (SA)).

AccountSubscriptionAccount: OwnerAccount: AdministratorAccount: Co-Administrators1-*

Whereas only the Account Administrator (AA) can see billing information (Credit Card info, etc.) any of the above Accounts can create services/resources (including Azure AD instances, which we'll get back to later).

An Account can have several Administration Roles1) per service2). The Service can be Azure in general, or a Service within Azure (eg Azure AD).


  • /home/skysigal/public_html/data/pages/it/ad/azure/account/home.txt
  • Last modified: 2023/11/04 22:53
  • by 127.0.0.1