Providing Active Directory access
- Active Directory is used for storing below in an enterprise.
- users
- groups
- computers
- To setup new active directory on Cloud
- AWS Directory Services
- Microsoft Entra Id
- If we want to sync existing users into cloud
- Azure AD /Microsoft Entra Connector
- AWS AD Connect
-
Approaches for syncing users
- Password Hash (One way)
- Password writeback (Two way)
- Active Directory Federation Services (ADFS)
- To use AD Users into AWS IAM Refer Here
Azure
- Microsoft Entra B2C
- Microsoft Entra B2B
AWS
- STS
Storing sensitive information
- AWS:
- KMS for keys used for encryption or decryption
- Secrets Manager for storing
- username and passwords
- database credentials
- tokens
- Azure:
- Azure Key Vault for storing everything above
