{"id":91597,"date":"2020-07-27T09:00:51","date_gmt":"2020-07-27T16:00:51","guid":{"rendered":"https:\/\/www.microsoft.com\/en-us\/security\/blog\/\/?p=91597"},"modified":"2023-05-15T23:02:46","modified_gmt":"2023-05-16T06:02:46","slug":"guiding-principles-identity-products","status":"publish","type":"post","link":"https:\/\/www.microsoft.com\/en-us\/security\/blog\/2020\/07\/27\/guiding-principles-identity-products\/","title":{"rendered":"Guiding principles of our identity strategy: staying ahead of evolving customer needs"},"content":{"rendered":"
Last June, when I shared the 5 principles driving a customer-obsessed identity strategy at Microsoft<\/a>, many of you had embraced the idea of a boundaryless environment, but relatively few had implemented it in practice. A global pandemic made remote access essential and forced many of you to accelerate your digital transformation plans.<\/p>\n The new reality requires not only supporting secure remote productivity and collaboration, but also other remote operations, such as onboarding, offboarding, and training employees. And this reality will continue for the near future. According to our most recent Work Life Index<\/a>, 71 percent of employees and managers (Information Workers) reported a desire to continue working from home at least part-time post-pandemic.<\/p>\n Your experiences and insights have helped shape the investments we\u2019re making in our identity services for the coming year and beyond. Today, I\u2019m sharing with you the updated set of guiding principles we\u2019re following to deliver a secure and scalable identity solution that\u2019s seamless for your end-users.<\/p>\n An identity system that is secure from the ground up continues to drive our product investments. In a recent survey of over 500 security executives, achieving a high level of protection without impeding user productivity was rated the number one challenge. <\/span><\/span>Using risk-based\u00a0<\/span><\/span>Conditional Access<\/span><\/span><\/a> policies in Azure AD, you can protect sensitive data with minimal friction to your end-users. Th<\/span><\/span>is<\/span><\/span>\u00a0combines the power of\u00a0<\/span><\/span>I<\/span><\/span>dentity\u00a0<\/span><\/span>P<\/span><\/span>rotection with\u00a0<\/span><\/span>C<\/span><\/span>onditional\u00a0<\/span><\/span>A<\/span><\/span>ccess to only prompt users when the sign-in is considered risky.<\/span><\/span>\u00a0<\/span><\/span><\/p>\n To enhance identity security, we\u2019re investing in compromise prevention technologies such as security defaults<\/a>, attack blocking, and password protection, as well as reputation and anti-abuse systems. Security mechanisms like end-user notifications and in-line interrupts can help everyone defend themselves from malicious actors. Every day, our data scientists and investigators evaluate the threat and log data to gather real-world insights, so they can adjust our machine learning algorithms to recognize and protect our customers from the latest threats.<\/span>\u00a0<\/span>\u00a0<\/span>\u00a0<\/span><\/p>\n Our product and ecosystem investments are guided by embracing\u00a0<\/span>Zero Trust<\/span><\/a>\u00a0security strategy as our worldview. We build Azure AD on the principles of Zero<\/span>\u00a0Trust<\/span>\u00a0to make implementing this model across your entire digital estate achievable at scale.<\/span>\u00a0<\/span><\/p>\n When your employees need to get things done, delivering a great user experience is essential. Employees who interact directly with customers, patients, and citizens need tools that are simple to learn and use. Because an easy, fast sign-in experience can make all the difference for your users\u2014and your Help Desk\u2014we\u2019re continuing our investments in Firstline Worker scenarios to address the challenges they face, for example, by providing seamless handoffs of shared mobile devices and enhancing tools and workflows for managers.<\/span>\u00a0<\/span><\/p>\n We\u2019ve seen more interest than ever in minimizing the use of passwords and\u00a0<\/span>eliminating them completely<\/span><\/a>. We continue our commitment to identity standards that help scale the technology and make it more useful and accessible for everyone.\u00a0<\/span>We\u2019re also\u00a0<\/span>developing<\/span> easy-to-use self-service options for end-users,\u00a0<\/span>such as<\/span>\u00a0managing security information, requesting access to apps and groups, and getting automatic recommendations for approved applications based on what peers are using most.\u00a0<\/span>\u00a0<\/span><\/p>\n Your customers, business partners, and suppliers also deserve a great, consumer-grade sign-in and collaboration experience. With the\u00a0<\/span>External Identities feature in Azure AD<\/span><\/a>, we are investing in making it easier for organizations and developers to secure, manage, and build apps that connect with different users outside your organization.<\/span>\u00a0<\/span>\u00a0<\/span><\/p>\n We\u2019re also looking ahead to technologies that respect everyone\u2019s privacy<\/span>,<\/span>\u00a0such as\u00a0<\/span>decentralized identity<\/span><\/a>\u00a0systems and verifiable credentials, that can verify information about an individual without requiring another username and password. Verifiable credentials are based on open standards from W3C and leverage the OIDC protocol, so you will be able to incorporate them into your existing systems.<\/span>\u00a0<\/span><\/p>\n I<\/span><\/span>t\u2019s hard to scale and manage security when you have overlapping products from multiple vendors that need to work together. You have a portfolio of on-premises and cloud-based applications that you need to manage\u00a0<\/span><\/span>and provide secure access to your users<\/span><\/span>. W<\/span><\/span>e ar<\/span><\/span>e simplifying\u00a0<\/span><\/span>these\u00a0<\/span><\/span>experiences in Azure AD, making it easier to manage all your\u00a0<\/span><\/span>applications for all your users in a single place<\/span><\/span>. We\u2019<\/span><\/span>re<\/span><\/span>\u00a0also consolidat<\/span><\/span>ing<\/span><\/span>\u00a0our APIs into Microsoft Graph to unify programmatic access to and management of data across workloads in Microsoft 365, including Azure AD.<\/span><\/span>\u00a0<\/span><\/p>\n By embracing open standards, we can help you more easily manage and secure your hybrid environment. We\u2019re working with partners like\u00a0<\/span><\/span>Box<\/span><\/span><\/a>\u00a0and\u00a0<\/span><\/span>Workday<\/span><\/span><\/a>\u00a0to further deepen our product integrations and streamline identity processes. Azure AD is pre-integrated with thousands of SaaS applications,\u00a0<\/span><\/span>and more to come,\u00a0<\/span><\/span>so you can provide users one set of credentials for\u00a0<\/span><\/span>secure access to any application<\/span><\/span><\/a>.\u00a0<\/span><\/span>We are continuing to extend capabilities in Azure AD so that you can migrate access for all your applications to be\u00a0<\/span>managed<\/span> in the cloud.<\/span><\/span>\u00a0<\/span><\/p>\n While having the ability to control access requests, approvals, and privileges in a timely and efficient manner is key, traditional identity governance and privileged access management solutions can be cumbersome and inflexible. This is true particularly now that these workflows are more often done remotely than in person. P<\/span>roviding<\/span>\u00a0every user<\/span>\u00a0access to the apps and files\u00a0<\/span>they\u00a0<\/span>need should be as simple as\u00a0<\/span>defining access packages<\/span><\/a>\u00a0and group assignments upfront<\/span>. Onboarding and offboarding employees then become easy with an automated solution connected to your HR system.<\/span>\u00a0<\/span><\/p>\n We want to help more companies adopt these scenarios and incorporate our machine learning technology in Azure AD to provide better recommendations and alerts in response to unusual behavior or too many unnecessary privileges. Our goal is for these capabilities to span both employee and\u00a0<\/span>external identity<\/span>\u00a0scenarios, built in the cloud for maximum benefit. This will help strengthen your overall security, efficiency, and compliance.<\/span>\u00a0<\/span>\u00a0<\/span><\/p>\n The last several months have been a whirlwind for all of us. We\u2019re in it with you, committed to helping you on your digital transformation journey. Whatever happens, you can be sure that we\u2019ll continue to listen to your feedback and input, so we can evolve our engineering priorities and principles to help you stay ahead and prepare for what comes next. Thank you for your continued trust!\u00a0\u00a0<\/span>\u00a0<\/span><\/p>\n To learn more about Microsoft Security solutions visit our website.<\/a>\u00a0 Bookmark the\u00a0Security blog<\/a>\u00a0to keep up with our expert coverage on security matters. Also, follow us at\u00a0@MSFTSecurity<\/a>\u00a0for the latest news and updates on cybersecurity.<\/p>\n","protected":false},"excerpt":{"rendered":" A global pandemic made remote access essential and forced many of professionals to accelerate their digital transformation plans. <\/p>\n","protected":false},"author":96,"featured_media":91599,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"ep_exclude_from_search":false,"_classifai_error":"","footnotes":""},"content-type":[3659],"topic":[3673,3682,3689],"products":[3702,3703],"threat-intelligence":[],"tags":[3824],"coauthors":[2093],"class_list":["post-91597","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","content-type-best-practices","topic-identity-and-access-management","topic-secure-remote-work","topic-zero-trust","products-microsoft-entra","products-microsoft-entra-id","tag-hybrid-work"],"yoast_head":"\nSecure adaptive access<\/h3>\n
Seamless user experiences<\/h3>\n
Unified identity management<\/h3>\n
Simplified identity governance<\/h3>\n