1. Start with Cloud-Based Sign-In
Begin by asking yourself:— Do you want Azure AD to handle sign-in completely in the cloud? If you answer Yes, continue to the next decision point. If not, you’ll later explore federation environments.
2. Enforce User-Level Azure AD Security Policies
Next, determine whether you require enforcement of user-level security policies during sign-in:— Do you want to enforce user-level Azure AD security policies? This helps you balance the benefits of cloud-based authentication against the control provided by your own infrastructure.
3. Consider Integration with an Existing Federation Provider
At this point, evaluate the need to integrate with an existing federation provider. This step is essential if your customer already maintains a federation infrastructure. Choose between integrating with the current setup or opting for a greenfield deployment that might exclude ADFS entirely.- For the branch that selects integration with a federation provider, two additional considerations emerge:
- Do you have sign-in requirements that are not natively supported by Azure AD?
- If on the other branch you answer No, ask again: is there any requirement that Azure AD doesn’t natively support?
4. Evaluate Disaster Recovery and Leaked Credential Reporting Needs
If integrating with an existing federation provider, the next step is to assess your need for sign-in disaster recovery or leaked credential reports:— Do you require sign-in disaster recovery or access to leaked credential reports?
For scenarios involving ADFS and PTA, on-premises authentication may become unavailable in events such as network failures. Azure AD Identity Protection can provide valuable leaked credential reports—especially if user passwords have been exposed on the dark web.
5. Decide on PTA and Seamless SSO with PHS
If you prefer not to integrate with an existing federation environment yet require sign-in disaster recovery and credentials leakage reports, consider using PTA plus Seamless SSO along with PHS. In this setup:- Your on-premises infrastructure handles authentication.
- If on-premises authentication fails, Azure AD’s disaster recovery plan automatically transitions to PHS since passwords are synchronized to the cloud.
If disaster recovery is not required, you may choose to rely solely on PTA with Seamless SSO.