Hi @Anonymous • Thank you for reaching out. Please find my response inline:
a) Do we need to buy a separate subscription for this particular purpose for the whole users or our existing Office365 accounts AAD can make use of that purpose ?
- No, there is no need for a separate Azure AD subscription as the existing Azure AD that you are using for your O365 accounts can be used for this purpose.
b) How is the the subscription model for AAD ?
- If the application which available in AAD enterprise apps list is a Gallery App (available by default in AAD, e.g. Salesforce, ServiceNow etc.), there is no need to subscribe for any licenses. For Gallery apps, Microsoft have done the basic integration and has made most of the generic settings already pre-created in Azure for the users. With the free edition of Azure AD end users who have been assigned access to software as a service (SaaS) apps can get single sign-on access to unlimited number of cloud apps. c) Currently our AD is hosted in on-prem.
- To provided SSO experience to on-prem users while accessing Galley/SAAS apps, the users must be synced to Azure AD via Azure AD Connect tool.
Additional Info:
https://learn.microsoft.com/en-us/azure/active-directory/hybrid/how-to-connect-install-express
https://www.microsoft.com/en-us/security/business/identity-access-management/azure-ad-pricing
Please "Accept the answer" if the information helped you. This will help us and others in the community as well.