How to use Windows Azure with a Windows Azure Active Directory account

There has been some news about Windows Azure Active Directory recently. Yesterday an announce has been made about a deeper integration between Windows Azure portal and Windows Azure Active Directory (https://blogs.msdn.com/b/windowsazure/archive/2013/03/04/more-identity-and-access-management-improvements-in-windows-azure.aspx).

 

I had created a Windows Azure Active Directory standalone tenant a few weeks ago. You can do this yourself; it is available at https://activedirectory.windowsazure.com/Signup/QuickSignup.aspx?ru=https://activedirectory.windowsazure.com/default.aspx&ali=1.

 

In order to access Windows Azure resources from a Windows Azure Active Directory (from now on WAAD) account, it is possible to go the Windows Azure Management portal (https://manage.windowsazure.com) and connect like an Office 365 user. In this case we’ll see how to create a free subscription with this account.

 

Browse to https://manage.windowsazure.com

image

 

 image

image

image

 

image

 

 

clip_image001

clip_image002

image

you receive a text message on your phone that you can enter:

 

image

image

 

You can then fill the following form. Note that the e-mail can be changed to an e-mail address where you prefer to receive messages (this may not be the same as your WAAD account).

 

clip_image006

Click Next, and the subscription will be created

clip_image007

before you are redirected to the following page:

clip_image008

click on the Portal link in the upper right corner. You get a few welcome screens that show how the portal works:

clip_image009

clip_image010

clip_image011

clip_image012

clip_image013

then you get the usual experience:

clip_image014

In the Active Directory part of the portal, you can access your WAAD domain and manage users. In particular, you can create a co-admin account and ensure this account connects only with 2 factor authentication:

image

image

image

image

image

Add the user as a co-admin

image

image

image

Then, this user can connect thru https://activedirectory.windowsazure.com

 

image

image

image

image

you receive an SMS on your phone and you are asked to answer it with a code

Type the code on the phone and answer the SMS

image

 

image

 

image

 

Then this user can connect to the management portal

image

image

 

image

 

Smile

Benjamin