Determine which directory integration scenario to use

Updated: July 13, 2015

Applies To: Azure, Office 365, Windows Intune

An important part of planning your Azure Active Directory experience is determining how you want to administer your directory, as well as how your users will sign into Microsoft cloud services.

The objective of this topic is to help you quickly find the list of directory integration features and benefits you need and map them to the most appropriate directory integration scenario.

Use the following decision matrix if your corporate environment has a single on-premises source forest:

I need to… DirSync with Password Sync DirSync with Single Sign-On

Sync new user, contact, and group accounts created in my on-premises Active Directory to the cloud automatically

                    Checklist

                      Checklist

Sync incremental updates made to existing accounts in my on-premises Active Directory to the cloud automatically

                    Checklist

                      Checklist

Set up my tenant for Office 365 hybrid scenarios

                    Checklist1

                      Checklist

Enable my users to sign in and access cloud services using their on-premises password

                    Checklist

                      Checklist

Reduce password administration costs

                    Checklist

                      Checklist

Control password policies from my on-premises Active Directory

                    Checklist

                      Checklist

Enable cloud-based multi-factor authentication solutions

                    Checklist

 

Enable on-premises multi-factor authentication solutions

 

                      Checklist

Ensure user authentications occur in my on-premises Active Directory

 

                      Checklist

Implement single sign-on using corporate credentials

 

                      Checklist

Customize the user Sign-In page

 

                      Checklist

Limit access to cloud services based on the location, client type or Exchange endpoint of the client

 

                      Checklist

1 Provides limited support

If you need to synchronize identity data from a multi-forest on-premises Active Directory environment to Azure AD, see the Multi-forest - DirSync with Single Sign-On.

See Also

Concepts

Directory integration
DirSync with Password Sync
DirSync with Single Sign-On
Multi-forest - DirSync with Single Sign-On