Overviewing directory-based authentication in depth
Microsoft Azure Stack Hub supports multiple Active Directory topologies for identity and authentication depending on the identity provider chosen. There are also differences depending on whether this Azure Stack Hub is a single-tenant or multi-tenancy deployment. By default, when Azure Stack Hub is deployed with AAD as the identity provider, then it is configured as a single-tenant topology. Let's start by discussing that topology in more detail.
Understanding the AAD single-tenant topology
This is the default topology that is chosen when you deploy Azure Stack Hub with AAD selected as the identity provider. A single-tenant topology is useful when all users are part of the same tenant. It is the typical topology used by an organization that hosts an Azure Stack Hub instance. This is shown in the following figure:
This topology means...