Differentiating between AD and AAD
A common misconception when comparing AD and AAD is that AAD is just AD in the cloud. This statement is not true.
While AD is the directory service for on-premises domains, AAD allows users to access Office 365, the Azure portal, SaaS applications, internal resources, and other cloud-based apps.
Both are identity and access management solutions, yes. But besides that, both technologies are very different, as you can see in the following figure:
Figure 7.1 – AD versus AAD
AAD can sync with an on-premises AD (hybrid identity) and supports federation (e.g., through Security Assertion Markup Language (SAML)) or can be used as a single identity and access provider. It supports different types of authentication, such as the following:
- Cloud-only authentication: In this scenario, AAD acts as the sole IdP, without any synchronization with an on-premises AD. Users authenticate directly with AAD for access...