Contoso Inc. security architecture
After a series of security workshops with their implementation partner Proseware Inc., and after gaining a full understanding of the Power Platform security possibilities, Contoso Inc. has created a security architecture for their Power Platform solution.
In this section, we will describe their security decisions in more detail.
Active Directory integration
After Contoso Inc. already decided to use a two-tenant architecture, it was further decided that a federation-based integration will be implemented with their two AAD tenants. For this purpose, Contoso Inc. will establish a testing Active Directory forest and implement the Azure AD Connect component for both tenants with all features, including ADFS. This approach will allow them to keep full control over the user identities, security policies, and other already very well-established IT standards within their existing IT landscape. They will enable the following ADFS features:
...