AAD
AAD provides single sign-on (SSO) and multi-factor authentication (MFA) to Windows 10 Enterprise and MEM to help protect your users from 99.9 percent of cybersecurity attacks.
AAD is the evolution of traditional AD (AD DS) and makes it possible to do the following:
- SSO simplifies access to your apps from anywhere.
- Conditional Access and MFA help to protect your environment from outside intruders.
- As a single identity platform, it lets you engage with internal and external users more securely.
- Developer tools make it easy to integrate identity into your apps and services.
Let's look at AAD users next.
AAD users
AAD users include the account settings of a user in your organization and only live in the Microsoft Azure cloud. Creating and deleting users can be done by using either the AAD Global Administrator role or an account that has the account administrator role-based access control (RBAC) role assigned.