Azure AD was the first service made available on Azure, and it is the authority service for user management in Microsoft Office 365. It is a core service, built on a global infrastructure, meant to provide a base identity management system to each organization.
What is identity management? It is a foundational system for any environment, which maintains the identity of each user object in a central location and controls access to other users, resources, and objects of that environment.
Identity management has two components—authentication and authorization, as shown in the following figure:
![](https://static.packt-cdn.com/products/9781788622073/graphics/assets/6fabe261-8f0a-4397-ab59-92f3b2f41e08.png)
As shown in the following figure, your organization may want to connect its on-premises AD with Office 365:
![](https://static.packt-cdn.com/products/9781788622073/graphics/assets/d9986fca-4dc5-493d-bcae-763af39af3e8.png)