Managing Windows Azure AD from the Windows Azure Portal 3– Add a Co-Admin, Use 2FA
Here there’s the last of three super quick visual guides about playing with the new Windows Azure Active Directory features in the Windows Azure portal. Please make sure you read Alex’s announcement and watch Abhishek’s video first! Also, you should read the first two posts of the series first.
I’ll try to keep the word count down, and let the screenshots speak! Hopefully this will entice you to try things yourself, and provide some reassurance if you are going through the process and get stuck. Note, I didn’t work at all on this great feature! All the credit goes to the UX and directory teams, who did a super job here. I just went through the following steps as any other customer would, and took screenshots along the way.
I broke down things in three posts:
- The first post shows you how to sign up for a new Windows Azure subscription using an organizational account from an existing Windows Azure Active Directory tenant (e.g. your existing directory from an Office 365 subscription, etc). This option is actually not new, it was already available to you few weeks ago. I captured it anyway to give you a full end-to-end walkthrough with coherent names & screens.
- The second post goes through the main directory management features offered by the portal
- This post will demonstrate something really really cool: we’ll create a new directory user, make it a global admin in the directory, and a co-admin in the Windows Azure subscription. Then… we’ll configure that account to enforce phone-based additional authentication factor when accessing the portal
pretty awesome, eh? Spoiler alert: there will be pictures of my phone.
REMEMBER: the multi-factor authentication feature is currently in PREVIEW.
Ready? Let’s do this thing. Go back to the list of users, and click “create”.
Fill the details in, and make sure you assing the global administrator role. Also, check the “require multi-factor” option.
User created! Paste the temporary password somewhere, we’ll need it later.
Now, we want to mark the newly created directory user as a co-admin for the current subscription. I didn’t want to do too many screenshots for this, hence I compressed the instructions into one:
- go to the settings tab
- choose the administrators header
- click add
- enter the UPN of the newly created user
- check the 3-months trial subscription
- hit the “ok” check button
As established, your new user is now a co-admin. Time to test it! Sign out, and sign in as the new user.![]()
Now, things will get a bit frantic. We created a new user: normally, that would entail at first login using the temporary password and changing it right away. On top of that, we are requesting multi-factor authentication: that too needs to be set up, and will also require extra steps. Long story short: this first sign in will have many steps, but it’s a one-time only thing.
Let’s dive right in. Sign in with the temporary password.
Windows Azure AD sees that the user is required to use multi-factor auth, but that was not set up yet; hence, it offers to set things up right this moment. Go ahead and click the blue button.
Here you are asked to provide a phone number and choose how verification will take place, phone call or SMS. I picked SMS, given that it’s pretty late at night and my wife would not appreciate a call ![]()
As soon as you hit save, the system will initialize by sending you a message.
…and sure enough, here there’s the message. This will time out pretty fast, as I discovered when taking too much time capturing screens. Reply to the text with the provided code, then see what happens in the browser.
Your phone authentication factor is set up. Once you hit close, the system will make you use it right away.
Here there’s the normal verification screen; expect the same phone flow as before.
OK, now you concluded your directory sign-in; however, you are still using your temporary password… hence you’ll have to change it.
Once you change it, you are finally down with the setup! All that was a one-time thing, the steps from now on are the steps you will go through for signing in from now on.
Sign in with the new password.
Do the phone authentication factor flow.
…and you are in!!! Pretty cool, If I may say so ![]()
Alrighty, this concludes our quick visual tour on the new Windows Azure Active Directory features in the Windows Azure AD portal. Once again, make sure you read Alex’s post about this. This is very exciting stuff!!! ![]()
3 Responses to Managing Windows Azure AD from the Windows Azure Portal 3– Add a Co-Admin, Use 2FA
Leave a Reply Cancel reply
Vittorio who?
Follow @vibronet
Vittorio Bertocci is a developer, speaker, published author, avid reader, troublemaker, foodie, Italian expat, and other things that would not be wise to mention here.
This is Vittorio's personal blog. The views and opinions expressed here are his, and not those of his employer.
"I like the minimalist edge this one sports :-) http://t.co/RMovcUCwXI"yesterday"Wife (abt a 3rd party): "dude! If you don't know SQL, be quiet abt it and quickly learn it!" #dinnertimeatbertoccihousehold"2 days ago"starting to feel "new PC setup fatigue". Why can't all apps & settings roam seamlessly like the Widows Store ones?"4 days agoPosts
- May 2013 (2)
- April 2013 (17)
- March 2013 (16)
- February 2013 (6)
- January 2013 (4)
- December 2012 (3)
- November 2012 (5)
- October 2012 (1)
- August 2012 (3)
- July 2012 (6)
- June 2012 (9)
- April 2012 (1)
- March 2012 (7)
- February 2012 (1)
- December 2011 (1)
- November 2011 (1)
- October 2011 (2)
- September 2011 (1)
- August 2011 (2)
- July 2011 (5)
- June 2011 (2)
- May 2011 (15)
- April 2011 (9)
- March 2011 (2)
- February 2011 (5)
- January 2011 (8)
- December 2010 (3)
- November 2010 (3)
- October 2010 (6)
- September 2010 (6)
- August 2010 (8)
- July 2010 (2)
- June 2010 (9)
- May 2010 (13)
- April 2010 (4)
- March 2010 (6)
- February 2010 (1)
- December 2009 (3)
- November 2009 (16)
- September 2009 (3)
- August 2009 (5)
- July 2009 (6)
- June 2009 (7)
- May 2009 (10)
- April 2009 (11)
- March 2009 (4)
- February 2009 (2)
- January 2009 (6)
- December 2008 (3)
- November 2008 (9)
- October 2008 (3)
- September 2008 (5)
- August 2008 (7)
- July 2008 (8)
- June 2008 (6)
- May 2008 (6)
- April 2008 (11)
- March 2008 (10)
- February 2008 (9)
- January 2008 (12)
- December 2007 (6)
- November 2007 (5)
- October 2007 (10)
- September 2007 (4)
- August 2007 (1)
- July 2007 (1)
- June 2007 (17)
- May 2007 (8)
- April 2007 (10)
- March 2007 (10)
- February 2007 (4)
- January 2007 (6)
- December 2006 (2)
- November 2006 (3)
- October 2006 (5)
- September 2006 (3)
- August 2006 (7)
- July 2006 (3)
- June 2006 (7)
- May 2006 (4)
- April 2006 (6)
- March 2006 (8)
- February 2006 (3)
- January 2006 (2)
- December 2005 (5)
- November 2005 (2)
- October 2005 (6)
- July 2005 (12)
- June 2005 (6)
- May 2005 (3)
- April 2005 (8)
- March 2005 (4)
- February 2005 (14)
- January 2005 (9)
- December 2004 (5)
- November 2004 (1)
- October 2004 (3)
- June 2004 (3)
- May 2004 (3)
- April 2004 (3)
- March 2004 (1)
- February 2004 (2)
- January 2004 (3)
- December 2003 (5)
- November 2003 (5)
- October 2003 (5)
- September 2003 (5)
- July 2003 (2)
- June 2003 (4)
- May 2003 (1)
- April 2003 (9)







[...] Managing Windows Azure AD from the Windows Azure Portal 3– Add a Co-Admin, Use 2FA Managing Windows Azure AD from the Windows Azure Portal 1– Sign Up with an Organizational Account [...]
[...] The third post will demonstrate something really really cool: we’ll create a new directory user, make it a global admin in the directory, and a co-admin in the Windows Azure subscription. Then… we’ll configure that account to enforce phone-based additional authentication factor when accessing the portal pretty awesome, eh? Spoiler alert: there will be pictures of my phone. [...]
[...] phone-based multifactor authentication preview is probably my favorite new feature. For details, check out this walkthrough; but in a nutshell, [...]