{"id":1566,"date":"2013-03-04T08:11:47","date_gmt":"2013-03-04T17:11:47","guid":{"rendered":"http:\/\/www.cloudidentity.com\/blog\/?p=1566"},"modified":"2013-03-04T22:25:59","modified_gmt":"2013-03-05T07:25:59","slug":"managing-windows-azure-ad-from-the-windows-azure-portal-3-add-a-co-admin-use-2fa","status":"publish","type":"post","link":"https:\/\/www.cloudidentity.com\/blog\/2013\/03\/04\/managing-windows-azure-ad-from-the-windows-azure-portal-3-add-a-co-admin-use-2fa\/","title":{"rendered":"Managing Windows Azure AD from the Windows Azure Portal 3&ndash; Add a Co-Admin, Use 2FA"},"content":{"rendered":"<p>Here there\u2019s the last of three super quick visual guides about playing with the new Windows Azure Active Directory features in the Windows Azure portal. Please make sure you read <a href=\"http:\/\/blogs.msdn.com\/b\/windowsazure\/archive\/2013\/03\/04\/more-identity-and-access-management-improvements-in-windows-azure.aspx\">Alex\u2019s announcement<\/a> and watch Abhishek\u2019s video first! Also, you should read the first two posts of the series first.<\/p>\n<p>I\u2019ll try to keep the word count down, and let the screenshots speak! Hopefully this will entice you to try things yourself, and provide some reassurance if you are going through the process and get stuck. Note, I didn\u2019t work at all on this great feature! All the credit goes to the UX and directory teams, who did a super job here. I just went through the following steps as any other customer would, and took screenshots along the way.<\/p>\n<p>I broke down things in three posts:<\/p>\n<ol>\n<li><a href=\"https:\/\/www.cloudidentity.com\/blog\/2013\/03\/04\/managing-windows-azure-ad-from-the-windows-azure-portal-1-sign-up-with-an-organizational-account\/\">The first post<\/a> shows you how to sign up for a new Windows Azure subscription using an organizational account from an existing Windows Azure Active Directory tenant (e.g. your existing directory from an Office 365 subscription, etc). This option is actually not new, it was already available to you few weeks ago. I captured it anyway to give you a full end-to-end walkthrough with coherent names &amp; screens.<\/li>\n<li><a href=\"https:\/\/www.cloudidentity.com\/blog\/2013\/03\/04\/managing-windows-azure-ad-from-the-windows-azure-portal-2-explore-the-directory-features\/\">The second post<\/a> goes through the main directory management features offered by the portal<\/li>\n<li><strong>This post <\/strong>will demonstrate something really really cool: we\u2019ll create a new directory user, make it a global admin in the directory, and a co-admin in the Windows Azure subscription. Then\u2026 we\u2019ll configure that account to enforce phone-based additional authentication factor when accessing the portal <img decoding=\"async\" class=\"wlEmoticon wlEmoticon-smile\" alt=\"Smile\" src=\"https:\/\/www.cloudidentity.com\/blog\/wp-content\/uploads\/2013\/03\/wlEmoticon-smile2.png\" \/> pretty awesome, eh? Spoiler alert: there will be pictures of my phone.<br \/>\nREMEMBER: the multi-factor authentication feature is currently in PREVIEW.<\/li>\n<\/ol>\n<p>Ready? Let\u2019s do this thing. Go back to the list of users, and click \u201ccreate\u201d.<\/p>\n<p><a href=\"https:\/\/www.cloudidentity.com\/blog\/wp-content\/uploads\/2013\/03\/image.png\"><img loading=\"lazy\" decoding=\"async\" style=\"background-image: none; padding-top: 0px; padding-left: 0px; margin: 0px; display: inline; padding-right: 0px; border-width: 0px;\" title=\"image\" alt=\"image\" src=\"https:\/\/www.cloudidentity.com\/blog\/wp-content\/uploads\/2013\/03\/image_thumb.png\" width=\"604\" height=\"566\" border=\"0\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>Fill the details in, and make sure you assing the global administrator role. Also, check the \u201crequire multi-factor\u201d option.<\/p>\n<p><a href=\"https:\/\/www.cloudidentity.com\/blog\/wp-content\/uploads\/2013\/03\/image1.png\"><img loading=\"lazy\" decoding=\"async\" style=\"background-image: none; padding-top: 0px; padding-left: 0px; display: inline; padding-right: 0px; border-width: 0px;\" title=\"image\" alt=\"image\" src=\"https:\/\/www.cloudidentity.com\/blog\/wp-content\/uploads\/2013\/03\/image_thumb1.png\" width=\"604\" height=\"757\" border=\"0\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>User created! Paste the temporary password somewhere, we\u2019ll need it later.<\/p>\n<p><a href=\"https:\/\/www.cloudidentity.com\/blog\/wp-content\/uploads\/2013\/03\/image2.png\"><img loading=\"lazy\" decoding=\"async\" style=\"background-image: none; padding-top: 0px; padding-left: 0px; margin: 0px; display: inline; padding-right: 0px; border-width: 0px;\" title=\"image\" alt=\"image\" src=\"https:\/\/www.cloudidentity.com\/blog\/wp-content\/uploads\/2013\/03\/image_thumb2.png\" width=\"604\" height=\"757\" border=\"0\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>Now, we want to mark the newly created directory user as a co-admin for the current subscription. I didn\u2019t want to do too many screenshots for this, hence I compressed the instructions into one:<\/p>\n<ol>\n<li>go to the settings tab<\/li>\n<li>choose the administrators header<\/li>\n<li>click add<\/li>\n<li>enter the UPN of the newly created user<\/li>\n<li>check the 3-months trial subscription<\/li>\n<li>hit the \u201cok\u201d check button<\/li>\n<\/ol>\n<p><a href=\"https:\/\/www.cloudidentity.com\/blog\/wp-content\/uploads\/2013\/03\/image3.png\"><img loading=\"lazy\" decoding=\"async\" style=\"background-image: none; padding-top: 0px; padding-left: 0px; margin: 0px; display: inline; padding-right: 0px; border-width: 0px;\" title=\"image\" alt=\"image\" src=\"https:\/\/www.cloudidentity.com\/blog\/wp-content\/uploads\/2013\/03\/image_thumb3.png\" width=\"603\" height=\"757\" border=\"0\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>As established, your new user is now a co-admin. Time to test it! Sign out, and sign in as the new user.<a href=\"https:\/\/www.cloudidentity.com\/blog\/wp-content\/uploads\/2013\/03\/image4.png\"><img loading=\"lazy\" decoding=\"async\" style=\"background-image: none; padding-top: 0px; padding-left: 0px; margin: 0px; display: inline; padding-right: 0px; border-width: 0px;\" title=\"image\" alt=\"image\" src=\"https:\/\/www.cloudidentity.com\/blog\/wp-content\/uploads\/2013\/03\/image_thumb4.png\" width=\"603\" height=\"757\" border=\"0\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>Now, things will get a bit frantic. We created a new user: normally, that would entail at first login using the temporary password and changing it right away. On top of that, we are requesting multi-factor authentication: that too needs to be set up, and will also require extra steps. Long story short: this first sign in will have many steps, but it\u2019s a one-time only thing.<br \/>\nLet\u2019s dive right in. Sign in with the temporary password.<\/p>\n<p><a href=\"https:\/\/www.cloudidentity.com\/blog\/wp-content\/uploads\/2013\/03\/image5.png\"><img loading=\"lazy\" decoding=\"async\" style=\"background-image: none; padding-top: 0px; padding-left: 0px; margin: 0px; display: inline; padding-right: 0px; border-width: 0px;\" title=\"image\" alt=\"image\" src=\"https:\/\/www.cloudidentity.com\/blog\/wp-content\/uploads\/2013\/03\/image_thumb5.png\" width=\"604\" height=\"408\" border=\"0\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>Windows Azure AD sees that the user is required to use multi-factor auth, but that was not set up yet; hence, it offers to set things up right this moment. Go ahead and click the blue button.<\/p>\n<p><a href=\"https:\/\/www.cloudidentity.com\/blog\/wp-content\/uploads\/2013\/03\/image6.png\"><img loading=\"lazy\" decoding=\"async\" style=\"background-image: none; padding-top: 0px; padding-left: 0px; margin: 0px; display: inline; padding-right: 0px; border-width: 0px;\" title=\"image\" alt=\"image\" src=\"https:\/\/www.cloudidentity.com\/blog\/wp-content\/uploads\/2013\/03\/image_thumb6.png\" width=\"604\" height=\"368\" border=\"0\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>Here you are asked to provide a phone number and choose how verification will take place, phone call or SMS. I picked SMS, given that it\u2019s pretty late at night and my wife would not appreciate a call <img decoding=\"async\" class=\"wlEmoticon wlEmoticon-smile\" alt=\"Smile\" src=\"https:\/\/www.cloudidentity.com\/blog\/wp-content\/uploads\/2013\/03\/wlEmoticon-smile2.png\" \/><\/p>\n<p><a href=\"https:\/\/www.cloudidentity.com\/blog\/wp-content\/uploads\/2013\/03\/image7.png\"><img loading=\"lazy\" decoding=\"async\" style=\"background-image: none; padding-top: 0px; padding-left: 0px; margin: 0px; display: inline; padding-right: 0px; border-width: 0px;\" title=\"image\" alt=\"image\" src=\"https:\/\/www.cloudidentity.com\/blog\/wp-content\/uploads\/2013\/03\/image_thumb7.png\" width=\"604\" height=\"389\" border=\"0\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>As soon as you hit save, the system will initialize by sending you a message.<\/p>\n<p><a href=\"https:\/\/www.cloudidentity.com\/blog\/wp-content\/uploads\/2013\/03\/image8.png\"><img loading=\"lazy\" decoding=\"async\" style=\"background-image: none; padding-top: 0px; padding-left: 0px; margin: 0px; display: inline; padding-right: 0px; border-width: 0px;\" title=\"image\" alt=\"image\" src=\"https:\/\/www.cloudidentity.com\/blog\/wp-content\/uploads\/2013\/03\/image_thumb8.png\" width=\"604\" height=\"459\" border=\"0\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>\u2026and sure enough, here there\u2019s the message. This will time out pretty fast, as I discovered when taking too much time capturing screens. Reply to the text with the provided code, then see what happens in the browser.<\/p>\n<p><a href=\"https:\/\/www.cloudidentity.com\/blog\/wp-content\/uploads\/2013\/03\/image9.png\"><img loading=\"lazy\" decoding=\"async\" style=\"background-image: none; padding-top: 0px; padding-left: 0px; margin: 0px; display: inline; padding-right: 0px; border-width: 0px;\" title=\"image\" alt=\"image\" src=\"https:\/\/www.cloudidentity.com\/blog\/wp-content\/uploads\/2013\/03\/image_thumb9.png\" width=\"604\" height=\"342\" border=\"0\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>Your phone authentication factor is set up. Once you hit close, the system will make you use it right away.<\/p>\n<p><a href=\"https:\/\/www.cloudidentity.com\/blog\/wp-content\/uploads\/2013\/03\/image10.png\"><img loading=\"lazy\" decoding=\"async\" style=\"background-image: none; padding-top: 0px; padding-left: 0px; margin: 0px; display: inline; padding-right: 0px; border-width: 0px;\" title=\"image\" alt=\"image\" src=\"https:\/\/www.cloudidentity.com\/blog\/wp-content\/uploads\/2013\/03\/image_thumb10.png\" width=\"604\" height=\"487\" border=\"0\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>Here there\u2019s the normal verification screen; expect the same phone flow as before.<\/p>\n<p><a href=\"https:\/\/www.cloudidentity.com\/blog\/wp-content\/uploads\/2013\/03\/image11.png\"><img loading=\"lazy\" decoding=\"async\" style=\"background-image: none; padding-top: 0px; padding-left: 0px; display: inline; padding-right: 0px; border-width: 0px;\" title=\"image\" alt=\"image\" src=\"https:\/\/www.cloudidentity.com\/blog\/wp-content\/uploads\/2013\/03\/image_thumb11.png\" width=\"604\" height=\"409\" border=\"0\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>OK, now you concluded your directory sign-in; however, you are still using your temporary password\u2026 hence you\u2019ll have to change it.<\/p>\n<p><a href=\"https:\/\/www.cloudidentity.com\/blog\/wp-content\/uploads\/2013\/03\/image12.png\"><img loading=\"lazy\" decoding=\"async\" style=\"background-image: none; padding-top: 0px; padding-left: 0px; display: inline; padding-right: 0px; border-width: 0px;\" title=\"image\" alt=\"image\" src=\"https:\/\/www.cloudidentity.com\/blog\/wp-content\/uploads\/2013\/03\/image_thumb12.png\" width=\"604\" height=\"394\" border=\"0\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>Once you change it, you are finally down with the setup! All that was a one-time thing, the steps from now on are the steps you will go through for signing in from now on.<\/p>\n<p>Sign in with the new password.<\/p>\n<p><a href=\"https:\/\/www.cloudidentity.com\/blog\/wp-content\/uploads\/2013\/03\/image13.png\"><img loading=\"lazy\" decoding=\"async\" style=\"background-image: none; padding-top: 0px; padding-left: 0px; margin: 0px; display: inline; padding-right: 0px; border-width: 0px;\" title=\"image\" alt=\"image\" src=\"https:\/\/www.cloudidentity.com\/blog\/wp-content\/uploads\/2013\/03\/image_thumb13.png\" width=\"604\" height=\"397\" border=\"0\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>Do the phone authentication factor flow.<\/p>\n<p><a href=\"https:\/\/www.cloudidentity.com\/blog\/wp-content\/uploads\/2013\/03\/image14.png\"><img loading=\"lazy\" decoding=\"async\" style=\"background-image: none; padding-top: 0px; padding-left: 0px; margin: 0px; display: inline; padding-right: 0px; border-width: 0px;\" title=\"image\" alt=\"image\" src=\"https:\/\/www.cloudidentity.com\/blog\/wp-content\/uploads\/2013\/03\/image_thumb14.png\" width=\"604\" height=\"411\" border=\"0\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>&#8230;and you are in!!! Pretty cool, If I may say so <img decoding=\"async\" class=\"wlEmoticon wlEmoticon-smile\" alt=\"Smile\" src=\"https:\/\/www.cloudidentity.com\/blog\/wp-content\/uploads\/2013\/03\/wlEmoticon-smile2.png\" \/><\/p>\n<p><a href=\"https:\/\/www.cloudidentity.com\/blog\/wp-content\/uploads\/2013\/03\/image15.png\"><img loading=\"lazy\" decoding=\"async\" style=\"background-image: none; padding-top: 0px; padding-left: 0px; margin: 0px; display: inline; padding-right: 0px; border-width: 0px;\" title=\"image\" alt=\"image\" src=\"https:\/\/www.cloudidentity.com\/blog\/wp-content\/uploads\/2013\/03\/image_thumb15.png\" width=\"604\" height=\"493\" border=\"0\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>Alrighty, this concludes our quick visual tour on the new Windows Azure Active Directory features in the Windows Azure AD portal. Once again, <a href=\"http:\/\/blogs.msdn.com\/b\/windowsazure\/archive\/2013\/03\/04\/more-identity-and-access-management-improvements-in-windows-azure.aspx\">make sure you read Alex\u2019s post about this<\/a>. This is very exciting stuff!!! <img decoding=\"async\" class=\"wlEmoticon wlEmoticon-smile\" alt=\"Smile\" src=\"https:\/\/www.cloudidentity.com\/blog\/wp-content\/uploads\/2013\/03\/wlEmoticon-smile2.png\" \/><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Here there\u2019s the last of three super quick visual guides about playing with the new Windows Azure Active Directory features in the Windows Azure portal. Please make sure you read Alex\u2019s announcement and watch Abhishek\u2019s video first! Also, you should read the first two posts of the series first. I\u2019ll try to keep&#8230;<\/p>\n","protected":false},"author":1,"featured_media":1553,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_kad_post_transparent":"","_kad_post_title":"","_kad_post_layout":"","_kad_post_sidebar_id":"","_kad_post_content_style":"","_kad_post_vertical_padding":"","_kad_post_feature":"","_kad_post_feature_position":"","_kad_post_header":false,"_kad_post_footer":false,"footnotes":""},"categories":[1],"tags":[],"class_list":["post-1566","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized"],"_links":{"self":[{"href":"https:\/\/www.cloudidentity.com\/blog\/wp-json\/wp\/v2\/posts\/1566","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.cloudidentity.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.cloudidentity.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.cloudidentity.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.cloudidentity.com\/blog\/wp-json\/wp\/v2\/comments?post=1566"}],"version-history":[{"count":3,"href":"https:\/\/www.cloudidentity.com\/blog\/wp-json\/wp\/v2\/posts\/1566\/revisions"}],"predecessor-version":[{"id":1636,"href":"https:\/\/www.cloudidentity.com\/blog\/wp-json\/wp\/v2\/posts\/1566\/revisions\/1636"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.cloudidentity.com\/blog\/wp-json\/wp\/v2\/media\/1553"}],"wp:attachment":[{"href":"https:\/\/www.cloudidentity.com\/blog\/wp-json\/wp\/v2\/media?parent=1566"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.cloudidentity.com\/blog\/wp-json\/wp\/v2\/categories?post=1566"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.cloudidentity.com\/blog\/wp-json\/wp\/v2\/tags?post=1566"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}