Tech in 5 minutes: Azure AD Application Proxy

Поділитися
Вставка
  • Опубліковано 7 вер 2024
  • In about 5 minutes(Excluding the intro 😉), I walk you through Azure AD Application proxy, what it can be used for, how to set it up, and what improvements it could bring you.
    In my example I am protecting a Unifi Controller, but it could of course be used for any other web application too. If you liked this video, check out my blogs at cyberdrain.com too. :)

КОМЕНТАРІ • 38

  • @tech_junky
    @tech_junky 2 роки тому +1

    One of the most under used azure functionalities. Great video

  • @DanialBulloch
    @DanialBulloch 3 роки тому +2

    Thanks Kelvin. Great content as always. Small note, when you go to set this up, you will need to turn of Translate URLs in Headers for authentication to work.

    • @KelvinTegelaar
      @KelvinTegelaar  3 роки тому +1

      Good call bud! I forgot to cover in the video to disable URL translations by default.

  • @GavinStone85
    @GavinStone85 3 роки тому +1

    I had no idea about this functionality. Great video, Kelvin! Thank you for all your effort you put in to things like this.

  • @Solabo95
    @Solabo95 3 місяці тому

    Your video is amazingly informative sir thank you very much!

  • @ErnestDotPro
    @ErnestDotPro 3 роки тому +3

    This is super informative and something we should all be using. Thank you so much! Well done, I can't wait to see more. =D

    • @KelvinTegelaar
      @KelvinTegelaar  3 роки тому +1

      Thanks Ernest, looking forward to making more! :)

  • @craig4
    @craig4 3 роки тому +1

    Great video and can’t wait to see more!

  • @villaran9295
    @villaran9295 Рік тому

    Thank you so much!

  • @Mw2SnipeEm
    @Mw2SnipeEm 3 роки тому +1

    Really underrated! I subscribed

  • @TechFromYorkshire
    @TechFromYorkshire 3 роки тому +1

    Good video but super annoying it requires P1 or BP licensing. If Microsoft was serious about security, they would make it more available at lower licensing levels! Having said that, we keep saying that we’re not getting the most out of our subscription so videos like this are really useful! Thank you 😊

    • @KelvinTegelaar
      @KelvinTegelaar  3 роки тому +3

      M365 BP is really the most cost effective method to achieve it, but I do agree that some security features should be made available to more tiers. :)

  • @brantschafer9733
    @brantschafer9733 3 роки тому

    Very helpful, thank you for publishing. Time to hit the "subscribe" button.

  • @lgiraldo
    @lgiraldo 3 роки тому +3

    Thanks Kelvin, welcome to the Tube! Does the password-based SSO option in an application proxy assume the login uses AD credentials, and inject the user’s creds automatically, or would a user have the option of providing custom credentials?

    • @KelvinTegelaar
      @KelvinTegelaar  3 роки тому +2

      You would have to input the credentials to be used by the plugin as the admin once, so the user would never get access to those credentials, and thanks! :)

  • @Maxtorgain
    @Maxtorgain 3 роки тому

    I had no idea this functionality existed, and the explanation and example were fantastic. Thanks. Can I ask if anyone has this in production, and if so is there any additional alert monitoring you implemented resultant of it?

    • @KelvinTegelaar
      @KelvinTegelaar  3 роки тому +1

      Yes, we use it in production all over. We have some extra monitoring on the proxy services, and on the Azure side if the App Proxy is online.

  • @bbansbach
    @bbansbach 3 роки тому +1

    This is awesome! Seems like a great way to open up WAN access to secured devices without having to limit to specific locations. Are you able to allow access to multiple devices through the one installed connector? For instance, non-cloud managed management portals (firewall, UPS, ESXi, etc.)?

    • @KelvinTegelaar
      @KelvinTegelaar  3 роки тому +2

      Yes! you can access anything the proxy has access to, I would suggest multiple proxy installs in the case one of the machines goes down though. :)

    • @bbansbach
      @bbansbach 3 роки тому +1

      @@KelvinTegelaar I'm excited to give this a try now, wasn't even aware of it. Thanks for the reply and the content!

  • @abdelalielghazrani5956
    @abdelalielghazrani5956 2 роки тому

    thks for your tuto

  • @jonathanlackman7198
    @jonathanlackman7198 3 роки тому

    I believe this is for web applications only, and won't yet support local on prem fat client VB or compiled apps. Maybe that's down the road, it would be pretty cool.

  • @user-oq5or9ep1e
    @user-oq5or9ep1e 10 місяців тому

    Hi Kelvin, how can we add more proxies ? is the internal link is our proxy link ? i am so new to this

  • @anandkumarmyadam2821
    @anandkumarmyadam2821 2 роки тому

    @Kelvin Tegelaar, Can we also expose the API's hosted in OnPremise through this and Manage using Azure APIM?

  • @yelowpunk
    @yelowpunk Рік тому

    whoa

  • @michaeelahmed5145
    @michaeelahmed5145 3 місяці тому

    Can you use this feature to sync up cached password on a hybrid joined device when there is no vpn available

  • @mma206224398
    @mma206224398 3 роки тому

    So we are investigating implementing a similar azure AD application proxy ...IE initial user authentication and then acting as a reverse proxy to the internal web applications
    We see this as a requirement to securely allow our employees to access selected internal applications from their own devices from external (internet)
    So could you assist please with guidance on how this can be achieved?
    Also how we can enable/implement sms and email?

  • @TechFromYorkshire
    @TechFromYorkshire 3 роки тому +1

    Quick question, I have a possible use case for this and just wondered how I would licence it. An external contractor needs access to an internal web app. I don’t want to punch holes in our firewall and we only have licences for M365 Business Standard and Exchange Online. Can I just buy a single P1 licence for this to work or do we have to licence everyone? Cheers

    • @KelvinTegelaar
      @KelvinTegelaar  3 роки тому

      Yes, you can only license the users that require access to the proxy.

    • @TechFromYorkshire
      @TechFromYorkshire 3 роки тому +1

      @@KelvinTegelaar ok, to be clear, if I buy a single P1 licence, that’s all I need to give the access I need to the user? Cheers

    • @KelvinTegelaar
      @KelvinTegelaar  3 роки тому +1

      @@TechFromYorkshire Correct. :)

    • @TechFromYorkshire
      @TechFromYorkshire 3 роки тому

      @@KelvinTegelaar cheers, I’ll go ahead and buy and test. You may have saved me a load of work and alleviated some of our security concerns! 👍

  • @petermooney5299
    @petermooney5299 3 роки тому +1

    Can this be used to do RDP?

    • @KelvinTegelaar
      @KelvinTegelaar  3 роки тому

      Yes, RDS/RDGateway access can be secured with this.

    • @petermooney5299
      @petermooney5299 3 роки тому +1

      @@KelvinTegelaar Can you do a Video on an RDS setup with this?