You can achieve all your conditions by either using ADFS or PTA(Pass Through Authentication).
Instead of using at least 4( depend on your use base) ADFS and proxy servers, you can use mostly 2-3 severs with PTA Agent.
This browser is no longer supported.
Upgrade to Microsoft Edge to take advantage of the latest features, security updates, and technical support.
I have a Solution that either using leverage existing ADFS infrastructure or any other alternative and need to restrich the follwoing :
1-ensure not to increase number of existing servers for authentication
2-restrict Current logon hours defined on AD need to be abided to for specific roles
3- No disruption to Exchange Online / hybrid access
4- Password should not be synced to the cloud
You can achieve all your conditions by either using ADFS or PTA(Pass Through Authentication).
Instead of using at least 4( depend on your use base) ADFS and proxy servers, you can use mostly 2-3 severs with PTA Agent.
is your answer covers the scenario below:
Brief:
Contoso Airlines has been leveraging Office 365 for 3 years for 100,000 employees with 40,000 cabin crew, 10,000 front line workers and the rest information workers. They are currently leveraging primarily EXO in hybrid mode as well as SPO, OneDrive, and most recently evaluating Teams and Yammer. BYOD is a core principal as Cabin Crew and Frontline workers leverage their own devices to access corporate resources. Contoso has also started to leverage other SaaS applications that are critical to its business such as Salesforce, Oracle HRMS and a small population of users leveraging Box. Because of its multinational operations, Contoso needs to abide by various regulations such as local data residency, GDPR, etc…
Business requirements
They are formulating their cyber security strategy and are looking at leveraging cloud-based security products as much as possible given their existing footprint in the cloud. Below are their key requirements from a business / security perspective.