4 ms·
I'm sorry but can someone explain to me how this might benefit my company? We have 20 employees and use Microsoft Office 365.
by chunkyslink 9y ago
I'm sorry but can someone explain to me how this might benefit my company? We have 20 employees and use Microsoft Office 365.
- pjc50 9y agoDo you want to write a webapp to manipulate AD? Otherwise this probably isn't of any use to you.
- nthcolumn 9y agoScenario #1: You have a small, team, busy people and have some process or workflow that would be greatly streamlined by a simple one-page app let's call it 'todo' which needs to integrate with email and provide single sign-on for ease of use. Your awesome dev Steph who dreams REST hand-pours with love your artisanal todo-365 app this weekend and everyone is using it next week and saving heaps of time because y'know there are only twenty of you... yet. FTW! Scenarios #2: Ugh okay, Alex is the devops, sysadmin, security officer, fire-warden and makes great bullet-coffee but even with twenty there are lot of domain groups to manage with your startup and lots of projects depending on them so Alex just needs a python script for his Ansible playbook and because powershell makes Alex want to throw up.
- toyg 9y agoDoesn't look to me like this can work with web-based AD, so it's probably useless unless you have an actual domain controller on-premises. For the record, web-based 365 ADs (and most modern on-prem) already support webservices, just soap (and somewhat painful) rather than rest. I use it to authenticate from an app outside our network, the implementation wasn't that hard (python) but i really only do auth, no manipulation. It would be cool if MS added REST as an option to make this sort of common case easier, but they are too busy selling you complex integrated services to do that in Azure ("use Visual Studio, next next next, your app is now deployed on Azure and completely integrated with all these management tools. Cool, uh? Now give me lots of money every month or turn it off.")
- nthcolumn 9y agoYes. 365 is cloud AD. My bad. Not familiar with it. Are there no endpoints?
- arethuza 9y agoAzure Active Directory has a pretty comprehensive REST & JSON API - the Azure Active Directory Graph API: https://docs.microsoft.com/en-us/azure/active-directory/develop/active-directory-graph-api https://docs.microsoft.com/en-us/azure/active-directory/deve...
- dpim 9y agoIt's recommended to access AAD through the Microsoft Graph API (as opposed to the AAD Graph API) unless it is one of the few scenarios not yet supported on Microsoft Graph. There is a lot of investment in adding new functionality to Microsoft Graph (such as the ability to extend AAD entities with custom, persisted properties on the /beta/ endpoint) and tooling. You can try/prototype out a bunch of your AAD requests in the Graph Explorer without writing code/needing to authenticate for most calls: https://developer.microsoft.com/en-us/graph/graph-explorer https://developer.microsoft.com/en-us/graph/graph-explorer
- arethuza 9y agoAh yes - well spotted. I actually did mean the main Microsoft API rather than the specific AAD one....
- sjark 9y agoAzure AD (Office 365) already has a REST API (https://developer.microsoft.com/en-us/graph/ https://developer.microsoft.com/en-us/graph/) so this is really for on-prem Active Directories. On-prem Active Directory also has AD Web Services (https://technet.microsoft.com/en-us/library/dd391908(v=ws.10).aspx https://technet.microsoft.com/en-us/library/dd391908(v=ws.10...) that I guess you could use instead of this, but a simple rest api like this will be easier to integrate with.
- KaiserPro 9y agoIf your AD doesn't have a saml endpoint, and you down want to talk directly to AD, this is _a_ way. However it doesn't allow kerberos, or 2fa, so its not _all_ that useful in an enterprise setting.