Top Banner
Zen & the Art of Enterprise Authentication: A Practitioner’s Viewpoint on Finding Balance Laura E. Hunter Identity Management Architect Microsoft IT @adfskitteh
23

CIS14: Zen and the Art of Cloud Adoption—a Practitioner’s Viewpoint on Finding Balance

Dec 02, 2014

Download

Technology

CloudIDSummit

Laura E. Hunter, Microsoft

Real-life tales from the trenches about how Microsoft IT is working to strike the right balance between enterprise requirements for security, privacy, control, and compliance, and creating a great experience for their users and customers who want to stay connected and productive no matter where they are or what device they’re using.
Welcome message from author
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
Page 1: CIS14: Zen and the Art of Cloud Adoption—a Practitioner’s Viewpoint on Finding Balance

Zen & the Art of Enterprise Authentication: A Practitioner’s Viewpoint on Finding

Balance

Laura E. Hunter Identity Management Architect Microsoft IT @adfskitteh

Page 2: CIS14: Zen and the Art of Cloud Adoption—a Practitioner’s Viewpoint on Finding Balance
Page 3: CIS14: Zen and the Art of Cloud Adoption—a Practitioner’s Viewpoint on Finding Balance
Page 4: CIS14: Zen and the Art of Cloud Adoption—a Practitioner’s Viewpoint on Finding Balance

But Security is No Laughing Matter…

Page 5: CIS14: Zen and the Art of Cloud Adoption—a Practitioner’s Viewpoint on Finding Balance

It’s All About Managing Expectations

Page 6: CIS14: Zen and the Art of Cloud Adoption—a Practitioner’s Viewpoint on Finding Balance

“Why Can’t I Use Facebook to Log Onto Payroll?”

Page 7: CIS14: Zen and the Art of Cloud Adoption—a Practitioner’s Viewpoint on Finding Balance

“Employees Must Use Smart Cards At All Times!”

Page 8: CIS14: Zen and the Art of Cloud Adoption—a Practitioner’s Viewpoint on Finding Balance

“We Don’t Allow Personal Devices On Our Network.”

Page 9: CIS14: Zen and the Art of Cloud Adoption—a Practitioner’s Viewpoint on Finding Balance

Physical Smart Cards @ Microsoft Today

u Walk into Building 92

u Present your driver’s license/passport

u Get your picture taken

u Pick a PIN

u Walk out with a smart card

u Don’t live in Redmond? We’ll mail it to your address of record. u What’s that? You’re travelling? Uhh…too bad, so sad?

Page 10: CIS14: Zen and the Art of Cloud Adoption—a Practitioner’s Viewpoint on Finding Balance

We need to make access easy and secure!

Page 11: CIS14: Zen and the Art of Cloud Adoption—a Practitioner’s Viewpoint on Finding Balance
Page 12: CIS14: Zen and the Art of Cloud Adoption—a Practitioner’s Viewpoint on Finding Balance

Multi-Factor Authentication Using Any Phone

•  Works with the user’s existing phone, anywhere in the world

•  Offers out-of-band protection from malware threats •  Verifies user logins, financial transactions, and more •  Features built-in support for leading on-premises

applications and cloud services

•  Streamlines user management and enrollment •  Backed by a scalable cloud service

Page 13: CIS14: Zen and the Art of Cloud Adoption—a Practitioner’s Viewpoint on Finding Balance

What Microsoft IT Has Learned So Far…

u Policy before technology u  “What is the assurance level of Phone Factor?”

u OOB registration experience == username & password

u Existing strong authenticators – physical/virtual smart cards

u  “So how do we proof the phone number?”

u Security – Physical smart card

u Usability – “Nobody likes to use smart cards!”

Page 14: CIS14: Zen and the Art of Cloud Adoption—a Practitioner’s Viewpoint on Finding Balance

Example of a “Balanced” Policy

Page 15: CIS14: Zen and the Art of Cloud Adoption—a Practitioner’s Viewpoint on Finding Balance

“Immutable Laws of Phone Authentication”

u The user must be expecting the challenge

u Otherwise, the user gets trained to always succeed the auth, thus defeating the point of strong auth entirely

u Corollary: the user must not be subjected to numerous auth requests in a row

Page 16: CIS14: Zen and the Art of Cloud Adoption—a Practitioner’s Viewpoint on Finding Balance

“Immutable Laws of Phone Authentication”

u The calling system must be reasonably assured of the user’s identity before initiating Phone Authentication u Phone Authentication is a secondary

authenticator, not primary, otherwise it’s trivial for an attacker to make a victim’s phone ring at 3:00 AM knowing only his or her username

Page 17: CIS14: Zen and the Art of Cloud Adoption—a Practitioner’s Viewpoint on Finding Balance

Other Fun Factors

u Be sure that “2FA” means what you think it means u Soft phones

u Call forwarding

u PIN protection

u  Think about international costs u Free in the US, inbound/outbound charges elsewhere

u Phone call vs data plan vs SMS

Page 18: CIS14: Zen and the Art of Cloud Adoption—a Practitioner’s Viewpoint on Finding Balance

About Those Pesky Twitter Accounts…

Page 19: CIS14: Zen and the Art of Cloud Adoption—a Practitioner’s Viewpoint on Finding Balance

Passwords Aren’t Quite Dead Yet…

u  How does the user authenticate to the portal?

u  Single-factor vs Dual-factor

u  Dual-factor does not prevent phishing, but mitigates the results of a successful phish

u  Who controls the password?

u  “What do you mean you’ve taken FaceBook off my phone?”

u  “Why do I have to give my Twitter password to IT?”

u  “@adfskitteh isn’t corporate, it’s mine!”

Page 20: CIS14: Zen and the Art of Cloud Adoption—a Practitioner’s Viewpoint on Finding Balance

Looking Ahead…

u Now that strong auth is easy(-ier), enforce it more broadly

u Client support “shims” where needed…

u Get rid of that “bag of passwords” u Or at least ask really nicely…

u  Focus on device protection u Registration, health, “device as smart card”

Page 21: CIS14: Zen and the Art of Cloud Adoption—a Practitioner’s Viewpoint on Finding Balance

THANK YOU! @ADFSKITTEH

Page 22: CIS14: Zen and the Art of Cloud Adoption—a Practitioner’s Viewpoint on Finding Balance
Page 23: CIS14: Zen and the Art of Cloud Adoption—a Practitioner’s Viewpoint on Finding Balance

© 2010 Microsoft Corporation. All rights reserved. This presentation is for informational purposes only. Microsoft makes no warranties, express or implied, in this summary.