Top Banner
Identity & Access Control in the Cloud Sachin Vinod Rathi Architect Advisor, Microsoft Corporation Niraj Bhatt Enterprise Architect, Windows Azure MVP
24

Identity & Access Control in the Cloud Sachin Vinod Rathi Architect Advisor, Microsoft Corporation Niraj Bhatt Enterprise Architect, Windows Azure MVP.

Dec 21, 2015

Download

Documents

Welcome message from author
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
Page 1: Identity & Access Control in the Cloud Sachin Vinod Rathi Architect Advisor, Microsoft Corporation Niraj Bhatt Enterprise Architect, Windows Azure MVP.

Identity & Access Control in the Cloud

Sachin Vinod RathiArchitect Advisor, Microsoft Corporation

Niraj BhattEnterprise Architect, Windows Azure MVP

Page 2: Identity & Access Control in the Cloud Sachin Vinod Rathi Architect Advisor, Microsoft Corporation Niraj Bhatt Enterprise Architect, Windows Azure MVP.

Identity Crisis

• Typical enterprise has dozens of providers– AD, SunOne, SQL, SAP, Oracle...

• Need to consolidate these, and federate where consolidation isn’t possible

• Goal: single enterprise identity service

Page 3: Identity & Access Control in the Cloud Sachin Vinod Rathi Architect Advisor, Microsoft Corporation Niraj Bhatt Enterprise Architect, Windows Azure MVP.

Identity Capabilities

Federation Authentication Authorization

Audit Provisioning Removal

Self Service

Page 4: Identity & Access Control in the Cloud Sachin Vinod Rathi Architect Advisor, Microsoft Corporation Niraj Bhatt Enterprise Architect, Windows Azure MVP.

Federation

UK Immigration Trusts US Passport

Office

Page 5: Identity & Access Control in the Cloud Sachin Vinod Rathi Architect Advisor, Microsoft Corporation Niraj Bhatt Enterprise Architect, Windows Azure MVP.

Claims Will Get the Job Done

Page 6: Identity & Access Control in the Cloud Sachin Vinod Rathi Architect Advisor, Microsoft Corporation Niraj Bhatt Enterprise Architect, Windows Azure MVP.
Page 7: Identity & Access Control in the Cloud Sachin Vinod Rathi Architect Advisor, Microsoft Corporation Niraj Bhatt Enterprise Architect, Windows Azure MVP.

On-Premises Applications

Page 8: Identity & Access Control in the Cloud Sachin Vinod Rathi Architect Advisor, Microsoft Corporation Niraj Bhatt Enterprise Architect, Windows Azure MVP.

On-Premises Applications

Demo

Page 9: Identity & Access Control in the Cloud Sachin Vinod Rathi Architect Advisor, Microsoft Corporation Niraj Bhatt Enterprise Architect, Windows Azure MVP.

Managing Access for a Windows Azure Application

?

Page 10: Identity & Access Control in the Cloud Sachin Vinod Rathi Architect Advisor, Microsoft Corporation Niraj Bhatt Enterprise Architect, Windows Azure MVP.

Managing Access for a Windows Azure Application

Name : NirajRole : Architect

Page 11: Identity & Access Control in the Cloud Sachin Vinod Rathi Architect Advisor, Microsoft Corporation Niraj Bhatt Enterprise Architect, Windows Azure MVP.

Managing Access for a Windows Azure Application

Name : SachinRole :

Architect

• .NET Framework Extension• Programming model for claims• Visual Studio Tools & Templates

• Windows Server Role• An STS for AD• WS-Federation, WS-Trust, SAML

Page 12: Identity & Access Control in the Cloud Sachin Vinod Rathi Architect Advisor, Microsoft Corporation Niraj Bhatt Enterprise Architect, Windows Azure MVP.

Basic Use of WIF & STS

Demo

Page 13: Identity & Access Control in the Cloud Sachin Vinod Rathi Architect Advisor, Microsoft Corporation Niraj Bhatt Enterprise Architect, Windows Azure MVP.

Authenticating Users from Business Partners

Name :

Sachin

Role :

Architect

Name :

Sachin

Role :

Architect

Home Realm

Discovery

Home Realm

Discovery

Page 14: Identity & Access Control in the Cloud Sachin Vinod Rathi Architect Advisor, Microsoft Corporation Niraj Bhatt Enterprise Architect, Windows Azure MVP.

Authenticating Users from Business Partners

Name :

Sachin

Role :

Architect

Name :

Sachin

Role :

Architect

Home Realm

Discovery

Name :

Sachin

Role :

Architect

Home Realm

Discovery

Name :

Sachin

Role :

Architect

• Hosts an STS in the Cloud• Handles relationship with Business Partners & Social Providers• WS-Federation, WS-Trust, OpenID, OAuth

Page 15: Identity & Access Control in the Cloud Sachin Vinod Rathi Architect Advisor, Microsoft Corporation Niraj Bhatt Enterprise Architect, Windows Azure MVP.

Handling Relationships, HRD and Token Normalization

Demo

Page 16: Identity & Access Control in the Cloud Sachin Vinod Rathi Architect Advisor, Microsoft Corporation Niraj Bhatt Enterprise Architect, Windows Azure MVP.

Authenticating Users from Web and Social Providers

HRD1. FaceBook2. Live3. Yahoo4. Google

Name :

Sachin

Role :

Architect

Name :

Sachin

Role :

Architect

Page 17: Identity & Access Control in the Cloud Sachin Vinod Rathi Architect Advisor, Microsoft Corporation Niraj Bhatt Enterprise Architect, Windows Azure MVP.

FabrikamShipping: Automating Customer SignUp from Social Providers

Demo

Page 18: Identity & Access Control in the Cloud Sachin Vinod Rathi Architect Advisor, Microsoft Corporation Niraj Bhatt Enterprise Architect, Windows Azure MVP.

Authenticating Mobile Users

Name :

Sachin

Role :

Architect

Name :

Sachin

Role :

Architect

Page 19: Identity & Access Control in the Cloud Sachin Vinod Rathi Architect Advisor, Microsoft Corporation Niraj Bhatt Enterprise Architect, Windows Azure MVP.

Reusing Existing Identities in Mobile Applications

Demo

Page 20: Identity & Access Control in the Cloud Sachin Vinod Rathi Architect Advisor, Microsoft Corporation Niraj Bhatt Enterprise Architect, Windows Azure MVP.

Claims Will Get the Job Done

Page 21: Identity & Access Control in the Cloud Sachin Vinod Rathi Architect Advisor, Microsoft Corporation Niraj Bhatt Enterprise Architect, Windows Azure MVP.
Page 22: Identity & Access Control in the Cloud Sachin Vinod Rathi Architect Advisor, Microsoft Corporation Niraj Bhatt Enterprise Architect, Windows Azure MVP.

Resources

• www.microsoft.com/wif• acs.codeplex.com• www.windowsazure.com

Page 23: Identity & Access Control in the Cloud Sachin Vinod Rathi Architect Advisor, Microsoft Corporation Niraj Bhatt Enterprise Architect, Windows Azure MVP.

Q&A

Page 24: Identity & Access Control in the Cloud Sachin Vinod Rathi Architect Advisor, Microsoft Corporation Niraj Bhatt Enterprise Architect, Windows Azure MVP.

© 2011 Microsoft Corporation. All rights reserved. Microsoft, Windows, Windows Vista and other product names are or may be registered trademarks and/or trademarks in the U.S. and/or other countries.

The information herein is for informational purposes only and represents the current view of Microsoft Corporation as of the date of this presentation. Because Microsoft must respond to changing market conditions, it should not be interpreted to be a commitment on the part of Microsoft, and

Microsoft cannot guarantee the accuracy of any information provided after the date of this presentation. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.