identity & access control in the cloud sachin vinod rathi architect advisor, microsoft...

24
Identity & Access Control in the Cloud Sachin Vinod Rathi Architect Advisor, Microsoft Corporation Niraj Bhatt Enterprise Architect, Windows Azure MVP

Post on 21-Dec-2015

219 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: Identity & Access Control in the Cloud Sachin Vinod Rathi Architect Advisor, Microsoft Corporation Niraj Bhatt Enterprise Architect, Windows Azure MVP

Identity & Access Control in the Cloud

Sachin Vinod RathiArchitect Advisor, Microsoft Corporation

Niraj BhattEnterprise Architect, Windows Azure MVP

Page 2: Identity & Access Control in the Cloud Sachin Vinod Rathi Architect Advisor, Microsoft Corporation Niraj Bhatt Enterprise Architect, Windows Azure MVP

Identity Crisis

• Typical enterprise has dozens of providers– AD, SunOne, SQL, SAP, Oracle...

• Need to consolidate these, and federate where consolidation isn’t possible

• Goal: single enterprise identity service

Page 3: Identity & Access Control in the Cloud Sachin Vinod Rathi Architect Advisor, Microsoft Corporation Niraj Bhatt Enterprise Architect, Windows Azure MVP

Identity Capabilities

Federation Authentication Authorization

Audit Provisioning Removal

Self Service

Page 4: Identity & Access Control in the Cloud Sachin Vinod Rathi Architect Advisor, Microsoft Corporation Niraj Bhatt Enterprise Architect, Windows Azure MVP

Federation

UK Immigration Trusts US Passport

Office

Page 5: Identity & Access Control in the Cloud Sachin Vinod Rathi Architect Advisor, Microsoft Corporation Niraj Bhatt Enterprise Architect, Windows Azure MVP

Claims Will Get the Job Done

Page 6: Identity & Access Control in the Cloud Sachin Vinod Rathi Architect Advisor, Microsoft Corporation Niraj Bhatt Enterprise Architect, Windows Azure MVP
Page 7: Identity & Access Control in the Cloud Sachin Vinod Rathi Architect Advisor, Microsoft Corporation Niraj Bhatt Enterprise Architect, Windows Azure MVP

On-Premises Applications

Page 8: Identity & Access Control in the Cloud Sachin Vinod Rathi Architect Advisor, Microsoft Corporation Niraj Bhatt Enterprise Architect, Windows Azure MVP

On-Premises Applications

Demo

Page 9: Identity & Access Control in the Cloud Sachin Vinod Rathi Architect Advisor, Microsoft Corporation Niraj Bhatt Enterprise Architect, Windows Azure MVP

Managing Access for a Windows Azure Application

?

Page 10: Identity & Access Control in the Cloud Sachin Vinod Rathi Architect Advisor, Microsoft Corporation Niraj Bhatt Enterprise Architect, Windows Azure MVP

Managing Access for a Windows Azure Application

Name : NirajRole : Architect

Page 11: Identity & Access Control in the Cloud Sachin Vinod Rathi Architect Advisor, Microsoft Corporation Niraj Bhatt Enterprise Architect, Windows Azure MVP

Managing Access for a Windows Azure Application

Name : SachinRole :

Architect

• .NET Framework Extension• Programming model for claims• Visual Studio Tools & Templates

• Windows Server Role• An STS for AD• WS-Federation, WS-Trust, SAML

Page 12: Identity & Access Control in the Cloud Sachin Vinod Rathi Architect Advisor, Microsoft Corporation Niraj Bhatt Enterprise Architect, Windows Azure MVP

Basic Use of WIF & STS

Demo

Page 13: Identity & Access Control in the Cloud Sachin Vinod Rathi Architect Advisor, Microsoft Corporation Niraj Bhatt Enterprise Architect, Windows Azure MVP

Authenticating Users from Business Partners

Name :

Sachin

Role :

Architect

Name :

Sachin

Role :

Architect

Home Realm

Discovery

Home Realm

Discovery

Page 14: Identity & Access Control in the Cloud Sachin Vinod Rathi Architect Advisor, Microsoft Corporation Niraj Bhatt Enterprise Architect, Windows Azure MVP

Authenticating Users from Business Partners

Name :

Sachin

Role :

Architect

Name :

Sachin

Role :

Architect

Home Realm

Discovery

Name :

Sachin

Role :

Architect

Home Realm

Discovery

Name :

Sachin

Role :

Architect

• Hosts an STS in the Cloud• Handles relationship with Business Partners & Social Providers• WS-Federation, WS-Trust, OpenID, OAuth

Page 15: Identity & Access Control in the Cloud Sachin Vinod Rathi Architect Advisor, Microsoft Corporation Niraj Bhatt Enterprise Architect, Windows Azure MVP

Handling Relationships, HRD and Token Normalization

Demo

Page 16: Identity & Access Control in the Cloud Sachin Vinod Rathi Architect Advisor, Microsoft Corporation Niraj Bhatt Enterprise Architect, Windows Azure MVP

Authenticating Users from Web and Social Providers

HRD1. FaceBook2. Live3. Yahoo4. Google

Name :

Sachin

Role :

Architect

Name :

Sachin

Role :

Architect

Page 17: Identity & Access Control in the Cloud Sachin Vinod Rathi Architect Advisor, Microsoft Corporation Niraj Bhatt Enterprise Architect, Windows Azure MVP

FabrikamShipping: Automating Customer SignUp from Social Providers

Demo

Page 18: Identity & Access Control in the Cloud Sachin Vinod Rathi Architect Advisor, Microsoft Corporation Niraj Bhatt Enterprise Architect, Windows Azure MVP

Authenticating Mobile Users

Name :

Sachin

Role :

Architect

Name :

Sachin

Role :

Architect

Page 19: Identity & Access Control in the Cloud Sachin Vinod Rathi Architect Advisor, Microsoft Corporation Niraj Bhatt Enterprise Architect, Windows Azure MVP

Reusing Existing Identities in Mobile Applications

Demo

Page 20: Identity & Access Control in the Cloud Sachin Vinod Rathi Architect Advisor, Microsoft Corporation Niraj Bhatt Enterprise Architect, Windows Azure MVP

Claims Will Get the Job Done

Page 21: Identity & Access Control in the Cloud Sachin Vinod Rathi Architect Advisor, Microsoft Corporation Niraj Bhatt Enterprise Architect, Windows Azure MVP
Page 22: Identity & Access Control in the Cloud Sachin Vinod Rathi Architect Advisor, Microsoft Corporation Niraj Bhatt Enterprise Architect, Windows Azure MVP

Resources

• www.microsoft.com/wif• acs.codeplex.com• www.windowsazure.com

Page 23: Identity & Access Control in the Cloud Sachin Vinod Rathi Architect Advisor, Microsoft Corporation Niraj Bhatt Enterprise Architect, Windows Azure MVP

Q&A

Page 24: Identity & Access Control in the Cloud Sachin Vinod Rathi Architect Advisor, Microsoft Corporation Niraj Bhatt Enterprise Architect, Windows Azure MVP

© 2011 Microsoft Corporation. All rights reserved. Microsoft, Windows, Windows Vista and other product names are or may be registered trademarks and/or trademarks in the U.S. and/or other countries.

The information herein is for informational purposes only and represents the current view of Microsoft Corporation as of the date of this presentation. Because Microsoft must respond to changing market conditions, it should not be interpreted to be a commitment on the part of Microsoft, and

Microsoft cannot guarantee the accuracy of any information provided after the date of this presentation. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.