introduction to identity management -...

26
INTRODUCTION TO IDENTITY MANAGEMENT Nathan Dors Assistant Director, Identity & Access Management University of Washington INTERNET2 TECHNOLOGY EXCHANGE OCTOBER 28, 2014

Upload: lyhanh

Post on 31-Mar-2018

226 views

Category:

Documents


2 download

TRANSCRIPT

Page 1: INTRODUCTION TO IDENTITY MANAGEMENT - Internet2meetings.internet2.edu/media/medialibrary/2014/11/06/20141028-dors... · INTRODUCTION TO IDENTITY MANAGEMENT ... “Identity and access

INTRODUCTION TO IDENTITY MANAGEMENT

Nathan Dors Assistant Director, Identity & Access Management University of Washington

INTERNET2 TECHNOLOGY EXCHANGE OCTOBER 28, 2014

Page 2: INTRODUCTION TO IDENTITY MANAGEMENT - Internet2meetings.internet2.edu/media/medialibrary/2014/11/06/20141028-dors... · INTRODUCTION TO IDENTITY MANAGEMENT ... “Identity and access

PURPOSE

> What are the purposes behind developing and deploying an identity management system?

> What problems does it solve? > What are the benefits? > What’s the value? > Why now?

QUESTIONS

Page 3: INTRODUCTION TO IDENTITY MANAGEMENT - Internet2meetings.internet2.edu/media/medialibrary/2014/11/06/20141028-dors... · INTRODUCTION TO IDENTITY MANAGEMENT ... “Identity and access

AGENDA

>  1:30pm – Welcome >  1:40pm – What is IAM? (Nathan) >  1:45pm – Why Do We Care? (Dennis, Mark) >  2:30pm – Walk-through (Nathan) >  3:00pm – Adjourn

TOPICS

Page 4: INTRODUCTION TO IDENTITY MANAGEMENT - Internet2meetings.internet2.edu/media/medialibrary/2014/11/06/20141028-dors... · INTRODUCTION TO IDENTITY MANAGEMENT ... “Identity and access

WHAT IS IAM?

>  An acronym? >  A set of related processes? >  A complex undertaking? >  A project… or a program? >  A discipline?

IDENTITY & ACCESS MANAGEMENT

Page 5: INTRODUCTION TO IDENTITY MANAGEMENT - Internet2meetings.internet2.edu/media/medialibrary/2014/11/06/20141028-dors... · INTRODUCTION TO IDENTITY MANAGEMENT ... “Identity and access

WHAT IS IAM?

“Identity and access management is a security, risk management, and business discipline that ensures the right individuals have the right access to the right resources at the right time for the right reasons.” (Source: Gartner, Inc.)

DEFINITION

Page 6: INTRODUCTION TO IDENTITY MANAGEMENT - Internet2meetings.internet2.edu/media/medialibrary/2014/11/06/20141028-dors... · INTRODUCTION TO IDENTITY MANAGEMENT ... “Identity and access

WHAT IS IAM?

WHO YOU ARE –  name –  image –  identifiers –  contact info –  address, location –  biographical sketch, tagline –  belongings (nationality, groups, affiliations, demographics) –  other indicators of identity (biometrics) –  privacy and data sharing preferences –  interests, intentions –  activities, responsibilities, projects –  reputation

IDENTITY MANAGMENT

Page 7: INTRODUCTION TO IDENTITY MANAGEMENT - Internet2meetings.internet2.edu/media/medialibrary/2014/11/06/20141028-dors... · INTRODUCTION TO IDENTITY MANAGEMENT ... “Identity and access

WHAT IS IAM?

WHAT YOU CAN DO –  authority –  delegation –  roles –  groups –  permissions –  entitlements –  limits, constraints –  as they relate to access to resources

ACCESS MANAGEMENT

Page 8: INTRODUCTION TO IDENTITY MANAGEMENT - Internet2meetings.internet2.edu/media/medialibrary/2014/11/06/20141028-dors... · INTRODUCTION TO IDENTITY MANAGEMENT ... “Identity and access

WHAT IS IAM?

A team. At the UW, IAM is an organizational unit with these responsibilities: •  Identity registration

& administration •  Account & password

management •  Access management •  Authentication &

Authorization •  Non-person identity

management •  Federation & trust

Page 9: INTRODUCTION TO IDENTITY MANAGEMENT - Internet2meetings.internet2.edu/media/medialibrary/2014/11/06/20141028-dors... · INTRODUCTION TO IDENTITY MANAGEMENT ... “Identity and access

WHAT IS IAM?

A set of services. We offer these IAM services through the central IT service catalog: •  UW NetID •  Access Management •  Authentication •  Directory Services •  UW Windows

Infrastructure

Page 10: INTRODUCTION TO IDENTITY MANAGEMENT - Internet2meetings.internet2.edu/media/medialibrary/2014/11/06/20141028-dors... · INTRODUCTION TO IDENTITY MANAGEMENT ... “Identity and access

WHAT IS IAM?

A set of capabilities. The essential work of our IAM team is coordinating these IAM processes and activities with our diverse customers and stakeholders.

Page 11: INTRODUCTION TO IDENTITY MANAGEMENT - Internet2meetings.internet2.edu/media/medialibrary/2014/11/06/20141028-dors... · INTRODUCTION TO IDENTITY MANAGEMENT ... “Identity and access

IDENTITY REGISTRATION & ADMINISTRATION

“Help me register people affiliated with the university to participate in online activities.”

CUSTOMER ASKS:

Page 12: INTRODUCTION TO IDENTITY MANAGEMENT - Internet2meetings.internet2.edu/media/medialibrary/2014/11/06/20141028-dors... · INTRODUCTION TO IDENTITY MANAGEMENT ... “Identity and access

ACCOUNT & CREDENTIAL MANAGEMENT

“Give me and my users trustworthy identification to use online.”

CUSTOMER ASKS:

Page 13: INTRODUCTION TO IDENTITY MANAGEMENT - Internet2meetings.internet2.edu/media/medialibrary/2014/11/06/20141028-dors... · INTRODUCTION TO IDENTITY MANAGEMENT ... “Identity and access

ACCESS GOVERNANCE & ADMINISTRATION

“Help me manage how I enable and disable access to my resources.”

CUSTOMER ASKS:

Page 14: INTRODUCTION TO IDENTITY MANAGEMENT - Internet2meetings.internet2.edu/media/medialibrary/2014/11/06/20141028-dors... · INTRODUCTION TO IDENTITY MANAGEMENT ... “Identity and access

PROVISIONING & INTEGRATION

“Help me integrate with identity services and orchestrate processes to provision data and access.”

CUSTOMER ASKS:

Page 15: INTRODUCTION TO IDENTITY MANAGEMENT - Internet2meetings.internet2.edu/media/medialibrary/2014/11/06/20141028-dors... · INTRODUCTION TO IDENTITY MANAGEMENT ... “Identity and access

ACCESS CONTROL

“Help me authenticate and authorize users as they access my resources and make online transactions.”

CUSTOMER ASKS:

Page 16: INTRODUCTION TO IDENTITY MANAGEMENT - Internet2meetings.internet2.edu/media/medialibrary/2014/11/06/20141028-dors... · INTRODUCTION TO IDENTITY MANAGEMENT ... “Identity and access

REPORTING & ANALYTICS

“Give me reports and activity data I can analyze to make decisions and manage risk.”

CUSTOMER ASKS:

Page 17: INTRODUCTION TO IDENTITY MANAGEMENT - Internet2meetings.internet2.edu/media/medialibrary/2014/11/06/20141028-dors... · INTRODUCTION TO IDENTITY MANAGEMENT ... “Identity and access

WHAT IS IAM?

> More than an acronym >  A set of related processes >  A set of related services >  An enabler of solutions to complex problems >  A way to deliver value to customers IAM is a means of delivering value to customers by helping them manage their users (who they are, what they can do) without the burden of operating the related IT services.

IDENTITY & ACCESS MANAGEMENT

Page 18: INTRODUCTION TO IDENTITY MANAGEMENT - Internet2meetings.internet2.edu/media/medialibrary/2014/11/06/20141028-dors... · INTRODUCTION TO IDENTITY MANAGEMENT ... “Identity and access

NEXT UP

> Dennis Cromwell Associate Vice President, Client Services and Support Indiana University

> Mark McConahay Associate Vice Provost and Registrar Indiana University

Duration: 30min

WHY CAMPUS ADMINISTRATORS CARE

Page 19: INTRODUCTION TO IDENTITY MANAGEMENT - Internet2meetings.internet2.edu/media/medialibrary/2014/11/06/20141028-dors... · INTRODUCTION TO IDENTITY MANAGEMENT ... “Identity and access

NEXT UP: WALK-THROUGH

> Demonstrate IAM functions >  Simulate IAM processes > Discuss benefits

–  who? –  how? –  why?

> Discover themes & variations Duration: 20-30min

PURPOSE

Page 20: INTRODUCTION TO IDENTITY MANAGEMENT - Internet2meetings.internet2.edu/media/medialibrary/2014/11/06/20141028-dors... · INTRODUCTION TO IDENTITY MANAGEMENT ... “Identity and access

SERVICE PROVIDER

>  offers a service valuable to end users >  understands the value of the assets >  decides access control policy >  uses access controls to enforce policy

Page 21: INTRODUCTION TO IDENTITY MANAGEMENT - Internet2meetings.internet2.edu/media/medialibrary/2014/11/06/20141028-dors... · INTRODUCTION TO IDENTITY MANAGEMENT ... “Identity and access

ACCESS CONTROL

>  authenticates users – establishes user identity or externalizes this function to an authentication service

>  authorizes actions – allow/deny access decisions based on user’s access roles and permissions; can be externalized to an access management service

Page 22: INTRODUCTION TO IDENTITY MANAGEMENT - Internet2meetings.internet2.edu/media/medialibrary/2014/11/06/20141028-dors... · INTRODUCTION TO IDENTITY MANAGEMENT ... “Identity and access

ACCESS MANAGEMENT

>  define roles and permissions >  add users to roles >  remove users from roles >  review a user’s access >  access request and approval workflows >  provide data for access control decisions

Page 23: INTRODUCTION TO IDENTITY MANAGEMENT - Internet2meetings.internet2.edu/media/medialibrary/2014/11/06/20141028-dors... · INTRODUCTION TO IDENTITY MANAGEMENT ... “Identity and access

ACCOUNTS & CREDENTIALS

>  issue credentials to registered users > manage credential lifecycle >  help users recover account (resent password)

Page 24: INTRODUCTION TO IDENTITY MANAGEMENT - Internet2meetings.internet2.edu/media/medialibrary/2014/11/06/20141028-dors... · INTRODUCTION TO IDENTITY MANAGEMENT ... “Identity and access

IDENTITY REGISTRATION

>  issue credentials to registered users > manage credential lifecycle >  help users recover account (resent password)

Page 25: INTRODUCTION TO IDENTITY MANAGEMENT - Internet2meetings.internet2.edu/media/medialibrary/2014/11/06/20141028-dors... · INTRODUCTION TO IDENTITY MANAGEMENT ... “Identity and access

IDENTITY PROVIDER

>  authenticates users – establishes user identity by verifying credentials issued to user

>  can be used by a service provider to externalize user authentication

>  provides identity assertions to service providers – username, attributes, etc.

Page 26: INTRODUCTION TO IDENTITY MANAGEMENT - Internet2meetings.internet2.edu/media/medialibrary/2014/11/06/20141028-dors... · INTRODUCTION TO IDENTITY MANAGEMENT ... “Identity and access

POLICY & OVERSIGHT

>  oversees decisions >  responsible for institutional risk >  decides investments