CIO Council: IAM Update

Slides:



Advertisements
Similar presentations
Employee Self Service (ESS) Registration
Advertisements

Oracle IDM at First National Bank
FIspace Security Components FIspace Security Components NetFutures 2015 FIspace project Javier Romero Negrín Javier Hitado Simarro ATOS Serdar Arslan KoçSistem.
Confidential 1 Electronic Prescribing of Controlled Substances (EPCS) Part 1 of a 3 Part Series Chuck Klein, Ph.D. GM/Director, Medication Management.
Don’t Let Anybody Slip into Your Network! Using the Login People Multi-Factor Authentication Server Means No Tokens, No OTP, No SMS, No Certificates MICROSOFT.
Technology Steering Group January 31, 2007 Academic Affairs Technology Steering Group February 13, 2008.
University of Michigan Administrative Information Services Two-Factor Authentication An Update Linda Hancock Green August 2006.
Technology Steering Group January 31, 2007 Academic Affairs Technology Steering Group February 13, 2008.
Multi-Factor Authentication Added protection for a more secure you Presenter: Jeff Penn.
Updating User Information Password – use this field to change your own password Confirm Password – retype the new password for verification purposes To.
Empower Enterprise Mobility Jasbir Gill Azure Mobility.
Access and Identity Management System (AIMS) Federal Student Aid PESC Fall 2009 Data Summit October 20, 2009 Balu Balasubramanyam.
NEW MOBILE WEB. August ‘Mobile First’ Mentality “If you don’t have a mobile strategy, you don’t have a future strategy.” - Dr. Eric Schmidt, Executive.
U.S. Department of Agriculture eGovernment Program August 14, 2003 eAuthentication Agency Application Pre-Design Meeting eGovernment Program.
Identity on Force.com & Benefits of SSO Nick Simha.
COMPDIRS NATHAN DORS APRIL 16, AGENDA  IAM – who we are, what we do  HRP Modernization & Workday  What’s new in IAM?  Identity.UW soft.
U.S. Department of Agriculture eGovernment Program July 15, 2003 eAuthentication Initiative Pre-Implementation Status eGovernment Program.
© 2015 Universal Service Administrative Company. All rights reserved. How to Use the Portal E-rate Program Applicant Training Washington DC Tampa Albuquerque.
Empowering people-centric IT Unified device management Access and information protection Desktop Virtualization Hybrid Identity.
“The FIDO Alliance Today”
How to Use the Portal E-rate Program Applicant Training November 2015.
© 2014 IBM Corporation Mobile Customization & Administration IBM Connections 5.0 Workshop Author: Paul Godby IBM Ecosystem Development Duration: 30 minutes.
Business Objects XIr2 Windows NT Authentication Single Sign-on 18 August 2006.
Accessing HRMS Off Campus Two-Factor Authentication and Wyosecure.
BuckeyePass Multi-Factor Authentication. 2 What is Multi-Factor Authentication? Adds a 2 nd layer of security Combines something you know with something.
Protect your data Enable your users Desktop Virtualization Information protection Mobile device & application management Identity and Access Management.
Identity Standards Architect, Microsoft
Improving the Efficiency of the IT Service Desk
SafeNet MobilePKI for BlackBerry® SSO solution, backed by strong MobilePKI-based security Name, Title.
Collaboration Program CIO Council Update
Implementing and Managing Azure Multi-factor Authentication
ArchPass Duo Presentation
Group Services CIO Council Update
INFORMATION TECHNOLOGY NEW USER ORIENTATION
Cloud SaaS Integrates with Office 365 to Meet the Needs for Business Contact Management “Pobuca combined with Microsoft Office 365 and Azure Active Directory.
Two-factor authentication
Thanks for being a Hero Customer!
Multifactor Authentication
How TO access Yahoo account? Visit Us:-
Multi-Factor Authentication (MFA)
SafeNet MobilePKI for BlackBerry® SSO solution, backed by strong MobilePKI-based security Name, Title.
My Settings allows a user to manage their Business Banking personal information and preferences, including: Contact information Username and Password Security.
CIO Council Identity and Access Management
CIO Council Update: HarvardKey
How To Recover Your Account If You Forget Your Gmail Password.
Technology Services Multi-Factor Authentication gsw
First-time Login to Business Banking:
Community Service Hours
Multifactor Authentication & First Time Login
Two-Step Verification
Duo Deployment Project: Update and Communications
Identity and Access Management
Identity and Access Management Program Update CIO Council Update
Microsoft Ignite /20/2018 2:21 PM
smartmail & smartportal: Introducing Two-Factor Authentication
Multi-Factor Authentication
Two Factor Authentication
INFORMATION TECHNOLOGY NEW USER ORIENTATION
INFORMATION TECHNOLOGY NEW USER ORIENTATION
NEW! To meet the growing requirements for managing our courses and events, Olympic ESD 114 has partnered with a new program called pdEnroller. pdEnroller.
What are IAM Key Processes.
This presentation document has been prepared by Vault Intelligence Limited (“Vault") and is intended for off line demonstration, presentation and educational.
UC Path Network October 24, 2018 Zoom meeting ID:
MyLion Registration Website | Mobile device
TPAF – My Pension Online
Identity Management Warren Gordon U.S. Department of Education 2012 Software Developers Webinar #3.
STR -11 What if Saas tools work together, what would this mean for IBM #engageug.
Enabling Edmonton’s Communities
Student user guide for getting started with Microsoft
Getting Started With LastPass Enterprise
Presentation transcript:

CIO Council: IAM Update 5/19/2018 CIO Council: IAM Update Jason June 15, 2015 Monday 4:25-5:00 p.m. 561 Smith Center

Jason Agenda HarvardKey: The Benefits Rollout Timeline A Sneak Peek 5/19/2018 Agenda HarvardKey: The Benefits Rollout Timeline  A Sneak Peek Multifactor Authentication How Does MFA Work? The Components Integration Strategies Jason 2

HarvardKey: The Benefits 5/19/2018 HarvardKey: The Benefits HarvardKey is a unifying credential that enables access to email, desktop, and Web resources with a single login name and password. Successor to Harvard’s current PIN System New, mobile-responsive user experience for the login screen and account management suite (looks great on tablets, too!) Authentication and authorization are much more nimble Supports optional multifactor authentication Easier onboarding and off-boarding Supports the HUIT goal of “One Identity for Life” for any person — regardless of role — including seamless support for changes between roles, schools, etc. Jason 3

SEPT: Alumni OCT: FAS Central 5/19/2018 Rollout Timeline You’ll see changes to the old PIN login screen beginning in September, with waves of user populations invited to activate a HarvardKey soon after. September 22, 2015: New HarvardKey self-service account management functions available to all Alumni users October 6, 2015: HarvardKey available to FAS and Central users in conjunction with Harvard’s IT Security Campaign Within 18 months, every Harvard Community user will be invited to onboard SEPT: Alumni OCT: FAS Central Jason – Grouper functionality will be used to power HarvardKey (we will roll out Grouper’s external functions when we can) 4

Rollout Timeline As we rebrand, all screens that currently contain PIN branding will be converted to HarvardKey. Alumni (Post.Harvard) credential goes away (this includes all active students) In October, for FAS and CADM+: New Harvard users will claim a HarvardKey during onboarding All password reset requests will go through HarvardKey Existing users may claim a HarvardKey if they wish Harvard Phone users will require HarvardKey One-year cycle for CADM+, since those users will need to reset password on anniversary Rollout will be coordinated with Security Campaign to reinforce strong- password requirement (including reminder that strong passwords don’t need to be periodically reset) and ensure that users will recognize the “claim your HarvardKey” email No changes to applications anticipated 5

5/19/2018 A Sneak Peek Jason 6

Multifactor Authentication Multifactor authentication (MFA) is an authentication method that requires the user’s identity to be verified by more than one independent factor. Types of factors: Something you know: Password Something you have: Security token or smartphone app push notification response Something you are: Fingerprint We will use the user’s smartphone as a primary second-factor device in addition to standard username/password authentication. (Users without smartphones will have other phone-based options.) User enables MFA for selected app(s) using HarvardKey self-service User downloads app to smartphone When user goes to log in, he/she acknowledges a push notification on his/her phone and login proceeds as normal 7

Multifactor Authentication Integration Strategies An application requires use of MFA: Application registration with HarvardKey will be extended to support this option User prefers MFA on all his/her access points: User can use the self-service functionality within HarvardKey to set this preference Application requires MFA for some users (e.g. admin users): Grouper, IAM’s group management tool, will be used to support this requirement 8

Questions?

Thank you!