SAML 2.0 og ”Geneva” OIOSAML Workshop 31. marts 2009 Århus René Løhde, Microsoft

Slides:



Advertisements
Similar presentations
Secure Single Sign-On Across Security Domains
Advertisements

Securing Your Applications and Web Services with the Geneva Framework Jim Lavin.
Office 365 Identity June 2013 Microsoft Office365 4/2/2017
Agenda AD to Windows Azure AD Sync Options Federation Architecture
 Jan Alexander Program Manager Microsoft Corporation BB43.
 Rich Randall Development Lead Microsoft Corporation BB44.
Core identity scenarios Federation and synchronization 2 3 Identity management overview 1 Additional features 4.
2 Connecting Active Directory To Cloud Services Jorgen Thelin Senior Program Manager Microsoft Corporation Session Code: IDA306.
Eunice Mondésir Pierre Weill-Tessier 1 Federated Identity with Ping Federate Project Supervisor: M. Maknavicius-Laurent ASR Coordinator: G. Bernard ASR.
Key Point: Federation relationships are based on trust.
Authentication solutions for Outlook and Office 365 Multi-factor authentication for Office 365 Outlook client futures.
2 3 Who are you? What are you allowed to do? How should your experience be personalized? How do I get apps that are provably securable and manageable?
SIM403. Claims Provider Trust Relying Party x Relying Party Trust Claims Provider Trust Your ADFS STS Partner ADFS STS & IP Relying Party Trust Partner.
11 steve plank (“planky”) identity architect microsoft uk.
Infocard and Eduroam Enrique de la Hoz, Diego R. L ó pez, Antonio Garc í a, Samuel Mu ñ oz.
Adoption Time Single paradigm, mature tools, stable design patterns and frameworks Software developer’s comfort zone Competing paradigms, no tools,
T Network Application Frameworks and XML Service Federation Sasu Tarkoma.
 Lynn Ayres Program Manager Identity Services  Tore Sundelin Program Manager Identity Services BB29.
Vittorio Bertocci Sr. Architect Evangelist Microsoft Corporation ARC204.
Identity & Access Control in the Cloud Sachin Vinod Rathi Architect Advisor, Microsoft Corporation Niraj Bhatt Enterprise Architect, Windows Azure MVP.
Problem Statement AD DB App1 DB App2 AD App4 App6 AD App5 Intranet Extranet Cloud AD App3 DB SSO Separate Sign-in Separate Sign-in Separate Sign-in.
 Kim Cameron Distinguished Engineer Microsoft Corporation BB11.
A claims-based Identity Metasystem
SIM205. (On-Premises) Storage Servers Networking O/S Middleware Virtualization Data Applications Runtime You manage Infrastructure (as a Service)
Troubleshooting Federation, AD FS 2.0, and More…
David Chappell Chappell & Associates
OFC-B317 Overview Identity Management in Office 365 Synchronization Topics Federation Topics Integration of SAML/OAUTH with Office Works with Office.
Claims Based Authentication
A Claims Based Identity System Steve Plank Identity Architect Microsoft UK.
Troubleshooting Federation, AD FS 2.0, and More…
Windows Azure Dave Glover Developer Evangelist Microsoft Australia Tel:
Chad La Joie Shibboleth’s Future.
Module 5 Configuring Authentication. Module Overview Lesson 1: Understanding Classic SharePoint Authentication Providers Lesson 2: Understanding Federated.
SharePoint Security Fundamentals Introduction to Claims-based Security Configuring Claims-based Security Development Opportunities.
Identity & Access Control in the Cloud Name Title Organization.
Office 365 deployment choices Cutover, Staged, Hybrid What is AD FS (Active Directory Federation Services) Attribute Stores, ADFS Configuration Database.
Shibboleth Akylbek Zhumabayev September Agenda Introduction Related Standards: SAML, WS-Trust, WS-Federation Overview: Shibboleth, GSI, GridShib.
Using Enterprise Logins in Portal for ArcGIS via SAML Greg Ponto & Tom Shippee.
Forms Based Auth Windows SAML Claim TypeValue NameidentifierContoso\gbadea PrimarysidS UserlogonnameContoso\gbadea.
Windows Server Active Directory Intranet Managed Access Managed Identities Integrated Business Apps.
Keith Brown Cofounder pluralsight.com SIA312 Outline What is identity? Challenges Federated identity How it works from a 10,000 foot view Terminology.
 Stuart Kwan Group Program Manager Microsoft Corporation  Caleb Baker Senior SDET Microsoft Corporation BB42.
Dmitry Sotnikov New Product Research Manager Quest Software DTL404.
David Chappell Chappell & Associates ARC206.
Claims-Based Identity Solution Architect Briefing zoli.herczeg.ro Taken from David Chappel’s work at TechEd Berlin 2009.
Session: MIX09-T27F. Web Developers Customizable identity UX Single Sign On Access to user data ISVs Federation for selling their applications to organizations.
Bronze Sky customer premises AD MS Online Directory Sync Provisioning platform Provisioning platform Lync Online Lync Online SharePoint Online SharePoint.
 Justin Smith Sr. Program Manager Microsoft Corporation BB28.
Configuring, Managing and Maintaining Windows Server® 2008 Servers Course 6419A.
Linus Joyeux Valerie Alonso Managing consultantLead consultant blue-infinity (Switzerland) Active Directory Federation Services v2.
Introduction to.NET FX 3.0 (+ sneak preview of.NET FX 3.5) Martin Parry Developer & Platform Group Microsoft Ltd
SAML Token Claims Based Identity SAML Token Claims Based Identity SPUser.
steve plank “planky” microsoft connecting your private and public clouds with adfs
Alex Thissen | Achmea Designing and implementing a claims-based architecture Alex Thissen | Achmea Claim typeValue
Agenda  Microsoft Directory Synchronization Tool  Active Directory Federation Server  ADFS Proxy  Hybrid Features – LAB.
F5 APM & Security Assertion Markup Language ‘sam-el’
Networks ∙ Services ∙ People Jean Marie THIA GN4-1 Symposium, Vienna A case study GÉANT AuthN / AuthZ 9 march 2016 Solutions Architect -
ADFS - Does it Still have a Place? Fitting into the EMS puzzle Frank C. Drewes III 2016 Redmond Summit | Identity.
Secure Single Sign-On Across Security Domains
Azure Active Directory - Business 2 Consumer
Federation made simple
Solving the Identity Crisis
Introduction How to combine and use services in different security domains? How to take into account privacy aspects? How to enable single sign on (SSO)
ACS and ADFS.
Office 365 Identity Management
AD FS Installation Active Directory Federation Services (AD FS) 7.1
Building "One Size Fits All" Identity Systems Possible or Fantasy
Martin Parry Developer Evangelist Microsoft
INTEGRATIONS WITH Single Sign-On
Presentation transcript:

SAML 2.0 og ”Geneva” OIOSAML Workshop 31. marts 2009 Århus René Løhde, Microsoft

Another level of indirection Geneva Fx Geneva Server Geneva Cardspace

Relationship Claims Provider (Security Token Service) Claims Provider (Security Token Service) 2. Get claims 3. Send claims 1. Require claims SUBJECT Application (requires Claims) Application (requires Claims)

Microsoft Services Identity Backbone YOUR CUSTOMER YOUR Application YOUR Application ? THEIR PARTNER Active Directory Active Directory Active Directory Active Directory

Claims Microsoft Services Identity Backbone Active Directory Active Directory Active Directory Active Directory YOUR Application YOUR Application “Geneva” Framework “Geneva” Server Enterprise Identity Backbone

Microsoft Services Identity Backbone Active Directory Active Directory Active Directory Active Directory “Geneva” Server Enterprise Identity Backbone User Database User Database “Geneva” Server Third Party STS YOUR Application YOUR Application “Geneva” Framework

Microsoft Services Identity Backbone Live ID Managed Domains Managed Domains Consumers Active Directory Active Directory “Geneva” Server YOUR Application YOUR Application “Geneva” Framework User Database User Database Third Party STS Microsoft Federation Gateway

Beta 2 soooon Supports SAML 2 metadata, IdP lite, SP lite and GSA Price? If you got Windows Server 2008 or higher, you got Geneva Server!