Brian Arkills Software Engineer, LDAP geek, AD bum, Senior Heckler, and Associate Troublemaking Officer State of Windows Services at the UW.

Slides:



Advertisements
Similar presentations
UTILIZING WITH ITA. offers an entire suite of benefits for you and your students. You can also set up s for the purpose.
Advertisements

Single Sign-On with GRID Certificates Ernest Artiaga (CERN – IT) GridPP 7 th Collaboration Meeting July 2003 July 2003.
Office 365 Identity June 2013 Microsoft Office365 4/2/2017
Agenda AD to Windows Azure AD Sync Options Federation Architecture
Unified communications platform Enterprise-ready.
Office 365 for Enterprises: Pricing & Licensing Overview
1 / 54 [ a university near you ] Mark Renne Microsoft >>
System Center Operations Manager 2007 Management Pack Roadmap (Apr/May 2008)
Integration: Office 365 Brian Arkills Software Engineer, LDAP geek, AD bum, and Associate Troublemaking Officer Identity and Access Management, UW-IT.
WIN.MIT.EDU  Where are we today  Related services  Current enhancements  Some future enhancements  SharePoint  Panel Discussion.
Implementing and Administering AD FS
Welcome Micronet! TAM: Susan Tobes Enterprise Windows: Mike Blasingame Enterprise UNIX: Jeff Makaiwi Database Services: Karen Kato Web Applications: Vahid.
A.Vandenberg August 7, 2001 HE PKI Summit State of Georgia and PKI Art Vandenberg Director, Advanced Campus Services Information Systems & Technology.
UW Windows Infrastructure: Delegated OUs Brian Arkills Software Engineer, LDAP geek, AD bum, and Associate Troublemaking Officer Identity and Access Management,
Understanding Active Directory
Confidential FullArmor Corp Platform for SaaS and mobile apps to remotely access, migrate, and sync Active Directory resources with the cloud ADanywhere.
Brian Arkills Software Engineer, LDAP geek, AD bum, and Associate Troublemaking Officer UW Windows Infrastructure.
Enterprise Single Sign On Identity management for web applications.
Internet Services Alberto Pace. Internet Services Group u Mission and Goals u Provide core computing services, worldwide u Three specific areas u Collaborative.
HalFILE 3.0 Active Directory Integration. halFILE 3.0 AD – What is it? Centralized organization of network objects and security – servers, computers,
Empower Enterprise Mobility Jasbir Gill Azure Mobility.
Active Directory Lecture 3 – Domain Services Primer.
Identity and Access Management Business Ready Security Solutions.
UW Windows Authentication Group Multiple forest scenario task force - Testing report and recommendations.
OUC204. Recently Announced… Identity Integration Options 2 3 Identity Management Overview 1.
Brown University Exchange 2003 Molly Baird Manager, Windows-Novell Services.
MCSE Guide to Microsoft Exchange Server 2003 Administration Chapter Four Configuring Outlook and Outlook Web Access.
©Kwan Sai Kit, All Rights Reserved Windows Small Business Server 2003 Features.
Christopher Chapman | MCT Content PM, Microsoft Learning, PDG Planning, Microsoft.
5 | Microsoft Confidential 6 | Microsoft Confidential.
Microsoft Active Directory(AD) A presentation by Robert, Jasmine, Val and Scott IMT546 December 11, 2004.
A detailed look at the Microsoft Windows Infrastructure at UWE including Active Directory (AD), MIIS, Exchange, SMS, IIS, SQL Server, Terminal Services.
Collaboration Tools and Challenges at the University of Washington Tony Chang, Senior Strategic Integration Architect Computing and Communications Scott.
Brian Arkills Software Engineer, LDAP geek, AD guy, Chief Troublemaking Officer Windows HiEd Conference 2006 Managed Workstations: UW Nebula.
Active Directory Harikrishnan V G 18 March Presentation titlePage 2 Agenda ► Introduction – Active Directory ► Directory Service ► Benefits of Active.
1 Introduction to Microsoft Windows 2000 Windows 2000 Overview Windows 2000 Architecture Overview Windows 2000 Directory Services Overview Logging On to.
Empowering people-centric IT Unified device management Access and information protection Desktop Virtualization Hybrid Identity.
Paul Andrew. Recently Announced… Identity Integration Options 2 3 Identity Management Overview 1.
Module 12 Integrating Exchange Server 2010 with Other Messaging Systems.
Brian Arkills Software Engineer, LDAP geek, AD bum, Senior Heckler, and Associate Troublemaking Officer Fill-in Topics for Windows HiEd Conference 2007.
Introduction to Microsoft Windows 2000 Welcome to Chapter 1 Windows 2000 Server.
Single Sign-On in the Danish Educational Sector Per Thorboll Deputy director UNI-C.
SharePoint in the Education Space Presented by: Daniel Petersen Director of Business Solutions Applied Tech.
Bronze Sky customer premises AD MS Online Directory Sync Provisioning platform Provisioning platform Lync Online Lync Online SharePoint Online SharePoint.
Module 13: Enterprise PKI Active Directory Certificate Services (AD CS)
Implementing Microsoft Exchange Online with Microsoft Office 365
Module 3 Planning for Active Directory®
FROM MIT KERBEROS TO MICROSOFT ACTIVE DIRECTORY The Pennsylvania State University’s move from a lower case MIT Kerberos realm to a Standard Microsoft Active.
Drive Down Costs? Boost Operational Efficiency! Philippe Lemmens Product Marketing Manager Microsoft BeLux.
Be Microsoft’s first and best customer Enabling world-class and predictable customer, client, and partner experience Protecting Microsoft’s physical and.
Unlocking your CORE CAL with Lync Server 2010 Marc Perez Senior Consultant, Unified Communications Microsoft Corporation.
MCSE Guide to Microsoft Exchange Server 2003 Administration Chapter One Introduction to Exchange Server 2003.
Microsoft IT Team & Enterprise Collaboration Kimberly Malone Group Program Manager Microsoft IT Collaboration Services.
Introduction to the PKI Issues at UW Madison Presented to ITC on Friday, 3/18/2005 Tom Jordan Systems Engineer,
Active Directory Domain Services (AD DS). Identity and Access (IDA) – An IDA infrastructure should: Store information about users, groups, computers and.
Fermilab supports several authentication mechanisms for user and computer authentication. This talk will cover our authentication systems, design considerations,
ADFS - Does it Still have a Place? Fitting into the EMS puzzle Frank C. Drewes III 2016 Redmond Summit | Identity.
Private KEEP OFF! Private KEEP OFF! Open! What is a cloud? Cloud computing is a model for enabling convenient, on-demand network access to a shared.
Secure Connected Infrastructure
New Developments in Central Directory Service and Account Provisioning Dan Menicucci Enterprise Architect - University of Pittsburgh.
Guy D. Falsetti Sr. Systems Architect University of Iowa
Overview of CSE and UW Computing Facilities
City-wide Active Directory Project Town Hall II
IT Connects: Lync and Box Staff Association Council
State of Windows Services at the UW
Overview of CSE and UW Computing Facilities
IT services Miki Kallio Liaison Manager (IT and Research), PhD
Overview of CSE and UW Computing Facilities
Overview of CSE and UW Computing Facilities
Microsoft Virtual Academy
Presentation transcript:

Brian Arkills Software Engineer, LDAP geek, AD bum, Senior Heckler, and Associate Troublemaking Officer State of Windows Services at the UW

The Windows platform, circa 2000 Lots of Windows platform distrust; is it enterprise ready? Windows client base had a heavy mix of “home” OS flavor (Win98, Windows Me) New fangled domain-based features like Kerberos, LDAP, and DNS-integration IIS 4 proved to have many security vulnerabilities

Where we’ve come from, circa 2000 C&C Windows services included: the UW forest, to facilitate resource sharing across units Nebula, to facilitate managed workstations UW Pubcookie ISAPI module for IIS Over 450 Windows domains & more than 1,200 Windows domain controllers across campus

Key Pain Points Between Then and 2006 Remember Nimda, CodeRed, Blaster, Slammer? High rate of domain compromises MS made UW forest service problematic C&C chose to not run Dynamic DNS, nor Exchange. No central IIS web platform offering either Nebula cost was high until 2006 Departmental silos of Windows services: multiple user provisioning processes and multiple passwords No good IIS authorization mechanism

Enabling infrastructure; Provides ability to offer Windows services to entire UW audience Automated UW NetID provisioning with password Trusts permitted for campus domains Some automated group provisioning, including affiliation (faculty, staff, student, etc.) and courses Does not solve managed user scenario … more to come aka the NETID domain or netid.washington.edu 2006: UW Windows Infrastructure

The Near Future Share vision that most campus Windows domains should consolidate into the NETID domain Microsoft roadmap drafted to enable partnership with campus C&C will work with campus partners to provide central service offerings for Exchange and SharePoint on an expedited schedule Nebula will move into the NETID domain and pilot these services

Microsoft Numbers, since 1/2007 Based on campus security scans 1 : 223 campus domain controllers campus IIS web servers 74 campus Microsoft Dynamic DNS servers Based on C&C survey: 38% use “Pine” vs. 32% use “Outlook” Calendar: 19% use Outlook vs. 12% use Oracle Relative use of OS: 75% of campus uses Windows more than 80% of time

Future Possibilities Provide Windows user and group management mechanisms Office Communication Server / Exchange Unified Messaging AD integrated certificate authority Unix and Mac interoperability Dynamic DNS VPN Services 2-way password sync? Collapse Kerberos realms? Active Directory Federated Services Phase out UW forest? Central IIS web service offering? (other than SharePoint)

Nebula in a Nutshell 0 domain or server compromises over 10-year history Many “models” of computers with differing support levels: –Gold workstations = we manage, $52/month –Bronze workstation = you manage, $26/month –Kiosks = we manage –Strongly managed servers = we manage –Loosely managed servers = we manage OS, you manage app –Locally managed servers = you manage Services provided include: –Help desk support –Networked home directory and group file space –Group management services –Automated software deployment –Security management and reporting –Discounts for other C&C services (Oracle Calendar, BES, and others) More Info at:

Want to Know More? UW Windows Infrastructure MS Collaborative Applications Roadmap MS Collaborative Applications Engineering Blog UW Windows Infrastructure Engineering Blog Windows Domains at the UW

The End Brian Arkills Author of “LDAP Directories Explained”