Microsoft’s Roles Based Authorization Manager CSG, May 2004
Shipping with Server 2003 Authorization Manager MMC snap-in AzMan Application Basic Groups LDAP Query Groups Authorization Store Role Based Access Control
New Group Types Application Basic Groups –Features of NT and Win2k ACL groups –Adds a non-member list to the DSACL to enable exclusions LDAP Query Groups –real time queries of user’s attributes to determine group membership
Authorization Store Active Directory may be used as the store XML files may be used as the store –Implies that each application developer can create an authorization store without the cooperation of Domain or OU administrators
interfaces COM –Creation of the authorization store –Creation of roles, tasks, operations –Initialization of the store –Enumeration of memberships –Implication – a vbscript programmer can use these to perform all tasks Point-and-click: AzMan MMC snap-in
Uses Native applications Internal web services Interaction with Trustbridge slated for Longhorn
References Role-Based Access Control Using Windows Server 2003 Authorization Manager : en-us/dnnetserv/html/AzManRoles.asp en-us/dnnetserv/html/AzManRoles.asp Using Dynamic Business Rules in Windows Server 2003 Authorization Manager : en-us/dnnetserv/html/AzManBizRules.asp en-us/dnnetserv/html/AzManBizRules.asp Federating Identity and Authorization Across Organizations and Platforms, by Matt Hur : s/sessions/default.aspx s/sessions/default.aspx