Microsoft Identity Integration Server & Role Base Access Theo Kostelijk Consultant Microsoft BV

Slides:



Advertisements
Similar presentations
Directory Infrastructure Roadmap Overcoming Fragmented Identities - Roadmap to a Reliable Directory Infrastructure Thorsten Butschke & Dr. Martin Dehn.
Advertisements

Forefront Identity Manager 2010
Agenda 2 factor authentication Smart cards Virtual smart cards FIM CM
Agenda AD to Windows Azure AD Sync Options Federation Architecture
Policing the Power of Identity Controls Power Behavior Verify that controls are in place and functioning Monitor user behavior and verify that people.
Quality in Identity and Access Management Systems IDM: Overview Michele Brass, PMP PMI Westchester Chapter Program Manager – Collaboration Tools.
To learn more about Directory Concepts and how we can help your organisation please contact a Directory Concepts relationship manager near you: Sydney.
Microsoft Forefront Identity Manager 2010
Microsoft Identity Solutions
IBM Software Group ® Accessing Domino via Outlook iNotes Access for Microsoft Outlook - Notes Domino 5.5 – Domino Access for MS Outlook - Notes Domino.
Identity Lifecycle Management Rafal Lukawiecki Strategic Consultant, Project Botticelli Ltd Copyright.
Active Directory: Final Solution to Enterprise System Integration
Virtual techdays INDIA │ august 2010 Managing Active Directory Using Microsoft Forefront Identity Manager: Amol R Bhandarkar │ Tech Specialist –
Identity Management with Microsoft Identity Integration Server.
Identity and Access Management: Strategy and Solution Sandeep Sinha Lead Product Manager Windows Server Product Management Redmond,
Important when you launch Yammer Enterprise Create an engaged and trusted community Decide about User Profile Syncs Various User and Admin.
Identity Management: The Legacy and Real Solutions Project Overview.
Identity and Access Management
Access and Identity Management for Enterprise Portals Rohit Gupta Director, Identity Management Product Management Oracle Corporation.
Microsoft Identity Integration Server 2003 (MIIS) Kim Mikkelsen Senior Technology Specialist Microsoft.
#CONVERGE2014 Session 1304 Managing Telecom Directories in a Distributed or Multi-Vendor Environment David Raanan Starfish Associates.
IDENTITY PROBLEM Too Many User Names and Passwords Across Multiple Systems.
© 2008 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice. HP Automates Infrastructure Outsourcing.
Microsoft Identity and Access Solutions Market Trends and Futures
EXTENDING FOREFRONT IDENTITY MANAGER Phil Whipps Principal Consultant CGI Australia SESSION CODE: SEC304 (c) 2011 Microsoft. All rights reserved.
Identity Lifecycle Management Jonny Chambers Senior Technical Specialist Microsoft Ireland
IDENTITY MANAGEMENT Hoang Huu Hanh (PhD), OST – Hue University hanh-at-hueuni.edu.vn.
May 30 th – 31 st, 2006 Sheraton Ottawa. Microsoft Certificate Lifecycle Manager Saleem Kanji Technology Solutions Professional - Windows Server Microsoft.
Rev Jul-o6 Oracle Identity Management Automate Provisioning to Oracle Applications and Beyond Kenny Gilbert Director of Technology Services.
Overview of Access and Information Protection
Christian Jäggli Principal Consultant Microsoft Corporation.
Module 8 Configuring and Securing SharePoint Services and Service Applications.
A detailed look at the Microsoft Windows Infrastructure at UWE including Active Directory (AD), MIIS, Exchange, SMS, IIS, SQL Server, Terminal Services.
Lecture 23 Internet Authentication Applications modified from slides of Lawrie Brown.
Forefront Identity Manager 2010 Deep Dive
Computer Security: Principles and Practice First Edition by William Stallings and Lawrie Brown Lecture slides by Lawrie Brown Chapter 22 – Internet Authentication.
Microsoft SharePoint Server 2010 for the Microsoft ASP.NET Developer Yaroslav Pentsarskyy
SharePoint Security Fundamentals Introduction to Claims-based Security Configuring Claims-based Security Development Opportunities.
Riva Managed Identity Integration for Active Directory and Novell ® GroupWise ® Aldo Zanoni CEO, Managing Director Omni Technology Solutions
Sudha Iyer Principal Product Manager Oracle Corporation.
MIIS in the Real World - MIIS at Centrica Mathew Rawlings Designer.
Tech Ed North America /24/2017 1:59 AM SESSION CODE: SIA327
PS Security By Deviprasad. Agenda Components of PS Security Security Model User Profiles Roles Permission List. Dynamic Roles Static Roles Building Roles/Rules.
Identity Solution in Baltic Theory and Practice Viktors Kozlovs Infrastructure Consultant Microsoft Latvia.
Empowering people-centric IT Unified device management Access and information protection Desktop Virtualization Hybrid Identity.
James Akrigg Microsoft Ltd Integrating InfoPath Forms Into Workflow Solutions And Business Processes.
DEP311 Identity Management with Microsoft Identity Integration Server (formerly MMS) Steve Plank Architectural Engineer |Microsoft UK Visit
PRESENTATION | OBLIX CORPORATE OVERVIEW Oblix Introduction Securely Managing Business in a Connected World.
Windows Role-Based Access Control Longhorn Update
Microsoft’s Roles Based Authorization Manager CSG, May 2004.
Claims-Based Identity Solution Architect Briefing zoli.herczeg.ro Taken from David Chappel’s work at TechEd Berlin 2009.
DirXML ™ Competitive Comparisons Ed Anderson Director, Product Management Novell, Inc. Joe Skehan Product Management Directory.
Module 9 User Profiles and Social Networking. Module Overview Configuring User Profiles Implementing SharePoint 2010 Social Networking Features.
Copyright Microsoft Corp Sandeep Katyal TechnologistMicrosoft Solving the Identity Management problem using MIIS and ADFS.
Introduction to Identity Management with MIIS 2003 Steve Plank Architectural Engineer Session code.
Autorisierung und rollenbasierte Sicherheit in.NET Anwendungen Jürgen Pfeifer Senior Architect Evangelist Developer & Platform Strategy Group Microsoft.
Identities and Azure AD Premium
Microsoft Identity Integration Server 2003 Overview Microsoft Corporation April 2004.
QlikView Integration Overview June Agenda Data Source Integration Web & Application Integration Security Integration Integration with 3rd party.
Chris Louloudakis Solution Specialist Identity & Access Management Microsoft Corporation SVR302.
WINDOWS AZURE AND THE HYBRID CLOUD. Hybrid Concepts and Cloud Services.
Productivity Architect Meet Chris Bortlik Author, Blogger, Speaker.
Azure Active Directory Uday Hegde 2016 Redmond Summit | Identity Without Boundaries May 26, 2016 Group Program Manager, Azure AD
Protect your data Enable your users Desktop Virtualization Information protection Mobile device & application management Identity and Access Management.
Introduction to the Microsoft Identity Integration Server and Roadmap
Secure Connected Infrastructure
9/13/2018 4:54 PM BRK How to get Office 365 to the next level with Azure Active Directory Premium Brjann Brekkan Program Manager Lead – Customer.
Autorisierung und rollenbasierte Sicherheit in .NET Anwendungen
Implementing Database Roles in the Enterprise Geodatababse
James Cowling Senior Technical Architect
Presentation transcript:

Microsoft Identity Integration Server & Role Base Access Theo Kostelijk Consultant Microsoft BV

Agenda Microsoft Identity Integration Server Concepts & Architecture (MIIS) Authorization Manager (AzMan)

What is Microsoft Identity Integration Server? Directory Synchronization Password Management Provisioning and Workflow Identity Data LDAP SQL NOS Mainframe/Unix MIIS

Connectivity in MIIS 2003, Enterprise Edition Active Directory Active Directory Application Mode Active Directory Global Address List (GAL) Attribute-value pair text file Delimited text file Directory Service Markup Language (DSML) 2.0 Exchange Server 5.5 Exchange Server 5.5 (Bridgehead Server) Extensible Connectivity Fixed-width text file IBM DB2 Universal Database IBM Directory Server LDAP Data Interchange Format (LDIF) Lotus Notes Novell eDirectory and 8.7 Oracle Database 8i and 9i SQL Server 7.0 and 2000 Sun and Netscape Directory Servers Windows NT 4.0

Exchange 5.5 Directory Synchronization Synchronizes multiple repositories Management agents use “touchless” connection to other systems Provides attribute-level control Manage global address lists (GAL) Automate group and DL management Active Directory Notes SunOne SQL Oracle MIIS

Directory Synchronisation HRSystem MIIS LotusNotes ActiveDirectory API API LDAP LDAP DB DB

Attribute Flow

Password Management Initial password set when provisioning Centralized password control via a Web app & ctr-alt-del –Self-service password change –Helpdesk password reset Active Directory Sun One Web app & CTRL-ALT-DEL MIIS

Provisioning & Workflow Simple Provisioning & De-provisioning –Provision users as they appear in authoritative systems –Set initial values for attributes (including password) –Disable or delete accounts Complex Workflow –Initiate workflow or provisioning system –Integrate with BizTalk –Integrate with 3rd party provisioning systems

Provisioning Scenario HRSystem MIIS iPlanetDirectory ActiveDirectory DB LDAP

De-Provisioning Scenario HRSystem MIIS iPlanetDirectory ActiveDirectory DB LDAP

MIIS Architecture HR App with SQL ActiveDirectory Lotus Notes Metaverse Connector Space Metaverse Object Connector Connector Space Object

Authorization Manager AzMan Advantages Centralized authorization policy for multiple applications The ability to create security groups outside of Active Directory and managed by the application administrator The ability to create groups based on the result of an LDAP query Relies on a Policy Store for one or more apps –Delegated Admin (AD & ADAM only) –XML Store – not recommended for Enterprise Apps –Authorized users “Must” have an actual account on the web server or user account in AD or ADAM Introduced in Windows Server 2003 – Also available for Windows Server 2000

Authorization Manager Advantages 3 Key Mechanisms for user Role Assignments: –Membership in AD or Local Server, or AzMan Groups –LDAP Query Groups –BizRules Centrally Managed across the organization without managing Web.config files or changing application code

Web Expense Application Role={Tasks}, Task={Operations} Database Operation Web Operation Directory Operation Payment System Operation AdministratorApproverSubmitter Change Approver Approve Deny Payment Approve Reject Report Submit Report Cancel Report Check Status

AzMan Groups

AzMan Operation Defenitions

AzMan Task Definitions

How to use AzMan in your code?

MIIS & AzMan (HRApp naar MIIS)

MIIS & AzMan (MIIS Naar AD)

MIIS & AzMan (AzMan & AD)