Federation and Cloud Services

Size: px
Start display at page:

Download "Federation and Cloud Services"

Transcription

1 Federation and Cloud Services for the K12 Community Quilt/InCommon K12 Pilot Project Summary Two Cases: Illinois and Nebraska What is Envisioned, Experiences, and Challenges Bernie Jim Peterson Jason Radford Scott Isaacson Mike

2 Illinois Shared Learning Environment The One-Slide Summary

3 Producers ED-FI Data Model Data Store Services Content Brokers Consumers Application Program Interface ( API ) Search & Registry Index for Content Illinois Shared Learning Environment ISLE SLC (Service Agreement): ISBE/LEA RttT-3 Grant : ISBE/LEA RttT-Early Childhood : ISBE/LEA Pathways/STEM LE : ISBE/DCEO GOMB ISLE Grant ISLE-IGA: Partners: DCEO -> NCSA/UIUC NCSA/UIUC -> NIU,SIU, & IC Partner Institutions Data Centers Create, Find, Map, Use, and Visualize Data Linked to Content and Standards enabling Personalized Learning and Career Preparedness for All Illinois Learners (P-K12 & Life-Long). Learning Maps & Learning Content Apps DB Compute Applications and Dashboards Collect, Assemble, & Propagate Ed-FI Data Model Participating LEA: 2 SLC Pilot 35 RttT-3 ~ 20% of Illinois Students with RttT-3 SD, ~840 to go. Dynamic Cloud Infrastructure Local School District Students, Educators, Parents, Researchers, Schools, Institutions and Agencies empowered by the Middleware infrastructure and Dynamic Self-Service Procurement Cloud Platform Services: *Learning Maps *Applications *Dashboards*Portal Integration *Databases *Collaboration Tools *Development Incubator *Advanced Analytics*Shared Data Services*Enterprise Services

4 ISLE K12 School Districts, Partners, & Data Centers Create, Find, Map, Use, and Visualize Data Linked to Content and Standards enabling Personalized Learning and Career Preparedness for All Illinois Learners (P-K12 & Life-Long). Learning Maps, Assemssments, & Learning Content Partner Institutions Data Centers Dynamic Cloud Infrastructure Apps DB Applications and Dashboards Compute Partners: Students, Educators, Parents, Researchers, Schools, Institutions and Agencies empowered by the Middleware infrastructure and Dynamic Self-Service Procurement Cloud Platform Services: *Learning Maps *Applications *Dashboards*Portal Integration *Databases *Collaboration Tools *Development Incubator *Advanced Analytics*Shared Data Services*Enterprise Services

5 Nebraska K12/P20W Pilot Four Slide Summary

6 Basic Services VM Hosting SIS DB ETL Nebraska K-12 Federation Learning Object Repository Ed-Fi ODS Compute Metrics Learning Management Systems Auto-provision & Deprovision Ed-Fi Dashboards District Integration Authentication & Authorization IdP Proxy Self-service Portal

7

8 Courtesy of Tom Rolfes, Nebraska Office of the CIO Internet2 (K.C. GigaPop)

9 Network Nebraska- Education CURRENT Partners (261) 223 public school districts 16 Educational Service Units 10 public colleges 7 nonpublic colleges 2 tribal colleges 3 nonpublic schools 1 public library Network Nebraska- Education POTENTIAL Partners (460+) 28 public school districts 1 Educational Service Unit 7 nonpublic colleges 159 nonpublic schools 269 public libraries Courtesy of Tom Rolfes, Nebraska Office of the CIO

10 K12 to P20 Vision Resources Compelling case for effective utilization of resources Might call this zero system administration. Jack s story is the vision of interoperability through standards Data Quality Campaign infographicvision on using data Visionary Resources: A little on the techie side Learning Registry Advanced Distributed Learning: SCORM IMS Global: SETDA :

11 Illinois Shared Learning Environment Exploring the Learning Map Concept: A Revolutionary Catalyst for the K12 Community and Pedagogy

12 What is a Learning Map? 1.) Visual Representation of a Series of Learning Objectives & Assessment of Mastery Learning Objective #1 Learning Objective #2 Learning Objective #3 Learning Objective #... Learning Objective #N N Assessment Measures #1 Assessment Measures #2 Assessment Measures #3 Assessment Measures #... Assessment Measures #N The visualization may be non-linear with branches and junctions having alternative paths. Branch Node 2a 3a Junction Node N multiple Path options 2b 3b multiple Paths converge

13 How Does a Learning Map Work? 2.) Coded Alignment of Objectives and Measures enables Content to be Linked to a Map! N Actions (Clicks, Pop-up Options) Content User Interface Options (Hoover Over & Zoom Into) Linked Learning Modules Aligned and Coded with Objectives Empower: Learners to explore proficiency tasks Mentors to find, create, and share Measures of effectiveness can be quantified by community experience and qualitative analysis of use. Objectives Map Node Measures Linked Assessment Bank Items Aligned and Coded with Objectives Empower: Learners to explore skill proficiency Mentors to find, create, and share Measures of effectiveness can be quantified by community experience and qualitative analysis of use. Link Content Aligned by Codes (Tagging) Create, Find, Use, and Shared Experience Pooling Objective Modules & Assessment Items Maps may be Presented using Interactive-Visual-Objects for each location marker along the path it shows

14 Why are Learning Maps Centrally Important? 3.) Learning Map Perspectives (or Views) of Learners Progression using Data in Alignment with Codified Objectives, Measures, & Content with variability in number of Learners & Time Scale N Learner Perspective Where am I and what tasks are to do Find, create, use, and share content Peer& mentor collaboration Personalize pathway potential How do my peer compare with me Measures of effectiveness can be quantified by community experience with qualitative analytics capacity. Objectives Content Map Node Measures Educator Perspective All Educators are also Learners Find, create, use, and share content Professional Development Support Virtual Professional Peer Groups How do my peer compare with me Measures of effectiveness can be quantified by community experience with qualitative analytics capacity. Guardian Perspectives The Learning Map Concept may be Presented using Role-Based-Visual-Objects integrated with API Driven Dynamic-Data-Aggregation for a Variety of Role Perspectives Apply Learner & Educator Perspectives of Progress along the learning map pathways: Workgroup Perspectives Real-Time Perspectives Future Perspectives Perspectives: Role & Aggregation State & Local Education Authority Perspectives Building Perspectives Institutional Perspectives

15 How can the Learning Map Concepts be Implemented? Content Objectives Map Node Learner Data Measures N

16 What is Required to Implement Learning Map Concepts? Parents & Guardians Learner Progression & Achievement Data Mentors & Interest Groups SEA Curriculum Guidance & Standards Learning Content Repositories Identity Access Management Services (IDP/Proxy Hybrid: IAM) Three Essential Pillars of Support: A K12 Federation Model for the Core Centralized Services & Operations: Data, Identity, & Presentation Application Services Multi-tenant Portal for School Districts Content Archives, Libraries, and Museums Data Services (Authoritative Source systems, ETL to SIF ZIS, and automated propagation to other data models). LEA Curriculum Workgroups & Standards Learning Registry Network of Nodes

17 Illinois Shared Learning Environment The Platform s Three Pillars of Support: Data, Identity, & Appliction The Core-Central K12 Federation Services

18 What Are The Three Service Pillars? IlliniCloudis a non-profit organization providing services for primarily for K12 school district all over the state of Illinois. Acting as a K12 federation operator and service provider, the IlliniCloudis establishing three foundational service dimensions for the K12 community: Data Services Identity Services Application Services Minimal threshold of Adoption: The implementation is focused on mitigating integration requirements for K12 school districts adoption of services with little to no modification of existing practices and procedures. Backend Interfaces & Services Tenants (School Districts) End-User Facing Interfaces Tenants (School Districts)

19 Illinois Shared Learning Environment The Platform s First Pillar of Support: Data Services

20 How Does The Data Service Work? Source 1 Source Source N Operational Data Store Any Data Model Reports Analytics Raw Source System Intermediate Data Product Data Matrices Data Model(s) Propagation Collection Assemble Produce

21 District/LEA Data Entry How Does the Data Validation Service Work? IlliniCloud Student Information User corrects data and resubmits If the data is rejected, an error message is generated to the user Teacher/Staff Data ERRORS Data is collected in the ODS, where the Data Validation Rules Engine runs to check for errors NO ERRORS Valid data is moved to the Data Marts Analyze the data in a spreadsheet Prepare a report Create a presentation Better Research Leads to Better Decisions REAL TIME REPORTS Data can now be analyzed longitudinal data analysis can be performed Data is Stored in the Longitudinal Data Warehouse 28

22 How Does Data Service Propagation Work for Apps? SP SP SIF/ZIS Integration API Any DM Source 1 Source Source N School District ZIS Reports Analytics Relational Data Store Ed FI API SP SP Object Data Store InBloom API SP SP Ingest Data Validation and Assembly SIF 2.5 for each local district sites. Data Propagation for Alternative DataModels Implicitly enables use of Application Programmatic Interfaces (API)

23 How Can Data Service Propagation Work for State Reporting? SIS FS TR School District Authoritative Source Systems Propagate Manage Error Resolution Illinois State Board of Education Data Mart(s) Automate Data Set Assembly and Propagation

24 Illinois Shared Learning Environment The Platform s Second Pillar of Support: Identity Services

25 What is the Federated Identity Service? incommon Google 4 Edu Other Service Providers School District Users/Orgs Trust 3 rd Party Service Providers & Other Federations Workforce Development Users/Orgs Federated Central Service School District Metadata Proxy IDP/SP Non-School District Metadata SAML 2.0 OAuth OpenID Read-Only Query Functionality Authentication Delegation to Authoritative Source Trust Native Directory Interface Districts (1.. N) using Active Directory Districts (1.. N) using edirectory Districts (1.. N) using LDAP/Kerberos

26 How Does the Federated Identity Service Work? InCommon Federation SP Metadata InC Net+ SP Google EDU IDP Does not Forward to Federated Idm Cloud Provider External Federations & Service Providers IDP K12 Federation IDP Proxy Publish Subscribe Metadata SP SP Apps SP SP K12 Federation Service Providers SSO Enabled Custom ISLE Applications Centralized Idm(SAML2) provides local directory mapping and profiles for federated service uses SP Custom District Applications K12 Org 1 K12 Org K12 Org N SP Not SSO Enabled K12 Organization Local Service Providers Directory Authoritative Directory Source AD LDAP Kerberos edirectory SP SSO Enabled School Districts have preexisting directories and business procedures that govern practices & processing

27 How Do Attribute/Value Assertions & Web SSO Sessions Work? If No Session then Prompt Fed-Login else goto4 Collects: edupersonprinciplename Manages the Delegated Authentication Challenge/Response If Session then Process Attribute Assertions for SP Collects & Assembles: edupersonaffiliation Manages computing edupersonetitlements that are needed for SP. 3 4 Advanced Configuration: IDP/P + SP itrust Federation Registry IDP K12 Federation IDP Proxy 0 Request Response SP Attributes Needed & Parsing: edupersonprinciplename edupersonaffiliation edupersonorgdn edupersonentitlement*(agreed) SP User has Navigated here IDP Attribute Resolvers & Filters: edupersonprinciplename edupersonaffiliation edupersonorgdn edupersonentitlement*(agreed) 7 8 Browser Accesses Protected App Resource ** May Have Distinct Entitlements for Individual Applications/Resources 1

28 How Does the IDP use Tenant User s Profile? Browser Redirected to IDP/Proxy LOGIN Service 1. UserName 2. PassWord 3. OrgDN Delegate Authentication Tenant s Authoritative Directory 1. OrganizationDN 2. EPPN 3. Affiliation 4. SP/Entitlement Browser Accesses Protected App Resource (SP) IDP K12 Federation IDP Proxy Shibboleth/IDP DBMS Connected AttributeResolver Tenant(s) Authoritative User Session Profile Populates Tenant User Profile Table Just-In-Time Provisioning OR Verification/Validation of Existing Shibboleth/IDP AttributeFilters SP/SP Groups Using attribute/value pairs available propagate authorized assertions to the SP * given_name, <dc:column columnname="given_name" attributeid="givenname" /> * surname, <dc:column columnname="surname" attributeid="sn" /> edu_person_nickname, <dc:column columnname="edu_person_nickname" attributeid="edupersonnickname" * /> mail, <dc:column columnname="mail" attributeid="mail" /> * organization_name, <dc:column columnname="organization_name" attributeid="organizationname" /> * home_organization_type, <dc:column columnname="home_organization_type" attributeid="homeorganizationtype" edu_person_affiliation, /> <dc:column columnname="edu_person_affiliation" attributeid="edupersonaffiliationlist" edu_person_primary_affiliation, /> <dc:column columnname="edu_person_primary_affiliation" attributeid="edupersonprimaryaffiliation" edu_person_scoped_affiliation, /> <dc:column columnname="edu_person_scoped_affiliation" attributeid="edupersonscopedaffiliation" edu_person_org_dn, /> <dc:column columnname="edu_person_org_dn" attributeid="edupersonorgdn" /> edu_person_org_unit_dn, <dc:column columnname="edu_person_org_unit_dn" attributeid="edupersonorgunitdnlist" edu_person_primary_org_unit_dn, /> <dc:column columnname="edu_person_primary_org_unit_dn" attributeid="edupersonprimaryorgunitdn" * uid, /> <dc:column columnname="uid" attributeid="uid" /> edu_person_principal_name, <dc:column columnname="edu_person_principal_name" attributeid="edupersonprincipalname" edu_person_targeted_id, /> <dc:column columnname="edu_person_targeted_id" attributeid="edupersontargetedid" edu_person_unique_id, /> <dc:column columnname="edu_person_unique_id" attributeid="edupersonuniqueid" /> edu_person_assurance, <dc:column columnname="edu_person_assurance" attributeid="edupersonassurance" /> edu_person_principal_name_prior, <dc:column columnname="edu_person_principal_name_prior" attributeid="edupersonprincipalnameprior" edu_person_entitlement, /> <dc:column columnname="edu_person_entitlement" attributeid="edupersonentitlement" * member_of /> <dc:column columnname="member_of" attributeid="memberoflist" />

29 How does edupersonentitlement Look Up-Close? Privilege Groups Of Interest IDP Attribute Resolvers & Filters: edupersonprinciplename edupersonaffiliation edupersonorgdn edupersonentitlement*(agreed) Facualty, Staff,, Library Walk-in dc=district, dc=ext Any String as a UR(N,I,L) SP Attributes Required Values When Group Member: Needs fine grain privilege mapping to align to some collection of cohort declarations the user is a member of in the authoritative source system of reference. edupersonentitlement Attribute value(s) to assert: Because the Login User Has Relative: memberof Attributes Associated

30 What is the User Profile? 1 IlliniCloud IAM Service Anonymous User No Session 2a User s Personal Preferences IDP Registration External Identity Provider OAuth Google, Facebook, MSN, Yahoo, & Others App Login or Registration Is External Authenticate? Known Person Yes Yes Is User Registering? Personal Profile? 2b School District User s IDP Registration is automated No No No Yes Yes Is Managing Profile? OrgDN Profile? Is Fed-Realm No No No No Is User AuthN? Fed-Realm? External AuthN? Yes No Yes IAM Identity-Repo 3a Has Profile 3b No Anonymous User No Session 4a Yes Registered Realm User Session Okay Yes Delegate AuthN To District 4b Yes Registered Public User Session Okay 4c Known User, Profile Persistent, & Session

31 Illinois Shared Learning Environment The Platform s Third Pillar of Support: Application Services Multiple Tenant Portal and Application Launcher

32 Who Will Use the Application Service? CASE 1: Non-Authenticated Users, Anonymous Unknown User May see only informational content Presentation Service Data Identity CASE 3: Authenticated by IC IDP/P implies defined Domain and Affiliation with Authorities expressed in Entitlements Known User No Affiliation & Organization Domain may use public Applications CASE 2: Federated IDP Other Than IC IDP/P Authenticates User and implicitly claims identity authority for a user s logical session. LEA Tenant Known User with Affiliation assigned may use organizations informational content, services, and applications

33 What is the Application Service, a Portal? 1.) Web Browser Based Visual Presentation & Workspace Much like the graphical user interface provided by a computer s operating system (Windows, Macintosh, Tablets, & Smart-phones). Portal Leverages SSO Service Buttons & Menus Clickable Actions or Pop-up May Take Input May Grouped Visually Functionally Can be Combined with Visual Theme Preferences May be Locate Anywhere Vertical (Button Bar) Button # 1 Button # 2 Button #... Button #N Input: Button Icon Symbol Header: * Optional: May include Active Controls Background Visual Attributes are generally user definable and persisted as Preferences Portlet# 1 Floating Window Portlet Workspace Visual Workspace: Footer: * Optional: May include Active Controls Portlet#2 Window w/no Controls Portlet Workspace Portlet# 3 : Minimized Window Portlet#.. : Minimized Window Portlet# N: Invisible Win/Service PortletAttributes: are generally user definable and persisted as Preferences (for each portlet) including size (min, max, full) & relative workspacelocationand window state. Portlets Optional Visual Window May Contain Buttons Input/Forms Any Media Content May be an Application May be a Service May be Resized or Static Full Screen (WrkSpc) Floating Window Minimized (Visible) Layered May be Remote Service May be Local Service May be Support Any Media Shares Session Attributes User/Role Organization Access Rules Authorizations Horizontal (Button Bar) S #1 S #2 S #... S #N Input: Portal is the outer visual wrapper and user interface Manages User Identity for primary SSO/Sessions Shares Session State with Gadgets & Portlets

34 How Does the Portal Work for Users? Anonymous &Non-District Authenticated Users: Public Apps & Informational Page(s) Login: Multi-Tenancy Application Launcher: Individual school districts are tenants ISLE Apps Info Page Tab Bar ISLE Apps District Apps My Page Tab Bar Illinois Open Education Resource Search Illinois Open Education Resource Search Educator Dashboard Each tenant must be able to customize the appearance & content of the portal for its own needs. Users who log into the portal get the appropriate experience for the tenant (district) to which they are connected. Customization examples include logo, colors, header/footer text, navigation(tabs), and content(portlets). Tenants, moreover, not only need to manage these items, they also need to manage the managers they must be able to grant or deny access to these management functions with regard to their own staff

35 How Does the Portal Login Process Work? Multi-Tenancy Global Login (IDP/Proxy): Get User & Organization Anonymous User Invokes Login Action A.) Input edupersonprinciplename 1 Login: UserID: Domain Name List. 123 Login Name [@domainname.ext] Populates OrgDN List for Login Name if more than one force a choice. Determine Tenancy for Authentication ISLE Apps Tenant Info Illinois Open Education Resource Search Tab Bar B.) Derive: edupersonorgdn(/orgunitdn) Authentication Service Action Multi-Tenancy Global Login (IDP/Proxy): Delegate Authentication as Required C.) Compute: edupersonaffiliation faculty student staff alum member affiliate employee library-walk-in Typical Affiliation List for Login Name if Educator then faculty,member,employee If Staff Employee then staff,member,employee If Student then student, member If Parent/Gardian then Affiliate If Externally AuthN then library-walk-in 2 Determine Role Privileges D.) Compute: edupersonentitlement

36 User s Tenant & Role are Manifested as a Result of Login General Purpose Login Process Tenant Portal-Manager Controls Visual Attribute Customizations User Role Based Content Customizations Teacher@district87.org Isle Apps District Apps EC/PK Apps My Page Tab Bar Teacher Illinois Open Education Resource Search Educator Dashboard Administrator@unit5.org Staff@illiniCloud.org Student Isle Apps Isle Apps Tenant Apps Office Apps Grade 8 Apps Office Apps My Page Tab Bar Student@usd116.org My Page Staff Tab Bar Administrator Isle Apps District Apps Illinois Open Education Resource Search Admin Tools My Page Educator Dashboard Tab Bar

37 Illinois Shared Learning Environment Three Pillars of Support Married With Application Programmatic Interfaces: Offer Significant Potential for LEAs* to Realize the Promise Envisioned for the ISLE Platform Operated as a K12 Federation for K12 by K12! * Local Educational Authority

38 illinicloud Services SD001 SIF_2.5 to EDFI inbloom Services SD-Managed Org SD SD002 SD ODS to inbloom Data-Store SD Staff SD Edu Application Registry SDNNN Local System to SIF_2.5 inbloom Data, Roles and Identity Edu Kid SD001 SD002 SD SDNNN inbloom Data, Roles and Identity Directory incommon Data, Roles and Identity Federated IAM Service Auth[N/Z] IAM Integration inbloom Applications API Service Auth[N/Z] Provider Registration incommon Services incommon Services and Applications Auth[N/Z] Net+ and Affiliate Services Federated Services incommon Federation Application Providers inbloom Application Providers

39 illinicloud Services SD001 SD002 SD SDNNN SD001 SD002 SD SDNNN ODS Local System to SIF_2.5 inbloom Data, Roles and Identity Directory incommon Data, Roles and Identity incommon Services SIF_2.5 to EDFI Person Roles MD Agrgtr Federated IAM Service Auth[N/Z] Roles & Id Data-Store Fed 2Fed Auth[N/Z] inbloom Operator Data, Role & Id API Service IAM Integration Org SD SD Staff SD Edu Edu Kid Data, Role & Id Auth[N/Z] App/Key inbloom Services Application Providers inbloom Application Providers inbloom Data, Roles and Identity inbloom Applications Provider Registration API Service Application Registry Application Providers incommon Services and Applications Federated Services Net+ and Affiliate Services incommon Federation Third Party Third Party Application Providers

40 How Does the ibmlss Define a Tenant from the Top-Level? Service Owner Create Tenant-Adm SLC Operator admin api 3 inbloom Model Local Service Stack dashboard databrowser lz 2 Tenant #1 portal Tenant Admin Management ibmlss LDAP sidp 1 New LDAP Entry LDAP Entry Good SN=? Text?

41 How the ibmlss Works with SimpleIDP& DataStore Services? ibmlss LDAP sidp Tenant User #1 admin api lz Validation & Approval Process Designate AuthN Service Creates Logical Data Store/LZ

42 How Does the ibmlss LDAP Service Work with SimpleIDP Service? ibmlss LDAP sidp Tenant User #1 admin api lz Validation & Approval Process Designate AuthN Service Create Logical LandingZone

43 How Does the ibmlsswork with API User Roles & Dir-Groups? ibmlss LDAP sidp admin api lz Directory Groups Map To Fixed-Role Privileges (Manual ) LDAP to SAML

44 The image part with relationship ID rid2 was not found in the file.

45 Questions & Comments Bernie Jim Peterson Jason Radford Scott Isaacson Mike

Enterprise & Vertical Reporting. Challenges and Solutions

Enterprise & Vertical Reporting. Challenges and Solutions Enterprise & Vertical Reporting Challenges and Solutions The Challenge: How do you design a real time data collection system that is scalable for states and districts that is easy to use and extendible

More information

Single Sign On at Colorado State. Ron Splittgerber

Single Sign On at Colorado State. Ron Splittgerber Single Sign On at Colorado State Ron Splittgerber Agenda Identity Management Authentication Authorization The Problem The Solution: Federation Trust Between Institutions Trust Between Institution and Federal

More information

Shibboleth User Verification Customer Implementation Guide 2015-03-13 Version 3.5

Shibboleth User Verification Customer Implementation Guide 2015-03-13 Version 3.5 Shibboleth User Verification Customer Implementation Guide 2015-03-13 Version 3.5 TABLE OF CONTENTS Introduction... 1 Purpose and Target Audience... 1 Commonly Used Terms... 1 Overview of Shibboleth User

More information

Configuring Parature Self-Service Portal

Configuring Parature Self-Service Portal Configuring Parature Self-Service Portal Chapter 2 The following is an overview of the steps required to configure the Parature Self-Service Portal application for single sign-on (SSO) via SAML. Parature

More information

Egnyte Single Sign-On (SSO) Installation for OneLogin

Egnyte Single Sign-On (SSO) Installation for OneLogin Egnyte Single Sign-On (SSO) Installation for OneLogin To set up Egnyte so employees can log in using SSO, follow the steps below to configure OneLogin and Egnyte to work with each other. 1. Set up OneLogin

More information

The Top 5 Federated Single Sign-On Scenarios

The Top 5 Federated Single Sign-On Scenarios The Top 5 Federated Single Sign-On Scenarios Table of Contents Executive Summary... 1 The Solution: Standards-Based Federation... 2 Service Provider Initiated SSO...3 Identity Provider Initiated SSO...3

More information

SAP NetWeaver Fiori. For more information, see "Creating and enabling a trusted provider for Centrify" on page 108-10.

SAP NetWeaver Fiori. For more information, see Creating and enabling a trusted provider for Centrify on page 108-10. Chapter 108 Configuring SAP NetWeaver Fiori The following is an overview of the steps required to configure the SAP NetWeaver Fiori Web application for single sign-on (SSO) via SAML. SAP NetWeaver Fiori

More information

Flexible Identity Federation

Flexible Identity Federation Flexible Identity Federation Quick start guide version 1.0.1 Publication history Date Description Revision 2015.09.23 initial release 1.0.0 2015.12.11 minor updates 1.0.1 Copyright Orange Business Services

More information

SP-initiated SSO for Smartsheet is automatically enabled when the SAML feature is activated.

SP-initiated SSO for Smartsheet is automatically enabled when the SAML feature is activated. Chapter 87 Configuring Smartsheet The following is an overview of the steps required to configure the Smartsheet Web application for single sign-on (SSO) via SAML. Smartsheet offers both IdP-initiated

More information

econtrol 3.5 for Active Directory & Exchange Administrator Guide

econtrol 3.5 for Active Directory & Exchange Administrator Guide econtrol 3.5 for Active Directory & Exchange Administrator Guide This Guide Welcome to the econtrol 3.5 for Active Directory and Exchange Administrator Guide. This guide is for system administrators and

More information

Nebraska ESUCC InCommon K-12 Pilot Summary

Nebraska ESUCC InCommon K-12 Pilot Summary Nebraska ESUCC InCommon K-12 Pilot Summary September 14, 2015 Overview Our experience with the Quilt Internet2 InCommon Federation s K 12 pilot program has been incredibly valuable for the knowledge our

More information

Connected Data. Connected Data requirements for SSO

Connected Data. Connected Data requirements for SSO Chapter 40 Configuring Connected Data The following is an overview of the steps required to configure the Connected Data Web application for single sign-on (SSO) via SAML. Connected Data offers both IdP-initiated

More information

NCSU SSO. Case Study

NCSU SSO. Case Study NCSU SSO Case Study 2 2 NCSU Project Requirements and Goals NCSU Operating Environment Provide support for a number Apps and Programs Different vendors have their authentication databases End users must

More information

Configuring. Moodle. Chapter 82

Configuring. Moodle. Chapter 82 Chapter 82 Configuring Moodle The following is an overview of the steps required to configure the Moodle Web application for single sign-on (SSO) via SAML. Moodle offers SP-initiated SAML SSO only. 1 Prepare

More information

UNI. UNIfied identity management. Krzysztof Benedyczak ICM, Warsaw University

UNI. UNIfied identity management. Krzysztof Benedyczak ICM, Warsaw University UNI TY UNIfied identity management Krzysztof Benedyczak ICM, Warsaw University Outline The idea Local database Groups, Entities, Identities and Attributes UNITY Authorization Local authentication Credentials

More information

An overview of configuring Intacct for single sign-on. To configure the Intacct application for single-sign on (an overview)

An overview of configuring Intacct for single sign-on. To configure the Intacct application for single-sign on (an overview) Chapter 94 Intacct This section contains the following topics: "An overview of configuring Intacct for single sign-on" on page 94-710 "Configuring Intacct for SSO" on page 94-711 "Configuring Intacct in

More information

Configuring Salesforce

Configuring Salesforce Chapter 94 Configuring Salesforce The following is an overview of how to configure the Salesforce.com application for singlesign on: 1 Prepare Salesforce for single sign-on: This involves the following:

More information

Table of Contents INTRODUCTION... 2 HOME PAGE... 3. Announcements... 7 Personalize & Change Password... 8 Reminders... 9 SERVICE CATALOG...

Table of Contents INTRODUCTION... 2 HOME PAGE... 3. Announcements... 7 Personalize & Change Password... 8 Reminders... 9 SERVICE CATALOG... Table of Contents INTRODUCTION... 2 HOME PAGE... 3 Announcements... 7 Personalize & Change Password... 8 Reminders... 9 SERVICE CATALOG... 11 Raising a Service Request... 12 Edit the Service Request...

More information

Business and Process Requirements Business Requirements mapped to downstream Process Requirements. IAM UC Davis

Business and Process Requirements Business Requirements mapped to downstream Process Requirements. IAM UC Davis Business and Process Requirements Business Requirements mapped to downstream Process Requirements IAM UC Davis IAM-REQ-1 Authorization Capabilities The system shall enable authorization capabilities that

More information

OpenAM All-In-One solution to securely manage access to digital enterprise and customer services, anytime and anywhere.

OpenAM All-In-One solution to securely manage access to digital enterprise and customer services, anytime and anywhere. OpenAM All-In-One solution to securely manage access to digital enterprise and customer services, anytime and anywhere. OpenAM, the only all-in-one open source access management solution, provides the

More information

Getting Started with Single Sign-On

Getting Started with Single Sign-On Getting Started with Single Sign-On I. Introduction Your institution is considering or has already purchased Collaboratory from Treetop Commons, LLC. One benefit provided to member institutions is Single

More information

SAP NetWeaver AS Java

SAP NetWeaver AS Java Chapter 75 Configuring SAP NetWeaver AS Java SAP NetWeaver Application Server ("AS") Java (Stack) is one of the two installation options of SAP NetWeaver AS. The other option is the ABAP Stack, which is

More information

Copyright: WhosOnLocation Limited

Copyright: WhosOnLocation Limited How SSO Works in WhosOnLocation About Single Sign-on By default, your administrators and users are authenticated and logged in using WhosOnLocation s user authentication. You can however bypass this and

More information

Q&A Session for Understanding Atrium SSO Date: Thursday, February 14, 2013, 8:00am Pacific

Q&A Session for Understanding Atrium SSO Date: Thursday, February 14, 2013, 8:00am Pacific Q: Is the challenge required or can pass through authentication be used with regard to automatic login after you login to your corporate domain? A: You can configure the system to pass on the challenge

More information

For details about using automatic user provisioning with Salesforce, see Configuring user provisioning for Salesforce.

For details about using automatic user provisioning with Salesforce, see Configuring user provisioning for Salesforce. Chapter 41 Configuring Salesforce The following is an overview of how to configure the Salesforce.com application for singlesign on: 1 Prepare Salesforce for single sign-on: This involves the following:

More information

OpenLogin: PTA, SAML, and OAuth/OpenID

OpenLogin: PTA, SAML, and OAuth/OpenID OpenLogin: PTA, SAML, and OAuth/OpenID Ernie Turner Chris Fellows RightNow Technologies, Inc. Why should you care about these features? Why should you care about these features? Because users hate creating

More information

Protect Everything: Networks, Applications and Cloud Services

Protect Everything: Networks, Applications and Cloud Services Protect Everything: Networks, Applications and Cloud Services Tokens & Users Cloud Applications Private Networks Corporate Network API LDAP / Active Directory SAML RADIUS Corporate Network LDAP / Active

More information

Alfresco Online Collaboration Tool

Alfresco Online Collaboration Tool Alfresco Online Collaboration Tool USER MANUAL BECOMING FAMILIAR WITH THE USER INTERFACE... 4 MY DASHBOARD... 4 MY PROFILE... 6 VIEWING YOUR FULL PROFILE... 6 EDITING YOUR PROFILE... 7 CHANGING YOUR PASSWORD...

More information

VMware Identity Manager Administration

VMware Identity Manager Administration VMware Identity Manager Administration VMware Identity Manager 2.4 This document supports the version of each product listed and supports all subsequent versions until the document is replaced by a new

More information

Shibboleth Authentication. Information Systems & Computing Identity and Access Management May 23, 2014

Shibboleth Authentication. Information Systems & Computing Identity and Access Management May 23, 2014 Shibboleth Authentication Information Systems & Computing Identity and Access Management May 23, 2014 For every question an answer: Why should I care about SAML? What is a Shibboleth? What is a Federation?

More information

An overview of configuring WebEx for single sign-on. To configure the WebEx application for single-sign on from the cloud service (an overview)

An overview of configuring WebEx for single sign-on. To configure the WebEx application for single-sign on from the cloud service (an overview) Chapter 190 WebEx This chapter includes the following sections: "An overview of configuring WebEx for single sign-on" on page 190-1600 "Configuring WebEx for SSO" on page 190-1601 "Configuring WebEx in

More information

Configuring SuccessFactors

Configuring SuccessFactors Chapter 117 Configuring SuccessFactors The following is an overview of the steps required to configure the SuccessFactors Enterprise Edition Web application for single sign-on (SSO) via SAML. SuccessFactors

More information

Get Cloud Ready: Secure Access to Google Apps and Other SaaS Applications

Get Cloud Ready: Secure Access to Google Apps and Other SaaS Applications Get Cloud Ready: Secure Access to Google Apps and Other SaaS Applications Matt Weisberg Vice President & CIO, Weisberg Consulting, Inc. matt@weisberg.net Paul McKeith Technical Sales, Novell, Inc. pmckeith@novell.com

More information

Northern Illinois University Request for Proposals ISLE Learning Map and Assessment Applications Exhibits

Northern Illinois University Request for Proposals ISLE Learning Map and Assessment Applications Exhibits Northern Illinois University Request for Proposals ISLE Learning Map and Assessment Applications Exhibits Contents: Exhibit A: ISLE Technology Development & Deployment Plan 2 Exhibit B: Learning Map Requirements..

More information

IBM API Management Overview. 2014 IBM Corporation

IBM API Management Overview. 2014 IBM Corporation IBM API Management Overview Please Note IBM s statements regarding its plans, directions, and intent are subject to change or withdrawal without notice at IBM s sole discretion. Information regarding potential

More information

Dell One Identity Cloud Access Manager 8.0.1 - How to Develop OpenID Connect Apps

Dell One Identity Cloud Access Manager 8.0.1 - How to Develop OpenID Connect Apps Dell One Identity Cloud Access Manager 8.0.1 - How to Develop OpenID Connect Apps May 2015 This guide includes: What is OAuth v2.0? What is OpenID Connect? Example: Providing OpenID Connect SSO to a Salesforce.com

More information

Alex Wong Senior Manager - Product Management Bruce Ong Director - Product Management

Alex Wong Senior Manager - Product Management Bruce Ong Director - Product Management Alex Wong Senior Manager - Product Management Bruce Ong Director - Product Management 1 Product Roadmap Disclaimer Any forward-looking indication of plans for products is preliminary and all future release

More information

Copyright Pivotal Software Inc, 2013-2015 1 of 10

Copyright Pivotal Software Inc, 2013-2015 1 of 10 Table of Contents Table of Contents Getting Started with Pivotal Single Sign-On Adding Users to a Single Sign-On Service Plan Administering Pivotal Single Sign-On Choosing an Application Type 1 2 5 7 10

More information

UW System Identity & Access Management (IAM) Recommended Strategic Roadmap

UW System Identity & Access Management (IAM) Recommended Strategic Roadmap UW System Identity & Access Management (IAM) Recommended Strategic Roadmap Fall 2015 ITMC (Rev 1/11) Our challenge CIOs charged IAM-TAG with recommending an IAM strategy that would: Establish an identity

More information

An overview of configuring WebEx for single sign-on. To configure the WebEx application for single-sign on from the cloud service (an overview)

An overview of configuring WebEx for single sign-on. To configure the WebEx application for single-sign on from the cloud service (an overview) Chapter 83 WebEx This chapter includes the following sections: An overview of configuring WebEx for single sign-on Configuring WebEx for SSO Configuring WebEx in Cloud Manager For more information about

More information

Configuring. SugarCRM. Chapter 121

Configuring. SugarCRM. Chapter 121 Chapter 121 Configuring SugarCRM The following is an overview of the steps required to configure the SugarCRM Web application for single sign-on (SSO) via SAML. SugarCRM offers both IdP-initiated SAML

More information

How To Use Salesforce Identity Features

How To Use Salesforce Identity Features Identity Implementation Guide Version 35.0, Winter 16 @salesforcedocs Last updated: October 27, 2015 Copyright 2000 2015 salesforce.com, inc. All rights reserved. Salesforce is a registered trademark of

More information

INCOMMON FEDERATION: PARTICIPANT OPERATIONAL PRACTICES

INCOMMON FEDERATION: PARTICIPANT OPERATIONAL PRACTICES INCOMMON FEDERATION: PARTICIPANT OPERATIONAL PRACTICES Participation in the InCommon Federation ( Federation ) enables a federation participating organization ("Participant") to use Shibboleth identity

More information

Cloudwork Dashboard User Manual

Cloudwork Dashboard User Manual STUDENTNET Cloudwork Dashboard User Manual Make the Cloud Yours! Studentnet Technical Support 10/28/2015 User manual for the Cloudwork Dashboard introduced in January 2015 and updated in October 2015 with

More information

VMware Identity Manager Administration

VMware Identity Manager Administration VMware Identity Manager Administration VMware Identity Manager 2.6 This document supports the version of each product listed and supports all subsequent versions until the document is replaced by a new

More information

Nevepoint Access Manager 1.2 BETA Documentation

Nevepoint Access Manager 1.2 BETA Documentation Nevepoint Access Manager 1.2 BETA Documentation Table of Contents Installation...3 Locating the Installation Wizard URL...3 Step 1: Configure the Administrator...4 Step 2: Connecting to Primary Connector...4

More information

Open Source Identity Management

Open Source Identity Management Open Source Management OpenAlt 2015 Radovan Semančík November 2015 Ing. Radovan Semančík, PhD. Software architect Co-owner of Evolveum (open source company) Architect of midpoint project Apache committer

More information

Configuring. SuccessFactors. Chapter 67

Configuring. SuccessFactors. Chapter 67 Chapter 67 Configuring SuccessFactors The following is an overview of the steps required to configure the SuccessFactors Enterprise Edition Web application for single sign-on (SSO) via SAML. SuccessFactors

More information

OPENIAM ACCESS MANAGER. Web Access Management made Easy

OPENIAM ACCESS MANAGER. Web Access Management made Easy OPENIAM ACCESS MANAGER Web Access Management made Easy TABLE OF CONTENTS Introduction... 3 OpenIAM Access Manager Overview... 4 Access Gateway... 4 Authentication... 5 Authorization... 5 Role Based Access

More information

Federated Identity: Leveraging Shibboleth to Access On and Off Campus Resources

Federated Identity: Leveraging Shibboleth to Access On and Off Campus Resources Federated Identity: Leveraging Shibboleth to Access On and Off Campus Resources Paul Riddle University of Maryland Baltimore County EDUCAUSE Mid-Atlantic Regional Conference January 16, 2008 Copyright

More information

EMC Documentum Webtop

EMC Documentum Webtop EMC Documentum Webtop Version 6.5 User Guide P/N 300 007 239 A01 EMC Corporation Corporate Headquarters: Hopkinton, MA 01748 9103 1 508 435 1000 www.emc.com Copyright 1994 2008 EMC Corporation. All rights

More information

SAML Authentication Quick Start Guide

SAML Authentication Quick Start Guide SAML Authentication Quick Start Guide Powerful Authentication Management for Service Providers and Enterprises Authentication Service Delivery Made EASY Copyright 2013 SafeNet, Inc. All rights reserved.

More information

User Guide Version 5.1

User Guide Version 5.1 User Guide Version 5.1 Copyright 2010 Pearson Education, Inc. or its affiliate(s). All rights reserved. No part of this publication may be reproduced or transmitted in any form or by any means, electronic

More information

Identity Management in Liferay Overview and Best Practices. Liferay Portal 6.0 EE

Identity Management in Liferay Overview and Best Practices. Liferay Portal 6.0 EE Identity Management in Liferay Overview and Best Practices Liferay Portal 6.0 EE Table of Contents Introduction... 1 IDENTITY MANAGEMENT HYGIENE... 1 Where Liferay Fits In... 2 How Liferay Authentication

More information

PRACTICAL IDENTITY AND ACCESS MANAGEMENT FOR CLOUD - A PRIMER ON THREE COMMON ADOPTION PATTERNS FOR CLOUD SECURITY

PRACTICAL IDENTITY AND ACCESS MANAGEMENT FOR CLOUD - A PRIMER ON THREE COMMON ADOPTION PATTERNS FOR CLOUD SECURITY PRACTICAL IDENTITY AND ACCESS MANAGEMENT FOR CLOUD - A PRIMER ON THREE COMMON ADOPTION PATTERNS FOR CLOUD SECURITY Shane Weeden IBM Session ID: CLD-W01 Session Classification: Advanced Agenda Cloud security

More information

Configuring Single Sign-on from the VMware Identity Manager Service to ServiceNow

Configuring Single Sign-on from the VMware Identity Manager Service to ServiceNow Configuring Single Sign-on from the VMware Identity Manager Service to ServiceNow VMware Identity Manager AUGUST 2015 V1 Configuring Single Sign-On from VMware Identity Manager to ServiceNow Table of Contents

More information

TIBCO Spotfire Metrics Modeler User s Guide. Software Release 6.0 November 2013

TIBCO Spotfire Metrics Modeler User s Guide. Software Release 6.0 November 2013 TIBCO Spotfire Metrics Modeler User s Guide Software Release 6.0 November 2013 Important Information SOME TIBCO SOFTWARE EMBEDS OR BUNDLES OTHER TIBCO SOFTWARE. USE OF SUCH EMBEDDED OR BUNDLED TIBCO SOFTWARE

More information

Dell One Identity Cloud Access Manager 8.0.1 - How to Configure for SSO to SAP NetWeaver using SAML 2.0

Dell One Identity Cloud Access Manager 8.0.1 - How to Configure for SSO to SAP NetWeaver using SAML 2.0 Dell One Identity Cloud Access Manager 8.0.1 - How to Configure for SSO to SAP NetWeaver using SAML 2.0 May 2015 About this guide Prerequisites and requirements NetWeaver configuration Legal notices About

More information

Google Apps and Open Directory. Randy Saeks Twitter: @rsaeks http://www.techrecess.com

Google Apps and Open Directory. Randy Saeks Twitter: @rsaeks http://www.techrecess.com Google Apps and Open Directory Randy Saeks Twitter: @rsaeks http://www.techrecess.com Agenda Quick Google Apps Overview Structure Setup Preparing OD Configuration Q&A&S Resources http://techrecess.com/technical-papers/gapps/

More information

SWISSVBS LEARNING CLOUD (SLC)

SWISSVBS LEARNING CLOUD (SLC) SWISSVBS LEARNING CLOUD (SLC) OVERVIEW The LMS for the Mobile-Cloud World The SwissVBS Learning Cloud (SLC) is an enterprise-class learning management and analytics platform. It is designed from the ground

More information

An Overview of Samsung KNOX Active Directory-based Single Sign-On

An Overview of Samsung KNOX Active Directory-based Single Sign-On C E N T R I F Y W H I T E P A P E R. S E P T E M B E R 2013 An Overview of Samsung KNOX Active Directory-based Single Sign-On Abstract Samsung KNOX is a set of business-focused enhancements to the Android

More information

SAML application scripting guide

SAML application scripting guide Chapter 151 SAML application scripting guide You can use the generic SAML application template (described in Creating a custom SAML application profile) to add a SAML-enabled web application to the app

More information

Single Sign On. SSO & ID Management for Web and Mobile Applications

Single Sign On. SSO & ID Management for Web and Mobile Applications Single Sign On and ID Management Single Sign On SSO & ID Management for Web and Mobile Applications Presenter: Manish Harsh Program Manager for Developer Marketing Platforms of NVIDIA (Visual Computing

More information

EXTENDING SINGLE SIGN-ON TO AMAZON WEB SERVICES

EXTENDING SINGLE SIGN-ON TO AMAZON WEB SERVICES pingidentity.com EXTENDING SINGLE SIGN-ON TO AMAZON WEB SERVICES Best practices for identity federation in AWS Table of Contents Executive Overview 3 Introduction: Identity and Access Management in Amazon

More information

Delegated Administration Quick Start

Delegated Administration Quick Start Delegated Administration Quick Start Topic 50200 Delegated Administration Quick Start Updated 22-Oct-2013 Applies to: Web Filter, Web Security, Web Security Gateway, and Web Security Gateway Anywhere,

More information

TIB 2.0 Administration Functions Overview

TIB 2.0 Administration Functions Overview TIB 2.0 Administration Functions Overview Table of Contents 1. INTRODUCTION 4 1.1. Purpose/Background 4 1.2. Definitions, Acronyms and Abbreviations 4 2. OVERVIEW 5 2.1. Overall Process Map 5 3. ADMINISTRATOR

More information

Only LDAP-synchronized users can access SAML SSO-enabled web applications. Local end users and applications users cannot access them.

Only LDAP-synchronized users can access SAML SSO-enabled web applications. Local end users and applications users cannot access them. This chapter provides information about the Security Assertion Markup Language (SAML) Single Sign-On feature, which allows administrative users to access certain Cisco Unified Communications Manager and

More information

Okta/Dropbox Active Directory Integration Guide

Okta/Dropbox Active Directory Integration Guide Okta/Dropbox Active Directory Integration Guide Okta Inc. 301 Brannan Street, 3rd Floor San Francisco CA, 94107 info@okta.com 1-888- 722-7871 1 Table of Contents 1 Okta Directory Integration Edition for

More information

Cloud. Hosted Exchange Administration Manual

Cloud. Hosted Exchange Administration Manual Cloud Hosted Exchange Administration Manual Table of Contents Table of Contents... 1 Table of Figures... 4 1 Preface... 6 2 Telesystem Hosted Exchange Administrative Portal... 7 3 Hosted Exchange Service...

More information

Mobile Security. Policies, Standards, Frameworks, Guidelines

Mobile Security. Policies, Standards, Frameworks, Guidelines Mobile Security Policies, Standards, Frameworks, Guidelines Guidelines for Managing and Securing Mobile Devices in the Enterprise (SP 800-124 Rev. 1) http://csrc.nist.gov/publications/drafts/800-124r1/draft_sp800-124-rev1.pdf

More information

INCOMMON FEDERATION: PARTICIPANT OPERATIONAL PRACTICES

INCOMMON FEDERATION: PARTICIPANT OPERATIONAL PRACTICES INCOMMON FEDERATION: PARTICIPANT OPERATIONAL PRACTICES 1. Federation Participant Information 1.1 The InCommon Participant Operational Practices information below is for: InCommon Participant organization

More information

SAML single sign-on configuration overview

SAML single sign-on configuration overview Chapter 34 Configurin guring g Clarizen Configure the Clarizen Web-SAML application profile in Cloud Manager to set up single sign-on via SAML with Clarizen. Configuration also specifies how the application

More information

Cloud Single Sign-On and On-Premise Identity Federation with SAP NetWeaver Cloud White Paper

Cloud Single Sign-On and On-Premise Identity Federation with SAP NetWeaver Cloud White Paper Cloud Single Sign-On and On-Premise Identity Federation with SAP NetWeaver Cloud White Paper TABLE OF CONTENTS INTRODUCTION... 3 Where we came from... 3 The User s Dilemma with the Cloud... 4 The Administrator

More information

Getting Started with Single Sign-On

Getting Started with Single Sign-On Getting Started with Single Sign-On I. Introduction NobleHour sets out to incentivize civic engagement by enabling users within companies, educational institutions, and organizations to conduct and coordinate

More information

esoc SSA DC-I Part 1 - Single Sign-On and Access Management ICD

esoc SSA DC-I Part 1 - Single Sign-On and Access Management ICD esoc European Space Operations Centre Robert-Bosch-Strasse 5 64293 Darmstadt Germany Tel: (49)615190-0 Fax: (49)615190485 www.esa.int SSA DC-I Part 1 - Single Sign-On and Access Management ICD Prepared

More information

Securing the Cloud through Comprehensive Identity Management Solution

Securing the Cloud through Comprehensive Identity Management Solution Securing the Cloud through Comprehensive Identity Management Solution Millie Mak Senior IT Specialist What is Cloud Computing? A user experience and a business model Cloud computing is an emerging style

More information

Flexible Identity Federation

Flexible Identity Federation Flexible Identity Federation Administration guide version 1.0.1 Publication history Date Description Revision 2015.09.24 initial release 1.0.0 2015.12.11 minor updates 1.0.1 Copyright Orange Business Services

More information

How To Manage A Plethora Of Identities In A Cloud System (Saas)

How To Manage A Plethora Of Identities In A Cloud System (Saas) TECHNICAL WHITE PAPER Intel Cloud SSO How Intel Cloud SSO Works Just as security professionals have done for ages, we must continue to evolve our processes, methods, and techniques in light of the opportunities

More information

TRUST AND IDENTITY EXCHANGE TALK

TRUST AND IDENTITY EXCHANGE TALK TRUST AND IDENTITY EXCHANGE TALK Ken Klingenstein, Internet2 2015 Internet2 Trust and Identity Why It Matters An Identity Layer for the Internet Benefits for the Rest of the Stack What It Is Technologies

More information

IAM, Enterprise Directories and Shibboleth (oh my!)

IAM, Enterprise Directories and Shibboleth (oh my!) IAM, Enterprise Directories and Shibboleth (oh my!) Gary Windham Senior Enterprise Systems Architect University Information Technology Services windhamg@email.arizona.edu What is IAM? Identity and Access

More information

Identity Implementation Guide

Identity Implementation Guide Identity Implementation Guide Version 37.0, Summer 16 @salesforcedocs Last updated: May 26, 2016 Copyright 2000 2016 salesforce.com, inc. All rights reserved. Salesforce is a registered trademark of salesforce.com,

More information

Best Practices for Libraries and Library Service Providers

Best Practices for Libraries and Library Service Providers Best Practices for Libraries and Library Service Providers These best practices were developed by the InCommon Library Consortium in 2009. The consortium was formed to explore various potential solutions.

More information

SharePoint Integration Framework Developers Cookbook

SharePoint Integration Framework Developers Cookbook Sitecore CMS 6.3 to 6.6 and SIP 3.2 SharePoint Integration Framework Developers Cookbook Rev: 2013-11-28 Sitecore CMS 6.3 to 6.6 and SIP 3.2 SharePoint Integration Framework Developers Cookbook A Guide

More information

Okta Identity Management for Portals Built on Salesforce.com. An Architecture Review. Okta Inc. 301 Brannan Street San Francisco, CA 94107

Okta Identity Management for Portals Built on Salesforce.com. An Architecture Review. Okta Inc. 301 Brannan Street San Francisco, CA 94107 Okta Identity Management for Portals Built on Salesforce.com An Architecture Review Okta Inc. 301 Brannan Street San Francisco, CA 94107 info@okta.com 1-888-722-7871 Contents 1 Okta: A Platform for Cloud

More information

To set up Egnyte so employees can log in using SSO, follow the steps below to configure VMware Horizon and Egnyte to work with each other.

To set up Egnyte so employees can log in using SSO, follow the steps below to configure VMware Horizon and Egnyte to work with each other. w w w. e g n y t e. c o m Egnyte Single Sign-On (SSO) Installation for VMware Horizon To set up Egnyte so employees can log in using SSO, follow the steps below to configure VMware Horizon and Egnyte to

More information

Configuring Single Sign-on from the VMware Identity Manager Service to WebEx

Configuring Single Sign-on from the VMware Identity Manager Service to WebEx Configuring Single Sign-on from the VMware Identity Manager Service to WebEx VMware Identity Manager SEPTEMBER 2015 V 2 Configuring Single Sign-On from VMware Identity Manager to WebEx Table of Contents

More information

Integrating Web Applications with Shibboleth

Integrating Web Applications with Shibboleth Integrating Web Applications with Shibboleth Application Authentication Done Right July 11, 2016 Eric Goodman, UCOP IAM Architect Jeffrey Crawford, UCSC Application Admin What is Shibboleth? Shibboleth

More information

Federated Identity for Cloud Computing and Cross-organization Collaboration

Federated Identity for Cloud Computing and Cross-organization Collaboration Federated Identity for Cloud Computing and Cross-organization Collaboration Steve Moitozo Strategy and Architecture SIL International 20110616.2 (ICCM) Follow me @SteveMoitozo2 2 Huge Claims You want federated

More information

Authentication Methods

Authentication Methods Authentication Methods Overview In addition to the OU Campus-managed authentication system, OU Campus supports LDAP, CAS, and Shibboleth authentication methods. LDAP users can be configured through the

More information

Integrating VMware Horizon Workspace and VMware Horizon View TECHNICAL WHITE PAPER

Integrating VMware Horizon Workspace and VMware Horizon View TECHNICAL WHITE PAPER Integrating VMware Horizon Workspace and VMware Horizon View TECHNICAL WHITE PAPER Table of Contents Introduction.... 3 Requirements.... 3 Horizon Workspace Components.... 3 SAML 2.0 Standard.... 3 Authentication

More information

Identity Access Management IAM 101. Mike Conlon Director of Data Infrastructure mconlon@ufl.edu

Identity Access Management IAM 101. Mike Conlon Director of Data Infrastructure mconlon@ufl.edu Identity Access Management IAM 101 Mike Conlon Director of Data Infrastructure mconlon@ufl.edu 1 Three Processes Identity Answers the question Who is in our environment? Authentication Answers the question

More information

T0 Federation Scaling through self service. September, Heath Marks, Manager AAF.

T0 Federation Scaling through self service. September, Heath Marks, Manager AAF. T0 Federation Scaling through self service September, Heath Marks, Manager AAF. Big responsibility, small footprint The value of the AAF is a shared service for Australian Research and Education We allow

More information

INCOMMON FEDERATION: PARTICIPANT OPERATIONAL PRACTICES

INCOMMON FEDERATION: PARTICIPANT OPERATIONAL PRACTICES INCOMMON FEDERATION: PARTICIPANT OPERATIONAL PRACTICES Participation in the InCommon Federation ( Federation ) enables a federation participating organization ("Participant") to use Shibboleth identity

More information

Qlik Sense Enabling the New Enterprise

Qlik Sense Enabling the New Enterprise Technical Brief Qlik Sense Enabling the New Enterprise Generations of Business Intelligence The evolution of the BI market can be described as a series of disruptions. Each change occurred when a technology

More information

SAML AS AN SSO STANDARD FOR CUSTOMER IDENTITY MANAGEMENT. How to Create a Frictionless, Secure Customer Identity Management Strategy

SAML AS AN SSO STANDARD FOR CUSTOMER IDENTITY MANAGEMENT. How to Create a Frictionless, Secure Customer Identity Management Strategy SAML AS AN SSO STANDARD FOR CUSTOMER IDENTITY MANAGEMENT How to Create a Frictionless, Secure Customer Identity Management Strategy PART 1: WHAT IS SAML? SAML in Context Security Assertion Markup Language

More information

managing SSO with shared credentials

managing SSO with shared credentials managing SSO with shared credentials Introduction to Single Sign On (SSO) All organizations, small and big alike, today have a bunch of applications that must be accessed by different employees throughout

More information

Federated Identity Management and Shibboleth. Noreen Hogan Asst. Director Enterprise Admin. Applications

Federated Identity Management and Shibboleth. Noreen Hogan Asst. Director Enterprise Admin. Applications Federated Identity Management and Shibboleth Noreen Hogan Asst. Director Enterprise Admin. Applications Federated Identity Management Management of digital identity/credentials (username/password) Access

More information

Administering Jive for Outlook

Administering Jive for Outlook Administering Jive for Outlook TOC 2 Contents Administering Jive for Outlook...3 System Requirements...3 Installing the Plugin... 3 Installing the Plugin... 3 Client Installation... 4 Resetting the Binaries...4

More information

File Share Navigator Online 1

File Share Navigator Online 1 File Share Navigator Online 1 User Guide Service Pack 3 Issued November 2015 Table of Contents What s New in this Guide... 4 About File Share Navigator Online... 5 Components of File Share Navigator Online...

More information

This research note is restricted to the personal use of christine_tolman@byu.edu

This research note is restricted to the personal use of christine_tolman@byu.edu Burton IT1 Research G00234483 Identity Management Published: 9 July 2012 Analyst(s): Ian Glazer, Bob Blakley Identity management (IdM) has become a distinct aggregation of functions for the maintenance

More information