Identity and Access Management Technical Oversight Committee



Similar documents
Identity and Access Management Technical Oversight Committee

Identity and Access Management PI-1 Demo. December 2, 2014 Tuesday 10:00 A.M. 6 Story Street

NCSU SSO. Case Study

UW System Identity & Access Management (IAM) Recommended Strategic Roadmap

Cloud & DevOps Program Big Group. March 13, 2015 Friday 2:00-3:00 p.m. Science Center Hall A

Getting Started with Clearlogin A Guide for Administrators V1.01

WHITEPAPER. 13 Questions You Must Ask When Integrating Office 365 With Active Directory

Identity and Access Management IAM Lifecycle Committee. October 1, 2014 Wednesday 11 a.m. 1 p.m. 6 Story Street

Hybrid Cloud Identity and Access Management Challenges

Microsoft Enterprise Mobility Suite

Documentation. CloudAnywhere. Page 1

Easy as 1-2-3: The Steps to XE. Mark Hoye Services Portfolio Consultant

Security Best Practices for Microsoft Azure Applications

System Administration Training Guide. S100 Installation and Site Management

Stephen Hess. Jim Livingston. Program Name. IAM Executive Sponsors. Identity & Access Management Program Charter Dated 3 Jun 15

SINGLE & SAME SIGN-ON ASPECTS

Centrify Cloud Connector Deployment Guide

Microsoft Azure Multi-Factor authentication. (Concept Overview Part 1)

Total Cost of Ownership Overview ADFS vs OneLogin WHITEPAPER

AVG Business Secure Sign On Active Directory Quick Start Guide

Enabling Single Sign-On for Oracle Applications Oracle Applications Users Group PAGE 1

Implementing Microsoft Azure Infrastructure Solutions

ABOUT TOOLS4EVER ABOUT DELOITTE RISK SERVICES

All your apps & data in the cloud, all in one place.

Google Identity Services for work

Integrating Single Sign-on Across the Cloud By David Strom

HOW MICROSOFT AZURE AD USERS CAN EMPLOY SSO

Three Ways to Integrate Active Directory with Your SaaS Applications OKTA WHITE PAPER. Okta Inc. 301 Brannan Street, Suite 300 San Francisco CA, 94107

Multi-Factor Authentication for your Analytics Implementation. Siamak Ziraknejad VP, Product Management

Course 20533: Implementing Microsoft Azure Infrastructure Solutions

RFP BOR-1511 Federated Identity Services - Response to Questions / Answers

Microsoft Power BI. Nov 21, 2015

Where in the Cloud are You? Session Thursday, March 5, 2015: 1:45 PM-2:45 PM Virginia (Sheraton Seattle)

Identity & Access Management The Cloud Perspective. Andrea Themistou 08 October 2015

HOTPin Integration Guide: Google Apps with Active Directory Federated Services

managing SSO with shared credentials

Microsoft Enterprise Mobility and Client Futures

Azure Active Directory

Multi-Factor Authentication Reference Guide

Multi-Factor Authentication Job Aide

Andrej Zdravkovic Regional Vice President, Platform Solutions Intellinet

White paper Contents

Implementing Microsoft Azure Infrastructure Solutions 20533B; 5 Days, Instructor-led

How To Manage A Plethora Of Identities In A Cloud System (Saas)

Course 20533B: Implementing Microsoft Azure Infrastructure Solutions

MY1LOGIN SOLUTION BRIEF: PROVISIONING. Automated Provisioning of Users Access to Apps

Multi-Factor Authentication, Assurance, and the Multi-Context Broker

Course Description. Course Audience. Course Outline. Course Page - Page 1 of 5. Microsoft Azure Fundamentals M Length: 2 days Price: $ 1,295.

Keyword: Cloud computing, service model, deployment model, network layer security.

Agenda. Federation using ADFS and Extensibility options. Office 365 Identity overview. Federation and Synchronization

Configuration Guide. BlackBerry Enterprise Service 12. Version 12.0

Introduction to Mobile Access Gateway Installation

i-mobile Multi-Factor Authentication

Project Charter IDENTITY AND ACCESS MANAGEMENT. Project Information. Project Overview. Project Purpose and Benefits to Campus. Project Scope Statement

What s New in Centrify Privilege Service Centrify Identity Platform 15.4

The Trusted Technology Partner in Business Innovation PASSION DISCIPLINE INNOVATION TEAMING INTEGRITY

Aurora Hosted Services Hosted AD, Identity Management & ADFS

External Authentication with Windows 2003 Server with Routing and Remote Access service Authenticating Users Using SecurAccess Server by SecurEnvoy

Active Directory Integration twitter.com/onelogin ONELOGIN WHITEPAPER

Web Admin Console - Release Management. Steve Parker Richard Lechner

User Management Tool 1.5

About Me. Software Architect with ShapeBlue Specialise in. 3 rd party integrations and features in CloudStack

Interact Intranet Version 7. Technical Requirements. August Interact

F-Secure Messaging Security Gateway. Deployment Guide

Network Security. Mike Trice, Network Engineer Richard Trice, Systems Specialist Alabama Supercomputer Authority

Agenda. Enterprise challenges. Hybrid identity. Mobile device management. Data protection. Offering details

Identity Federation: Bridging the Identity Gap. Michael Koyfman, Senior Global Security Solutions Architect

SaaS at Pfizer. Challenges, Solutions, Recommendations. Worldwide Business Technology

Configuration Guide BES12. Version 12.1

Employee Active Directory Self-Service Quick Setup Guide

Alex Wong Senior Manager - Product Management Bruce Ong Director - Product Management

Microsoft SharePoint Architectural Models

Integrating Active Directory Federation Services (ADFS) with Office 365 through IaaS

Sophos Mobile Control SaaS startup guide. Product version: 6

How To Use Salesforce Identity Features

Configuring -to-Feed in MangoApps

Cloud Security Through Threat Modeling. Robert M. Zigweid Director of Services for IOActive

Ensuring Enterprise Data Security with Secure Mobile File Sharing.

Folder Proxy + OWA + ECP/EAC Guide. Version 2.0 April 2016

Google Cloud Print Administrator Configuration Guide

Your Mission: Use F-Response Cloud Connector to access Google Apps for Business Drive Cloud Storage

Integrating Cisco ISE with GO!Enterprise MDM Quick Start

How to configure the TopCloudXL WHMCS plugin (version 2+) Update: Version: 2.2

Enterprise Mobility Services

Introduction to Directory Services

Introduction to the EIS Guide

INTEGRATE OFFICE 365 WITH ON-PREMISE ERP

BlackBerry Enterprise Service 10. Secure Work Space for ios and Android Version: Security Note

Federation At Fermilab. Al Lilianstrom National Laboratories Information Technology Summit May 2015

Increase the Security of Your Box Account With Single Sign-On

Transcription:

Identity and Access Management Technical Oversight Committee March 12, 2015 Thursday 1:00-2:00 p.m. 6 Story Conference Room

Agenda Meeting Purpose and Intended Outcomes Approval of Previous Minutes (5 min) Chair s Report & Executive Committee Summary (10 min) Shared Topics of Interest: MFA Update (5 min) Shared Topics of Interest: Login Name and SaaS (5 min) Shared Topics of Interest: PIN/CAS/IdP & Cloud HU-LDAP (20 min) General Discussion (15 min) 2

Meeting Purpose and Intended Outcomes Purpose Present the latest status of the IAM Program Plan Provide update on MFA vendor selection and implementation Discuss login name and SaaS Talk about PIN/CAS/IdP and cloud Harvard LDAP Intended Outcomes Bring everyone up to date on progress of IAM s MFA work Better knowledge of interaction between login name and SaaS applications Clarify relationship between PIN/CAS/IdP and the cloud Harvard LDAP 3

Approval of Previous Minutes February 5 Meeting PIN3 Decommissioning InCommon Bronze HarvardKey Multifactor Authentication Action Item: Distribute communications strategy Action Item: Investigate how third-party service providers work using nonharvard domains for login Action Item: Look into MFA vendor for federation in Schools 4

Previous Minutes: Action Items Distribute communications strategy (including for application owners and different business owners) Developing general steps to be used, but strategy will be tailored to each rollout population Starting outreach to all PIN app owners Town Hall meeting is in late March Think about how third-party service providers would work with using non-harvard domains for login, e.g. O365 Addressed as a discussion topic in today s meeting Look into MFA vendor ability to use federation in schools, so same app on phone does all Addressed as a discussion topic in today s meeting 5

Chair s Report: Executive Committee See the latest dashboard at iam.harvard.edu/executive-dashboard Program Status: Green Key points: Cloud Harvard LDAP deployed, Alumni API completed, HMS analysis continues, PI-2 demo March 10 6

Shared Topics: MFA Update MFA vendor selection criteria: Must be deployable in our own infrastructure Flexible provisioning and deprovisioning of users Integrates with multiple platforms especially the ones in which we are interested Why not use Google Authenticator? Can t be deployed in our own infrastructure Many campuses were burned by lost key and switched vendors ADFS support: We are considering two vendors for POC: Toopher supports ADFS Callsign is working on ADFS support MFA POC will be completed in PI-3 (June), and should be available in production in PI-4 (Fall). 7

Shared Topics: Login Name and SaaS Benefits of using an email address as the login name: Easy to remember it s your Harvard email address Provides a degree of personalization Common practice in many consumer applications today An overall improved experience, even considering challenges: Longer to type Not compatible with all systems, such as UNIX command-line Assumptions on user scoping may be made by some applications, such as Office 365 and Windows Azure Example of a HarvardKey login name: tim_gleason@harvard.edu tdg396 is the assigned UID alternative 8

Shared Topics: Login Name and SaaS HarvardKey support for external federation InCommon and other federations refer the user to the HarvardKey login page based on a user selection The Office 365 generic login screen attempts to determine the home authentication system by the email domain; domains are scoped to the Harvard authentication provider 9

Shared Topics: Login Name and SaaS HarvardKey support for external federation: HarvardKey login name with an @harvard and associated subdomains function as expected Without the domain selection option, non-harvard email domains in the HarvardKey are not valid in many SaaS applications: user@gmail.com cannot be made to resolve to Harvard An alternative Harvard-assigned address will be issued based on the unique UID value: abc1234@harvard.edu is an alternative address Ideally, a current Harvard user should be using a Harvard email address as his or her HarvardKey login name 10

Shared Topics: AuthN/CAS/IdP & HLDAP to Cloud Moving the new AuthN/CAS/IdP and HLDAP (consolidated LDAP for HarvardKey) to the cloud has a number of benefits: Improved availability #1: Active-active HA across two data centers #2: DR across regions Improved security Key management services Improved encryption of disks and configuration Additional best practices for storing passwords in LDAP Working with Security group for additional cloud firewalls and outgoing proxies for active monitoring for malicious traffic 11

High-Level System Context 12

AuthN/CAS/IdP System Context 13

AuthN/CAS/IdP Instance Setup 14

HLDAP System Context 15

HLDAP Master System Context 16

Across Region DR 17

Thank you!

Appendix A Technical Oversight Committee Members

Technical Oversight Committee Members Chair: Magnus Bjorkman, Director of IAM Engineering Name School/Group Indir Avdagic SEAS Carolyn Brzezinski SIS Steve Duncan Harvard Kennedy School David Faux HUIT Admin Tech/FAS & College Dan Fitzpatrick Partners Eileen Flood Campus Services Tim Gleason HUIT IAM/AD Sherif Hashem Harvard Law School Ken Ho GSE Yadhav Jayaraman Harvard Business School Name School/Group Tyson Kamikawa Harvard Medical School Colin Murtaugh HUIT Academic/TLT Micah Nelson HUIT Security Rich Ohlsten HUIT Admin Tech/Alumni Brian Pedranti HSPH Jonah Pollard Unified Communication/Cloud Sara Sclaroff HUIT Admin Tech/HR Randy Stern Library IT 20