AuthXAccess Administration User Interface

Similar documents
TIBCO Spotfire Platform IT Brief

Active Directory Integration twitter.com/onelogin ONELOGIN WHITEPAPER

Okta/Dropbox Active Directory Integration Guide

Authentication Integration

Directory Integration with Okta. An Architectural Overview. Okta Inc. 301 Brannan Street San Francisco, CA

Integrating Hitachi ID Suite with WebSSO Systems

The Primer: Nuts and Bolts of Federated Identity Management

EXTENDING SINGLE SIGN-ON TO AMAZON WEB SERVICES

The Primer: Nuts and Bolts of Federated Identity Management

NCSU SSO. Case Study

Web Applications Access Control Single Sign On

Directory Integration with Okta. An Architectural Overview. Okta White paper. Okta Inc. 301 Brannan Street, Suite 300 San Francisco CA, 94107

Configuring and Troubleshooting Internet Information Services in Windows Server 2008

The Top 5 Federated Single Sign-On Scenarios

Active Directory Integration WHITEPAPER

Open Directory. Apple s standards-based directory and network authentication services architecture. Features

Password Reset PRO INSTALLATION GUIDE

Course 50382A: Implementing Forefront Identity Manager 2010 OVERVIEW

Oracle Enterprise Single Sign-on Technical Guide An Oracle White Paper June 2009

Product overview. CA SiteMinder lets you manage and deploy secure web applications to: Increase new business opportunities

Course Syllabus. Configuring and Troubleshooting Internet Information Services in Windows Server Key Data. Audience. At Course Completion

etoken TMS (Token Management System) Frequently Asked Questions

IBM Tivoli Identity Manager

MS Managing and Maintaining Windows 8

WHMCS LUXCLOUD MODULE

How To Use Saml 2.0 Single Sign On With Qualysguard

Safewhere*Identify 3.4. Release Notes

SAML SSO Configuration

ADFS for. LogMeIn and join.me authentication

Managing Your Microsoft Windows Server Fleet with AWS Directory Service. May 2015

Brivo Directory Agent. User Guide

Google Identity Services for work

A Technical White Paper

Understanding Enterprise Cloud Governance

GFI White Paper PCI-DSS compliance and GFI Software products

Symantec Managed PKI Service Deployment Options

Oracle Identity Management for SAP in Heterogeneous IT Environments. An Oracle White Paper January 2007

NetworkingPS Federated Identity Solution Solutions Overview

Designing IT Platform Collaborative Applications with Microsoft SharePoint 2003 Workshop

Entrust Secure Web Portal Solution. Livio Merlo Security Consultant September 25th, 2003

Critical Issues with Lotus Notes and Domino 8.5 Password Authentication, Security and Management

End-to-End Identity Management With Oblix and Microsoft WHITEPAPER

SharePoint User Management

Total Cost of Ownership Overview ADFS vs OneLogin WHITEPAPER

Oracle Access Manager. An Oracle White Paper

ZervicePoint Provides Automated, End-to-End Provisioning of Accounts, Services, and Material

ITAR Compliant Data Exchange

SAML-Based SSO Solution

Configuring and Troubleshooting Windows Server 2008 Active Directory Domain Services

Introduction to Directory Services

Automating User Management and Single Sign-on for Salesforce.com OKTA WHITE PAPER. Okta Inc nd Street Suite 350 San Francisco CA, 94107

Introduction to SAML

Locking down a Hitachi ID Suite server

Perceptive Experience Single Sign-On Solutions

Security Overview Enterprise-Class Secure Mobile File Sharing

Add Microsoft Azure as the Federated Authenticator in WSO2 Identity Server

Password Reset Server Installation Guide Windows 8 / 8.1 Windows Server 2012 / R2

Course: 10174B: Configuring and Administering Microsoft SharePoint 2010

LifeSize Control Installation Guide

Choosing an SSO Solution Ten Smart Questions

INTEGRATION GUIDE. IDENTIKEY Federation Server for Juniper SSL-VPN

A brief on Two-Factor Authentication

Hybrid for SharePoint Server Search Reference Architecture

User Management Tool 1.5

Installing, Configuring, and Managing a Microsoft Active Directory

Configuring and Troubleshooting Windows Server 2008 Active Directory Domain MOC 6425

CL_50382 Implementing Forefront Identity Manager 2010

Enterprise Vault.cloud Deployment Checklist

USING FEDERATED AUTHENTICATION WITH M-FILES

Secure, Centralized, Simple

Federated Directory Services

HOTPin Integration Guide: Microsoft Office 365 with Active Directory Federated Services

White Paper. BD Assurity Linc Software Security. Overview

Extranet Access Management Web Access Control for New Business Services

Global Headquarters: 5 Speen Street Framingham, MA USA P F

4cast Server Specification and Installation

Bill Fiddes Learning and Development Specialist Rob Latino Program Manager in Office 365 Support

Identity and Access Management Integration with PowerBroker. Providing Complete Visibility and Auditing of Identities

Integration Guide. SafeNet Authentication Service. Using SAS as an Identity Provider for Tableau Server

Active Directory Provider User s Guide

Symantec Enterprise Security Manager Baseline Policy Manual for CIS Benchmark. For Windows Server 2008 (Domain Member Servers and Domain Controllers)

activecho Driving Secure Enterprise File Sharing and Syncing

Building Secure Applications. James Tedrick

DocuSign Single Sign On Implementation Guide Published: March 17, 2016

iphone in Business How-To Setup Guide for Users

CONFIGURING MICONTACT CENTER ACTIVE DIRECTORY SYNCHRONIZATION AND WINDOWS AUTHENTICATION

Defender Token Deployment System Quick Start Guide

Password Management Buyer s Guide. FastPass Password Manager V 3.3 Enterprise & Service Provider Editions

SharePoint 2010 Intranet Case Study. Presented by Peter Carson President, Envision IT

Top Eight Identity & Access Management Challenges with SaaS Applications. Okta White Paper

Table of Contents. Introduction. Audience. At Course Completion

Using Entrust certificates with VPN

Session 17 Windows 7 Professional DNS & Active Directory(Part 2)

Secure network guest access with the Avaya Identity Engines portfolio

MS-6425C - Configuring Windows Server 2008 Active Directory Domain Services

Microsoft Enterprise Mobility Suite

SECURITY AND REGULATORY COMPLIANCE OVERVIEW

Hardening Security in ASP.NET Applications & Services. Rick G. Garibay

Transcription:

Market Situation Laboratory directors have a critical need to provide agency wide access to their extranet applications. As these applications are served up to geographically dispersed users, the burden of managing multiple usernames and passwords becomes an ever-increasing operational expense. Additionally, the breach of just one password can expose critical information and compromise organizational security. The shortage of IT personnel to manage the growing number of access credentials combined with the high cost of legacy identity management solutions also compounds the problem. Solution AuthXAccess was architected to make identity management deployment easy. The solution delivers secure extranet access by equipping customers with the ability to manage credentials for their own users. The module provides a centralized system for secure account management and eliminates the need for custom software for each external customer connection. A single AuthXAccess module can support enterprise wide connections so external users are provided with the powerful capabilities to access a laboratory s resources, securely, over the Internet. Key features include: Administrative console that correctly configures external partner connections without requiring IT staff to have extensive knowledge of identity federation standards (ie: SAML 1.0, SAML 1.1, SAML 2.0, WS-Federation) Out-of-the-box integration provides easy integration, tying into existing identity infrastructure, as well as linking into target application environments Automatically creates trusted connections when users from external agencies request site access, eliminating the need to manually configure each partner connection AuthXAccess Administration User Interface AuthXAccess Module Description 1 1/27/2009

Implementation The implementation of legacy identity management systems typically requires six to nine months or more. AuthXAccess provides access, security, and control, rapidly, in just weeks. Through standardsbased identity management, AuthXAccess distributes user account creation and password management tasks to those who are the best source of that information the users. AuthXAccess and Forensic Advantage TM Forensic laboratories process evidence examination requests from a number of external agencies. When one of these agencies requires lab services, they record the specifics of the case, a description of evidence submitted, and enter requests for forensic examination services. This data is entered into a multi-part, paper form presented to the lab with the evidence at the time of submission. Clerical operations at the laboratory transcribe this information from the paper forms into their LIMS. Additional activities such as clerical operations that respond to requests for examination status and disseminate the resulting laboratory reports throughout the organization also occur. Forensic Advantage TM combined with browser-based module, AuthXAccess permits the external agency to easily manage users, enter evidence descriptions, request laboratory examinations, obtain examination status and access laboratory reports, all electronically, in one seamless solution. AuthXAccess functionality for authorized administrators at a laboratory Create, read, update, deactivate an agency and agency-related information Import agencies and agency-related information from a Microsoft Excel spreadsheet Create, read, update, deactivate a credential Import identities associated with an agency from a Microsoft Excel spreadsheet Delegate identity administration to an authorized administrator at an agency Search for an identity within an agency or across all agencies AuthXAccess functionality for authorized agency issuers (delegated administrators) at a requesting agency Read and update agency information (name, address, email, phone, fax) List information for identities associated with the agency Create, read, update, deactivate an identity s credentials Reset an identity s password Suspend / Reinstate an identity Unblock an identity s credentials (after failed login attempts, restore access without password reset) Security Benefits Security is an imperative to protect the enterprise, its users and service providers. AuthXAccess assists organizations extend their security policy to incorporate inbound and outbound single sign on while the risk of password sharing and impersonation of usernames by: Utilizing mature peer-reviewed standards such as SAML Proactively going beyond the standards to address common loopholes associated with underlying technologies AuthXAccess Module Description 2 1/27/2009

Decentralizing management and monitoring of security credentials and identity traffic AuthXAccess Interrelationship with the Forensic Advantage Platform Forensic Advantage Extranet (IIS) FAReader / FAOrganizationReader Forensic Advantage Intranet FA Client FA Web Login SAML token FA Extranet SDDS AuthX Management Module (IIS) AuthX Login SSL message Security AuthenticateUser Admin / Delegate SAML token Message Encryption User maintenance IPSec transport AuthX Mgmt AuthX Access Token Service AuthX Identity Store FA Application Services FA Identity Sync Adapter FA Agency / Officer data Agency maintenance ASP.NET Membership Services AuthXAccess implements an ASP.NET Membership Services provider to permit easy integration with ASP.NET Forms Authentication. ASP.NET provides a built-in method to validate and access user credentials. AuthXAccess leverages and extends ASP.NET membership capabilities to help manage user authentication within web sites. AuthXAccess membership capabilities can be used with ASP.NET Forms authentication or with the ASP.NET login controls to create a complete system for authenticating users. The module also provides the following capabilities: Creates new credentials and passwords Implements a custom provider that delivers a robust system whereby a limited scope of credential management functions may be delegated Stores membership information (identity names, passwords and authorization data) in Microsoft SQL Server, Microsoft Active Directory, or an alternative data store Authenticates users programmatically, or use ASP.NET login controls to create a complete authentication system that requires minimal custom coding Manage passwords (ie: creating, changing, and resetting). Application extensions provide an automated password-reset system that accepts a user-supplied question and response Usage policies provide for activation and suspension of credentials based on a time span from initial credential issuance and latest use Provides a unique identification for authenticated user identities for use within applications and integrates with ASP.NET s personalization and role-management (authorization) systems Credential and membership data may be maintained in a custom data store, accessed using a documented provider model AuthXAccess Module Description 3 1/27/2009

Documented web service interface provides bi-directional identity and organization synchronization with one or more external systems Services Services and support for each step of the AuthXAccess identity management deployment process is packaged to enable enterprise level organizations achieve operational status within thirty days or less and turn around subsequent connections in less than a week. Laboratories that take advantage of AuthXAccess combined with these turnkey services can achieve lower operational costs, increased enterprise security and efficient operations, quickly and easily. Key solution and service benefits include: Decreased configuration time of agency connections Simplified management for all inbound and internal access Improved security of resources accessed over the Internet AuthXAccess User Operation Screen About Forensic Advantage TM Systems Forensic Advantage TM Systems, a division of The Computer Solution Company, is a Microsoft Gold Certified Partner and leader in Forensic Laboratory Information Management Systems (LIMS). Delivering technology solutions to the criminal justice marketplace since 2002, Forensic Advantage TM Systems enjoys a growing install-base among forensic and medical examiner laboratories. The Forensic Advantage TM technology platform addresses the unique requirements of laboratories that recognize the benefits of conducting their case management and analysis activities electronically. The Forensic Advantage TM Suite includes Breath Alcohol, DNA/CODIS and LIMS solutions that leverage the Microsoft Office platform. The application suite improves individual productivity by enabling examiners to focus on delivering timely, accurate results. AuthXAccess Module Description 4 1/27/2009

Forensic Advantage TM Systems 1525 Huguenot Road Midlothian, Virginia 23113 Phone: (800) 662-0976 Fax: (804) 794-6194 To learn more about Forensic Advantage TM visit us at www.forensicadvantagesystems.com AuthXAccess Module Description 5 1/27/2009