Extending Identity and Access Management Michael Quirin Sales Engineer Citrix Systems 1 2006 Citrix Systems, Inc. All rights reserved.
Company Overview Leader in Access Infrastructure NASDAQ 100 and S&P 500 company (CTXS) $909 million in 2005 revenue (25% growth) ~50% revenue from outside of No. America 3,000+ employees in 35 countries 6,200 partners in over 100 countries 180,000 customers 94% customer loyalty 75% of all Internet users Microsoft Global ISV of the Year 2003 and 2005 2 2006 Citrix Systems, Inc. All rights reserved.
Identity Management - Defined Solutions used to identify users in a system (employees, customers, contractors, etc.) and control user access to resources. IDC Identity & Access Management is becoming the glue that ties together all the internal and external elements in an application ecosystem. Brian Burke, IDC 3 2006 Citrix Systems, Inc. All rights reserved.
Hype Cycle for Identity and Access Management Technologies, 2006 4 2006 Citrix Systems, Inc. All rights reserved.
Citrix View on IAM User Identification Who is the user? Do we trust them? Provisioning What accounts should the user have? Authentication Is the user who they say they are? Access Control What permissions should the user have? Access Method How is the user gaining access? Auditing What has this user previously accessed? 5 2006 Citrix Systems, Inc. All rights reserved.
Managing Identities and the Front Door Single Sign-On to Windows, Web and host-based applications Access to Any Application One Primary Logon Windows Enterprise SSO Solution Web Distinct credentials for each backend application/resource Host 6 2006 Citrix Systems, Inc. All rights reserved.
Providing Self-Service Each time an end-user calls the help desk, it costs the organization $25-$50. Forrester 30 percent of all calls to the help desk are for password resets Gartner Group 7 2006 Citrix Systems, Inc. All rights reserved.
User Access Speed and Productivity Hot Desktop Speed and Security for Shared Workstations 90% faster than standard desktop logons SmoothRoaming optimized Built in workstation security Eliminates workstation lockouts User switches audited Integrates with Biometric, Smartcard and Proximity aauthentication solutions 8 2006 Citrix Systems, Inc. All rights reserved.
Password Management Survey Who has more than 5 user accounts to manage for application access? Who uses the same password (or 2) for all their accounts? Who uses sticky notes or a spreadsheet to manage accounts? Who changes their password by incrementing a number? Who never changes their password on applications? 9 2006 Citrix Systems, Inc. All rights reserved.
Changing the Locks Regulatory Compliance Driven SOX, GLBA, HIPAA Automated Password Generation Complex Password Policies Password Expiry Management Timer controls Audit Trails Proof just in case 10 2006 Citrix Systems, Inc. All rights reserved.
Simplifying 2-Factor Authentication With a skeleton key, the front door must be stronger! Direct integration for network login and SSO application credentials Eliminates need for application integration with 2-factor authentication Where costs range from $500 to $4,000 for investigation, development, and testing per application* Mix and match form factors for the right access scenario * Reference: Forrester - Justifying E-SSO: Benefits Beyond The Help Desk 11 2006 Citrix Systems, Inc. All rights reserved.
Integration with User Provisioning Citrix Password Manager provides a standards-based (SPML v2) interface to user provisioning systems Available connectors: Courion AccountCourier and PasswordCourier HP Select Identity IBM Tivoli Identity Manager As user accounts are provisioned, credentials are automatically encrypted and stored in Password Manager User Provisioning System App #1 App #2 App #3 Active Directory (or LDAP) End User (Single sign-on) 12 2006 Citrix Systems, Inc. All rights reserved.
Citrix Password Manager for Authentication, Auditing, Provisioning Challenge Decrease support calls and lower helpdesk costs User Access Speed and Productivity Achieve regulatory compliance Automate employee life cycle Solution SSO decreases forgotten passwords Self-service password reset decreases support calls Increase speed to access applications Hot Desktop for shared workstations Automated password changes Password expiry protects applications Enforces termination procedures Logs all logon and password events Account Provisioning Integration One-click user de-provisioning 13 2006 Citrix Systems, Inc. All rights reserved.
Seamless SmartAccess example Office Kiosk Hotel In Transit In Transit Full Access, all applications and features Browser based email only No print or local save Full native email including sync No access to financial documents 14 2006 Citrix Systems, Inc. All rights reserved.
Action Control Advanced Endpoint Sensing Granular Access Rights Action Control Which User + User Scenario View Only Edit Print Save 15 2006 Citrix Systems, Inc. All rights reserved.
Citrix Access Gateway for Access Control and Presentation Challenge Decrease remote access support costs Protect customer data (e.g. Healthcare) Protect proprietary data (e.g. Patents) Decrease access vulnerabilities Solution Simple mgmt./administration Clientless access option Advanced Access Control auto-changes access/viewing privileges by user, location, device, and connection Action Rights Control auto-changes data manipulation privileges by user, location, device, and connection End-point scanning prevents unsafe network and information access 16 2006 Citrix Systems, Inc. All rights reserved.
Before you leave, let s recap IAM User Identification Who is the user? Do we trust them? Provisioning What accounts should the user have? Authentication Is the user who they say they are? Access Control What permissions should the user have? Access Method How is the user gaining access? Auditing What has this user previously accessed? 17 2006 Citrix Systems, Inc. All rights reserved.
Demo Presentation Server 4.0 Application Virtualization Smooth Roaming Web Interface 4.2 Simple Web Access Password Manager 4.1 Password Management Enterprise Single Sign On Advanced Access Control 4.2 Smart Access Central Landing Page for Application and File Resources 18 2006 Citrix Systems, Inc. All rights reserved.