Access By Federation for Client Collaboration INFO 1



Similar documents
SINGLE & SAME SIGN-ON ASPECTS

Security+ Guide to Network Security Fundamentals, Fourth Edition. Chapter 10 Authentication and Account Management

Active Directory Integration twitter.com/onelogin ONELOGIN WHITEPAPER

New Single Sign-on Options for IBM Lotus Notes & Domino IBM Corporation

Critical Issues with Lotus Notes and Domino 8.5 Password Authentication, Security and Management

Flexible Identity Federation

Mod 2: User Management

Web Applications Access Control Single Sign On

Cisco ASA Adaptive Security Appliance Single Sign-On: Solution Brief

Set up Outlook for your new student e mail with IMAP/POP3 settings

Working with Structured Data in Microsoft Office SharePoint Server 2007 (Part1): Configuring Single Sign On Service and Database

Briefcase for Android. Release Notes

SharePoint 2010 as an Extranet Platform

Active Directory Integration WHITEPAPER

SharePoint 2013 Logical Architecture

Leveraging SAML for Federated Single Sign-on:

OVERVIEW. DIGIPASS Authentication for Office 365

SharePoint 2010 as an Extranet Platform

Single Sign-on (SSO) technologies for the Domino Web Server

The Top 5 Federated Single Sign-On Scenarios

Microsoft.NET Passport, a solution of single sign on

Single Sign On. SSO & ID Management for Web and Mobile Applications

Single sign-on for ASP.Net and SharePoint

USER GUIDE. Lightweight Directory Access Protocol (LDAP) Schoolwires Centricity

Oracle Enterprise Single Sign-on Technical Guide An Oracle White Paper June 2009

Using Entrust certificates with VPN

Enterprise Knowledge Platform

1 Outlook Web Access. 1.1 Outlook Web Access (OWA) Foundation IT Written approximately Dec 2010

Security Overview Enterprise-Class Secure Mobile File Sharing

Resco Mobile CRM Security

Securing access to Citrix applications using Citrix Secure Gateway and SafeWord. PremierAccess. App Note. December 2001

Entrust Managed Services PKI. Getting an end-user Entrust certificate using Entrust Authority Administration Services. Document issue: 2.

IT Exam Training online / Bootcamp

WHITE PAPER Usher Mobile Identity Platform

Citrix (SSL) Access Gateway End User Documentation

How to Set-up Microsoft Outlook to Connect to your Arrowmail Exchange Mailbox

Safewhere*Identify 3.4. Release Notes

Single Sign-On Framework in Tizen Contributors: Alexander Kanavin, Jussi Laako, Jaska Uimonen

Salesforce1 Mobile Security Guide

December P Xerox App Studio 3.0 Information Assurance Disclosure

Collaborating with External Users

How To Send An Encrypted To The State From The Outside (Public)

SAML-Based SSO Solution

INTEGRATION GUIDE. DIGIPASS Authentication for Google Apps using IDENTIKEY Federation Server

University Computing & Telecommunications Virtual Private Networking: How To/Self- Help Guide Windows 8.1 Operating System.

How To Use Netscaler As An Afs Proxy

Multi Factor Authentication API

Quick Start Guide Migration Planner

NCSU SSO. Case Study

IMAP and SMTP Setup in Clients

Cloud-Accelerated Hybrid Scenarios with SharePoint and Office 365

Single Sign-on Frequently Asked Questions

Secure Your Enterprise with Usher Mobile Identity

Two SSO Architectures with a Single Set of Credentials

McAfee One Time Password

How to use Certificate in Outlook Express

Entrust IdentityGuard Comprehensive

TECHNOLOGY LEADER IN GLOBAL REAL-TIME TWO-FACTOR AUTHENTICATION

Protected Trust Directory Sync Guide

How to Secure a Groove Manager Web Site

EURECOM VPN SSL for students User s guide

Agenda. Federation using ADFS and Extensibility options. Office 365 Identity overview. Federation and Synchronization

YouServ: A Web Hosting and Content Sharing Tool for the Masses

White paper December Addressing single sign-on inside, outside, and between organizations

External Authentication with WebCT. What We ll Discuss

Hybrid Architecture. Office 365. On-premises Exchange org (Exchange 2007+) Provisioned via DirSync. Secure Mail flow

SharePoint List Synchronizer for Excel. Documentation

Three Ways to Integrate Active Directory with Your SaaS Applications OKTA WHITE PAPER. Okta Inc. 301 Brannan Street, Suite 300 San Francisco CA, 94107

SHAREPOINT CLOUD SOLUTIONS COMPARISON. A Technical Comparison of SharePoint Cloud Approaches

kalmstrom.com Business Solutions

Increase the Security of Your Box Account With Single Sign-On

Configuration Guide - OneDesk to SalesForce Connector

HOTPin Integration Guide: Microsoft Office 365 with Active Directory Federated Services

Mod 3: Office 365 DirSync, Single Sign-On & ADFS

Millbeck Communications. Secure Remote Access Service. Internet VPN Access to N3. VPN Client Set Up Guide Version 6.0

Install and Configure SQL Server Database Software Interview Questions and Answers

Security Assertion Markup Language (SAML) Site Manager Setup

CHARTER BUSINESS custom hosting faqs 2010 INTERNET. Q. How do I access my ? Q. How do I change or reset a password for an account?

Migrating Exchange Server to Office 365

Entrust Managed Services PKI Administrator Guide

Microsoft Outlook 2013

Federation At Fermilab. Al Lilianstrom National Laboratories Information Technology Summit May 2015

Understanding VPN Technology Choices

CA Performance Center

Calendar Synchronization in OpenEMR. Business Need. Solution

White paper Contents

Authentication Integration

How To Use Kiteworks On A Microsoft Webmail Account On A Pc Or Macbook Or Ipad (For A Webmail Password) On A Webcomposer (For An Ipad) On An Ipa Or Ipa (For

What s New in Juniper s SSL VPN Version 6.0

Quick Start and Trial Guide (Mail) Version 3 For ios Devices

Sign in to view your Office 365 encrypted message

Tenrox. Single Sign-On (SSO) Setup Guide. January, Tenrox. All rights reserved.

Pick Your Identity Bridge

Transcription:

Access By Federation for Client Collaboration INFO 1

Introduction Holly Hanna, Microsoft Legal & Corporate Affairs hollyhan@microsoft.com @hollyhanna (Twitter) Karen Allen, Morgan Lewis & Bockius kallen@morganlewis.com

Authentication Issues Fundamental Questions Authentication: Who are you? Authorization: Are you allowed to do this? AD Accounts secure but a management nightmare Forms-based easier to implement, but less secure

Microsoft Yesterday: Two Options, Neither Good

Option 1: Extranet Requires user to be set up in PARTNER domain Passwords need to be updated every 70 days Environment running on SharePoint 2007 no way to collaborate in real time Management a constant headache for both administrator and user

Option 2: CorpNet Account 2+ week process for getting users set up in the system To remotely access the corporate network, external users must be approved for a smart card, requiring director-level approval Once remote access is approved, user must either visit a Microsoft location or send in picture and get a card mailed Once the user has access, they have access to the entire Microsoft corporate network not just the matter they are working on

MorganLewis Extranet Requires user to be set up in AD domain Used to limit access to sites and externally exposed applications Passwords complex, need to be updated every 90 days Environment running on SharePoint 2007 no way to collaborate in real time Management a constant for both administrator and user Dedicated support team for password resets and other access issues

Circumventing the System

IT Goal: Make It Easy When forced to choose between the right way to do something and the expedient way to do something, expedience wins every time Understand your security tradeoffs and undertake a solid risk analysis

Claims Authentication Fundamentals

Secure Authentication Options Claims-based = Authoritative Identity Source Microsoft Account ADFS OAuth

Microsoft Today: External Collaboration Made Easy External users need a Microsoft Account (formerly Live ID or Passport), which can be easily created by the end user and associated with their email address Site owner sends an invitation from O365 site to the associated email address

What s a Microsoft Account? Single sign-on web service formerly known as Passport and Windows Live ID Available to anyone with an email address; automatic with a Hotmail.com or outlook.com address User is authenticated via SSL connection; if the user opts to have a site remember them, an encrypted timelimited cookie is stored on their computer and attached to a triple DES encrypted ID tag ID is sent to the web site, which then plants another time-limited HTTP cookie on the user s computer.

O365 External Collaboration

Securing O365 Collaboration Invitation is tokenized; cannot be forwarded or used by anyone who is not the intended recipient Link expires after one week for external users Only internal users can be owners and send invitations While individual items can be shared with non-site users by external users, site sharing is restricted to owners External users have access only to the sites they ve been invited to and nothing else

Yammer External Collaboration

Single Sign-On via ADFS Client Request for single sign-on to SharePoint extranet site Client s AD configured as Claims Provider Configured SharePoint to trust the claims coming from ADFS for authentication Management Defined groups and roles within SharePoint to match the client s AD group name Linked the groups to Policies in SharePoint Group Membership in AD is managed in the client s AD Allows the client to add users as necessary

ADFS Architecture Simple View

ADFS Architecture Detail View

Application Configuration Extend Webapp to SSL site (extranet zone) Requires Federation Extensions for SharePoint Add external groups as Roles via WebApp policy

Microsoft Account Pros & Cons Advantages Makes it easy for attorneys to collaborate in real time with outside counsel Available for any device, anywhere; offline sync to local machine With Windows 8, user is already signed in; when accessing a collaboration site, pass-thru of credentials is seamless Disadvantages If user s Microsoft account is compromised, shared documents could be at risk No IT control over who has access to what data

ADFS Pros & Cons Advantages Shifts burden of authenticating users to the identity provider Vendor neutral SAML-based token Seamless for end users Disadvantages More complex configuration Support issues for end-users Troubleshooting on both sides

Coming Attractions Open Authentication Industry Standard Protocol Used by Citrix FileStream, Box.com, Windows Live, and others

Further Reading Claims-Based Identity Term Definitions http://msdn.microsoft.com/en-us/library/ee534975.aspx Open Authentication (OAuth) Overview http://en.wikipedia.org/wiki/oauth Microsoft Account https://signup.live.com ADFS Concepts http://technet.microsoft.com/enus/library/cc776617(v=ws.10).aspx