NCSU SSO. Case Study



Similar documents
Directory Integration with Okta. An Architectural Overview. Okta Inc. 301 Brannan Street San Francisco, CA

Directory Integration with Okta. An Architectural Overview. Okta White paper. Okta Inc. 301 Brannan Street, Suite 300 San Francisco CA, 94107

Google Identity Services for work

Three Ways to Integrate Active Directory with Your SaaS Applications OKTA WHITE PAPER. Okta Inc. 301 Brannan Street, Suite 300 San Francisco CA, 94107

Top 8 Identity and Access Management Challenges with Your SaaS Applications. Okta White paper

Flexible Identity Federation

White paper Contents

How To Manage A Plethora Of Identities In A Cloud System (Saas)

The increasing popularity of mobile devices is rapidly changing how and where we

Increase the Security of Your Box Account With Single Sign-On

Automating User Management and Single Sign-on for Salesforce.com OKTA WHITE PAPER. Okta Inc nd Street Suite 350 San Francisco CA, 94107

The Top 5 Federated Single Sign-On Scenarios

SAML SSO Configuration

Ensuring Enterprise Data Security with Secure Mobile File Sharing.

Alex Wong Senior Manager - Product Management Bruce Ong Director - Product Management

Top 8 Identity and Access Management Challenges with Your SaaS Applications. Okta Inc. 301 Brannan Street San Francisco, CA 94107

How To Make Your Computer System More Secure And Secure

Security Overview Enterprise-Class Secure Mobile File Sharing

Okta/Dropbox Active Directory Integration Guide

FileCloud Security FAQ

An Overview of Samsung KNOX Active Directory-based Single Sign-On

Active Directory Integration twitter.com/onelogin ONELOGIN WHITEPAPER

PortWise Access Management Suite

Google Apps Deployment Guide

STRONGER AUTHENTICATION for CA SiteMinder

When enterprise mobility strategies are discussed, security is usually one of the first topics

Secure WiFi Access in Schools and Educational Institutions. WPA2 / 802.1X and Captive Portal based Access Security

Frequently asked questions

How to Overcome Challenges in Deploying Cloud Apps to Get the Most from your IAM Investment

Enterprise Mobility Suite (EMS) Sean Lewis Principal Partner Technology Strategist

The Challenges of Managing Multiple Cloud Identities and Enterprise Identity by BlackBerry

API-Security Gateway Dirk Krafzig

Avoid the Hidden Costs of AD FS with Okta

What Are The Choices And Tradeoffs?

Dell World Software User Forum 2013

Active Directory Integration WHITEPAPER

The Cloud, Mobile and BYOD Security Opportunity with SurePassID

Entrust Secure Web Portal Solution. Livio Merlo Security Consultant September 25th, 2003

Apps. Devices. Users. Data. Deploying and managing applications across platforms is difficult.

How to Provide Secure Single Sign-On and Identity-Based Access Control for Cloud Applications

expanding web single sign-on to cloud and mobile environments agility made possible

Top. Reasons Federal Government Agencies Select kiteworks by Accellion

Egnyte Cloud File Server. White Paper

Overview of Microsoft Enterprise Mobility Suite (EMS) Cloud University

INTEGRATION GUIDE. DIGIPASS Authentication for Google Apps using IDENTIKEY Federation Server

Stop Password Sprawl with SaaS Single Sign-On via Active Directory

PortWise Access Management Suite

How To Use Salesforce Identity Features

Mobile device and application management. Speaker Name Date

Introduction to Identity and Access Management for the engineers. Radovan Semančík April 2014

People-Focused Access Management. Software Consulting Support Services

Top Eight Identity & Access Management Challenges with SaaS Applications. Okta White Paper

WHITEPAPER. NAPPS: A Game-Changer for Mobile Single Sign-On (SSO)

Getting Started with Clearlogin A Guide for Administrators V1.01

Centrify Cloud Connector Deployment Guide

Federated single sign-on (SSO) and identity management. Secure mobile access. Social identity integration. Automated user provisioning.

nexus Hybrid Access Gateway

Speeding Office 365 Implementation Using Identity-as-a-Service

OPENIAM ACCESS MANAGER. Web Access Management made Easy

Adding Stronger Authentication to your Portal and Cloud Apps

White Paper. Anywhere, Any Device File Access with IT in Control. Enterprise File Serving 2.0

owncloud Architecture Overview

An Overview of Samsung KNOX Active Directory and Group Policy Features

USER GUIDE. Lightweight Directory Access Protocol (LDAP) Schoolwires Centricity

Lenovo Secure Cloud Access Access your files, applications and reports from any device.

USING FEDERATED AUTHENTICATION WITH M-FILES

HOTPin Integration Guide: Google Apps with Active Directory Federated Services

RFP BOR-1511 Federated Identity Services - Response to Questions / Answers

Workday Mobile Security FAQ

SAP HANA Cloud Portal Overview and Scenarios

The Essential Security Checklist. for Enterprise Endpoint Backup

Identity & Access Management in the Cloud: Fewer passwords, more productivity

Mobile Security. Policies, Standards, Frameworks, Guidelines

Agenda. How to configure

Introduction and overview view of Citrix ShareFile provisioning. Preparing your Citrix ShareFile account for provisioning

Central Desktop Enterprise Edition (Security Pack)

Authentication Integration

WHITEPAPER SECUREAUTH AND CAC HSPD-12 AUTHENTICATION TO WEB, NETWORK, AND CLOUD RESOURCES

Single Sign On. SSO & ID Management for Web and Mobile Applications

Where are Organizations Today? The Cloud. The Current and Future State of IT When, Where, and How To Leverage the Cloud. The Cloud and the Players

Mobility, Security and Trusted Identities: It s Right In The Palm of Your Hands. Ian Wills Country Manager, Entrust Datacard

Addressing the BYOD Challenge with Okta Mobility Management. Okta Inc. 301 Brannan Street San Francisco, CA

Google Apps. Google Apps. On Steroids. Extend Google Apps to your directory services. Extend Google Apps to your directory services

Identity and Access Management (IAM) Across Cloud and On-premise Environments: Best Practices for Maintaining Security and Control

Enterprise Mobility Services

EOH Cloud Mobile Device Management. EOH Cloud Services - EOH Cloud Mobile Device Management

Top. Enterprise Reasons to Select kiteworks by Accellion

OVERVIEW. DIGIPASS Authentication for Office 365

SECURITY AND REGULATORY COMPLIANCE OVERVIEW

Mod 2: User Management

E l i m i n a t i n g Au t hentication Silos and Passw or d F a t i g u e w i t h Federated Identity a n d Ac c e s s

The Who, What, When, Where and Why of IAM Bob Bentley

EXTENDING SINGLE SIGN-ON TO AMAZON WEB SERVICES

Canadian Access Federation: Trust Assertion Document (TAD)

SAML-Based SSO Solution

Stoneware Inc. webnetwork Whitepaper. Stoneware, Inc. Date: November 2010 Related Product: webnetwork

JumpCloud is your Directory-as-a-Service. A fully managed directory to rule your infrastructure whether on-premise or in the cloud.

Leveraging SAML for Federated Single Sign-on:

seamless simplicity to simple identity management in education.

2003, Rainbow Technologies, Inc.

Transcription:

NCSU SSO Case Study 2 2

NCSU Project Requirements and Goals NCSU Operating Environment Provide support for a number Apps and Programs Different vendors have their authentication databases End users must remember 15 different credentials of different types; e.g., user name and password multi-factor authentication PIN numbers Number of apps in use is increasing at the rate of about 100 year 3

NCSU Project Requirements and Goals NCSU Goals for SSO Requires only one login per user to access all programs and applications Is easy enough for children as young as 6 years old to use Integrates with on-premisis active directory and supports parents or other outside users independent of Active Directory simultaneously Allows users to change passwords Can interface, at a minimum, with the following programs Can possibly interface with these other programs and applications OPALS, Destiny and Others Easy to implement user friendly interface for admin support 4

NCSU Project Requirements and Goals System will use minimal amount of Personal Identifiable Information (PII) Mandatory - End user first name and last name and email address Discretionary - alternate email address, phone number at user Ultimate control of user identity remains with our organization Work within budget constraints Identity Management Integrated into SSO backend Local control over information provided No unrestricted access to Student Data Avoid solutions that were too restrictive; e.g., locked into a corporate Silos Authentication strategies Goal of no additional username or password required SAML OAuth Domain Federation Account auto provisioning Leverage corporate SSO strategies 5

Key Challenges 1 2 3 SHIFT FROM ON-PREMISE TO CLOUD EXPLOSIVE GROWTH IN APPLICATIONS NEW DEVICES: ANYTIME, ANYWHERE ACCESS 4 5 6 DECENTRALIZE ADMINISTRATION DELIVER SECURE & CONVENIENT ACCESS SUPPORT NATIVE, BROWSER AND MOBILE 6 6

Pain for IT Time consuming user Provisioning 7 7

Pain for End Users Pain for End Users 8 8

Identacor @ NCSU 25 application integrations 3025 users across 8 districts and 14 schools 9 9

Mobile Workers Parents and Outsisde Users Firewall + 10 Active Directory Students and Faculty

Identacor - Connecting NCSUVT to Apps SSO Any Device, Any App Provisioning and Deprovisioning Workflow, Audit, Self Service Robust On Prem Integration Directories, Identity Management, Apps Centralized Admin & Reporting Policy, Compliance, Analytics 11

Identacor Connecting NCSUVT to Apps Firewall Internet NCSU Network Identacor Windows Authentication Agent 3 4 Port 443 SSL Encrypted 2 Identacor Active Directory Agent Active Directory 1 Local Users Remote Users 1 12

Identacor Advantage features Providing management with the tools to track company and employee access to and usage of its cloud-based resources. Audit Reporting Single Sign On One password access to all applications, eliminating the need for multiple usernames and passwords Application Access for Users including 3025 users, 25 groups, and 41 applications Centralized Management Simple Access No Software Install Active Directory Integration NCSU importing users and groups from main AD domain. Support one password for all apps. integrated with many custom apps including AppA, App B, App C leveraging Identacor Secure Auto-Login Custom Integrations Rapid Deployment Up and running within minutes Anytime, anywhere application access from any browser 13 integrated with out of the box apps like Google Apps (Provisioning & SSO) using standards based SAML protocol. App Integrations Mobile Devices Application access from desktops, laptops and all types of mobile devices and Chromebooks. 13

Identacor Cloud SSO Single Sign-on Unified Cloud Directory Multi-factor Authentication User Provisioning Anywhere, Any Device 14

Identacor Cloud SSO Unified Cloud Directory Multi-factor Authentication Single Sign-On User Provisioning Anywhere, Any Device 15

Identacor Cloud SSO Unified Cloud DIrectory Single Sign-on Multi-factor Authentication User Provisioning Anywhere, Any Device 16

Identacor Cloud SSO Unified Cloud Directory Single Sign-on User Provisioning Unified Cloud DIrectory Anywhere, Any Device 17

Identacor Cloud SSO Unified Cloud Directory Single Sign-on Anywhere, Any Device Unified Cloud DIrectory User Provisioning 18

Active Directory Integration - Benefits Firewall Employees Group Sales Remote/Mobile Employees 1 Remote users authenticate with AD username and password Agent(s) 2 Local users transparently authenticate using Integrated Windows Authentication Active Directory 3 Access policies driven by AD security groups Benefits: Simple agent install, no network configuration required Automatic De-Activation of Identacor Deleted / Disabled Users Delegate Authentication for Identacor to NCSU AD domain Integration into Windows Desktop Login 19

20 1000 s of Apps All pre-integrated

NCSUVT Key Benefits Realized Application Portal Page Security Ability to monitor application adoption User IT Department One Password through AD integration User de provisioning AD integration integrate easily with any web app 21

NCSUVT Key Benefits Realized Securely add apps at the speed of business Enforce security for apps and devices Minimize Identity Management spend Increase IT team productivity and enterprise security Engage employees to enforce policy and work more productively 22

Thank You 23 23