VMware AlwaysOn Point of Care Desktop. with Indigo Identityware software for Fast Access & Strong Authentication with Roaming Desktops



Similar documents
Enabling Fast and Secure Clinician Workflows with One-Touch Desktop Roaming W H I T E P A P E R

VMware Horizon Mobile Secure Workplace User Installed Applications Support with Liquidware Labs HOW-TO GUIDE

VMware Virtual Desktop Manager User Authentication Guide

HIPAA/HITECH Compliance Using VMware vcloud Air

DigitalPersona Pro Enterprise

Configuring Single Sign-on from the VMware Identity Manager Service to Dropbox

How To Use A Vmware View For A Patient Care System

Configuring Single Sign-on from the VMware Identity Manager Service to WebEx

VERGENCE TM : TECHNICAL DATA SHEET

5 Day Imprivata Certification Course Agenda

ThinPrint GPO Configuration for Location-Based Printing

Server and Storage Sizing Guide for Windows 7 TECHNICAL NOTES

Boost Healthcare Security and Patient Care with Imprivata Enhanced VDI

What s New in VMware Site Recovery Manager 6.1

VMware User Environment Manager

Now I get the same great benefits of virtualization for my storage. Virtual SAN is as budget-friendly as it is simple.

Configuring Single Sign-on from the VMware Identity Manager Service to ServiceNow

Explore the VMware Horizon 6 Toolbox Auditing and Remote Assistance Capabilities

Enterprise Desktop Solutions: VMware View 4.5

Implementing Federal Personal Identity Verification for VMware View. By Bryan Salek, Federal Desktop Systems Engineer, VMware

VMware Horizon FLEX 1.5 WHITE PAPER

vcenter Configuration Manager Backup and Disaster Recovery Guide VCM 5.3

VMware vcenter Configuration Manager and VMware vcenter Application Discovery Manager Integration Guide

VMware vsphere Data Protection 6.0

Oracle Enterprise Single Sign-on Technical Guide An Oracle White Paper June 2009

AlwaysOn Desktop Implementation with Pivot3 HOW-TO GUIDE

Mobile Secure Desktop Maximum Scalability, Security and Availability for View with F5 Networks HOW-TO GUIDE

How To Control Vcloud Air From A Microsoft Vcloud (Vcloud)

A Guide to Disaster Recovery in the Cloud. Simple, Affordable Protection for Your Applications and Data

VMware View Backup Best Practices

Administrator Guide. DigitalPersona Pro. for Active Directory. Version 4.0

The Technical Differential: Why Service Providers Choose VMware for Cloud-Hosted Desktops as a Service

Getting the Most Out of VMware Mirage with Hitachi Unified Storage and Hitachi NAS Platform WHITE PAPER

How to Migrate Citrix XenApp to VMware Horizon 6 TECHNICAL WHITE PAPER

The Benefits of an Industry Standard Platform for Enterprise Sign-On

Configuring Single Sign-On from the VMware Identity Manager Service to Office 365

Enhancing Password Management by Adding Security, Flexibility, and Agility IBM Redbooks Solution Guide

Why Choose VMware vsphere for Desktop Virtualization? WHITE PAPER

Endpoint Virtualization for Healthcare Providers

Configuring Single Sign-on from the VMware Identity Manager Service to Amazon Web Services

Deployment Guide. Deploying F5 BIG-IP Global Traffic Manager on VMware vcloud Hybrid Service

VMware Horizon 7. End-User Computing Today. Horizon 7: Delivering Desktops and Applications as a Service

VMware Solutions for Small and Midsize Business

White paper December IBM Tivoli Access Manager for Enterprise Single Sign-On: An overview

VMware vcenter Configuration Manager Backup and Disaster Recovery Guide vcenter Configuration Manager 5.4.1

Virtualization Essentials

VMware Business Continuity and Disaster Recovery Technology Consulting Services

XyLoc Security Server w/ AD Integration (XSS-AD 5.x.x) Administrator's Guide

VMware vsphere Data Protection 5.8 TECHNICAL OVERVIEW REVISED AUGUST 2014

VMware View 4 with PCoIP I N F O R M AT I O N G U I D E

Scalability Tuning vcenter Operations Manager for View 1.0

Upgrading Horizon Workspace

Virtual Machine Encryption Basics

VMware vcloud Networking and Security Overview

The VMware Reference Architecture for Stateless Virtual Desktops with VMware View 4.5

The BYOD Opportunity. Say Yes to Device Diversity and Enable New Ways to Drive Productivity WHITE PAPER

Tackling Third-Party Patches

Deployment Guide for Citrix XenDesktop

Integration with Active Directory

Managing Remote Access

VMware vsphere Data Protection Evaluation Guide REVISED APRIL 2015

VMware vrealize Automation

VMware vcenter Configuration Manager SQL Migration Helper Tool User's Guide vcenter Configuration Manager 5.6

Configuring Single Sign-on from the VMware Identity Manager Service to AirWatch Applications

Symantec and VMware: Virtualizing Business Critical Applications with Confidence WHITE PAPER

Smart Card Certificate Authentication with VMware View 4.5 and Above WHITE PAPER

Mastering Disaster Recovery: Business Continuity and Virtualization Best Practices W H I T E P A P E R

Using AnywhereUSB to Connect USB Devices

Choosing an SSO Solution Ten Smart Questions

Introduction to VMware vsphere Data Protection TECHNICAL WHITE PAPER

Migrating a Windows PC to Run in VMware Fusion VMware Fusion 2.0

Top 10 Reasons to Virtualize VMware Zimbra Collaboration Server with VMware vsphere. white PAPER

VMware vcenter Support Assistant 5.1.1

Implementation Considerations for VMware App Volumes in a Citrix XenApp Environment WHITE PAPER

Passlogix Sign-On Platform

DigitalPersona Pro Enterprise

CA ARCserve Replication and High Availability

HELP DOCUMENTATION E-SSOM INSTALLATION GUIDE

Check Point FDE integration with Digipass Key devices

F5 PARTNERSHIP SOLUTION GUIDE. F5 and VMware. Virtualization solutions to tighten security, optimize performance and availability, and unify access

Oracle Databases on VMware High Availability

Authentication: Password Madness

HP Software as a Service

DigitalPersona Pro Server for Active Directory v4.x Quick Start Installation Guide

Reducing the Cost and Complexity of Business Continuity and Disaster Recovery for

VMware vcloud Automation Center 6.0

VMware vsphere 5.0 Evaluation Guide

Releasing High Quality Applications More Quickly with vrealize Code Stream

VMware vcenter Server 5.5 Deployment Guide TECHNICAL MARKETING DOCUMENTATION V 1.0/NOVEMBER 2013/JUSTIN KING

Transcription:

VMware AlwaysOn Point of Care Desktop with Indigo Identityware software for with Roaming Desktops

Indigo Identityware provides clinical users fast and secure access to their VMware desktop through a fluid, easy and consistent user interface anywhere within the enterprise. Indigo meets all VMware s High Availability user experience requirements: Desktops are always on (VMware View) and enable fast logon Desktop follows user Failover support Access allowed from any endpoint device Familiar (transparent) interface to sustain same application workflow Quick provisioning (Indigo idna included in VMware golden image) Easy Management (Indigo Central Admin snap-in to the MMC) Maintained security (full two factor authentication, desktop locking, encrypted credentials) Low cost High Availability (distributed file caching system & automatic synchronization of user credentials) Fast Access & Strong Authetnication 2

Reference Architecture Desktops (Thick Clients) - Windows XP, 7, & 8 Thin Clients - Windows Embedded Secure Audit - Windows 2003, 2008, 2008R2 Failover Indigo Secure Audit Primary Indigo Secure Audit Microsoft AD Thin Clients (Windows Embedded) running VMware View & Indigo idna Windows Kiosks (thick or thin) for shared access in clinical areas generic local desktop allows Group Unlock of Windows vs. having each user logon to Windows Fast Access, and each user s credentials are authenticated on the VM desktop Windows Desktops VMware View & Indigo idna Legend Fast Access & Strong Authentication SSO & Workflow mgmt (optional) Indigo Secure Audit 3

Reference Architecture Zero Clients - no additional software View Desktop sessions - Windows 7 or 8 Secure Audit - Windows 2003, 2008, 2008R2 Failover Indigo Secure Audit Primary Indigo Secure Audit Microsoft AD Indigo Secure Virtual Kiosk connects user session to VM & provides fast user switching Zero Clients with USB redirection & supported proximity card or biometric readers Legend Fast Access & Strong Authentication SSO & Workflow mgmt (optional) Indigo Secure Audit 4

Test Validation VMware Labs on 9/25/2012 Indigo Identityware installed in VMware Labs on September 25, 2012 and performed a successful demonstration and validation test of its architecture and products. Installed & Configured idna on both a Win 7 and a Win XP client-side machines idna configured for Kiosk Workflow for Fast Access to VMware View Desktop sessions and for other workflows defined by employee role Demonstrated authentication with both proximity card/reader and biometric reader The user logged into the Windows 7 client by tapping his proximity card & upon entering a 4-digit PIN, the local desktop opened was a generic Windows desktop, and the idna Agent immediately launched the VMware View client, providing View with the user s credentials. The user was presented with his VMware View desktop session with no additional authentication or intervention by the user needed. The user tapped his proximity card a second time and the local Windows desktop was immediately locked. User moved to the other local client-side machine (Win XP), authenticated via his proximity card & PIN, the local generic Windows desktop opened while idna automatically launched the VMware View client, and since the user s individual credentials were used in launching View, his VMware View desktop session was automatically roamed to his new location. Same functionality was demonstrated using biometric fingerprint readers. 5

Field Validation Indigo installed its products at a regional medical center in central Minnesota that had already deployed VMware View across the enterprise. Given their need to provide clinical staff: Fast Access to their VMware View desktop sessions, mobility to move from one area to another and easily roam their View session, and to ensure use of strong authentication to meet HIPAA compliance, they chose Indigo Identityware idna and InSession for SSO Workflow Management. 500 Indigo licenses purchased Standard installation of idna on client-side machines; local machines configured with proximity card readers. Shared workstations for clinical staff were configured with the kiosk workflow, where upon authentication, the user was presented with a generic local Windows desktop while idna automatically launched the VMware View session, providing the individual s credentials to VMware to access that user s View desktop session. Other workstations (e.g., executives, admin/finance, etc ) were also installed with idna, but their local desktops were not setup as shared kiosk workstations. Four different workflows were defined based on staff roles and Indigo InSession was installed and configured on the VMware View desktop images to provide SSO to six different enterprise-wide applications (EMR, imaging, prescriptions, etc ). Results The medical center has significantly reduced the time for staff to login to their VMware View desktop sessions, provided easier and simpler access (SSO) to applications based on an employee s role, and is confident that in conjunction with its adoption of VMware View, is both maximizing employee productivity and achieving HIPAA compliance. 6

The Indigo Identityware software components that are installed with the VMware AlwaysOn solution (along with VMware View Client, Agent, Manager, Centralized Desktops, et. al.) are as follows: Indigo idna (client agent for fast access & authentication) idna provides the user with One Touch Access (prox. card tap or finger touch) for clientside computers, automatically launches the VMware View Desktop and provides VMware View with the user s credentials. Indigo Secure Audit Secure Audit (SAS) software is used for user credential replication, disaster recovery and distributed record caching across the network. The SAS application can be easily installed on a virtual machine running Microsoft Windows (e.g., Win 7 or Windows 2008R2). Indigo recommends a minimum of two Secure Audit s per enterprise deployment for failover and credential record data duplication. Indigo Configuration Wizard The Configuration Wizard provides an easy-to-use interface to define the VDI access and workflow for end users and creates a.xml file that is called by idna when the user first authenticates to access the desktop. The customer can customize the launch script on a role by role basis or utilize a single launch script across the enterprise and distribute the script(s) to all client-side machines. Indigo snap-ins for idna local computer management and Central Management for machine groups Indigo InSession (optional) Indigo InSession provides password-free SSO & Workflow Management based on roles for enterprise applications (such as EHR) and can be customized on a enterpriseby-enterprise basis. InSession also provides Secondary Strong Authentication inside of applications to facilitate one-touch authentication for electronically signing charts or prescriptions. 7

VMware, Inc. 3401 Hillview Avenue Palo Alto CA 94304 USA Tel 877-486-9273 Fax 650-427-5001 www.vmware.com Copyright 2012 VMware, Inc. All rights reserved. This product is protected by U.S. and international copyright and intellectual property laws. VMware products are covered by one or more patents listed at http://www.vmware.com/go/patents. VMware is a registered trademark or trademark of VMware, Inc., in the United States and/or other jurisdictions. All other marks and names mentioned herein may be trademarks of their respective companies. Item No: VMW-HG-SECUWKSPDELIVERY- PLAYBK-20120427-WEB 8