Identity and Access Management for the Hybrid Enterprise



Similar documents
The Principles of Audit Automation for Access Control

Webinar Self-service in Microsoft Azure AD Premium

Creating a Single Sign on Web Portal using Azure. Robert Crane Office 365

Ondřej Výšek Sales Lead, Microsoft MVP.

Overview of Microsoft Enterprise Mobility Suite (EMS) Cloud University

Microsoft Enterprise Mobility Suite

Microsoft Azure Multi-Factor authentication. (Concept Overview Part 1)

SINGLE & SAME SIGN-ON ASPECTS

Microsoft Enterprise Mobility Suite

Azure Active Directory

Enterprise Mobility Suite (EMS) Sean Lewis Principal Partner Technology Strategist

Agenda. Federation using ADFS and Extensibility options. Office 365 Identity overview. Federation and Synchronization

Azure Active Directory Solutions for Identity and Access Management. February 2015

Planning your Microsoft Application Strategy in a Cloud Crazy World. Steve Soper Senior Managing Partner

Federated single sign-on (SSO) and identity management. Secure mobile access. Social identity integration. Automated user provisioning.

Bill Fiddes Learning and Development Specialist Rob Latino Program Manager in Office 365 Support

Centrify Cloud Connector Deployment Guide

Total Cost of Ownership Overview ADFS vs OneLogin WHITEPAPER

Connecting Users with Identity as a Service

Cloud-Accelerated Hybrid Scenarios with SharePoint and Office 365

Identity Governance Evolution

Identity & Access Management in the Cloud: Fewer passwords, more productivity

Enterprise Mobility Services

IDENTITY MANAGEMENT AND WEB SECURITY. A Customer s Pragmatic Approach

Hybrid Cloud Identity and Access Management Challenges

Course 50382A: Implementing Forefront Identity Manager 2010 OVERVIEW

Top 8 Identity and Access Management Challenges with Your SaaS Applications. Okta White paper

WHITEPAPER. 13 Questions You Must Ask When Integrating Office 365 With Active Directory

Speeding Office 365 Implementation Using Identity-as-a-Service

Identity. Provide. ...to Office 365 & Beyond

Office 365 deployment checklists

Overview of products, services and capabilities

Alexander De Houwer Technology Advisor Devices Win 10 Vincent Dal Technology Advisor Business Productivity

Office 365 deploym. ployment checklists. Chapter 27

Collaborating with External Users

Agenda. Enterprise challenges. Hybrid identity. Mobile device management. Data protection. Offering details

HOW MICROSOFT AZURE AD USERS CAN EMPLOY SSO

Top 8 Identity and Access Management Challenges with Your SaaS Applications. Okta Inc. 301 Brannan Street San Francisco, CA 94107

Identity + Mobile Management + Security = Enterprise Mobility Suite

An Overview of Samsung KNOX Active Directory and Group Policy Features

Digicomp Microsoft Evolution Day MIM 2016 Oliver Ryf. Partner:

ABOUT TOOLS4EVER ABOUT DELOITTE RISK SERVICES

Integrating Single Sign-on Across the Cloud By David Strom

Google Apps Deployment Guide

Implementing Forefront Identity Manager 2010

Implementing Microsoft Azure Infrastructure Solutions 20533B; 5 Days, Instructor-led

Documentation. CloudAnywhere. Page 1

PRACTICAL IDENTITY AND ACCESS MANAGEMENT FOR CLOUD - A PRIMER ON THREE COMMON ADOPTION PATTERNS FOR CLOUD SECURITY

Course 20533B: Implementing Microsoft Azure Infrastructure Solutions

Managing Access for External Users with ARMS

Extend and Enhance AD FS

Identity and Access Management (IAM) Across Cloud and On-premise Environments: Best Practices for Maintaining Security and Control

Manage all your Office365 users and licenses

CL_50382 Implementing Forefront Identity Manager 2010

Alex Wong Senior Manager - Product Management Bruce Ong Director - Product Management

<Insert Picture Here> Integrating your On-Premise Applications with Cloud Applications

An Overview of Samsung KNOX Active Directory-based Single Sign-On

Identity Federation: Bridging the Identity Gap. Michael Koyfman, Senior Global Security Solutions Architect

SharePoint 2013 Business Connectivity Services Hybrid Overview

Active Directory Automation RFSP # 1382 Addendum # 1 November 5, 2015

Configuration Guide - OneDesk to SalesForce Connector

ZervicePoint Provides Automated, End-to-End Provisioning of Accounts, Services, and Material

CA Single Sign-On Migration Guide

How to Overcome Challenges in Deploying Cloud Apps to Get the Most from your IAM Investment

IDENTITY & ACCESS MANAGEMENT

(A) User Convenience. Password Express Benefits. Increase user convenience and productivity

Identity and Access Management Memorial s Strategic Roadmap

Course 20533: Implementing Microsoft Azure Infrastructure Solutions

RSA Identity Management & Governance (Aveksa)

Mobile device and application management. Speaker Name Date

Identity and Access Management PI-1 Demo. December 2, 2014 Tuesday 10:00 A.M. 6 Story Street

Office365 Adoption eguide. Identity and Mobility Challenges. Okta Inc. 301 Brannan Street San Francisco, CA

The Top 5 Federated Single Sign-On Scenarios

Directory Integration with Okta. An Architectural Overview. Okta Inc. 301 Brannan Street San Francisco, CA

Aurora Hosted Services Hosted AD, Identity Management & ADFS

Azure Active Directory

Microsoft Enterprise Mobility and Client Futures

Implementing Microsoft Azure Infrastructure Solutions

Single Sign On. SSO & ID Management for Web and Mobile Applications

DEMYSTIFYING THE SHAREPOINT HYBRID ENVIRONMENT. Dan Charlton Senior Consultant MCSE, MCSA, MCP

Identity Management and Single Sign-On

Setup Reset Password Portal. CloudAnywhere. Auteur Emmanuel Dreux

Take Control of Identities & Data Loss. Vipul Kumra

Get started with cloud hybrid search for SharePoint

Implementing Microsoft Azure Infrastructure Solutions

Customer Identity and Access Management (CIAM) Buyer s Guide

B2C, B2B and B2E:! Leveraging IAM to Achieve Real Business Value

SAP Cloud Identity Service

Sage Integration Cloud Technology Whitepaper

AVG Business Secure Sign On Active Directory Quick Start Guide

Microsoft SharePoint Architectural Models

Top Six Things to Consider with an Identity-as-a-Service (IDaaS) Solution

Microsoft Power BI. Nov 21, 2015

<Insert Picture Here> Oracle Identity And Access Management

STRONGER AUTHENTICATION for CA SiteMinder

Transcription:

Identity and Access Management for the Hybrid Enterprise Redmond Identity Summit 2014 Directories Devices Identity Keith Brintzenhofe Microsoft Corporation

Thank You to our Sponsors Gold Silver Plus Silver

Agenda Windows Azure Active Directory Vision Windows Azure Active Directory and the Hybrid Enterprise Today Identity & Access Management Scenarios Q&A

Windows Azure Active Directory: The Vision A modern, cloud based identity management service providing federation, directory services, device registration, user provisioning, application access control & data protection. A natural extension to on premises directories, the combination of Windows Server AD and Windows Azure AD lets you secure today s hybrid enterprise. On-premises and cloud Active Directory managed as one Consistent identities for on-premises and cloud applications Easy end user experience with single sign on and self-service features

Windows Azure Active Directory and the Hybrid Enterprise - Today Self Service On premises and private cloud HR Forefront Identity Manager and Microsoft BHOLD Suite Windows Azure Active Directory Other apps Windows Server Active Directory DirSync Custom apps SaaS apps Active Directory Federation Services Microsoft Account Other Directories

Identity and Access Management Scenarios Simplify access and control of SaaS applications Reduce IT burden with self service IAM Easily meet governance and compliance targets for IAM Improve security posture with monitoring of cloud services Rapidly develop and deploy new enterprise capabilities

Simplify access and control of SaaS applications SaaS App Management Professional services company, 4500 employees Interested in Office 365, Workday, Salesforce, Yammer and other SaaS applications Needs centralized management of employee access to SaaS applications Windows Azure AD single sign on (SSO) for SaaS applications Access Panel at myapps.microsoft.com Next steps Enable user SaaS SSO from mobile devices Manage additional SaaS apps, including federation and provisioning

Simplify access and control of SaaS applications SaaS App User Provisioning Fortune 500 company with 100,000+ international employees Needed automated user provisioning and deprovisioning to SaaS apps including ServiceNow ServiceNow also requires group objects FIM connector to synchronize across on premises data sources and into Windows Azure AD Windows Azure AD provides user and group provisioning to ServiceNow and other SaaS apps Next Steps Develop standards such as OAuth and SCIM to extend the reach of provisioning to more apps

Simplify access and control of SaaS applications Windows Azure AD Connector Fortune 500 company with 100,000+ international employees Multiple data sources on premises Need to provision users and groups to Windows Azure AD for control of SaaS FIM connector from on premises data sources to Windows Azure AD Group based application assignment in WAAD Next steps Incorporate users from HR sources in addition to SAP, PeopleSoft and Oracle

Self service identity and access management Self Service Password Reset for Users University with 20,000 current students Existing on premises password reset solution in place does not cover alumni Mobile phone verification method User registration Customization of helpdesk URL and branding of Password Reset Portal with university s logo Next Steps Additional/alternate verification methods

Self service identity and access management Tenant Branding Financial services firm with 200+ offices Subsidiary organizations need consistent look and feel across authentication experiences Already using Office365 and Active Directory Customized sign in page experience for each of its subsidiaries

Self service identity and access management Self Service Group Management Enterprise with 100,000+ users Multiple AD forests On premises applications, cloud hosted LOB and SaaS applications On premises SSGM controls access across apps Coordinates both Administrator managed and owner managed groups across multiple AD forests Users can find and request to join groups Configurable work flow for approvals and notifications Next steps SSGM as a Service

Easily meet governance and compliance targets for IAM Roles and attestation Enterprise with 25,000 employees Role based access control for LOB applications Policy based role assignment (based on job title get one or more roles assigned to them automatically) Attestation allows for review and sign off on permissions on a regular basis Analytics for identification of users not in compliance with business policy Next steps Engage with partners such as OCG for further use of FIM and BHOLD capabilities

Easily meet governance and compliance targets for IAM Multi Factor Authentication Local government agency Protect access to sensitive applications Avoid end user lock out using multiple MFA methods: (Mobile App, Call / SMS Mobile, office or alternate phone) Targeted MFA for sensitive accounts Customization of MFA greetings, fraud alert, one time bypass. capabilities End user self service enrollment Next Steps MFA targeting for sensitive apps / actions

Security monitoring and alerting for cloud services Reporting Large multi national enterprise Frequent target of attempts to gain unauthorized access to employee accounts Anomaly detection: credential sharing credential misuse/loss brute force attacks access from behind anonymizers Detection of attacks spanning organizations Next Steps On premises data correlation and analytics

Rapidly develop and deploy new enterprise capabilities Custom application integration Healthcare Service Provider Apps needs to authenticate and authorize users based on enterprise directory data Web App, Web API and Mobile Clients SSO (leveraging strong authentication and federation) App Access user profile in the cloud Next Steps Social Identities and Guests Schema Extensions

Next Steps Sign up for Windows Azure Active Directory Premium Preview http://www.windowsazure.com/en us/services/preview/ Self service password reset User provisioning and de provisioning to SaaS apps Group management Advanced security reports More to come! Give us feedback via the forums at http://aka.ms/aadforum My contact info kbrint@microsoft.com

Q&A