Presentation is loading. Please wait.

Presentation is loading. Please wait.

Introduction to Grouper Part 1: Access Management & Grouper Tom Barton University of Chicago and Internet2 Manager – Grouper Project.

Similar presentations


Presentation on theme: "Introduction to Grouper Part 1: Access Management & Grouper Tom Barton University of Chicago and Internet2 Manager – Grouper Project."— Presentation transcript:

1 Introduction to Grouper Part 1: Access Management & Grouper Tom Barton University of Chicago and Internet2 Manager – Grouper Project

2 Lower cost and time to deliver a new service Simplify and make consistent by using the same group or role in many places 2 Why have an access management strategy? January 2012Grouper Training Physics 101 Course Group Lab Reservations Wiki Access Email Group

3 Empower the right people to manage access. Take central IT out of the loop. See who can access what, with a report rather than a fire drill 3 Additional benefits of access management January 2012Grouper Training

4 1.Start out using a single user attribute, affiliation, in LDAP or Active Directory. This lets services implement simple access policies. 4 Access management stages: authorization > authentication January 2012Grouper Training student faculty staff Affiliation guest Service Staff portal

5 2.Enrich & centralize access management with groups determined from systems of record Courses, financial accounts, departments Define service-specific access policies in the centralized access management system 5 Access management stages: authorization > authentication January 2012Grouper Training Math Faculty Group Math Faculty Resources Math Faculty Resources can access

6 3. Get central IT out of the loop Distributed management Exceptions Departmental applications 6 Access management stages: authorization > authentication January 2012Grouper Training Math Faculty Group Math Faculty Resources Math Faculty Resources can access Math Support Group +

7 4.Increase integration of access management Direct integration with applications using web services SOAP/REST/ESB Roles & privileges to support applications more deeply 7 Access management stages: authorization > authentication January 2012Grouper Training For Math Department, while John works there HR Admin Role

8 Open source, community-driven project of the Internet2 Middleware Initiative Initial release v0.5 in December 2004 8 The Grouper Story January 2012Grouper Training

9 Key aims Delegation and distributed management Integration with most any existing Identity Management infrastructure 9 The Grouper Story January 2012Grouper Training Existing IdM Infrastructure

10 Grouper v2.X expanded beyond groups Roles & permissions Rules 10 The Grouper Story January 2012Grouper Training -If removed from group A -then remove from group B -If removed from group A -then remove from group B HR-Admin

11 11 January 2012 Thanks! Further information: Infosheets, mail lists, wiki, downloads, etc: www.internet2.edu/grouper Grouper demo server: https://grouperdemo.internet2.edu/

12 12 January 2012 Next Video in Grouper Online Training is: Introduction to Grouper Part 2: Grouper’s Core Access Management Capabilities Click on title above, or go to Grouper Online Training Home at


Download ppt "Introduction to Grouper Part 1: Access Management & Grouper Tom Barton University of Chicago and Internet2 Manager – Grouper Project."

Similar presentations


Ads by Google