Brian Puhl Technology Architect Microsoft IT Session Code: ITS212.

Slides:



Advertisements
Similar presentations
MIX 09 4/15/ :14 PM © 2009 Microsoft Corporation. All rights reserved. Microsoft, Windows, Windows Vista and other product names are or may be registered.
Advertisements

Faith Allington Program Manager Microsoft Corporation Session Code: WSV304.
A claims-based Identity Metasystem
Matt Steele Senior Program Manager Microsoft Corporation SESSION CODE: SIA326.
Christopher Chapman | MCT Content PM, Microsoft Learning, PDG Planning, Microsoft.
Session 1.
Christopher Chapman | MCT Content PM, Microsoft Learning, PDG Planning, Microsoft.
John “JG” Chirapurath Director, Identity & Security BG Microsoft SIA-205 Business Ready Security.
© 2012 Microsoft Corporation. All rights reserved. Microsoft, Windows, Windows Vista and other product names are or may be registered trademarks and/or.
Identity & Access Control in the Cloud Name Title Organization.
Bhushan NeneGrzegorz Gogolowicz Principal ArchitectSenior ArchitectMicrosoft Session Code: DEV304.
© 2009 Microsoft Corporation. All rights reserved. Microsoft, Windows, Windows Vista and other product names are or.

customer.
“Click and Run ” “Click once repeat often” Admins Service Operations “ Install and forget” Engineering Support Key considerations: Deterministic, fool.
Aaron Margosis Principal Consultant Microsoft Session Code: CLI405.
demo © 2008 Microsoft Corporation. All rights reserved. Microsoft, Windows, Windows Vista and other product names.
demo Demo.
demo QueryForeign KeyInstance /sm:body()/x:Order/x:Delivery/y:TrackingId1Z
 Justin Smith Sr. Program Manager Microsoft Corporation BB28.
© 2009 Microsoft Corporation. All rights reserved. Microsoft, Windows, Windows Vista and other product names are or may be registered trademarks.
© 2008 Microsoft Corporation. All rights reserved. Microsoft, Windows, Windows Vista and other product names are or.
Arend-Jan Speksnijder Solutions Architect Microsoft Dynamics Lighthouse team Dynamics AX2009 Technical Overview and Demo (DYN301)
Sara Ford Program Manager Microsoft Corporation DPR301.

Patrick Ortiz Global SQL Solution Architect Dell Inc. BIN209.
Ben Robb MVP, SharePoint Server cScape Ltd OFC204.
David B. Cross Product Unit Manager Microsoft Corporation Session Code: SIA303 Donny Rose Senior Program Manager.
Scott Morrison Program Manager Microsoft Corporation Session Code: WUX308.
Tech·Ed North America /6/2018 2:20 AM
6/17/2018 5:54 AM OSP322 Getting the best of both worlds, making the most of SharePoint hybrid search solutions Shyam Narayan Microsoft © 2013 Microsoft.
6/26/2018 9:02 PM © 2009 Microsoft Corporation. All rights reserved. Microsoft, Windows, Windows Vista and other product names are or may be registered.
9/11/2018 5:53 PM © 2009 Microsoft Corporation. All rights reserved. Microsoft, Windows, Windows Vista and other product names are or may be registered.
Excel Services Deployment and Administration
SharePoint Online Management and Control
Integrating Microsoft SharePoint 2010 with Windows Azure
Sysinternals Tutorials
Deploying Windows Embedded with Style
Jason Zander Unplugged
Twenty Windows Tools You Never Knew Existed
Brian Keller Sr. Technical Evangelist Microsoft Session Code: DEV310
12/5/2018 3:24 PM © 2009 Microsoft Corporation. All rights reserved. Microsoft, Windows, Windows Vista and other product names are or may be registered.
Tech·Ed North America /5/2018 6:43 PM
Tech·Ed North America /7/2018 2:51 PM
Ben Robb MVP, SharePoint Server cScape Ltd Session Code: OFS207
Office 365 Identity Management
The Dirty Dozen: Windows PowerShell Scripts for the Busy DBA
12/27/ :01 PM © 2009 Microsoft Corporation. All rights reserved. Microsoft, Windows, Windows Vista and other product names are or may be registered.
Data Driven ASP.NET Web Forms Applications Deep Dive
Tech·Ed North America /17/2019 1:47 AM
Brian Keller Sr. Technical Evangelist Microsoft Session Code: DEV310
Office 365 Development.
Tech·Ed North America /22/2019 3:15 AM
Vittorio Bertocci Principal Technical Evangelist Microsoft
Building Silverlight Apps with RIA Services
Building SaaS Solutions on Windows Azure
2/27/2019 © 2014 Microsoft Corporation. All rights reserved. Microsoft, Windows, and other product names are or may be registered trademarks and/or trademarks.
Tech·Ed North America /28/ :49 PM
2/28/2019 © 2014 Microsoft Corporation. All rights reserved. Microsoft, Windows, and other product names are or may be registered trademarks and/or trademarks.
System Center Marketing
A Lap Around Internet Explorer 9 For Developers
Caleb Baker Sr. Program Manager
2010 Microsoft BI Conference
Hack-proofing your Clients using Windows 7 Security!
Lap Around the Windows Azure Platform
Building BI applications using PowerPivot for Excel
7/5/2019 © 2014 Microsoft Corporation. All rights reserved. Microsoft, Windows, and other product names are or may be registered trademarks and/or trademarks.
Azure AD Simon May Technical Evangelist.
What’s New in Visual Studio 2012 for Web Developers
Presentation transcript:

Brian Puhl Technology Architect Microsoft IT Session Code: ITS212

Agenda Federating identities Microsoft IT Federation environment Introducing Geneva Server Migrating from ADFS to Geneva Identity management when federating Microsoft IT Federation scenarios

Your COMPANY and your EMPLOYEES Your SUPPLIERS Your REMOTE and VIRTUAL EMPLOYEES Your CUSTOMERS Customer satisfaction and customer intimacy Cost competitiveness Reach, personalization Collaboration Outsourcing Faster business cycles; process automation Value chain M&A Mobile/global workforce Flexible/temp workforce Orgs Have to Extend Access Your PARTNERS

User Password Proliferation Domain Account REDMOND\BPuhl E-Company Store Fidelity 401K Social Security Number TravelPort Company Poll BPuhl Live Meeting BrianP Live ID Marketing Leads App Brian.Puhl Generic ID for everything else imav8n Sub-Keyboard Crypto API The same password for everything! Super-Secret Passphrase (more secure) - Only have to remember one thing - I never write it down - Easy for me to remember - Change it once per year Samantha_Is_17_Anika_Is_5

Agenda Federating identities Microsoft IT Federation environment Introducing Geneva Server Migrating from ADFS to Geneva Identity management when federating Microsoft IT Federation scenarios

Microsoft IT Federation Ecosystem ADFS v1 Federations Internal Network Perimeter Network 59 Federations 29 unique partners Using Ping, IBM, & Others Worldwide usage Corp (Internal) Live ID / Passport Self FS Proxies

Agenda Federating identities Microsoft IT Federation environment Introducing Geneva Server Migrating from ADFS to Geneva Identity management when federating Microsoft IT Federation scenarios

Geneva Server Security token service for AD Identity and federation provider Federation trust manager Automates trust management using metadata Standards-based and interoperable WS-* & SAML 2.0 protocols SAML 1.1 & 2.0 tokens Managed information card provider for AD CardSpace and 3 rd party identity selectors

Geneva Server Management APIs and UX Card Issuance Token Issuance MetadataMetadata Geneva Server Components Account Store Geneva Proxy Token Issuance Proxy Metadata Proxy Internet Client Policy Store Intranet Client

Geneva Server Management APIs and UX Card Issuance Token Issuance MetadataMetadata Geneva Server Components Account Store Geneva Proxy Token Issuance Proxy Metadata Proxy Internet Client Policy Store Intranet Client Geneva Clients: Web Browsers Windows CardSpace and Other Identity Selectors WS-* Aware Clients (WCF, etc.)

Geneva Server Management APIs and UX Card Issuance Token Issuance MetadataMetadata Geneva Server Components Account Store Geneva Proxy Token Issuance Proxy Metadata Proxy Internet Client Policy Store Intranet Client Geneva Policy Store: SQL Server

Geneva Server Management APIs and UX Card Issuance Token Issuance MetadataMetadata Geneva Server Components Account Store Geneva Proxy Token Issuance Proxy Metadata Proxy Internet Client Policy Store Intranet Client Geneva Server: Security Token Service for SOAP and browser clients Information card issuance web site Policy and service management

Agenda Federating identities Microsoft IT Federation environment Introducing Geneva Server Migrating from ADFS to Geneva Identity management when federating Microsoft IT Federation scenarios

Migrating from ADFS v1 to Geneva Identity Provider 1. Deploy parallel to ADFS 2. Configure Trust Policy using Powershell 3. Use client HOSTS files to test applications 4. Update DNS records Proxies look to internal Internet clients to proxie Internal Network Partner 1 Partner 2 Perimeter Network Geneva ADFS

Internal Network Perimeter Network Microsoft IT Federation Ecosystem

Agenda Federating Identities Microsoft IT Federation Environment Introducing Geneva Server Migrating from ADFS to Geneva Identity Management when Federating Microsoft IT Federation Scenarios

10 Things when troubleshooting federations

10. Network Connectivity & NLB 9. SQL Availability 8. URI’s 7. Event ID Fiddler or HTTP Watch

5. Enabling Logging 4. Dirty Data 3. Immutable ID’s

Troubleshooting Federation “If your ADFS is broken, it’s PKI. If it’s not PKI, you’ve got a typo. If it’s not a typo, it’s PKI.” - Laura Hunter

Troubleshooting Federation PKI issues: CRL Validation (CDP’s not discoverable) Elliptical curve key algorithm Managing Certificate Renewals Certificates – They expire! Configuration issues: Case sensitivity counts where you’d least expect it Geneva needs both ports 80 and 443 Make your life simple with Metadata Exchange!

Demo

Security Considerations ServerTokenCryptoAdministrator Domain ControllerKerberos or NTLMShared SecretDomain Admin

Security Considerations ServerTokenCryptoAdministrator Domain ControllerKerberos or NTLMShared SecretDomain Admin Certificate Authorityx.509 certificateTrusted chainCertificate Admin

Security Considerations Treat your Geneva servers like domain controllers Your Geneva Server admins are like domain administrators Geneva includes claims policy language, which is extremely powerful Manage your certificates Token signing protects from man-in-the-middle attacks SSL validates the end-points ServerTokenCryptoAdministrator Domain ControllerKerberos or NTLMShared SecretDomain Admin Certificate Authorityx.509 certificateTrusted chainCertificate Admin Federation ServerSAMLx.509 certificate???

Agenda Federating Identities Microsoft IT Federation Environment Introducing Geneva Server Migrating from ADFS to Geneva Identity Management when Federating Microsoft IT Federation Scenarios

Geneva Server How Geneva is Changing Our Game

Geneva Server ADFS Partners

How Geneva is Changing Our Game Geneva Server ADFS Partners

How Geneva is Changing Our Game Geneva Server ADFS Partners SQL Authz Store

How Geneva is Changing Our Game Geneva Server ADFS Partners SQL Authz Store

How Geneva is Changing Our Game Geneva Server ADFS Partners SQL Authz Store Windows Live ID

Summary Federating identities is the path to SaaS Geneva is a lot more than just ADFS v2 Policy processing language Metadata Exchange SAML 2.0 Protocol Support Federation with Live ID Services

Sessions On-Demand & Community Resources for IT Professionals Resources for Developers Microsoft Certification & Training Resources Resources Required Slide Speakers, TechEd 2009 is not producing a DVD. Please announce that attendees can access session recordings at TechEd Online. Required Slide Speakers, TechEd 2009 is not producing a DVD. Please announce that attendees can access session recordings at TechEd Online.

Complete an evaluation on CommNet and enter to win an Xbox 360 Elite!

© 2009 Microsoft Corporation. All rights reserved. Microsoft, Windows, Windows Vista and other product names are or may be registered trademarks and/or trademarks in the U.S. and/or other countries. The information herein is for informational purposes only and represents the current view of Microsoft Corporation as of the date of this presentation. Because Microsoft must respond to changing market conditions, it should not be interpreted to be a commitment on the part of Microsoft, and Microsoft cannot guarantee the accuracy of any information provided after the date of this presentation. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION. Required Slide