1 Extending Authenticated Online Services with "Friend Accounts" at Washington State University Brian Foley Technology Architect/Application Developer.

Slides:



Advertisements
Similar presentations
Office of Information Technology Affiliates/Guests – Who are these people and how do we give them services? Copyright, Barbara Hope, University of Maryland,
Advertisements

Student, Faculty, and Staff Data Availability and Protection What’s the Back-Up Plan? (for academic computing) Sponsored by.
Copyright Tom Parker, Ron DiNapoli, Andrea Beesing, Joy Veronneau This work is the intellectual property of the authors. Permission is granted for.
Supporting and Hosting Web- Based Learning Systems Educause 2001 Charlene Douglas – Director Kathryn Gomm - Training Manager Sharon McCarrager – Accessibility.
Seeing the Forest and the Acorns in the Decision Tree Sandy Burke Computing Center HelpDesk Manager Copyright Sandy Burke, This work is the intellectual.
Copyright Dickinson College This work is the intellectual property of the author. Permission is granted for this material to be shared for non-commercial,
Andrea Eastman-Mullins Information & Technology Coordinator University of North Carolina, Office of the President Teaching and Learning with Technology.
Using Levels of Assurance Renee Shuey nmi-edit CAMP: Charting Your Authentication Roadmap February 8, 2007.
Copyright Jill M. Forrester This work is the intellectual property of the author. Permission is granted for this material to be shared for non- commercial,
February 2006 copyright Michael Welch, Blinn College This work is the intellectual property of the author. Permission is granted for this material to be.
The Homegrown Single Sign On (SSO) Project at UM – St. Louis.
Identity Management: The Legacy and Real Solutions Project Overview.
Copyright Statement © Jason Rhode and Carol Scheidenhelm This work is the intellectual property of the authors. Permission is granted for this material.
Providing and Managing Technology Training Providing & Managing Technology Training Susan McKibben The University of Akron.
FAMILY EDUCATIONAL RIGHTS AND PRIVACY ACT Electronic Signatures This work is the intellectual property of the author. Permission is granted for this material.
Copyright Anthony K. Holden, This work is the intellectual property of the author. Permission is granted for this material to be shared for non-commercial,
Five Berkeley Campuses Three in NJ; Two in NY Bachelor of Science in Business Administration Degree Online Online Courses Hybrid Courses Web Enhanced Courses.
1 No More Paper, No More Stamps: Targeted myWSU Communications Jack Alilunas, Lavon Frazier October 20, 2004.
How Collaboration Created an Online Help Desk and Knowledge Base for the Campus Community EDUCAUSE Mid-Atlantic Regional Conference 2008.
Copyright Shanna Smith & Tom Bohman (2003). This work is the intellectual property of the authors. Permission is granted for this material to be shared.
Turning Information Into Action: Enterprise Reporting at Columbia University Maria E. Mosca, Director Student Information Systems Columbia University in.
Tangible Flags Collaborative Educational Technology to enhance grade school field trips Gene Chipman PhD Candidate in Computer Science
Cheryl Ast Project Team Leader, Administrative Computing Services (949) EDUCAUSE Southwest Regional Conference University of.
Cheryl Ast Project Team Leader, Administrative Computing Services (949) CUMREC 2003 University of California, Irvine Tuesday, May.
Moving Your Paperwork Online Western Washington University E-Sign Web Forms Copyright Western Washington University, This work is the intellectual.
Darrel S. Huish Katherine J. Ranes Arizona State University Lessons Learned During the First Year of myASU, a Large Institution Portal Copyright Darrel.
So You Want to Switch Course Management Systems? We Have! Come Find Out What We’ve Learned. Copyright University of Okahoma This work is the intellectual.
CAMP - June 4-6, Copyright Statement Copyright Robert J. Brentrup and Mark J. Franklin This work is the intellectual property of the authors.
Copyright - L. Thanasides, 2002 Using the Right FACTS Can Be Informative: Florida’s Statewide Student Information System Linda Thanasides Marsha Stickel.
Putting the We in… We are Penn State! Copyright [Carol Findley, Lisa Dibert] [2003]. This work is the intellectual property of the authors. Permission.
CAMP Med Mapping HIPAA to the Middleware Layer Sandra Senti Biological Sciences Division University of Chicago C opyright Sandra Senti,
Identity Management – Why and How Experiences at CU-Boulder Copyright Linda Drake, Director of Development and Integration, University of Colorado, Boulder,
EDUCAUSE April 25, 2006Enforcing Compliance with Security Policies … Enforcing Compliance of Campus Security Policies Through a Secure Identity Management.
Baylor University and Xythos EduCause Southwest 2007 Dr. Sandra Bennett Program Manager Online Teaching and Learning System Copyright Sandra Bennett 2007.
Sharing MU's SharePoint Experience 2005 Midwest Regional Conference Innovative Use of Technology: Getting IT Done Wednesday, March 23, 2005.
Meeting Strategic Initiatives with Legacy Applications Donovan Follette Washington State University Copyright Donovan Follette This work is the intellectual.
ProACT : High Tech, High Touch Prospect and Communication Tracking System CUMREC 2004 “Spicing Up Technology” Austin, Texas May 17, 2004 Van Follette Washington.
1 No More Paper, No More Stamps: Targeted myWSU Communications Lavon R. Frazier April 27, 2005 Copyright Lavon R. Frazier, This work is the intellectual.
Herding CATS: the Community of Academic Technology Staff Lou Zweier, Director CSU Center for Distributed Learning The California State University NLII,
Beyond the Campus Gates: Bringing Alumni, Parents, and Prospects into the Campus Portal William P. Wilson Mark R. Albert John C. Duffy Gettysburg College.
Catalyst Portfolio Tool Copyright Tom Lewis, This work is the intellectual property.
Serving MERLOT on Your Campus Gerry Hanley California State University and MERLOT Seminars on Academic Computing August 7, 2002 Snowmass CO Copyright Gerard.
HumaniTech®: Educause, Seattle October 24, 2007 Bridging Divides, Building Collaborations
NERCOMP Managing Campus Affiliates Managing Campus Affiliates Faculty? Student? Faculty? Student? Staff? Criss Laidlaw Director of Administrative.
Office of Information Technology Balancing Technology and Privacy – the Directory Conundrum January 2007 Copyright Barbara Hope and Lori Kasamatsu 2007.
NERCOMP 2002 Ten Things IT Staff Need to Know About Education Records Privacy Jeff von Munkwitz-Smith University Registrar University of Connecticut.
UWM CIO Office Where Did These Customizations Come From? Do We Need Them? March 14, 2007 Jill Unglaub, Senior Application Analyst Information and Media.
University of Michigan Enterprise Directory Services Appendix A Conceptual Architecture.
Copyright Copyright University of Washington This work is the intellectual property of the author. Permission is granted for this material to be.
UCLA Enterprise Directory Identity Management Infrastructure UC Enrollment Service Technical Conference October 16, 2007 Ying Ma
Copyright © 2003, The University of Texas at Austin. This work is the intellectual property of the author. Permission is granted for this material to be.
MEMBERSHIP AND IDENTITY Active server pages (ASP.NET) 1 Chapter-4.
Copyright © 2006, Infinite Campus, Inc. All rights reserved. User Security Administration.
EDUCAUSE 2003 Copyright Toshiyuki Urata 2003 This work is the intellectual property of the author. Permission is granted for this material to be shared.
Copyright Statement Copyright Robert J. Brentrup This work is the intellectual property of the author. Permission is granted for this material to.
Quickly Establishing A Workable IT Security Program EDUCAUSE Mid-Atlantic Regional Conference January 10-12, 2006 Copyright Robert E. Neale This.
Authors: Victoria F. Sarkisian, Linguistic Coordinator at the Academic Learning Center Austin C. Schilling, Senior Consultant at IBM In collaboration with:
NMI-EDIT and Rice University Federated Identity Management: Managing Access to Resources in Texas Barry Ribbeck Director System Architecture and Infrastructure.
Copyright Michael White and Sylvia Maxwell, This work is the intellectual property of the author. Permission is granted for this material to be shared.
© Scottsdale Community College Leveraging the Power of E-Learning Taking your course to a higher level Presented by Sidne Tate Director, Instructional.
Resources to CAMP: Charting Your Authentication Roadmap.
University of Southern California Identity and Access Management (IAM)
Federated Identity Management at Virginia Tech
John O’Keefe Director of Academic Technology & Network Services
University of Southern California Identity and Access Management (IAM)
October 20, 2004 CAMP: Delivering, Sourcing, and Securing Services Throughout the Student Identity Life Cycle Stage 1: Establishing a Relationship.
myIS.neu.edu – presentation screen shots accompany:
October 20, 2004 CAMP: Delivering, Sourcing, and Securing Services Throughout the Student Identity Life Cycle Stage 1: Establishing a Relationship.
Managing Enterprise Directories: Operational Issues
Presentation transcript:

1 Extending Authenticated Online Services with "Friend Accounts" at Washington State University Brian Foley Technology Architect/Application Developer Washington State University 2007 Washington State University This work is the intellectual property of the author. Permission is granted for this material to be shared for non-commercial, educational purposes, provided that this copyright statement appears on the reproduced materials and notice is given that the copying is by permission of the author. To disseminate otherwise or to republish requires written permission from the author.

2 Summary About Washington State University Identity Management at WSU Need for Friend Accounts Friend Accounts Project Friend Accounts Demo Future Use Recap Questions

3 About Washington State University Land-grant university founded in ,428 students statewide Research I status Four regional campuses Multiple learning centers Distance education program 10 Colleges and a Graduate School 245 Fields of Study with over 150 majors

4 Pullman Tri-Cities Vancouver Spokane ~DDP~

5

6 Identity Management at WSU WSU’s technology environment as relevant to Friend Accounts…

8 Identity Management at WSU Active Directory Primary identity store User accounts, user attributes, group memberships, and computer accounts Authenticates users to web and computer resources Group memberships for authorizations Single Sign On with Active Directory Federation Services (ADFS) Provisioning of identity information with Microsoft Identity Integration Server (MIIS)

9 Identity Management at WSU WSU Network ID’s –Must have a WSU ID Number to be eligible for a Network ID WSU ID Number –Nine digit unique identifier –Only WSU Student, Faculty, or Staff are eligible for a WSU ID Number –Assigned at the point that an associate is entered into core legacy system and is the primary key

10 Need for Friend Accounts Non-WSU students attending WSU courses and guest teachers/lecturers –Learning Management Systems WebCT, Blackboard, SharePoint –Lab access –“myWSU” portal access –VPN wireless network access

11 Need for Friend Accounts Parents/Guardians/Relatives/Spouse –Online electronic payments of tuition, housing, child care, etc. NACHA Requirements –Precursor to “Proxy Access”

12 Need for Friend Accounts Prospective Employers & Outside Advisors –View online portfolios (“mySite”) Conference Attendees –VPN wireless network access Search Committees/Advisory Groups with non-WSU members –SharePoint collaboration sites

13 Friend Accounts Project Project Team Collaborative project between two ITS groups –University Information System Services Director, Student Systems Coordinator, Data Architect, Technology Architect, 2-3 Application Developer/Analysts Analysis, Design, Development, and Implementation of application –Operations & System Support (Infrastructure) Director, Coordinator, Systems Developer/Analyst Analysis, Design, Development, and Implementation of identity provisioning interfaces.

14 Friend Accounts Project Design Decisions Friend Accounts to reside in Active Directory –Parallel to Network IDs Authentication identical to Network IDs –Resources that authenticate against Active Directory should not have to change to be able to authenticate Friend Accounts (although some business rules may change after authentication) Friend Account user ID is equal to the “friend’s” address

15 Friend Accounts Project Design Decisions Friend Account ID must be changeable –As address changes we must allow user to change Friend Account ID Different types of authorizations –Role-based sponsorship to specific resources VPN Wireless Network, Class resources, myWSU Portal, etc. –External authorizations Online portfolio, SharePoint collaboration sites, etc. –Automatic authorizations Authorized if authenticated (no authorization, just authentication)

16 Friend Accounts Project Design Decisions Friend Account does NOT have a WSU ID Number –Friend Account holders do not have a student/faculty/staff official relationship with the university –Not entered into WSU’s core legacy administrative systems –Alternate unique identifier generated when created CN = sAMAccountName = “fred!F4679”

17 Friend Accounts Project Design Decisions Friend Account can be created by a sponsor or by self-service –User with WSU Network ID or a Friend Account can sponsor the creation of a Friend Account Sponsor can grant authorizations to resources at the same time (depending on sponsor’s role) –“Friend” can create a Friend Account on their own “Friend” cannot grant their own authorizations to resources

18 Friend Accounts Project Design Decisions Friend Account Activation/Verification –Friend Accounts are created in “expired” status, and are non-functional –Activation is sent to the Friend Account holder at the address that his/her Friend Account ID is named after –Friend Account holder receives the Activation containing a one-time randomly generated password

19 Friend Accounts Project Design Decisions Friend Account Activation/Verification –Friend Account holder must go to Friend Accounts web page to activate their account and reset password –Friend Account holder verifies his/her Name and Address information and indicates if that information should be restricted from the campus directory –Friend Account is then set to active and resource authorizations (if any) are provisioned into Active Directory, myWSU portal, etc.

20 Friend Accounts Project Design Decisions Class Resource Authorizations –Needed for a non-WSU student taking a WSU course or a guest teacher/lecturer –Authorization to class resources are sponsored by authorizing to course section(s) Only WSU employees can sponsor class resource authorizations –Class “membership” provisioned to Active Directory groups, myWSU portal groups, and Learning Management Systems

21 Identity Management at WSU WSU’s new technology environment as relevant to Friend Accounts…

23 Friend Accounts Demo Scenario: –I am a WSU teacher with a non-WSU student attending my course. I have a Blackboard site for my class that I need her to be able to participate in. The student also needs access to the myWSU Portal. Sponsored creation and authorizations…  WSU Employee role  Non-WSU Student role

24 Future Use Proxy Access –Granted Authorizations Students would give parents/relatives/spouse/etc. access to view their myWSU services/data –Increased Security Students would no longer feel the need to give their parents their Network ID and Password

25 Future Use Proxy Access –Example: Student gives access to her mom to be able to see her account balances and class schedule. She also gives her dad access to see her grades and her DARS degree audit. Both mom and dad would have a Friend Account that she could give specific proxy authorizations to. Note: She could also give proxy access to her spouse, who is also a WSU student and has a WSU Network ID (proxy access not restricted to Friend Accounts).

26 Recap Success! –Non-WSU students/teachers –Conference attendees –Parents/Guardians/Family –Outside advisors –Consultants Excellent Feedback –Highlighted on front page of WSU newspaper –Departments are excited

27 Questions? Brian Foley Technology Architect / Applications Developer Analyst University Information Systems Services Washington State University