Emory University Case Study I2 Day Camp November 5, 2010 John Ellis & Elliot Kendall.

Slides:



Advertisements
Similar presentations
Click to edit Master title style HEALTH INFORMATION 1 Identity & Access Management Presenter: Mike Davis (760) January 09, 2007.
Advertisements

Office 365 Identity June 2013 Microsoft Office365 4/2/2017
How Identity and Access Management Can Help Your Institution Touch Its Toes Renee Woodten Frost Internet2 and University of Michigan Kevin Morooney The.
Doug Couto Information Systems and Technology Committee (ABJ50) Washington, DC January 25, 2011.
Overview of Priorities and Activities: Shared Services Canada Presentation to the Information Technology Infrastructure Roundtable June 17, 2013 Liseanne.
1 Johns Hopkins Community Physicians Presentation to MCMS October 25, 2012 Presented by: Matt Poffenroth, MD, MBA Director of Clinical Integration, JHCP.
SINGLE SIGN-ON. Definition - SSO Single sign-on (SSO) is a session/user authentication process that permits a user to enter one name and password in order.
1 eAuthentication in Higher Education Tim Bornholtz Session #47.
1 MAIS Student Administration Advisory Group Meeting #31 October 4, 2006.
1 Identity Management and Access Control Status UNITS Forum, June 2006 Tom Board, NUIT Info Systems Architecture.
Identity and Access Management: Strategy and Solution Sandeep Sinha Lead Product Manager Windows Server Product Management Redmond,
Identity and Access Management
Identity Management and PKI Credentialing at UTHSC-H Bill Weems Academic Technology University of Texas Health Science Center at Houston.
#CONVERGE2014 Session 1304 Managing Telecom Directories in a Distributed or Multi-Vendor Environment David Raanan Starfish Associates.
OAuth option for mHealth Brief Profile Proposal for 2013/14 presented to the IT Infrastructure Planning Committee R Horn (Agfa Healthcare)
Identity and Access Management Business Ready Security Solutions.
Aegis Identity Software, Inc. presents Trends in Identity and Access Management in Higher Education to US Federations June 20, 2012 Janet Yarbrough – Director.
Scenario covered in this presentation Separate credential from on- premises credential Authentication occurs via cloud directory service Does not.
SOA – Development Organization Yogish Pai. 2 IT organization are structured to meet the business needs LOB-IT Aligned to a particular business unit for.
Mission Assurance SI International’s Quality Management System John Wheeler Director, Mission Assurance 16, April 2008.
State of Information Technology Presentation for Faculty Council November 14, 2013 Mike Carlin Vice Chancellor for IT and CIO.
Copyright © The OWASP Foundation Permission is granted to copy, distribute and/or modify this document under the terms of the OWASP License. The OWASP.
Business Intelligence Case Study Sean Downer, Manager Decision Support Royal Children’s Hospital Melbourne.
Re-organizing Information Technology University at Buffalo.
3 Nov 2003 A. Vandenberg © Second NMI Integration Testbed Workshop on Experiences in Middleware Deployment, Anaheim, CA 1 Shibboleth Pilot Local Authentication.
Value & Excitement University Technology Services Oakland University Information Technology Strategic Planning Theresa Rowe October 2004 Copyright Theresa.
Global Customer Partnership Council Forum | 2008 | November 18 1IBM - GCPC MeetingIBM - GCPC Meeting IBM Lotus® Sametime® Meeting Server Deployment and.
Identity Management Practical Issues Associated with Sharing Federated Services UT System Identity Management Federation William A. Weems The University.
Successful Deployment and Solid Management … Close Relatives Tim Sinclair, General Manager, Windows Enterprise Management.
Exploring InCommon Getting Started with InCommon: Creating Your Roadmap.
0 Presentation to: Health IT HIPPA Workshop Presented by: Stacey Harris, Director of Health IT Innovation September 26, 2014 Division of Health Information.
Deploying SharePoint Products and Technologies for Enterprise Collaboration Microsoft IT group’s Centrally Hosted Collaboration Solution.
SECURITY & THE UNIVERSITY INCLUDING A HOSPITAL October 3, 2008 Doyle Friskney Chief Technology Officer University of Kentucky.
Commonwealth IT Consolidation Background and Basic Talking Points (Update Title as Needed) Committee or Person Presenting Date MM/DD/YYYY.
SOM Department Administrators Orientation - IT Overview Rich Mendola VP for Information Technology and CIO
SUNY System Administration Federation Overview Gavin Hogan July 15th, 2009 A work in progress….
Using AS 10g with EBS What are the Benefits of Integrating AS 10g with Oracle Applications?
Identity on Force.com & Benefits of SSO Nick Simha.
Federated or Not: Secure Identity Management Janemarie Duh Identity Management Systems Architect Chair, Security Working Group ITS, Lafayette College.
UCLA Enterprise Directory Identity Management Infrastructure UC Enrollment Service Technical Conference October 16, 2007 Ying Ma
EdReNe, 2nd Strategic Seminar (Lisbon, June 2008) (c) 2008, Daniel Weiler, Centre of Technology of Education Luxembourg’s Educational Portal Enabling Connected.
FEDERATIONS Clair Goldsmith, Ph.D., Associate Vice Chancellor and CIO September 27,
Empowering people-centric IT Unified device management Access and information protection Desktop Virtualization Hybrid Identity.
Shibboleth: An Introduction
Identity and Access Management Roadmap Presentations for Committee on Technology and Architecture March 21, 2012 Amy Day, MBA Director of GME IAM Committee.
Integrating the Healthcare Enterprise Personnel White Pages Profile Name of Presenter IHE affiliation.
Information Technology Current Work in System Architecture January 2004 Tom Board Director, NUIT Information Systems Architecture.
| Copyright© 2011 Microsoft Corporation 1 journey to the cloud KOEN VAN TOLHUYZEN TSP OFFICE 365 MICROSOFT CORPORATION.
The State of Identity Management on Your Campus Session Moderators Jacob Farmer, Indiana University Theresa Semmens, North Dakota State University November.
February, TRANSCEND SHIRO-CAS INTEGRATION ANALYSIS.
Review of ASP/SAS benefits and Web-based Concepts.
University of Washington Collaboration: Identity and Access Management Lori Stevens University of Washington October 2007.
Federations: The New Infrastructure Speaker Name Here Date Here Speaker Name Here Date Here.
Attribute Delivery - Level of Assurance Jack Suess, VP of IT
Identity Management, Federating Identities, and Federations November 21, 2006 Kevin Morooney Jeff Kuhns Renee Shuey.
Commonwealth IT Consolidation Background and Basic Talking Points Date MM/DD/YYYY.
BE-com.eu Brussel, 26 april 2016 EXCHANGE 2010 HYBRID (IN THE EXCHANGE 2016 WORLD)
Active Directory Domain Services (AD DS). Identity and Access (IDA) – An IDA infrastructure should: Store information about users, groups, computers and.
Quarterly Customer Meeting Office 365 License Activation and Office 365 Cloud Services Assessment Status April 2014.
1 Name of Meeting Location Date - Change in Slide Master Authentication & Authorization Technologies for LSST Data Access Jim Basney
OFFICE OF INNOVATION & TECHNOLOGY CITY OF PHILADELPHIA Innovation & Technology Status Update Adel W. EbeidCity of Philadelphia, Office of Innovation &
THE CAMPUS IDENTITY SYSTEM Lucy Lynch, NSRC. Learning Objectives Discovering the key role campus networks play in trusted identities for R&E Authoritative.
Instructional slide to Partner: REMOVE BEFORE PRESENTING TO CUSTOMER
New Developments in Central Directory Service and Account Provisioning Dan Menicucci Enterprise Architect - University of Pittsburgh.
Gain Control of Cloud Integration Strategies Before they Float Away
Shibboleth Project at GSU
Data and Applications Security Developments and Directions
John O’Keefe Director of Academic Technology & Network Services
Federated IdM Across Heterogeneous Clouding Environment
Identity Management at the University of Florida
Presentation transcript:

Emory University Case Study I2 Day Camp November 5, 2010 John Ellis & Elliot Kendall

Facts & Figures 2 Private university in suburban Atlanta ~ 13,000 undergrads, 7,000 grads Professional schools, including Medical, Law, Business, Public Health schools ~ 24,000 employees, including those from our academic medical center (hospitals and clinics) Centralized IT, but many strong departmental IT groups About Emory

Innovation xx NetCom Consolidated network and phone across Emory CIO Single Central IT structure across Emory Enterprise Common solutions across the enterprise (IdM, Exchange) ITIL & PM Frameworks for process improvements Efficiency More capacity available for strategic initiatives Alignment Transition from foundation and operational focus to services and business alignment Strategic Emory IT aligned as a strategic business partner Operational Excellence FoundationConsolidation UTS Combined telecom and application divisions SSO/F ed Shibboleth deployed in production Organizational Waves InCommon After Identity Manager deployment, joined InCommon, completed first POP Governance Transparent, aligned with enterprise mission

Governance and Prioritization for IT Initiatives 4 “Create a set of timely, transparent processes for IT governance and prioritization clearly aligned with the missions of Emory. Create a common business case template that can be used across Healthcare and the Academic enterprise. Develop reporting mechanisms that allow committees to understand performance of application and project portfolios.” IT Foundation

5 Governance

Standard Approach for Directory Services (ID Management, Authentication, Authorization) 6 Synchronize existing directories (e.g., LDAP and Active Directory) so that phone and lookups can occur for all University and Healthcare staff, irrespective of location. Synchronize approach for assigning network IDs across the Academic and Healthcare Enterprise. Migrate existing network IDs and synchronize password credentials and expiration policies. IT Foundation

Identity Management 7 Select identity management vendor; develop a phased-in approach for implementing priority modules such as provisioning and single sign-on. Completion Target Dates: –Proof of Concept by the end of October –Business case presented to IT Governance by January IT Foundation

Siteminder 8 In 2008, Emory had been using Siteminder for number of years Complex, difficult to maintain, difficult to use, and expensive Very low adoption rate No benefits from "single" sign-on Most sites used direct LDAP connections SSO History

With an eye towards federation 9 Wanted to provide better SSO service, improved security Did detailed comparison of popular options: CAS, CoSign, Siteminder, OpenSSO, Shibboleth, etc. Shibboleth distinguished by federation support SSO Choice

Proof of Concept deployed first 10 Shibboleth is complex, but well documented Most implementation time spent re-reading docs, packaging software Completely successfully in a few months, ahead of schedule Commercial contract implementations also available Shibboleth Chosen

Our implementation 11 Deployment on shared JBoss app cluster somewhat challenging Clustering multiple nodes with Terracotta inelegant but straightforward In production and stable on around half a dozen apps Additional apps on hold pending JBoss upgrade to fix bug inherited from old version of Tomcat Shibboleth in production

12 Need to support common attributes for federation – eduPerson, EPPN, etc. Two LDAP infrastructures. User education – understanding SSO Sign-off issues Challenges

13 Proof of concept federated authentication with Georgia Tech Gartner integration InCommon Wiki What’s Next

? 14 Click to add title Questions