Presentation is loading. Please wait.

Presentation is loading. Please wait.

Introducing Access Management

Similar presentations


Presentation on theme: "Introducing Access Management"— Presentation transcript:

1 Introducing Access Management
IAMUCLA Mini-Conference November 18, 2008

2 IAMUCLA “Simplified and Streamlined User Identity & Access Management”

3 IAMUCLA Access Management (Authorization) Authentication
Enterprise User Identity Store

4 IAMUCLA Authentication Access Management (Authorization)
UCLA Logon ID Standard Web SSO (Shibboleth) Groups and Roles Access Management (Authorization) Privilege Management Enterprise User Identity Store Enterprise User Identity Store

5 Authorization Re-cap <subject> can <perform action> on <resource> given <constraint>. Joe Bruin can edit pages on the IAMUCLA site. Students enrolled in Math 33A can view contents of the Math 33A Course Web Site.

6 “I manage access using roles
“I manage access using roles. Just tell me what groups the logged in person is in.” Most applications want group membership data. Applications use group member data to make authorization decisions

7 “Groups based on PPS/SRS/other university data are great, except that I need to add this one exception…”

8 Grouper Internet2 developed group management software Open source
Flexible group management capabilities Ongoing work to integrate with other I2 initiatives

9 Grouper in IAMUCLA PPS SRS Enterprise Directory Shibboleth Grouper
4 1 3 SRS Group Membership/Role Attribute Storage and Delivery 2 Grouper generates university groups/roles automatically using known data sources Administrators create custom groups Group data provisioned into Enterprise Directory Group data delivered to applications via Shibboleth Others Administrators University Data Sources Group Management

10 Demonstration

11 Grouper for Naga Gamers
PPS Enterprise Directory Shibboleth Grouper 4 1 3 SRS Group Membership/Role Attribute Storage and Delivery 2 Grouper generates university groups/roles automatically using known data sources Administrators create custom groups Group data provisioned into Enterprise Directory Group data delivered to applications via Shibboleth Others Administrators University Data Sources Group Management

12 Using Grouper Data to Manage Access
Group data delivered through Shibboleth attribute response Protect static content using Shibboleth SP Map attributes to groups in applications

13 https://spaces.ais.ucla.edu/iamucla

14 EVERYBODY PANIC!!! OMG! O NOES!


Download ppt "Introducing Access Management"

Similar presentations


Ads by Google