14
SAML-IN / SAML-OUT Scott Tomilson John DaSilva

CIS 2015 SAML-IN / SAML-OUT - Scott Tomilson & John Dasilva

Embed Size (px)

Citation preview

Page 1: CIS 2015 SAML-IN / SAML-OUT - Scott Tomilson & John Dasilva

SAML-IN / SAML-OUT Scott Tomilson John DaSilva

Page 2: CIS 2015 SAML-IN / SAML-OUT - Scott Tomilson & John Dasilva

Copyright © 2015 Cloud Identity Summit. All rights reserved. 2

Golf

Building Federated Relationships

Your Apps Your Partners

Acme

Beta

Com

SAML ✔

SAML ✔

SAML ✔

Fox Echo

Delta

Page 3: CIS 2015 SAML-IN / SAML-OUT - Scott Tomilson & John Dasilva

Copyright © 2015 Cloud Identity Summit. All rights reserved. 3

Groundhog Day

“It’s always February 2nd, and there’s nothing you can do about it.” “It’s always SSO Day, and there’s nothing you can do about it.”

Page 4: CIS 2015 SAML-IN / SAML-OUT - Scott Tomilson & John Dasilva

Copyright © 2015 Cloud Identity Summit . All rights reserved. 4 Copyright © 2015 Cloud Identity Summit. All rights reserved. 4

Give me SSO!!

Page 5: CIS 2015 SAML-IN / SAML-OUT - Scott Tomilson & John Dasilva

Copyright © 2015 Cloud Identity Summit. All rights reserved. 5

Building Federated Relationships

Your Apps Your Partners

Acme

Beta

Com

SAML

SAML

SAML

Federation Hub

Page 6: CIS 2015 SAML-IN / SAML-OUT - Scott Tomilson & John Dasilva

Extending Federation Capabilities

SSO

WS-Fed

Login Acme

Page 7: CIS 2015 SAML-IN / SAML-OUT - Scott Tomilson & John Dasilva

Extending Federation Capabilities

SSO

WS-Fed

Login

1 Protocol 1 Partner

Acme

Page 8: CIS 2015 SAML-IN / SAML-OUT - Scott Tomilson & John Dasilva

Extending Federation Capabilities

SSO

WS-Fed

Login

1 Protocol 1 Partner

Q: How can you extend your SharePoint environment to additional business partners?

Acme

Page 9: CIS 2015 SAML-IN / SAML-OUT - Scott Tomilson & John Dasilva

Extending Federation Capabilities

SSO

WS-Fed

Federation Hub

Page 10: CIS 2015 SAML-IN / SAML-OUT - Scott Tomilson & John Dasilva

Extending Federation Capabilities

SSO

WS-Fed

Login WS-Fed Acme

Federation Hub

Page 11: CIS 2015 SAML-IN / SAML-OUT - Scott Tomilson & John Dasilva

Extending Federation Capabilities

SSO

WS-Fed

Federation Hub

Login WS-Fed

Login

Login

SAML

SAML

Acme

Beta

Com

… this could easily be any app constrained to a 1 IdP configuration

Page 12: CIS 2015 SAML-IN / SAML-OUT - Scott Tomilson & John Dasilva

Federation Protocol Translation

SSO to SP

SSO From IdPs

Translate From Translate To SAML SAML

SAML WS-Fed

WS-Fed SAML

WS-Fed WS-Fed

SAML OpenID Connect

WS-Fed OpenID Connect

Page 13: CIS 2015 SAML-IN / SAML-OUT - Scott Tomilson & John Dasilva

Copyright © 2015 Cloud Identity Summit. All rights reserved. 13

Moving to Next Gen Identity

Your Apps Your Partners

Acme

Beta

Com

OpenID Connect

Federation Hub

OpenID Connect

OpenID Connect

SAML

Page 14: CIS 2015 SAML-IN / SAML-OUT - Scott Tomilson & John Dasilva

Copyright © 2015 Cloud Identity Summit . All rights reserved. 14 Copyright © 2015 Cloud Identity Summit. All rights reserved. 14

Holy SSO!!