Identity Management in Windows Server 2003 R2: Active Directory Federation Services
Identity Management in Windows Server 2003 R2: Active Directory Federation Services
OLAV TVEDT
EMENTOR
What Will We Cover?
• Identity Management
• New and improved features in R2
• What Active Directory® Federation
Services (ADFS) is, and what it does
• How ADFS works
Helpful Experience
• Knowledge of Active Directory
• Understanding of Certificates
• Authentication and authorization methods
• IIS and Web application principles
Level 300
Agenda
• Identity Management
• Active Directory Application Mode (ADAM)
• UNIX Identity Management
• Active Directory Federation Services (ADFS)
Identity Management Vision
UNIX
Workstation Windows
Workstation
UNIX
Workstation Windows
Workstation
UNIX Windows
Server Server
UNIX Identity Management
Objective of Interoperation
• Goal: Efficient cross-platform user
management
Consolidate administration and monitoring across
platforms
Manage Windows and UNIX-based systems with
the same tools
Server for NIS
• Makes a Windows Server 2003 Active Directory into an NIS
master server
NIS Clients
Server for NIS
SubordinateSubordinateSubordinate Master
NIS Clients
UNIX Password Synchronization
• Pull NIS schema into Active Directory
• Bidirectional Password Sync, user name
mapping
• Supported on several common platforms
• Mapping Server
Map Windows® User and Group Accounts to UNIX
• Testet ut på Sun Solaris 8 & 9, HP-UX 11i, IBM AIX 5L 5.2 og Red Hat 9.0, men bør virke på
alle LDAP baserte versjoner
Agenda
• Identity Management
• ADAM
• UNIX Identity Management
• ADFS
Federated Identity Management
• Federation: trust-based relationships
across organizations
• Benefits:
Accelerates creation of relationships
Standardization for integration with partners
Security
What is ADFS?
• Active Directory-based ID federation
Simplified, secure sharing of digital identities
across security boundaries
Web single sign-on
Interoperability via Web Services (WS-*)
ADFS: Standards-based Solution
Java, Unix,
.Net Apps IBM PingID Linux Apps
Active
Directory BMC Oracle
Federation CA Quest
Services RSA Centrify
+ others…
ADFS Architecture
Windows
LPC/Web Authentication/
Methods LDAP
FS-P FS HTTPS
AD or
ADAM
Federation Trust
Active Directory
Account Resource
Federation Server Federation Server
• Client Certificate
Web browser receives a request to present a client certificate and the
user may choose which certificate to present
• Forms-based
Present a customizable web page to the user requesting credentials
• Basic
Web browser presents the standard username/password dialog
Claims-aware Federation Process
• Configure environments
• Create claims
• Create claim transforms
• Establish trust
• Enable the claims for the application
Group
Custom
Understanding Transforms
• Transforms are instructions that map
claims between partners
• Used by the resource partner to make
authorization decisions
Establishing Trust
• Assumes proper partner relationship agreements
• Carefully consider security ramifications
Method for transfer of certificates between organizations
• Mechanics:
Account partner must transfer token signing certificate to resource
Resource uses ADFS snap-in to establish trust and enable account
partner
Demo
demonstration
Session Summary
• Windows Server 2003 R2 delivers important
functionality toward the Microsoft vision for
Identity Management
• ADFS is a key, new component
• ADFS is standards-based (WS-*), integrates
with third party federation solutions