Download - 2014-04-05 - SPSPhilly - Authentication and Authorization

Transcript
Page 1: 2014-04-05 - SPSPhilly - Authentication and Authorization

SPS Philly

Page 3: 2014-04-05 - SPSPhilly - Authentication and Authorization

SharePoint User Group

• SharePoint

• End Users

• Administrators

• Architects

• Developers

• IT Pros

• Meetings: 2nd Tuesday of the month, Microsoft Malvern, 5:30-8 pm

WEB: www.TriStateSharePoint.org

EMAIL: [email protected]

TWITTER: @tristateSP

Page 4: 2014-04-05 - SPSPhilly - Authentication and Authorization

Dan Usher

Lead Associate

Booz Allen Hamilton

[email protected]

http://www.sharepointdan.com

Page 5: 2014-04-05 - SPSPhilly - Authentication and Authorization
Page 6: 2014-04-05 - SPSPhilly - Authentication and Authorization

http://www.yammer.com/spyam

Page 7: 2014-04-05 - SPSPhilly - Authentication and Authorization
Page 8: 2014-04-05 - SPSPhilly - Authentication and Authorization
Page 9: 2014-04-05 - SPSPhilly - Authentication and Authorization

http://go.spdan.com/kerberos2010

http://go.spdan.com/kerberos2013

http://go.spdan.com/multihopwinrm

Page 10: 2014-04-05 - SPSPhilly - Authentication and Authorization

http://xkcd.com/1240/

Page 11: 2014-04-05 - SPSPhilly - Authentication and Authorization

Security in General

Page 12: 2014-04-05 - SPSPhilly - Authentication and Authorization

Security in General

Page 13: 2014-04-05 - SPSPhilly - Authentication and Authorization
Page 14: 2014-04-05 - SPSPhilly - Authentication and Authorization
Page 15: 2014-04-05 - SPSPhilly - Authentication and Authorization
Page 16: 2014-04-05 - SPSPhilly - Authentication and Authorization
Page 17: 2014-04-05 - SPSPhilly - Authentication and Authorization
Page 18: 2014-04-05 - SPSPhilly - Authentication and Authorization
Page 19: 2014-04-05 - SPSPhilly - Authentication and Authorization
Page 20: 2014-04-05 - SPSPhilly - Authentication and Authorization
Page 21: 2014-04-05 - SPSPhilly - Authentication and Authorization
Page 22: 2014-04-05 - SPSPhilly - Authentication and Authorization
Page 23: 2014-04-05 - SPSPhilly - Authentication and Authorization
Page 24: 2014-04-05 - SPSPhilly - Authentication and Authorization
Page 25: 2014-04-05 - SPSPhilly - Authentication and Authorization
Page 26: 2014-04-05 - SPSPhilly - Authentication and Authorization
Page 27: 2014-04-05 - SPSPhilly - Authentication and Authorization

Anonymous

Authentication

Is In Site Group?

Does user have claim attribute?

Web Application / Site Collection

Secured Site / Site Collection / Content

Content Repository

Content

Page 28: 2014-04-05 - SPSPhilly - Authentication and Authorization

So

urc

e: htt

p:/

/go

.sp

dan

.com

/iis

auth

ASP.

NET A

uth

en

tica

tio

n

Page 29: 2014-04-05 - SPSPhilly - Authentication and Authorization

http://go.spdan.com/cba

Page 30: 2014-04-05 - SPSPhilly - Authentication and Authorization

http://go.spdan.com/cba

Page 31: 2014-04-05 - SPSPhilly - Authentication and Authorization
Page 32: 2014-04-05 - SPSPhilly - Authentication and Authorization
Page 33: 2014-04-05 - SPSPhilly - Authentication and Authorization
Page 34: 2014-04-05 - SPSPhilly - Authentication and Authorization

htt

p:/

/go

.sp

dan.c

om

/cla

imse

nco

din

g

Page 35: 2014-04-05 - SPSPhilly - Authentication and Authorization

htt

p:/

/go

.sp

dan.c

om

/cla

imse

nco

din

g

Page 36: 2014-04-05 - SPSPhilly - Authentication and Authorization

1. Resource Requested

2. AuthN Request / Redirect

3. AuthN Request

4. Security Token

5. Security Token Request

6. Service Token

7. Resource Request w/Service Token

8. Resource Sent

Identity Provider Security Token Service

aka IP-STS

SharePoint 2010aka RP

Page 37: 2014-04-05 - SPSPhilly - Authentication and Authorization
Page 38: 2014-04-05 - SPSPhilly - Authentication and Authorization
Page 39: 2014-04-05 - SPSPhilly - Authentication and Authorization
Page 40: 2014-04-05 - SPSPhilly - Authentication and Authorization
Page 41: 2014-04-05 - SPSPhilly - Authentication and Authorization
Page 42: 2014-04-05 - SPSPhilly - Authentication and Authorization
Page 43: 2014-04-05 - SPSPhilly - Authentication and Authorization
Page 44: 2014-04-05 - SPSPhilly - Authentication and Authorization
Page 45: 2014-04-05 - SPSPhilly - Authentication and Authorization
Page 46: 2014-04-05 - SPSPhilly - Authentication and Authorization
Page 47: 2014-04-05 - SPSPhilly - Authentication and Authorization
Page 48: 2014-04-05 - SPSPhilly - Authentication and Authorization
Page 49: 2014-04-05 - SPSPhilly - Authentication and Authorization
Page 50: 2014-04-05 - SPSPhilly - Authentication and Authorization
Page 51: 2014-04-05 - SPSPhilly - Authentication and Authorization
Page 52: 2014-04-05 - SPSPhilly - Authentication and Authorization
Page 53: 2014-04-05 - SPSPhilly - Authentication and Authorization
Page 54: 2014-04-05 - SPSPhilly - Authentication and Authorization
Page 55: 2014-04-05 - SPSPhilly - Authentication and Authorization
Page 56: 2014-04-05 - SPSPhilly - Authentication and Authorization
Page 57: 2014-04-05 - SPSPhilly - Authentication and Authorization
Page 58: 2014-04-05 - SPSPhilly - Authentication and Authorization
Page 59: 2014-04-05 - SPSPhilly - Authentication and Authorization
Page 60: 2014-04-05 - SPSPhilly - Authentication and Authorization
Page 61: 2014-04-05 - SPSPhilly - Authentication and Authorization
Page 62: 2014-04-05 - SPSPhilly - Authentication and Authorization
Page 63: 2014-04-05 - SPSPhilly - Authentication and Authorization
Page 64: 2014-04-05 - SPSPhilly - Authentication and Authorization
Page 65: 2014-04-05 - SPSPhilly - Authentication and Authorization
Page 66: 2014-04-05 - SPSPhilly - Authentication and Authorization

https://sts.domain.com

Page 67: 2014-04-05 - SPSPhilly - Authentication and Authorization
Page 68: 2014-04-05 - SPSPhilly - Authentication and Authorization
Page 69: 2014-04-05 - SPSPhilly - Authentication and Authorization

Page 70: 2014-04-05 - SPSPhilly - Authentication and Authorization