Download - CIS14: Lean In: Enterprise Cloud Identity

Transcript
Page 1: CIS14: Lean In: Enterprise Cloud Identity

Nimble: Rethinking Enterprise Cloud Identity Mark Diodati Lean In: Enterprise Cloud Identity

@mark_diodati

Laura E. Hunter Zen and the Art of Enterprise Authentication

@adfskitteh

John Tolbert Is the Cloud Ready for Enterprise Identity and Security Requirements?

Page 2: CIS14: Lean In: Enterprise Cloud Identity

Lean In: Enterprise Cloud Identity

Mark Diodati Mon 14-07-21 [email protected] @mark_diodati

Page 3: CIS14: Lean In: Enterprise Cloud Identity

enterprises are leaning in to address cloud identity challenges

Page 4: CIS14: Lean In: Enterprise Cloud Identity

•  constituencies to applications problem

•  inability to provide identity services for most applications

4  

leaning in: cloud identity management

IDaaS

Page 5: CIS14: Lean In: Enterprise Cloud Identity

•  expansion and complexity

–  who

–  what

•  (im)maturity of cloud applications and platforms

5  

leaning in: cloud IGA

||who

what

Page 6: CIS14: Lean In: Enterprise Cloud Identity

CLOUD IDENTITY MANAGEMENT

Page 7: CIS14: Lean In: Enterprise Cloud Identity

7  

why cloud IAM?

•  IAM requirements for apps in the cloud •  corporate apps (email and office), CRM •  IAM services are not necessarily in the

cloud •  Desire for IDaaS (identity

management -aaS) •  SaaS application model is disrupting

IAM vendors •  Turnkey (faster time to value) •  Reduced costs (hardware and software) •  Elastic (pay as you grow)

Page 8: CIS14: Lean In: Enterprise Cloud Identity

8  

cloud identity components

•  bi-directional on-premises gateway

•  translates on-premises 1.0 identity protocols to cloud 2.0 protocols

•  essential for most enterprises

IDaaS

Page 9: CIS14: Lean In: Enterprise Cloud Identity

9  

to: identity bridge

hosted on-premises federation

IDP directory

sync Kerberos X.509

SaaS application

SS

O

LDAP

prov

isio

nin

g (R

ES

T)

Page 10: CIS14: Lean In: Enterprise Cloud Identity

application

from: identity bridge

hosted on-premises

SAML SP STS

application

partners partners

application

WAM cookie  

OAuth RS and AS

OpenID Provider

Page 11: CIS14: Lean In: Enterprise Cloud Identity

11  

cloud identity components

IDaaS •  Identity Management as a

Service •  externally-hosted, turnkey SaaS •  frequently used with an identity

bridge

Page 12: CIS14: Lean In: Enterprise Cloud Identity

12  

IDaaS market trends

•  More IaaS and PaaS vendors are moving into IDaaS •  Salesforce, Microsoft •  AWS - evolving towards

externalized identity

Page 13: CIS14: Lean In: Enterprise Cloud Identity

13  

IDaaS market trends

•  Mobile authentication vendors will be absorbed into IDaaS •  Completes IDaaS offering/ has

become/will be table stakes •  MFA has diminished value without

other identity services

Page 14: CIS14: Lean In: Enterprise Cloud Identity

Confidential  —  do  not  distribute  

IDaaS sub-market convergence

provisioning/ governance

SSO/ authentication

password vaulting

directory sync

federation

user management

Provisioning

access certification

multi-factor authn

sep of duties

self-service administrative scoping

& delegation

cloud directory

Page 15: CIS14: Lean In: Enterprise Cloud Identity

15  

in: IDaaS

hosted on-premises

SaaS applicati

on

provisioning

SSO authentication user

IDaaS

Page 16: CIS14: Lean In: Enterprise Cloud Identity

provisioning

SSO

16  

IDaaS: internal directory

hosted on-premises

SaaS applicati

on

authentication user

IDaaS

Page 17: CIS14: Lean In: Enterprise Cloud Identity

IDaaS: single directory (AD)

hosted on-premises

SaaS applicati

on

authentication

IDaaS

provisioning

SSO

directory sync Kerberos

Page 18: CIS14: Lean In: Enterprise Cloud Identity

IDaaS: single directory (Google)

directory sync/ runtime store

hosted on-premises

SaaS applicati

on

authentication

IDaaS provisioning

SSO

Sync or runtime

Page 19: CIS14: Lean In: Enterprise Cloud Identity

IDaaS: many-to-many directories

IDaaS partner

partner developer you

Central access policy

Page 20: CIS14: Lean In: Enterprise Cloud Identity

20  

enterprise grade IDaaS

hosted on-premises

IDaaS

identity bridge WAM

EC2`

SaaS application app

Page 21: CIS14: Lean In: Enterprise Cloud Identity

CLOUD IGA

Page 22: CIS14: Lean In: Enterprise Cloud Identity

22  

IGA: a wealth of talents

Provisioning self-service

access certification

separation of duties role management

entitlement management

Page 23: CIS14: Lean In: Enterprise Cloud Identity

An entitlement is a system object that can be granted to enable a user to

perform some set of actions in an application.

Burton Group, 2009

ENTITLEMENT

what

who

Page 24: CIS14: Lean In: Enterprise Cloud Identity

24  

expansion of who

employees contractors

constituency

identity stores

partners consumers

on-premises LDAP

Active

Directory HR

somewhere else LDAP

Active

Directory Facebook

Page 25: CIS14: Lean In: Enterprise Cloud Identity

25  

complexity of who

governance

complexity

“un-control” over identity stores

Page 26: CIS14: Lean In: Enterprise Cloud Identity

expansion of what

applications accessibility

good Active

Directory WAM SharePoint

ERP

maturing SaaS application IaaS

platform

Page 27: CIS14: Lean In: Enterprise Cloud Identity

27  

complexity of what

governance

complexity

“un-control” over applications

Page 28: CIS14: Lean In: Enterprise Cloud Identity

good ole days of IGA ;-)

IGA entitlement management

access certification SoD role management

hosted on-premises

Page 29: CIS14: Lean In: Enterprise Cloud Identity

prov

isio

nin

g (R

ES

T)

SS

O

reminder: to the cloud SSO

hosted on-premises federation IDP directory sync

Kerberos X.509

SaaS application

LDAP

Page 30: CIS14: Lean In: Enterprise Cloud Identity

cloud SSO: entitlement management

hosted on-premises

SaaS application

federation IDP

identity store

IGA entitlements

Page 31: CIS14: Lean In: Enterprise Cloud Identity

to the cloud SSO: entitlement view

CRM LDAP group IS_CRM_MGR LDAP

attribute

federation IDP

SaaS application

identity store

LDAP group and attribute(s) mapped to SaaS profile

CRM_MANAGER

CRM_MANAGER profile has access to SaaS and to specific transactions

Cou

rse

to fi

ne

CRM LDAP group get access to SaaS app with

IS_CRM_MGR attribute

Page 32: CIS14: Lean In: Enterprise Cloud Identity

32  

evolution of cloud IGA

quality of

governance

Component maturity

“distance” of identity store

AD/LDAP groups

federation IDP

entitlements

SaaS/IaaS entitlemen

ts federation/SaaSactivit

y logs

Page 33: CIS14: Lean In: Enterprise Cloud Identity

RECOMMENDATIONS the path forward

Page 34: CIS14: Lean In: Enterprise Cloud Identity

recommendations

• cloud IAM –  clarify your vision for modern IAM

–  monitor cloud IAM developments

•  holistic, SaaS-style integration

•  multi-constituency support

•  broader application management

34  

Page 35: CIS14: Lean In: Enterprise Cloud Identity

recommendations

• cloud IGA –  understand your IGA requirements before migrating

applications to the cloud

–  define a transitional IGA strategy for cloud applications •  Push your SaaS/IaaS vendors to add entitlement and activity

management capabilities

Page 36: CIS14: Lean In: Enterprise Cloud Identity