I'm attending a session on ADFS, Microsoft's implementation of Federated Identity and Access Management (FIAM). Diane Dickinson of WSU ITS is describing ADFS, noting that it is standards-based (WS-Federation passive requestor profile, SAML version 1.1). The architecture is split into a FS/STS, which manages federation policy, an FS Proxy, and the ADFS Web Agent. The Web Agent is made up of an ISAPI extension and an Authentication Service. The basic ADFS scenario can be summarized as: user / browser / application / ADFS. Dickinson pointed out that WSU was an early adopter of ADFS, which enabled greater interaction with Microsoft technologists during the implementation process.
Brian Foley just took the podium, describing ADFS unified sign-in. ADFS is generally supported on Windows Server 2003 R2 with ASP.NET 2.0. The .NET System.Web.Security.SingleSignOn assemblies must be referenced in application programs.
I've taken from this ITS Forum a greater appreciation of the data security issue. Alan Brill's presentation was both interesting and unnerving. He emphasized the importance of data minimization and of identifying and gaining control over stealth applications.
Subscribe to:
Post Comments (Atom)

No comments:
Post a Comment