SlideShare a Scribd company logo
Synergies Across APIs and IAM
Ingredients For winning digital transformation strategy
Nov , 2017
Sagara Gunathunga - Director, WSO2
ABOUT WSO2
2
Mountain View,
New York, London,
Sao Paolo, Colombo
Founded in 2005
Venture backed by
Cisco and Toba Capital
450 Employees;
300 Engineers
400+ Customers,
120 New Customers
in 2016
Profitable
Business since 2016
OPEN TECHNOLOGY FOR AGILE DIGITAL BUSINESS
3
Build internal and
external developer
ecosystems with an
API marketplace.
Manage identity,
security, and
privacy across
your digital
business.
Make mobile and IoT
devices integral to
your digital business.
Create real-time, intelligent,
actionable business insights
and data products.
Platform enable your digital
business with “micro-services”
and “micro-integrations”.
Digital Transformation
will decide and shape
The destiny of your business
Digital Transformation
is no longer a nice to
have or a differentiator,
it’s about the survival
of your business
Is it the Right Time to Think?
A nice to have
A differentiator
For survival
Is it Real?
Look Around You!
Is it Real?
Digitize Delivery
Channels
Personalized User
Experience
Highly connected
business offerings
Digital Transformation
• Sales increasingly based on real user reviews and ratings
than traditional marketing
• Physical stores replaced with digital channels (web
stores, mobile apps, IVR solutions)
• Fast consumer response time and convenience means
connectivity (e.g. Facebook, Twitter, WhatsApp)
Challenge 1 - Digitize Delivery Channels
Generic user experiences don’t
work, consumers now expect
– A highly personalized
experience
– Control over preferences
– Relativeness of content
Challenge 2 - Personalized User Experience
Fulfill all the related business requirements
at one-stop.
• Save consumer time and avoid data
duplications.
• Fast and efficient B2B integration.
• Adoption of open business interfaces
Challenge 3 - Highly connected business offerings
Synergies Across
APIs and IAM
is the right answer
API Management
Digitize Delivery
Channels
Highly connected
business offerings
Reality of Enterprise Systems Landscape
● Enterprise systems are complex
● Enterprise systems are bureaucratic
● Cannot afford the luxury of
complete re-write or having a clean
slate
● Comes with years of baggage
14
15
API Always Comes First
16
Present Day Enterprise Architecture
Analytics
Continuous-*
Security &
Access Management
API / Service discovery
Dev toolsDevops tools
Service router
API Gateway
Core
Microservices
Data
Container(s)
Delivery channels Digital Products
Messaging Channels Integration
MicroservicesExisting Services
17
APIs are found in Every Layer
18
The modern API
● RESTful & JSON savvy - being lightweight, REST style conformant
● Well documented - Methods, operations, responses, error codes etc
● Manageable (life-cycle, version)
● Discoverable - Searchable, testable
● Measurable
● Secured - Multiple security protocol support, transformable
Key Performance Factors of an API Platform
● Security
● Rate Limiting
● Integration
● Analytics
19
API Gateway
20
Security
Rate
Limiting
Integration
Analytics
Gateway
Apps Services and
Data
Security: Identity
● Authentication
● Single Sign On
● Federation
● Authorization
21
Authenticate via Facebook to Airbnb APIs
Security: Access Delegation
● Secure Trusted Clients
● Secure Untrusted Clients
● Unsecure Clients
● System to System Auth/z
22
People Apps
Rate Limiting: Front End
● Monetization
● Burst Control
● Fair Usage Policy
● Geographical Distribution
● Distribution by Device Type
23
People Apps Gateway
Rate Limiting: Back-End
● Prevent Total Service
Outage at Peaks
● Back-End Server
Maintenance
24
Gateway
Services
and Data
Integration
25
Interface
Integration
Integration
26
Analytics: Statistical Analysis
27
Analytics: Operational
● API Latency Distribution
● Alerting on Abnormalities
● API Health
28
WSO2 API Manager
30
● Currently at version 2.1.0 with over 6 years of engineering improvements
across 15 stable releases
● Geo distributed and clustered deployments
○ In production at StubHub / Verizon / Motorola / BYU / BNY
● Same code base at WSO2 API Cloud running with four 9s uptime
● One major and 3 minor releases per year
● Automated deployment with puppet
● Containerized with Docker
Battle hardened
31
WSO2 API Manager
● Available as a single
downloadable package
● Available as a cloud / SaaS
solution
● Flexible deployment choices
● High performance gateway
● API governance, marketplace
solution
32
Cloud First or Start On-Prem
● Multi-tenanted, shared
everything
● WSO2 Hosted and managed
● Pay as you go
● Multi-region availability
● VPN tunnel to private DC
● Guaranteed uptime
● Limited options in customizing
● Privately hosted
● WSO2 managed
● Upgrades, patches installation
● Guaranteed uptime
● Full flexibility in customization
● Better control
● Self hosted
● Self managed
● Full flexibility
● Dev-ops learning curve
● Self managed upgrades
http://wso2.com/api-management/cloud/
https://docs.wso2.com/display/ManagedCl
oud/WSO2+Managed+Cloud+Documenta
tion
33
Componentized
Identity and Access Management
Personalized User
Experience
Highly connected
business offerings
Users onboarding
• Employees vs.
customers
• Self signup
• Self signup with
verification
• Approval workflows
Bring Your Own Identity (BYOI)
New to Hi!
Sign Up
Welcome
Sagara
Authentication
• Multi-factor
authentication
• Adaptive authentication
• FIDO U2F, TOTP,
SMS/Email OTP
• LDAP, Database, AD
Social Authentication
New to Hi!
Sign Up
Welcome
Sagara
Two-Factor Authentication
STEP 1
STEP 2
Welcome
Sagara
Authorization
• Role-based
• Attribute-based
• XACML REST API
• Policy templates
Single sign-on (SSO)
• Social logins eliminate
password management
complexities from
consumer and business
side
• Out-of-the-box support
for strong authentication
options, such as 2-factor
authentication
Welcome
Welcome
Self-service
• User portal
• Password reset
• Self access requests
• Consent management
• Profile update
• Password reset
• Account recovery
Monitoring and Analytics
• Login analytics
• Session analytics
• Fraud
detection/prevention
WSO2 Identity Server
▪ Addresses critical IAM needs both in customer IAM and workforce IAM spaces
▪ Most of the WSO2 IS deployments are to address CIAM needs
▪ Extensive support for open standards - no vendor locking
▪ Large scale deployments over millions of users
▪ Rich eco system with 40+ connectors
(https://store.wso2.com/store/assets/isconnector/list)
▪ Support for multi-tenancy
▪ Web based management console and user portal (with easily customizable theme)
▪ Extensible product architecture to address complex IAM needs
▪ Docker friendly deployment
▪ Latest release - WSO2 Identity Server 5.3.0
WSO2 IDENTITY SERVER
Overview
▪ 75+ active subscribers, 200+ instances under subscription
▪ Key OEMs
○ WSO2 API Manager (Key Manager Profile)
○ WSO2.Telco
○ Ellucian (340 customers)
○ Accenture
▪ 1000+ product downloads each month
▪ 100% year to year growth of direct WSO2 IS customer base for last three
years.
▪ 100% open source (both the source code and the binaries are released
under most business friendly Apache 2.0 open source license)
WSO2 IDENTITY SERVER
Adoption
▪ Accounts management and identity provisioning
▪ Single sign-on and identity federation
▪ Identity broker
▪ Fine-grained access control
▪ Identity analytics
WSO2 IDENTITY SERVER
Focus Areas
▪ Support for heterogenous identity stores: database, LDAP, AD
▪ Largest deployment of WSO2 IS in Saudi Arabia (4M+ users in a MS SQL
database)
▪ State of Arizona uses WSO2 IS for both CIAM and workforce IAM over a
MSSQL database and AD
▪ Seagate uses WSO2 IS to manage 1M+ users/customers (Oracle DB)
▪ Trimble uses WSO2 IS to manage 1M+ users/customer (OpenLDAP)
ACCOUNTS MANAGEMENT & IDENTITY PROVISIONING
Multiple Identity Stores
ACCOUNTS MANAGEMENT & IDENTITY PROVISIONING
Self Service
▪ SAML 2.0
▪ OpenID Connect (OAuth 2.0)
▪ WS-Federation
▪ CAS
▪ OpenID
▪ GSMA Mobile Connect
SINGLE SIGN-ON & IDENTITY FEDERATION
Open Standards
▪ Multi-option based login
▪ Multi-factor authentication
▪ FIDO U2F, TOTP (Google Authenticator), OTP over SMS, OTP over
Email, Certificates, mePin, Duo Security, RSA SecurID
▪ OTP over SMS is the most used one in WSO2 IS deployments
▪ Nutanix uses Google Authenticator to secure access to WSO2 IS
admin console.
SINGLE SIGN-ON & IDENTITY FEDERATION
Strong Authentication
▪ Enable Social Login by service provider
▪ Facebook, LinkedIn, Twitter, Google, Yahoo, Microsoft Live
SINGLE SIGN-ON & IDENTITY FEDERATION
Social Login
IDENTITY ANALYTICS
Login Analytics
▪ Track success/failed login
attempts by user/service
provider/identity provider.
▪ Detect anomalous login
behaviours.
IDENTITY ANALYTICS
Session Analytics
▪ Track all the sessions in the
system by user and the
duration of the session
THANK YOU
wso2.com

More Related Content

PPTX
Securing Access to SaaS Apps with WSO2 Identity Server
PPTX
NYC Identity Summit Tech Day: ForgeRock Identity Platform Overview
PDF
ForgeRock Platform Release - Summer 2016
PDF
Digital Trust: How Identity Tackles the Privacy, Security and IoT Challenge
PPTX
NYC Identity Summit Business Day: Identity is the Center of Everything (Mike ...
PDF
[WSO2Con EU 2017] How API Management at Suva is Helping in Reducing Costs to ...
PPTX
Cms api integrations list-LoginRadius
PDF
[WSO2Con EU 2017] From the Trenches: IoT Customer Stories
Securing Access to SaaS Apps with WSO2 Identity Server
NYC Identity Summit Tech Day: ForgeRock Identity Platform Overview
ForgeRock Platform Release - Summer 2016
Digital Trust: How Identity Tackles the Privacy, Security and IoT Challenge
NYC Identity Summit Business Day: Identity is the Center of Everything (Mike ...
[WSO2Con EU 2017] How API Management at Suva is Helping in Reducing Costs to ...
Cms api integrations list-LoginRadius
[WSO2Con EU 2017] From the Trenches: IoT Customer Stories

What's hot (20)

PDF
The WSO2 Identity Server - An answer to your common XACML dilemmas
PPTX
Identity Gateway with the ForgeRock Identity Platform - So What’s New?
PDF
API-first Integration for Microservices
PPTX
Frictionless Adoption of Payment Services Directive (PSD2) with WSO2
PDF
SSO with the WSO2 Identity Server
PPTX
Webinar: Identity Wars: The Unified Platform Awakens
PPTX
Identity Summit 2015: EnerNOC Case Study: The Transformation of IAM for EnerN...
PPTX
Gateway/APIC security
PPTX
Ping Identity
PPTX
OAuth and OpenID Connect for PSD2 and Third-Party Access
PDF
OAuth 2.0 Threat Landscapes
ODP
Building open source identity infrastructures
PDF
Datapower it sec2019
PDF
Identity Federation Patterns with WSO2 Identity Server​
PDF
wso2 masterclass italia #13 - Open Healthcare: interoperabilità e sicurezza ...
PPTX
What's New in IdP 9.0 Behavioral Biometrics and more…
PDF
apidays LIVE India - Digital Trust Infrastructure - Key to digital transforma...
PPTX
apidays LIVE India - Asynchronous and Broadcasting APIs using Kafka by Rohit ...
PDF
APIC/DataPower security
PPTX
HSBC - ForgeRock Identity Summit 2017 Dusseldorf
The WSO2 Identity Server - An answer to your common XACML dilemmas
Identity Gateway with the ForgeRock Identity Platform - So What’s New?
API-first Integration for Microservices
Frictionless Adoption of Payment Services Directive (PSD2) with WSO2
SSO with the WSO2 Identity Server
Webinar: Identity Wars: The Unified Platform Awakens
Identity Summit 2015: EnerNOC Case Study: The Transformation of IAM for EnerN...
Gateway/APIC security
Ping Identity
OAuth and OpenID Connect for PSD2 and Third-Party Access
OAuth 2.0 Threat Landscapes
Building open source identity infrastructures
Datapower it sec2019
Identity Federation Patterns with WSO2 Identity Server​
wso2 masterclass italia #13 - Open Healthcare: interoperabilità e sicurezza ...
What's New in IdP 9.0 Behavioral Biometrics and more…
apidays LIVE India - Digital Trust Infrastructure - Key to digital transforma...
apidays LIVE India - Asynchronous and Broadcasting APIs using Kafka by Rohit ...
APIC/DataPower security
HSBC - ForgeRock Identity Summit 2017 Dusseldorf
Ad

Similar to Synergies across APIs and IAM (20)

PDF
[Workshop] API-driven Integration
PDF
API Management within a Microservice Architecture
PPTX
API Management Within a Microservices Architecture
PDF
WSO2Con2024 - WSO2's IAM Vision: Identity-Led Digital Transformation
PPTX
WSO2- OSC Korea - Accelerating Digital Businesses with APIs
PDF
Pre-built, Secure Identity Layer for Consumer Websites, B2B Portals and SaaS ...
PDF
Digital Asset Governance for the Enterprise
PDF
20190404 Blockchain GIG #2 Oracle Mark発表資料
PPTX
Platform for Secure Digital Business
PDF
Hybrid IAM: Fuelling Agility in the Cloud Transformation Journey | Gartner IA...
PDF
Warum ist Cloud-Sicherheit und Compliance wichtig?
PPT
#1922 rest-push2 ap-im-v6
PDF
CA Security - Deloitte IAM Summit - Vasu
PDF
[WSO2Con EU 2017] IAM: Catalyst for Digital Transformation
PPTX
Platform for Secure Digital Business
PPTX
Identity Management with the ForgeRock Identity Platform - So What’s New?
PDF
WSO2Con EU 2015: Securing, Monitoring and Monetizing APIs
PDF
Company and Market Overview
PPTX
Directory Services with the ForgeRock Identity Platform - So What’s New?
PDF
Webinar: Deep Diving Into the KuppingerCole IDaaS Leadership Compass
[Workshop] API-driven Integration
API Management within a Microservice Architecture
API Management Within a Microservices Architecture
WSO2Con2024 - WSO2's IAM Vision: Identity-Led Digital Transformation
WSO2- OSC Korea - Accelerating Digital Businesses with APIs
Pre-built, Secure Identity Layer for Consumer Websites, B2B Portals and SaaS ...
Digital Asset Governance for the Enterprise
20190404 Blockchain GIG #2 Oracle Mark発表資料
Platform for Secure Digital Business
Hybrid IAM: Fuelling Agility in the Cloud Transformation Journey | Gartner IA...
Warum ist Cloud-Sicherheit und Compliance wichtig?
#1922 rest-push2 ap-im-v6
CA Security - Deloitte IAM Summit - Vasu
[WSO2Con EU 2017] IAM: Catalyst for Digital Transformation
Platform for Secure Digital Business
Identity Management with the ForgeRock Identity Platform - So What’s New?
WSO2Con EU 2015: Securing, Monitoring and Monetizing APIs
Company and Market Overview
Directory Services with the ForgeRock Identity Platform - So What’s New?
Webinar: Deep Diving Into the KuppingerCole IDaaS Leadership Compass
Ad

More from Sagara Gunathunga (20)

PPTX
Microservices Security landscape
PPTX
Privacy by Design as a system design strategy - EIC 2019
PPTX
Consumer Identity World EU - Five pillars of consumer IAM
PPTX
kicking your enterprise security up a notch with adaptive authentication sa...
PPTX
GDPR impact on Consumer Identity and Access Management (CIAM)
PPTX
Introduction to the All New WSO2 Governance Centre
PPTX
Building Services with WSO2 Application Server and WSO2 Microservices Framewo...
PPTX
An Introduction to WSO2 Microservices Framework for Java
PPTX
Understanding Microservice Architecture WSO2Con Asia 2016
PDF
Introduction to the all new wso2 governance centre asia 16
PDF
Building Your Own Store with WSO2 Enterprise Store: The WSO2 Store Case Study
PDF
Introduction to the All New WSO2 Governance Centre
PDF
Java colombo-deep-dive-into-jax-rs
PDF
JavaEE and RESTful development - WSO2 Colombo Meetup
POTX
Application Monitoring with WSO2 App Server
PDF
WSO2 Application Server
PDF
Creating APIs with the WSO2 Platform
PDF
WSO2 AppDev platform
PDF
Apache contribution-bar camp-colombo
PDF
What is new in Axis2 1.7.0
Microservices Security landscape
Privacy by Design as a system design strategy - EIC 2019
Consumer Identity World EU - Five pillars of consumer IAM
kicking your enterprise security up a notch with adaptive authentication sa...
GDPR impact on Consumer Identity and Access Management (CIAM)
Introduction to the All New WSO2 Governance Centre
Building Services with WSO2 Application Server and WSO2 Microservices Framewo...
An Introduction to WSO2 Microservices Framework for Java
Understanding Microservice Architecture WSO2Con Asia 2016
Introduction to the all new wso2 governance centre asia 16
Building Your Own Store with WSO2 Enterprise Store: The WSO2 Store Case Study
Introduction to the All New WSO2 Governance Centre
Java colombo-deep-dive-into-jax-rs
JavaEE and RESTful development - WSO2 Colombo Meetup
Application Monitoring with WSO2 App Server
WSO2 Application Server
Creating APIs with the WSO2 Platform
WSO2 AppDev platform
Apache contribution-bar camp-colombo
What is new in Axis2 1.7.0

Recently uploaded (20)

PDF
gpt5_lecture_notes_comprehensive_20250812015547.pdf
PDF
How ambidextrous entrepreneurial leaders react to the artificial intelligence...
PDF
August Patch Tuesday
PDF
Getting Started with Data Integration: FME Form 101
PDF
TrustArc Webinar - Click, Consent, Trust: Winning the Privacy Game
PDF
STKI Israel Market Study 2025 version august
PDF
Architecture types and enterprise applications.pdf
PPTX
OMC Textile Division Presentation 2021.pptx
PDF
NewMind AI Weekly Chronicles – August ’25 Week III
PDF
Profit Center Accounting in SAP S/4HANA, S4F28 Col11
PDF
A novel scalable deep ensemble learning framework for big data classification...
PPTX
cloud_computing_Infrastucture_as_cloud_p
PDF
2021 HotChips TSMC Packaging Technologies for Chiplets and 3D_0819 publish_pu...
PDF
A comparative study of natural language inference in Swahili using monolingua...
PDF
Video forgery: An extensive analysis of inter-and intra-frame manipulation al...
PPTX
Chapter 5: Probability Theory and Statistics
PDF
Web App vs Mobile App What Should You Build First.pdf
PDF
Getting started with AI Agents and Multi-Agent Systems
PDF
Enhancing emotion recognition model for a student engagement use case through...
PDF
Assigned Numbers - 2025 - Bluetooth® Document
gpt5_lecture_notes_comprehensive_20250812015547.pdf
How ambidextrous entrepreneurial leaders react to the artificial intelligence...
August Patch Tuesday
Getting Started with Data Integration: FME Form 101
TrustArc Webinar - Click, Consent, Trust: Winning the Privacy Game
STKI Israel Market Study 2025 version august
Architecture types and enterprise applications.pdf
OMC Textile Division Presentation 2021.pptx
NewMind AI Weekly Chronicles – August ’25 Week III
Profit Center Accounting in SAP S/4HANA, S4F28 Col11
A novel scalable deep ensemble learning framework for big data classification...
cloud_computing_Infrastucture_as_cloud_p
2021 HotChips TSMC Packaging Technologies for Chiplets and 3D_0819 publish_pu...
A comparative study of natural language inference in Swahili using monolingua...
Video forgery: An extensive analysis of inter-and intra-frame manipulation al...
Chapter 5: Probability Theory and Statistics
Web App vs Mobile App What Should You Build First.pdf
Getting started with AI Agents and Multi-Agent Systems
Enhancing emotion recognition model for a student engagement use case through...
Assigned Numbers - 2025 - Bluetooth® Document

Synergies across APIs and IAM

  • 1. Synergies Across APIs and IAM Ingredients For winning digital transformation strategy Nov , 2017 Sagara Gunathunga - Director, WSO2
  • 2. ABOUT WSO2 2 Mountain View, New York, London, Sao Paolo, Colombo Founded in 2005 Venture backed by Cisco and Toba Capital 450 Employees; 300 Engineers 400+ Customers, 120 New Customers in 2016 Profitable Business since 2016
  • 3. OPEN TECHNOLOGY FOR AGILE DIGITAL BUSINESS 3 Build internal and external developer ecosystems with an API marketplace. Manage identity, security, and privacy across your digital business. Make mobile and IoT devices integral to your digital business. Create real-time, intelligent, actionable business insights and data products. Platform enable your digital business with “micro-services” and “micro-integrations”.
  • 4. Digital Transformation will decide and shape The destiny of your business
  • 5. Digital Transformation is no longer a nice to have or a differentiator, it’s about the survival of your business Is it the Right Time to Think? A nice to have A differentiator For survival
  • 6. Is it Real? Look Around You!
  • 8. Digitize Delivery Channels Personalized User Experience Highly connected business offerings Digital Transformation
  • 9. • Sales increasingly based on real user reviews and ratings than traditional marketing • Physical stores replaced with digital channels (web stores, mobile apps, IVR solutions) • Fast consumer response time and convenience means connectivity (e.g. Facebook, Twitter, WhatsApp) Challenge 1 - Digitize Delivery Channels
  • 10. Generic user experiences don’t work, consumers now expect – A highly personalized experience – Control over preferences – Relativeness of content Challenge 2 - Personalized User Experience
  • 11. Fulfill all the related business requirements at one-stop. • Save consumer time and avoid data duplications. • Fast and efficient B2B integration. • Adoption of open business interfaces Challenge 3 - Highly connected business offerings
  • 12. Synergies Across APIs and IAM is the right answer
  • 13. API Management Digitize Delivery Channels Highly connected business offerings
  • 14. Reality of Enterprise Systems Landscape ● Enterprise systems are complex ● Enterprise systems are bureaucratic ● Cannot afford the luxury of complete re-write or having a clean slate ● Comes with years of baggage 14
  • 16. 16 Present Day Enterprise Architecture Analytics Continuous-* Security & Access Management API / Service discovery Dev toolsDevops tools Service router API Gateway Core Microservices Data Container(s) Delivery channels Digital Products Messaging Channels Integration MicroservicesExisting Services
  • 17. 17 APIs are found in Every Layer
  • 18. 18 The modern API ● RESTful & JSON savvy - being lightweight, REST style conformant ● Well documented - Methods, operations, responses, error codes etc ● Manageable (life-cycle, version) ● Discoverable - Searchable, testable ● Measurable ● Secured - Multiple security protocol support, transformable
  • 19. Key Performance Factors of an API Platform ● Security ● Rate Limiting ● Integration ● Analytics 19
  • 21. Security: Identity ● Authentication ● Single Sign On ● Federation ● Authorization 21 Authenticate via Facebook to Airbnb APIs
  • 22. Security: Access Delegation ● Secure Trusted Clients ● Secure Untrusted Clients ● Unsecure Clients ● System to System Auth/z 22 People Apps
  • 23. Rate Limiting: Front End ● Monetization ● Burst Control ● Fair Usage Policy ● Geographical Distribution ● Distribution by Device Type 23 People Apps Gateway
  • 24. Rate Limiting: Back-End ● Prevent Total Service Outage at Peaks ● Back-End Server Maintenance 24 Gateway Services and Data
  • 28. Analytics: Operational ● API Latency Distribution ● Alerting on Abnormalities ● API Health 28
  • 30. 30 ● Currently at version 2.1.0 with over 6 years of engineering improvements across 15 stable releases ● Geo distributed and clustered deployments ○ In production at StubHub / Verizon / Motorola / BYU / BNY ● Same code base at WSO2 API Cloud running with four 9s uptime ● One major and 3 minor releases per year ● Automated deployment with puppet ● Containerized with Docker Battle hardened
  • 31. 31 WSO2 API Manager ● Available as a single downloadable package ● Available as a cloud / SaaS solution ● Flexible deployment choices ● High performance gateway ● API governance, marketplace solution
  • 32. 32 Cloud First or Start On-Prem ● Multi-tenanted, shared everything ● WSO2 Hosted and managed ● Pay as you go ● Multi-region availability ● VPN tunnel to private DC ● Guaranteed uptime ● Limited options in customizing ● Privately hosted ● WSO2 managed ● Upgrades, patches installation ● Guaranteed uptime ● Full flexibility in customization ● Better control ● Self hosted ● Self managed ● Full flexibility ● Dev-ops learning curve ● Self managed upgrades http://wso2.com/api-management/cloud/ https://docs.wso2.com/display/ManagedCl oud/WSO2+Managed+Cloud+Documenta tion
  • 34. Identity and Access Management Personalized User Experience Highly connected business offerings
  • 35. Users onboarding • Employees vs. customers • Self signup • Self signup with verification • Approval workflows
  • 36. Bring Your Own Identity (BYOI) New to Hi! Sign Up Welcome Sagara
  • 37. Authentication • Multi-factor authentication • Adaptive authentication • FIDO U2F, TOTP, SMS/Email OTP • LDAP, Database, AD
  • 38. Social Authentication New to Hi! Sign Up Welcome Sagara
  • 40. Authorization • Role-based • Attribute-based • XACML REST API • Policy templates
  • 41. Single sign-on (SSO) • Social logins eliminate password management complexities from consumer and business side • Out-of-the-box support for strong authentication options, such as 2-factor authentication Welcome Welcome
  • 42. Self-service • User portal • Password reset • Self access requests • Consent management • Profile update • Password reset • Account recovery
  • 43. Monitoring and Analytics • Login analytics • Session analytics • Fraud detection/prevention
  • 45. ▪ Addresses critical IAM needs both in customer IAM and workforce IAM spaces ▪ Most of the WSO2 IS deployments are to address CIAM needs ▪ Extensive support for open standards - no vendor locking ▪ Large scale deployments over millions of users ▪ Rich eco system with 40+ connectors (https://store.wso2.com/store/assets/isconnector/list) ▪ Support for multi-tenancy ▪ Web based management console and user portal (with easily customizable theme) ▪ Extensible product architecture to address complex IAM needs ▪ Docker friendly deployment ▪ Latest release - WSO2 Identity Server 5.3.0 WSO2 IDENTITY SERVER Overview
  • 46. ▪ 75+ active subscribers, 200+ instances under subscription ▪ Key OEMs ○ WSO2 API Manager (Key Manager Profile) ○ WSO2.Telco ○ Ellucian (340 customers) ○ Accenture ▪ 1000+ product downloads each month ▪ 100% year to year growth of direct WSO2 IS customer base for last three years. ▪ 100% open source (both the source code and the binaries are released under most business friendly Apache 2.0 open source license) WSO2 IDENTITY SERVER Adoption
  • 47. ▪ Accounts management and identity provisioning ▪ Single sign-on and identity federation ▪ Identity broker ▪ Fine-grained access control ▪ Identity analytics WSO2 IDENTITY SERVER Focus Areas
  • 48. ▪ Support for heterogenous identity stores: database, LDAP, AD ▪ Largest deployment of WSO2 IS in Saudi Arabia (4M+ users in a MS SQL database) ▪ State of Arizona uses WSO2 IS for both CIAM and workforce IAM over a MSSQL database and AD ▪ Seagate uses WSO2 IS to manage 1M+ users/customers (Oracle DB) ▪ Trimble uses WSO2 IS to manage 1M+ users/customer (OpenLDAP) ACCOUNTS MANAGEMENT & IDENTITY PROVISIONING Multiple Identity Stores
  • 49. ACCOUNTS MANAGEMENT & IDENTITY PROVISIONING Self Service
  • 50. ▪ SAML 2.0 ▪ OpenID Connect (OAuth 2.0) ▪ WS-Federation ▪ CAS ▪ OpenID ▪ GSMA Mobile Connect SINGLE SIGN-ON & IDENTITY FEDERATION Open Standards
  • 51. ▪ Multi-option based login ▪ Multi-factor authentication ▪ FIDO U2F, TOTP (Google Authenticator), OTP over SMS, OTP over Email, Certificates, mePin, Duo Security, RSA SecurID ▪ OTP over SMS is the most used one in WSO2 IS deployments ▪ Nutanix uses Google Authenticator to secure access to WSO2 IS admin console. SINGLE SIGN-ON & IDENTITY FEDERATION Strong Authentication
  • 52. ▪ Enable Social Login by service provider ▪ Facebook, LinkedIn, Twitter, Google, Yahoo, Microsoft Live SINGLE SIGN-ON & IDENTITY FEDERATION Social Login
  • 53. IDENTITY ANALYTICS Login Analytics ▪ Track success/failed login attempts by user/service provider/identity provider. ▪ Detect anomalous login behaviours.
  • 54. IDENTITY ANALYTICS Session Analytics ▪ Track all the sessions in the system by user and the duration of the session