SlideShare a Scribd company logo
Extranet Identity Management and Authentication for SharePoint On Premise, Office 365 and Beyond 
Presented by Peter Carson 
President, Envision IT 
October 22, 2014
Peter Carson 
•President, Envision IT 
•SharePoint MVP 
•Virtual Technical Specialist, Microsoft Canada 
•peter@envisionit.com 
•http://blog.petercarson.ca 
•www.envisionit.com 
•Twitter @carsonpeter 
•VP Toronto SharePoint User Group
Hugh Davidson 
Business Development Manager, Product Sales 
•e: hdavidson@envisionit.com 
•p: (905) 812-3009 x222
Denesh Sohan 
Director of Products 
•e: dsohan@envisionit.com 
•p: (905) 812-3009 x298
Corey Thokle 
Project Manager 
•e: cthokle@envisionit.com 
•p: (905) 812 3009 ext.248
Agenda 
•Envision IT Overview 
•Extranet Scenarios 
•Extranet User Manager Overview 
•SharePoint On Premises Demo 
•Federation 
•Office 365 Demo 
•Wrap-Up and Q&A
Envision it Webinar - Extranet Identity Management and Authentication for SharePoint On Premise, Office365 and Beyond
Focused on complex SharePoint solutions, Envision IT is the “go-to” partner for Microsoft SharePoint, building integrated public web sites, Intranets, Extranets, and web applications that leverage your existing systems anywhere over the Internet. 
Envision IT Services Overview
Public Web Sites 
We create interactive, content-rich customer-facing web sites that are able to grow and transform with changing needs
Collaboration Portals 
Our Collaboration Portals provide a secure space for teams to share knowledge and resources
Intranets 
Our Intranet Sites connect people to information, expertise and key business applications, and SharePoint provides a broad set of Enterprise Content Management features
Extranets 
Envision IT has a wealth of experience building Corporate Extranets that allow you to securely connect with customers and partners
What is an Extranet 
•An Extranetis a web site that is accessible to users outside of the corporate network, which allowsorganizations to share information and collaborate with their customers, partners, and/or vendors in a secure and easy-to-use environment 
•The Extranet may be added as amodule into the Intranet site to only allow external users into specific sub-sites of the Intranet
Poll 1 
Which Version of SharePoint are you currently using? 
•SharePoint Server 2013 
•Office 365 
•SharePoint Server 2010 
•SharePoint Foundation (2010 or 2013) 
•MOSS 2007 or WSS 3.0
Poll 2 
How do you use SharePoint today? 
•Internal collaboration 
•Internal web publishing (Intranet) 
•Extranets 
•Public facing website
Extranet Scenarios
SharePoint On Premise Authentication Options 
Windows Authentication 
Active Directory 
Windows Claims 
Or 
Classic Mode 
.NET Providers 
Forms-Based Authentication 
AD 
SQL 
Claims 
Relying Party 
Federated Identity 
Trusted Identity Provider 
AD 
User Store 
Claims
Office 365 Authentication Options 
Windows Azure Active Directory 
No Integration 
Cloud Identity 
Windows Azure Active Directory 
Integration with no 
federation 
Directory and Password 
Synchronization 
DirSync and Password Sync 
On Premise Identity 
Windows Azure Active Directory 
Single federated identity 
and credentials 
Federated Identity 
On Premise Identity 
Federation User Sync
SharePoint Extranets -OOTB 
•On premises SharePoint can be published externally through SSL 
•Unless an additional reverse proxy is used, the login experience is very basic 
•No forgotten password, change password, or self-registration 
•IT needs to setup and manage external users 
•No mechanism for getting credentials to users
SharePoint Extranets –Office 365 
•Up to 10,000 free external users in your Office 365 subscription through External Sharing 
•Must use the Microsoft login form 
•External users must have a Microsoft account, or be an Office 365 subscriber themselves 
•No control over what account is used to accept the invitation
SharePoint Extranets –Forms Based Authentication 
•Branded and friendly login form is possible 
•Requires custom development 
•Users can be stored outside of the corporate Active Directory 
•Installation is manual and requires re-configuring numerous configfiles on the SharePoint servers 
•Previous releases of Extranet User Manger (Version 2.6 and prior) addressed the login form, branding, installation, self- registration, forgotten password, and user management delegation issues
SharePoint Extranets -Federation 
•Supports SharePoint 2010 and 2013 on premises, and Office 365 
•Fully branded user experience 
•Friendly customizable login form 
•Login with email address 
•Automatic login for internal users 
•Customizable self-registration with approvals 
•Welcome email to set credentials 
•Forgotten password reset 
•Delegation of user management to business or externally 
•Delegated group management simplifies permissions 
•Supports single sign-on to other claims-aware applications 
•Improved governance over your Extranet
•Easy delegation of user management to business 
•Self-registration, approvals, forgotten password reset 
•Simplified login for both internal and external users 
Extranet User Manager
Main Components 
•Administration console 
Used by IT to configure EUM 
Used by the business to manage users and groups 
•End User 
Components that the Extranet users see 
Login, disclaimer, change password, forgotten password 
•Registration 
Allow users to self-register 
Support approval workflows
Pricing 
•Full pricing details available at www.envisionit.com/eum 
•Standard edition $8,000 USD per production farm 
No limits on the number of SharePoint web front ends 
Four hours of Premium Software Support 
•Enterprise Edition $13,000 USD 
Unlimited SSO authentication to claims aware applications 
Eight hours of Premium Software Support 
•20% annual Software Assurance provides all product updates 
•Devand QA farm licenses provided with up to date Software Assurance 
•Additional support packages available 
•Azure hosted monthly subscription plans coming next month
Registration
Registration Form Customizations
Approval Email
Approve the User
Welcome Email
Set Your Password
Login
Forgotten Password
Demo One –On Premises 
Registration through to Login
Demo Scenario 
•Sample site at https://productdemo13.envisionit.com 
•SharePoint 2013 on premises 
•AD FS for internal users 
•External users 
In a separate AD 
Authenticating through ThinktectureIdentity Server 
Managed with the Envision IT Extranet User Manager
Single Sign-On 
•https://productdemo13eum.envisionit.com 
Extranet User Manager 
Installed in its own IIS site outside of SharePoint 
•https://productdemo13sample.envisionit.com 
Sample ASP.NET 4.5 Visual Studio application 
Displays the claim information for the logged in user
Managing Your External Users with EUM 
•Supports SharePoint 2010 and 2013 on premises, and Office 365 
•Fully branded user experience 
•Friendly customizable login form 
•Login with email address 
•Automatic login for internal users 
•Customizable self-registration with approvals 
•Welcome email to set credentials 
•Forgotten password reset 
•Delegation of user management to business or externally 
•Delegated group management simplifies permissions 
•Supports single sign-on to other claims-aware applications 
•Improved governance over your Extranet
Technical Advantages 
•Fully supported by Microsoft with minimal changes to the SharePoint farm 
PowerShell script installs the required certificates into SharePoint 
•No open firewall ports from DMZ to internal required 
If internal users should be able to login externally without VPN, then ADFS needs to be published externally on port 443 
•External users can be stored in a separate DMZ AD, or in a SQL database 
•IT no longer needs to manage the external users, or reset their passwords
Poll 3 
When would you like us to follow up? 
•Right away 
•November / December 
•January
Single Sign-On and Federated Identities 
•Trusted Identity Provider does the authentication 
•Can be any SAML compliant provider 
Active Directory Federation Services 
ThinktectureIdentity Server 
owww.thinktecture.com 
Social identities 
•Can be AD, SQL, or other user repository under the hood 
•Relying parties (such as SharePoint) trust the SAML token and provide the authorization based off that identity 
•Provides Single Sign-On to multiple systems 
Can be any SAML claims compliant system, not just SharePoint
AD FS Servers 
Internal AD FS/DC Servers DMZ AD FS Proxies 
Web Application Proxy
AD FS Login Form 
•Internal users shouldn’t see this inside the network 
•Can be branded, within limits
Federation
Authentication Process 
Relying Party Identity Provider Active Directory 
Browse app 
Not authenticated 
Redirected to IP 
Authenticate 
User 
Query for user attributes 
Return SAML Security Token 
Return page 
and cookie 
Send Token 
ST 
ST 
RP trusts IP
Certificates 
• PKI SSL encryption is used for communication 
• Token can be self-signed by the Identity Provider 
• Token can also be encrypted with a self-signed certificate 
from the Identity Provider 
A Communication 
Signing 
Relying party Identity Provider 
ST 
Encryption ST 
B 
Public key of C C 
D Public key of D 
Root for B Root for A
Why Thinktectureover ADFS? 
•ThinktectureIdentity Server is embedded in Extranet User Manager 
•www.thinktecture.com/identityAndAccessControl 
•Open source allows any customization 
•Fully brandable(ADFS allows branding within very particular parameters) 
•Login with email address instead of AD username 
•Use SQL instead of AD as the underlying user repository 
•Ability to incorporate the home realm discovery into the login form
ezRealmHome Realm Discovery 
Internal IP Address? 
Internal email domain? 
No 
Yes 
Yes 
No
Demo Two –Office 365 
Registration through to Login
Demo Scenario 
•Sample site at https://eumdev.sharepoint.com 
•EUM installed at https://eum.eitdev.org 
•SharePoint Online in Office 365 
•AD FS for internal users 
•External users 
In a separate AD 
Authenticating through ThinktectureIdentity Server 
Managed with the Envision IT Extranet User Manager
Next Steps 
•Reach out to Hugh Davidson, Sales 
e: hdavidson@envisionit.com 
p: (905) 812-3009 x222 
•Installation Support on Premise 
•Minimum 30 day evaluation with all features enabled
Pricing 
•Full pricing details available at www.envisionit.com/eum 
•Standard edition $8,000 USD per production farm 
No limits on the number of SharePoint web front ends 
Four hours of Premium Software Support 
•Enterprise Edition $13,000 USD 
Unlimited SSO authentication to claims aware applications 
Eight hours of Premium Software Support 
•20% annual Software Assurance provides all product updates 
•Devand QA farm licenses provided with up to date Software Assurance 
•Additional support packages available
Product Roadmap 
•SQL User Store 
•Office 365 Support 
•Azure Support 
•Responsive design 
•Quick spin-up demo environment** 
•Multifactor Authentication 
•Social Identity Integration
Upcoming Events 
•ESPC Webinar –Oct 30th9am EST 
http://www.envisionit.com/products/events/ 
•CollabConToronto –November 24th–25th 
www.collabcon.org 
Use the discount code ENVISIONIT for a 10% discount
Links 
•www.envisionit.com 
•blog.petercarson.ca 
•www.envisionit.com/eum 
•Video and presentation deck will be at www.envisionit.com/events 
•Customer sites 
www.publichealthontario.ca 
www.bgccan.com 
www.g2gmarket.com 
www.redcrest.com.au 
www.transamerica.ca 
suppliers.kinross.com 
www.problemgambling.ca
Questions?

More Related Content

PDF
Envision it SharePoint Extranet Webinar Series - Federation and SharePoint On...
PDF
SharePointFest 2013 Washington DC - SPT 103 - SharePoint 2013 Extranets: How ...
PDF
Unlock your Big Data with Analytics and BI on Office 365 - OFF103
PPTX
Understanding SharePoint Apps, authentication and authorization infrastructur...
PPTX
Building Secure Extranets with Claims-Based Authentication #SPEvo13
PPTX
Hybrid SharePoint - Office 365 & On-prem SharePoint 2013 -part2
PPTX
Leveraging SharePoint for Extranets
PPTX
Deploying an Extranet on SharePoint
Envision it SharePoint Extranet Webinar Series - Federation and SharePoint On...
SharePointFest 2013 Washington DC - SPT 103 - SharePoint 2013 Extranets: How ...
Unlock your Big Data with Analytics and BI on Office 365 - OFF103
Understanding SharePoint Apps, authentication and authorization infrastructur...
Building Secure Extranets with Claims-Based Authentication #SPEvo13
Hybrid SharePoint - Office 365 & On-prem SharePoint 2013 -part2
Leveraging SharePoint for Extranets
Deploying an Extranet on SharePoint

What's hot (20)

PPTX
OAuth in SharePoint 2013
PPTX
SharePoint Saturday Austin - Share point authentication and authorization
PPTX
Oauth and SharePoint 2013 Provider Hosted apps
PPTX
The Who, What, Why and How of Active Directory Federation Services (AD FS)
PPTX
Preparing for Office 365
PPTX
SharePoint, ADFS and Claims Auth
PPTX
Office 365-single-sign-on-with-adfs
PPTX
SharePoint 2013 and ADFS
PPTX
Office 365 Identity Management options
PPTX
A Developer's Introduction to Azure Active Directory B2C
PDF
SharePoint Saturday The Conference DC - How the client object model saved the...
PPTX
Con8836 leveraging the cloud to simplify your identity management implement...
PPTX
How to deploy SharePoint 2010 to external users?
PPTX
T28 implementing adfs and hybrid share point
PPTX
Extending Authentication and Authorization
PPTX
ESPC15 - Extending Authentication and Authorization
PDF
Unified client management session from Microsoft partner boot camp
PPTX
OFM AIA FP Implementation View and Case Study
PDF
Avoiding the Hidden Costs of Active Directory Federation Services (AD FS)
PDF
SharePoint Saturday Kansas 2015 - Building Killer Office365 Public Sites
OAuth in SharePoint 2013
SharePoint Saturday Austin - Share point authentication and authorization
Oauth and SharePoint 2013 Provider Hosted apps
The Who, What, Why and How of Active Directory Federation Services (AD FS)
Preparing for Office 365
SharePoint, ADFS and Claims Auth
Office 365-single-sign-on-with-adfs
SharePoint 2013 and ADFS
Office 365 Identity Management options
A Developer's Introduction to Azure Active Directory B2C
SharePoint Saturday The Conference DC - How the client object model saved the...
Con8836 leveraging the cloud to simplify your identity management implement...
How to deploy SharePoint 2010 to external users?
T28 implementing adfs and hybrid share point
Extending Authentication and Authorization
ESPC15 - Extending Authentication and Authorization
Unified client management session from Microsoft partner boot camp
OFM AIA FP Implementation View and Case Study
Avoiding the Hidden Costs of Active Directory Federation Services (AD FS)
SharePoint Saturday Kansas 2015 - Building Killer Office365 Public Sites
Ad

Viewers also liked (6)

PPTX
Sa jka national tournament 31 may 2013
PPTX
Sa jka national tournament result slides 1 june 2013
PPTX
Sa jka national tournament results 1 june
PDF
CIS14: Case Study: Using a Federated Identity Service for Faster Application ...
PPTX
Top 10 Podcasts Every Salesperson Needs to be Listening To
PDF
Study: The Future of VR, AR and Self-Driving Cars
Sa jka national tournament 31 may 2013
Sa jka national tournament result slides 1 june 2013
Sa jka national tournament results 1 june
CIS14: Case Study: Using a Federated Identity Service for Faster Application ...
Top 10 Podcasts Every Salesperson Needs to be Listening To
Study: The Future of VR, AR and Self-Driving Cars
Ad

Similar to Envision it Webinar - Extranet Identity Management and Authentication for SharePoint On Premise, Office365 and Beyond (20)

PDF
Envision it SharePoint Extranet Webinar Series - Federation and Office 365
PDF
Envision it SharePoint Extranet Webinar Series - Extranet User Provisioning
PPTX
Introduction to Azure AD and Azure AD B2C
PPTX
Understanding Office 365’s Identity Solutions: Deep Dive - EPC Group
PDF
How to Build a Structured Extranet Using Azure AD B2B
PDF
Unstructured vs. Structured Extranets in office 365 Webinar - June 11, 2019
PDF
O365Con18 - Hybrid SharePoint Deep Dive - Thomas Vochten
PPTX
MindSurf 2013 - Improving Business Productivity with SharePoint 2013
PPTX
Sharepoint and office 365 hybrid configuration from A to Z #spstoronto 2015
PDF
Pre-built, Secure Identity Layer for Consumer Websites, B2B Portals and SaaS ...
PDF
Salesforce Identity: Connect and Collaborate Anywhere, Securely with Single S...
PPTX
Implementing and Managing Office 365 - Jacksonville IT Pro Camp 2017
PDF
04_Extending and Securing Enterprise Applications in Microsoft Azure_GAB2019
PPTX
SharePoint Authentication And Authorization SPTechCon San Francisco
PDF
Practical Tips for Migrating SharePoint Customizations to Office 365
PPTX
Moving to the cloud with Office 365
PPTX
SPSVB - Office 365 and Cloud Identity - What Does It Mean for Me?
PPTX
#spsuk: Understanding the Office 365 Architecture
PPTX
Introduction and What’s new in SharePoint 2013
PPTX
Configuring Hybrid Workloads for SharePoint 2013 and O365 by Neil Hodgkinson
Envision it SharePoint Extranet Webinar Series - Federation and Office 365
Envision it SharePoint Extranet Webinar Series - Extranet User Provisioning
Introduction to Azure AD and Azure AD B2C
Understanding Office 365’s Identity Solutions: Deep Dive - EPC Group
How to Build a Structured Extranet Using Azure AD B2B
Unstructured vs. Structured Extranets in office 365 Webinar - June 11, 2019
O365Con18 - Hybrid SharePoint Deep Dive - Thomas Vochten
MindSurf 2013 - Improving Business Productivity with SharePoint 2013
Sharepoint and office 365 hybrid configuration from A to Z #spstoronto 2015
Pre-built, Secure Identity Layer for Consumer Websites, B2B Portals and SaaS ...
Salesforce Identity: Connect and Collaborate Anywhere, Securely with Single S...
Implementing and Managing Office 365 - Jacksonville IT Pro Camp 2017
04_Extending and Securing Enterprise Applications in Microsoft Azure_GAB2019
SharePoint Authentication And Authorization SPTechCon San Francisco
Practical Tips for Migrating SharePoint Customizations to Office 365
Moving to the cloud with Office 365
SPSVB - Office 365 and Cloud Identity - What Does It Mean for Me?
#spsuk: Understanding the Office 365 Architecture
Introduction and What’s new in SharePoint 2013
Configuring Hybrid Workloads for SharePoint 2013 and O365 by Neil Hodgkinson

Recently uploaded (20)

PDF
Encapsulation_ Review paper, used for researhc scholars
PDF
Empathic Computing: Creating Shared Understanding
PPTX
Understanding_Digital_Forensics_Presentation.pptx
PPTX
A Presentation on Artificial Intelligence
PPT
“AI and Expert System Decision Support & Business Intelligence Systems”
PDF
NewMind AI Weekly Chronicles - August'25 Week I
PDF
Bridging biosciences and deep learning for revolutionary discoveries: a compr...
PDF
How UI/UX Design Impacts User Retention in Mobile Apps.pdf
PDF
CIFDAQ's Market Insight: SEC Turns Pro Crypto
PDF
Approach and Philosophy of On baking technology
PDF
KodekX | Application Modernization Development
PDF
Dropbox Q2 2025 Financial Results & Investor Presentation
PPTX
Effective Security Operations Center (SOC) A Modern, Strategic, and Threat-In...
PDF
Shreyas Phanse Resume: Experienced Backend Engineer | Java • Spring Boot • Ka...
PDF
Architecting across the Boundaries of two Complex Domains - Healthcare & Tech...
PPTX
20250228 LYD VKU AI Blended-Learning.pptx
PDF
Reach Out and Touch Someone: Haptics and Empathic Computing
PDF
Chapter 3 Spatial Domain Image Processing.pdf
PDF
Build a system with the filesystem maintained by OSTree @ COSCUP 2025
PPTX
PA Analog/Digital System: The Backbone of Modern Surveillance and Communication
Encapsulation_ Review paper, used for researhc scholars
Empathic Computing: Creating Shared Understanding
Understanding_Digital_Forensics_Presentation.pptx
A Presentation on Artificial Intelligence
“AI and Expert System Decision Support & Business Intelligence Systems”
NewMind AI Weekly Chronicles - August'25 Week I
Bridging biosciences and deep learning for revolutionary discoveries: a compr...
How UI/UX Design Impacts User Retention in Mobile Apps.pdf
CIFDAQ's Market Insight: SEC Turns Pro Crypto
Approach and Philosophy of On baking technology
KodekX | Application Modernization Development
Dropbox Q2 2025 Financial Results & Investor Presentation
Effective Security Operations Center (SOC) A Modern, Strategic, and Threat-In...
Shreyas Phanse Resume: Experienced Backend Engineer | Java • Spring Boot • Ka...
Architecting across the Boundaries of two Complex Domains - Healthcare & Tech...
20250228 LYD VKU AI Blended-Learning.pptx
Reach Out and Touch Someone: Haptics and Empathic Computing
Chapter 3 Spatial Domain Image Processing.pdf
Build a system with the filesystem maintained by OSTree @ COSCUP 2025
PA Analog/Digital System: The Backbone of Modern Surveillance and Communication

Envision it Webinar - Extranet Identity Management and Authentication for SharePoint On Premise, Office365 and Beyond

  • 1. Extranet Identity Management and Authentication for SharePoint On Premise, Office 365 and Beyond Presented by Peter Carson President, Envision IT October 22, 2014
  • 2. Peter Carson •President, Envision IT •SharePoint MVP •Virtual Technical Specialist, Microsoft Canada •peter@envisionit.com •http://blog.petercarson.ca •www.envisionit.com •Twitter @carsonpeter •VP Toronto SharePoint User Group
  • 3. Hugh Davidson Business Development Manager, Product Sales •e: hdavidson@envisionit.com •p: (905) 812-3009 x222
  • 4. Denesh Sohan Director of Products •e: dsohan@envisionit.com •p: (905) 812-3009 x298
  • 5. Corey Thokle Project Manager •e: cthokle@envisionit.com •p: (905) 812 3009 ext.248
  • 6. Agenda •Envision IT Overview •Extranet Scenarios •Extranet User Manager Overview •SharePoint On Premises Demo •Federation •Office 365 Demo •Wrap-Up and Q&A
  • 8. Focused on complex SharePoint solutions, Envision IT is the “go-to” partner for Microsoft SharePoint, building integrated public web sites, Intranets, Extranets, and web applications that leverage your existing systems anywhere over the Internet. Envision IT Services Overview
  • 9. Public Web Sites We create interactive, content-rich customer-facing web sites that are able to grow and transform with changing needs
  • 10. Collaboration Portals Our Collaboration Portals provide a secure space for teams to share knowledge and resources
  • 11. Intranets Our Intranet Sites connect people to information, expertise and key business applications, and SharePoint provides a broad set of Enterprise Content Management features
  • 12. Extranets Envision IT has a wealth of experience building Corporate Extranets that allow you to securely connect with customers and partners
  • 13. What is an Extranet •An Extranetis a web site that is accessible to users outside of the corporate network, which allowsorganizations to share information and collaborate with their customers, partners, and/or vendors in a secure and easy-to-use environment •The Extranet may be added as amodule into the Intranet site to only allow external users into specific sub-sites of the Intranet
  • 14. Poll 1 Which Version of SharePoint are you currently using? •SharePoint Server 2013 •Office 365 •SharePoint Server 2010 •SharePoint Foundation (2010 or 2013) •MOSS 2007 or WSS 3.0
  • 15. Poll 2 How do you use SharePoint today? •Internal collaboration •Internal web publishing (Intranet) •Extranets •Public facing website
  • 17. SharePoint On Premise Authentication Options Windows Authentication Active Directory Windows Claims Or Classic Mode .NET Providers Forms-Based Authentication AD SQL Claims Relying Party Federated Identity Trusted Identity Provider AD User Store Claims
  • 18. Office 365 Authentication Options Windows Azure Active Directory No Integration Cloud Identity Windows Azure Active Directory Integration with no federation Directory and Password Synchronization DirSync and Password Sync On Premise Identity Windows Azure Active Directory Single federated identity and credentials Federated Identity On Premise Identity Federation User Sync
  • 19. SharePoint Extranets -OOTB •On premises SharePoint can be published externally through SSL •Unless an additional reverse proxy is used, the login experience is very basic •No forgotten password, change password, or self-registration •IT needs to setup and manage external users •No mechanism for getting credentials to users
  • 20. SharePoint Extranets –Office 365 •Up to 10,000 free external users in your Office 365 subscription through External Sharing •Must use the Microsoft login form •External users must have a Microsoft account, or be an Office 365 subscriber themselves •No control over what account is used to accept the invitation
  • 21. SharePoint Extranets –Forms Based Authentication •Branded and friendly login form is possible •Requires custom development •Users can be stored outside of the corporate Active Directory •Installation is manual and requires re-configuring numerous configfiles on the SharePoint servers •Previous releases of Extranet User Manger (Version 2.6 and prior) addressed the login form, branding, installation, self- registration, forgotten password, and user management delegation issues
  • 22. SharePoint Extranets -Federation •Supports SharePoint 2010 and 2013 on premises, and Office 365 •Fully branded user experience •Friendly customizable login form •Login with email address •Automatic login for internal users •Customizable self-registration with approvals •Welcome email to set credentials •Forgotten password reset •Delegation of user management to business or externally •Delegated group management simplifies permissions •Supports single sign-on to other claims-aware applications •Improved governance over your Extranet
  • 23. •Easy delegation of user management to business •Self-registration, approvals, forgotten password reset •Simplified login for both internal and external users Extranet User Manager
  • 24. Main Components •Administration console Used by IT to configure EUM Used by the business to manage users and groups •End User Components that the Extranet users see Login, disclaimer, change password, forgotten password •Registration Allow users to self-register Support approval workflows
  • 25. Pricing •Full pricing details available at www.envisionit.com/eum •Standard edition $8,000 USD per production farm No limits on the number of SharePoint web front ends Four hours of Premium Software Support •Enterprise Edition $13,000 USD Unlimited SSO authentication to claims aware applications Eight hours of Premium Software Support •20% annual Software Assurance provides all product updates •Devand QA farm licenses provided with up to date Software Assurance •Additional support packages available •Azure hosted monthly subscription plans coming next month
  • 32. Login
  • 34. Demo One –On Premises Registration through to Login
  • 35. Demo Scenario •Sample site at https://productdemo13.envisionit.com •SharePoint 2013 on premises •AD FS for internal users •External users In a separate AD Authenticating through ThinktectureIdentity Server Managed with the Envision IT Extranet User Manager
  • 36. Single Sign-On •https://productdemo13eum.envisionit.com Extranet User Manager Installed in its own IIS site outside of SharePoint •https://productdemo13sample.envisionit.com Sample ASP.NET 4.5 Visual Studio application Displays the claim information for the logged in user
  • 37. Managing Your External Users with EUM •Supports SharePoint 2010 and 2013 on premises, and Office 365 •Fully branded user experience •Friendly customizable login form •Login with email address •Automatic login for internal users •Customizable self-registration with approvals •Welcome email to set credentials •Forgotten password reset •Delegation of user management to business or externally •Delegated group management simplifies permissions •Supports single sign-on to other claims-aware applications •Improved governance over your Extranet
  • 38. Technical Advantages •Fully supported by Microsoft with minimal changes to the SharePoint farm PowerShell script installs the required certificates into SharePoint •No open firewall ports from DMZ to internal required If internal users should be able to login externally without VPN, then ADFS needs to be published externally on port 443 •External users can be stored in a separate DMZ AD, or in a SQL database •IT no longer needs to manage the external users, or reset their passwords
  • 39. Poll 3 When would you like us to follow up? •Right away •November / December •January
  • 40. Single Sign-On and Federated Identities •Trusted Identity Provider does the authentication •Can be any SAML compliant provider Active Directory Federation Services ThinktectureIdentity Server owww.thinktecture.com Social identities •Can be AD, SQL, or other user repository under the hood •Relying parties (such as SharePoint) trust the SAML token and provide the authorization based off that identity •Provides Single Sign-On to multiple systems Can be any SAML claims compliant system, not just SharePoint
  • 41. AD FS Servers Internal AD FS/DC Servers DMZ AD FS Proxies Web Application Proxy
  • 42. AD FS Login Form •Internal users shouldn’t see this inside the network •Can be branded, within limits
  • 44. Authentication Process Relying Party Identity Provider Active Directory Browse app Not authenticated Redirected to IP Authenticate User Query for user attributes Return SAML Security Token Return page and cookie Send Token ST ST RP trusts IP
  • 45. Certificates • PKI SSL encryption is used for communication • Token can be self-signed by the Identity Provider • Token can also be encrypted with a self-signed certificate from the Identity Provider A Communication Signing Relying party Identity Provider ST Encryption ST B Public key of C C D Public key of D Root for B Root for A
  • 46. Why Thinktectureover ADFS? •ThinktectureIdentity Server is embedded in Extranet User Manager •www.thinktecture.com/identityAndAccessControl •Open source allows any customization •Fully brandable(ADFS allows branding within very particular parameters) •Login with email address instead of AD username •Use SQL instead of AD as the underlying user repository •Ability to incorporate the home realm discovery into the login form
  • 47. ezRealmHome Realm Discovery Internal IP Address? Internal email domain? No Yes Yes No
  • 48. Demo Two –Office 365 Registration through to Login
  • 49. Demo Scenario •Sample site at https://eumdev.sharepoint.com •EUM installed at https://eum.eitdev.org •SharePoint Online in Office 365 •AD FS for internal users •External users In a separate AD Authenticating through ThinktectureIdentity Server Managed with the Envision IT Extranet User Manager
  • 50. Next Steps •Reach out to Hugh Davidson, Sales e: hdavidson@envisionit.com p: (905) 812-3009 x222 •Installation Support on Premise •Minimum 30 day evaluation with all features enabled
  • 51. Pricing •Full pricing details available at www.envisionit.com/eum •Standard edition $8,000 USD per production farm No limits on the number of SharePoint web front ends Four hours of Premium Software Support •Enterprise Edition $13,000 USD Unlimited SSO authentication to claims aware applications Eight hours of Premium Software Support •20% annual Software Assurance provides all product updates •Devand QA farm licenses provided with up to date Software Assurance •Additional support packages available
  • 52. Product Roadmap •SQL User Store •Office 365 Support •Azure Support •Responsive design •Quick spin-up demo environment** •Multifactor Authentication •Social Identity Integration
  • 53. Upcoming Events •ESPC Webinar –Oct 30th9am EST http://www.envisionit.com/products/events/ •CollabConToronto –November 24th–25th www.collabcon.org Use the discount code ENVISIONIT for a 10% discount
  • 54. Links •www.envisionit.com •blog.petercarson.ca •www.envisionit.com/eum •Video and presentation deck will be at www.envisionit.com/events •Customer sites www.publichealthontario.ca www.bgccan.com www.g2gmarket.com www.redcrest.com.au www.transamerica.ca suppliers.kinross.com www.problemgambling.ca