SlideShare a Scribd company logo
JOURNEY TO THE
CLOUD

FIM 2010 Used for Management of
AD the core of your Identity in the
Private Cloud
Cloud Security Concerns
  • Security is the number 1 concern for cloud adoption
  • 75% responded 4 or 5 (on 1 to 5 scale) *
  • Key security issues:
     • Isolation of tenants from each other & hosting infrastructure
     • Compute and network layers
     • Authentication / Authorization / Auditing of access to cloud
       services
     • Unauthorized access / DoS due to weak (or mis)configuration




                                                 * Source: IDC Enterprise Panel
Three Pillars



          Authentication




                           Authorization




                                           Attributes
            Identity Management Platform
To The Cloud!
Typical Cloud ID Journey




                                      Authentication




                                                       Authorization




                                                                       Attributes
                         Federated
                         Islands of
       Silos              Identity
 (Islands of Identity)
A Better Journey




                                      Authentication




                                                       Authorization




                                                                       Attributes
                         Federated
                         Islands of
       Silos              Identity      Identity Management Platform
 (Islands of Identity)
What is Forefront Identity Manager


                                                        Self-Service
                                                        integration
                                                                       Windows
                                                                       Log On
                              FIM Portal




                                           Manages Active Directory
    LOB                                       - secure delegation
 Applications                                   of administration                      AD FS login across clouds
                                               - enable access to
                                                  private cloud




  Databases                                                                        Integrated login to applications




                Directories                                                      Secure the Private Cloud
Common Identity across clouds

                                                                                                                                             Private
                                                                                                                                             Cloud
HR System
            FirstName    Terry

            LastName     Adams

            Title        Sales Manager                                                  FirstName   Terry
                                                                                                                                             Exchange
            Dept         Sales                                                          LastName    Adams
                                                                                                                                                        SharePoint
            Mgr:         Melissa Meyers                                                 Title       Sales Manager
                                                                                                                                       Web
            EmplID       123                                                            Dept        Sales                              Sites Line of
                                          Group membership and user                     Mgr:        Melissa Meyers
                                                                                                                                             Business
                                             attributes generated                                                                             Apps      File /
                                                                                                                                                        Print
                                                                                        LoginID     Tadams
                                                                                                                          Integrated
                                                      Workflow                          Phone       555-1212              and
                                                                                                                          federated
                                                                                        Email        Tadams@litware.com
                                                                                                                          common
                                             FIM 2010                                                                     identity            Public
                                                                                                                                              Cloud
                                                                                        Groups      Melissa’s Directs

                                                                                                    All in Sales
                                                                                                                                           PaaS
 Phone                                                                                              Sales App Owners                           SaaS
             Firstname   Terry

             LastName    Adams
                                                                             AD                                                        Windows
                                                                                                                                        Azure Office 36
             Phone       555-1234

                                              Email
                                                         LoginID   Tadams

                                                         Email     tadams@litware.com
Private Cloud Enabled Identity

All Microsoft solutions for private cloud leverage a single identity store to authenticate users
with Microsoft® Active Directory® across physical and virtual systems.

   Active Directory                          System Center Virtual       Forefront Identity
                                                Machine Manager               Manager
    o   Single identity store to
        authenticate users
                                                       Forefront™ Security Solutions
    o   Support across physical and




                                                                                               Active Directory
        virtual systems                                     Virtualization
    o   Federated Identity                     Hardware        Presentation      Application

   Forefront Identity Manager
                                               Hyper-V™         Terminal         Microsoft
    o   Easy user provisioning                                  Services         App. Virt.

    o   Identity synchronization
    o   Simplified management of                        Network Access Protection

        cloud resources
                                                        Server and Domain Isolation
Solution Example –
 Enhancing Private Cloud with Identity


  •   Hyper-V and SC Virtual Machine Manager uses roles
  •   Roles can contain users or groups from AD
  •   Delegation of datacenter management
  •   Forefront Identity Manager securely manages membership in AD
      groups




                                                       Private Cloud
   Roles in        Leverage AD
                                      Manage AD         Self Service
 Hyper-V and        Groups in
                                     Groups in FIM      secure and
System Center          roles
                                                         compliant
Solution Example- Enhancing Private Cloud with Identity
Hyper-V Authorization Manager + Common identity in Private Cloud



 •   Default role allows access
     to all operations


 •   Additional roles with
     desired rights can be
     created
     •   33 different operations
         OOB
         grouped under
         •   Hyper-V Service
             Operations
         •   Hyper-V Networks
             Operations
         •   Hyper-V Virtual Machine
             Operations
Solution Example - Enhancing Private Cloud with Identity
Virtual Machine Manager + Common identity in Private Cloud



•   The Administrator profile
     •   Complete administrative access to
         all the hosts, virtual machines, and
         library servers in VMM 2008
•   The Delegated Administrator profile
     •   Grants administrative access to a
         defined set of host groups and
         library servers
•   The Self-Service User profile
     •   Administrative access to a defined
         set of virtual machines through the
         Web-based Virtual Machine
         Manager Self-Service Portal



•   Additional delegation capabilities
    in Self service portal
FIM (Helping) with The Cloud
                   Oh,
                 alright
                  then


                                       Can I have
                                     Admin access to
                                       cloud app?
                           Request
Approve




          User
EVERY JOURNEY NEEDS A HISTORY




                                      Authentication



                                                       Authorization



                                                                       Attributes



                                                                                    Audit
                         Federated
                         Islands of
       Silos              Identity      Identity Management Platform
 (Islands of Identity)
TO THE CLOUD!

    • Using Hyper-V as an infrastructure for Private Cloud is
      great for server optimization but, without an IAM
      architecture in place, this is just moving around the
      administrative problems
    • FIM provides a compliant and well managed AD.
      Compliance here is about automation of changing access
      permissions, making sure users have the right
      access, reporting.
    • Active Directory provides the common identity platform
      for classic datacenter hosted systems, to private cloud
      and also paves the way to enabling use of public cloud
      resources.
QUESTIONS ?

More Related Content

PPTX
Private cloud forefront identity manager 2010 (adam bresson)
PPTX
Iam4Cloud
PDF
ECM and Enterprise 2.0
PDF
SharePoint Saturday Boston - Collaboration doesn't end with SharePoint
PPTX
Manage Agility through Manage-ability – Introducing Design Time at Run Time ...
PDF
Exploring IBM's Advanced Collaboration Solutions
PPTX
Track 2, session 5, aligning security with business kartik shahani
PPT
Microsoft Unified Communications - Retail Presentation
Private cloud forefront identity manager 2010 (adam bresson)
Iam4Cloud
ECM and Enterprise 2.0
SharePoint Saturday Boston - Collaboration doesn't end with SharePoint
Manage Agility through Manage-ability – Introducing Design Time at Run Time ...
Exploring IBM's Advanced Collaboration Solutions
Track 2, session 5, aligning security with business kartik shahani
Microsoft Unified Communications - Retail Presentation

What's hot (8)

PDF
Microsoft X
PDF
Slimmer werken met Lotus Connections
PDF
Saurabh Gupta Design Portfolio 2002-08
PPTX
SharePoint & ERM
PDF
Jobo 1 ims_tm_value_2012_q2
PDF
Forefront Identity Manager2010
KEY
Now that I have CRM, what else can I do with it?
PDF
Microsoft X
Slimmer werken met Lotus Connections
Saurabh Gupta Design Portfolio 2002-08
SharePoint & ERM
Jobo 1 ims_tm_value_2012_q2
Forefront Identity Manager2010
Now that I have CRM, what else can I do with it?
Ad

Viewers also liked (14)

PDF
Implats Cloud Journey
PDF
Lessons Learned from an early Multi-Cloud journey
PPTX
Data Centre Evolution: Securing Your Journey to the Cloud
PDF
soCloud: distributed multi-cloud platform for deploying, executing and managi...
PPT
Standing on the clouds
PDF
Philip Hung Cao - Cloud security, the journey has begun
PDF
Security & Privacy in Cloud Computing
PDF
Privacy and security in the cloud Challenges and solutions for our future inf...
PDF
Journey to the Cloud, Hype or Opportunity
PDF
Dimension Data – Enabling the Journey to the Cloud: Real Examples
PPTX
Security: Enabling the Journey to the Cloud
PDF
#askSAP: Journey to the Cloud: SAP Strategy and Roadmap for Cloud and Hybrid ...
PPTX
Cloud computing security from single to multiple
PPTX
UKOUG Journey To The Cloud - March 2017
Implats Cloud Journey
Lessons Learned from an early Multi-Cloud journey
Data Centre Evolution: Securing Your Journey to the Cloud
soCloud: distributed multi-cloud platform for deploying, executing and managi...
Standing on the clouds
Philip Hung Cao - Cloud security, the journey has begun
Security & Privacy in Cloud Computing
Privacy and security in the cloud Challenges and solutions for our future inf...
Journey to the Cloud, Hype or Opportunity
Dimension Data – Enabling the Journey to the Cloud: Real Examples
Security: Enabling the Journey to the Cloud
#askSAP: Journey to the Cloud: SAP Strategy and Roadmap for Cloud and Hybrid ...
Cloud computing security from single to multiple
UKOUG Journey To The Cloud - March 2017
Ad

Similar to Journey to the cloud (20)

PPT
Microsoft Unified Communications - Overview Presentation
PPTX
Uc Microsoft Lync
PDF
emediaIT - Unified Communications - 2011.09.01
PDF
IDM & IAM 2012
PPT
Tech Executives Risk Mgmt And It Gov Frm Iam Persp Nov13
PPTX
Lync Server Notes from the Field: Options for Deployment
PPSX
Credexo IDM
PPSX
Lync 2013 business value compact
PPTX
Supporting architecture for office 365 spo
PPTX
Adfs azure
PPTX
How to provide AD, ADFS, DirSync in Windows Azure and hook it up with Office 365
PPTX
PDF
DirectAccess
PPTX
Deployment Planning for Success - #SPSBend
PDF
Enabling the Social Enterprise - Trae Chancellor
PDF
Enabling the Social Enterprise
PDF
Reference architecture for community clouds
PPTX
Unify² Polycom-Microsoft UCC Portfolio
PDF
Office 365: Planning and Automating for Hybrid Identity Scenarios in the Clou...
PDF
Csooow12 amit-jasuja-securing-new-experience6
Microsoft Unified Communications - Overview Presentation
Uc Microsoft Lync
emediaIT - Unified Communications - 2011.09.01
IDM & IAM 2012
Tech Executives Risk Mgmt And It Gov Frm Iam Persp Nov13
Lync Server Notes from the Field: Options for Deployment
Credexo IDM
Lync 2013 business value compact
Supporting architecture for office 365 spo
Adfs azure
How to provide AD, ADFS, DirSync in Windows Azure and hook it up with Office 365
DirectAccess
Deployment Planning for Success - #SPSBend
Enabling the Social Enterprise - Trae Chancellor
Enabling the Social Enterprise
Reference architecture for community clouds
Unify² Polycom-Microsoft UCC Portfolio
Office 365: Planning and Automating for Hybrid Identity Scenarios in the Clou...
Csooow12 amit-jasuja-securing-new-experience6

Recently uploaded (20)

PDF
Empathic Computing: Creating Shared Understanding
PPTX
Detection-First SIEM: Rule Types, Dashboards, and Threat-Informed Strategy
PPTX
Effective Security Operations Center (SOC) A Modern, Strategic, and Threat-In...
PDF
Reach Out and Touch Someone: Haptics and Empathic Computing
PDF
Approach and Philosophy of On baking technology
PDF
The Rise and Fall of 3GPP – Time for a Sabbatical?
PDF
CIFDAQ's Market Insight: SEC Turns Pro Crypto
PDF
NewMind AI Weekly Chronicles - August'25 Week I
PDF
TokAI - TikTok AI Agent : The First AI Application That Analyzes 10,000+ Vira...
PDF
Blue Purple Modern Animated Computer Science Presentation.pdf.pdf
PPTX
VMware vSphere Foundation How to Sell Presentation-Ver1.4-2-14-2024.pptx
PDF
Building Integrated photovoltaic BIPV_UPV.pdf
PPTX
Digital-Transformation-Roadmap-for-Companies.pptx
PDF
Advanced methodologies resolving dimensionality complications for autism neur...
PDF
Per capita expenditure prediction using model stacking based on satellite ima...
PDF
NewMind AI Monthly Chronicles - July 2025
PPTX
Big Data Technologies - Introduction.pptx
PPTX
A Presentation on Artificial Intelligence
PDF
Chapter 3 Spatial Domain Image Processing.pdf
PDF
Review of recent advances in non-invasive hemoglobin estimation
Empathic Computing: Creating Shared Understanding
Detection-First SIEM: Rule Types, Dashboards, and Threat-Informed Strategy
Effective Security Operations Center (SOC) A Modern, Strategic, and Threat-In...
Reach Out and Touch Someone: Haptics and Empathic Computing
Approach and Philosophy of On baking technology
The Rise and Fall of 3GPP – Time for a Sabbatical?
CIFDAQ's Market Insight: SEC Turns Pro Crypto
NewMind AI Weekly Chronicles - August'25 Week I
TokAI - TikTok AI Agent : The First AI Application That Analyzes 10,000+ Vira...
Blue Purple Modern Animated Computer Science Presentation.pdf.pdf
VMware vSphere Foundation How to Sell Presentation-Ver1.4-2-14-2024.pptx
Building Integrated photovoltaic BIPV_UPV.pdf
Digital-Transformation-Roadmap-for-Companies.pptx
Advanced methodologies resolving dimensionality complications for autism neur...
Per capita expenditure prediction using model stacking based on satellite ima...
NewMind AI Monthly Chronicles - July 2025
Big Data Technologies - Introduction.pptx
A Presentation on Artificial Intelligence
Chapter 3 Spatial Domain Image Processing.pdf
Review of recent advances in non-invasive hemoglobin estimation

Journey to the cloud

  • 1. JOURNEY TO THE CLOUD FIM 2010 Used for Management of AD the core of your Identity in the Private Cloud
  • 2. Cloud Security Concerns • Security is the number 1 concern for cloud adoption • 75% responded 4 or 5 (on 1 to 5 scale) * • Key security issues: • Isolation of tenants from each other & hosting infrastructure • Compute and network layers • Authentication / Authorization / Auditing of access to cloud services • Unauthorized access / DoS due to weak (or mis)configuration * Source: IDC Enterprise Panel
  • 3. Three Pillars Authentication Authorization Attributes Identity Management Platform
  • 5. Typical Cloud ID Journey Authentication Authorization Attributes Federated Islands of Silos Identity (Islands of Identity)
  • 6. A Better Journey Authentication Authorization Attributes Federated Islands of Silos Identity Identity Management Platform (Islands of Identity)
  • 7. What is Forefront Identity Manager Self-Service integration Windows Log On FIM Portal Manages Active Directory LOB - secure delegation Applications of administration AD FS login across clouds - enable access to private cloud Databases Integrated login to applications Directories Secure the Private Cloud
  • 8. Common Identity across clouds Private Cloud HR System FirstName Terry LastName Adams Title Sales Manager FirstName Terry Exchange Dept Sales LastName Adams SharePoint Mgr: Melissa Meyers Title Sales Manager Web EmplID 123 Dept Sales Sites Line of Group membership and user Mgr: Melissa Meyers Business attributes generated Apps File / Print LoginID Tadams Integrated Workflow Phone 555-1212 and federated Email Tadams@litware.com common FIM 2010 identity Public Cloud Groups Melissa’s Directs All in Sales PaaS Phone Sales App Owners SaaS Firstname Terry LastName Adams AD Windows Azure Office 36 Phone 555-1234 Email LoginID Tadams Email tadams@litware.com
  • 9. Private Cloud Enabled Identity All Microsoft solutions for private cloud leverage a single identity store to authenticate users with Microsoft® Active Directory® across physical and virtual systems.  Active Directory System Center Virtual Forefront Identity Machine Manager Manager o Single identity store to authenticate users Forefront™ Security Solutions o Support across physical and Active Directory virtual systems Virtualization o Federated Identity Hardware Presentation Application  Forefront Identity Manager Hyper-V™ Terminal Microsoft o Easy user provisioning Services App. Virt. o Identity synchronization o Simplified management of Network Access Protection cloud resources Server and Domain Isolation
  • 10. Solution Example – Enhancing Private Cloud with Identity • Hyper-V and SC Virtual Machine Manager uses roles • Roles can contain users or groups from AD • Delegation of datacenter management • Forefront Identity Manager securely manages membership in AD groups Private Cloud Roles in Leverage AD Manage AD Self Service Hyper-V and Groups in Groups in FIM secure and System Center roles compliant
  • 11. Solution Example- Enhancing Private Cloud with Identity Hyper-V Authorization Manager + Common identity in Private Cloud • Default role allows access to all operations • Additional roles with desired rights can be created • 33 different operations OOB grouped under • Hyper-V Service Operations • Hyper-V Networks Operations • Hyper-V Virtual Machine Operations
  • 12. Solution Example - Enhancing Private Cloud with Identity Virtual Machine Manager + Common identity in Private Cloud • The Administrator profile • Complete administrative access to all the hosts, virtual machines, and library servers in VMM 2008 • The Delegated Administrator profile • Grants administrative access to a defined set of host groups and library servers • The Self-Service User profile • Administrative access to a defined set of virtual machines through the Web-based Virtual Machine Manager Self-Service Portal • Additional delegation capabilities in Self service portal
  • 13. FIM (Helping) with The Cloud Oh, alright then Can I have Admin access to cloud app? Request Approve User
  • 14. EVERY JOURNEY NEEDS A HISTORY Authentication Authorization Attributes Audit Federated Islands of Silos Identity Identity Management Platform (Islands of Identity)
  • 15. TO THE CLOUD! • Using Hyper-V as an infrastructure for Private Cloud is great for server optimization but, without an IAM architecture in place, this is just moving around the administrative problems • FIM provides a compliant and well managed AD. Compliance here is about automation of changing access permissions, making sure users have the right access, reporting. • Active Directory provides the common identity platform for classic datacenter hosted systems, to private cloud and also paves the way to enabling use of public cloud resources.

Editor's Notes

  • #2: This is not directly related to Private Cloud - did you find this in private cloud mtrl from marketing then you are good to go. If not then this is for Public cloud.
  • #4: the pillar slides are generic to CLoud computing and not specific to Private Cloud so the speaker should make the audience aware of this and that identity is a common platform across private and public cloud
  • #8: modifying this slide to reflect private cloud. needs more work and perhaps needs to have builds where the left hand side is shown first to talk about enhancing data in Active directory with classic provisioning and synchronization then add the top level to provide info on how datacenter admin can give application owners a way to manage security groups that they will use inside of the applications they own and are deploying on top of the private cloud. same goes true for datacenter administrators that own the private cloud and want to delegate access to certain admins to have access to part of the private cloud (this is done in the VMM self service portal and it uses security groups in AD)
  • #9: moved this slide to kick off transfer from generic cloud discussion to private cloud. ... the final comment from speaker should be .. now lets look at how identity is levereged in managing the private cloud
  • #15: In Private cloud you really dont need the .CSV file to issue identities in the cloud app as it is all on-premises and is either AD integrated. Having this link to apps in private cloud that are not AD integrated is fine but dont use just a CSV file .. just say account provisioning
  • #16: Great value add for FIM to talk about the need for audit history of datacenter admins having requested new VM's, app owners creating new SG's and approving users access to their applications or provide devs access to their applciations and finally the end users requests for these apps.