SlideShare a Scribd company logo
JOURNEY TO THE
CLOUD

FIM 2010 Used for Management of
AD the core of your Identity in the
Private Cloud
Cloud Security Concerns
  • Security is the number 1 concern for cloud adoption
  • 75% responded 4 or 5 (on 1 to 5 scale) *
  • Key security issues:
     • Isolation of tenants from each other & hosting infrastructure
     • Compute and network layers
     • Authentication / Authorization / Auditing of access to cloud
       services
     • Unauthorized access / DoS due to weak (or mis)configuration




                                                 * Source: IDC Enterprise Panel
Three Pillars



          Authentication




                           Authorization




                                           Attributes
            Identity Management Platform
To The Cloud!
Typical Cloud ID Journey




                                      Authentication




                                                       Authorization




                                                                       Attributes
                         Federated
                         Islands of
       Silos              Identity
 (Islands of Identity)
A Better Journey




                                      Authentication




                                                       Authorization




                                                                       Attributes
                         Federated
                         Islands of
       Silos              Identity      Identity Management Platform
 (Islands of Identity)
What is Forefront Identity Manager


                                                        Self-Service
                                                        integration
                                                                       Windows
                                                                       Log On
                              FIM Portal




                                           Manages Active Directory
    LOB                                       - secure delegation
 Applications                                   of administration                      AD FS login across clouds
                                               - enable access to
                                                  private cloud




  Databases                                                                        Integrated login to applications




                Directories                                                      Secure the Private Cloud
Common Identity across clouds

                                                                                                                                             Private
                                                                                                                                             Cloud
HR System
            FirstName    Terry

            LastName     Adams

            Title        Sales Manager                                                  FirstName   Terry
                                                                                                                                             Exchange
            Dept         Sales                                                          LastName    Adams
                                                                                                                                                        SharePoint
            Mgr:         Melissa Meyers                                                 Title       Sales Manager
                                                                                                                                       Web
            EmplID       123                                                            Dept        Sales                              Sites Line of
                                          Group membership and user                     Mgr:        Melissa Meyers
                                                                                                                                             Business
                                             attributes generated                                                                             Apps      File /
                                                                                                                                                        Print
                                                                                        LoginID     Tadams
                                                                                                                          Integrated
                                                      Workflow                          Phone       555-1212              and
                                                                                                                          federated
                                                                                        Email        Tadams@litware.com
                                                                                                                          common
                                             FIM 2010                                                                     identity            Public
                                                                                                                                              Cloud
                                                                                        Groups      Melissa’s Directs

                                                                                                    All in Sales
                                                                                                                                           PaaS
 Phone                                                                                              Sales App Owners                           SaaS
             Firstname   Terry

             LastName    Adams
                                                                             AD                                                        Windows
                                                                                                                                        Azure Office 36
             Phone       555-1234

                                              Email
                                                         LoginID   Tadams

                                                         Email     tadams@litware.com
Private Cloud Enabled Identity

All Microsoft solutions for private cloud leverage a single identity store to authenticate users
with Microsoft® Active Directory® across physical and virtual systems.

   Active Directory                          System Center Virtual       Forefront Identity
                                                Machine Manager               Manager
    o   Single identity store to
        authenticate users
                                                       Forefront™ Security Solutions
    o   Support across physical and




                                                                                               Active Directory
        virtual systems                                     Virtualization
    o   Federated Identity                     Hardware        Presentation      Application

   Forefront Identity Manager
                                               Hyper-V™         Terminal         Microsoft
    o   Easy user provisioning                                  Services         App. Virt.

    o   Identity synchronization
    o   Simplified management of                        Network Access Protection

        cloud resources
                                                        Server and Domain Isolation
Solution Example –
 Enhancing Private Cloud with Identity


  •   Hyper-V and SC Virtual Machine Manager uses roles
  •   Roles can contain users or groups from AD
  •   Delegation of datacenter management
  •   Forefront Identity Manager securely manages membership in AD
      groups




                                                       Private Cloud
   Roles in        Leverage AD
                                      Manage AD         Self Service
 Hyper-V and        Groups in
                                     Groups in FIM      secure and
System Center          roles
                                                         compliant
Solution Example- Enhancing Private Cloud with Identity
Hyper-V Authorization Manager + Common identity in Private Cloud



 •   Default role allows access
     to all operations


 •   Additional roles with
     desired rights can be
     created
     •   33 different operations
         OOB
         grouped under
         •   Hyper-V Service
             Operations
         •   Hyper-V Networks
             Operations
         •   Hyper-V Virtual Machine
             Operations
Solution Example - Enhancing Private Cloud with Identity
Virtual Machine Manager + Common identity in Private Cloud



•   The Administrator profile
     •   Complete administrative access to
         all the hosts, virtual machines, and
         library servers in VMM 2008
•   The Delegated Administrator profile
     •   Grants administrative access to a
         defined set of host groups and
         library servers
•   The Self-Service User profile
     •   Administrative access to a defined
         set of virtual machines through the
         Web-based Virtual Machine
         Manager Self-Service Portal



•   Additional delegation capabilities
    in Self service portal
FIM (Helping) with The Cloud
                   Oh,
                 alright
                  then


                                       Can I have
                                     Admin access to
                                     the cloud app?
                           Request
Approve




          User
EVERY JOURNEY NEEDS A HISTORY




                                      Authentication



                                                       Authorization



                                                                       Attributes



                                                                                    Audit
                         Federated
                         Islands of
       Silos              Identity      Identity Management Platform
 (Islands of Identity)
TO THE CLOUD!

    • Using Hyper-V as an infrastructure for Private Cloud is
      great for server optimization but, without an IAM
      architecture in place, this is just moving around the
      administrative problems.
    • FIM provides a compliant and well managed AD.
      Compliance here is about automation of changing access
      permissions, making sure users have the right
      access, reporting.
    • Active Directory provides the common identity platform
      for classic datacenter hosted systems, to private cloud
      and also paves the way to enabling use of public cloud
      resources.
QUESTIONS ?

More Related Content

PPTX
Journey to the cloud
PPTX
Iam4Cloud
PDF
ECM and Enterprise 2.0
PPTX
Manage Agility through Manage-ability – Introducing Design Time at Run Time ...
PPTX
Track 2, session 5, aligning security with business kartik shahani
PPT
Microsoft Unified Communications - Retail Presentation
PDF
Microsoft X
PDF
SharePoint Saturday Boston - Collaboration doesn't end with SharePoint
Journey to the cloud
Iam4Cloud
ECM and Enterprise 2.0
Manage Agility through Manage-ability – Introducing Design Time at Run Time ...
Track 2, session 5, aligning security with business kartik shahani
Microsoft Unified Communications - Retail Presentation
Microsoft X
SharePoint Saturday Boston - Collaboration doesn't end with SharePoint

What's hot (7)

PPTX
Evolving RM to Information Governance to Protect Your Organizations
PDF
Exploring IBM's Advanced Collaboration Solutions
PDF
Saurabh Gupta Design Portfolio 2002-08
PPTX
SharePoint & ERM
KEY
Now that I have CRM, what else can I do with it?
PDF
PPTX
Business Computing in Future with Voice
Evolving RM to Information Governance to Protect Your Organizations
Exploring IBM's Advanced Collaboration Solutions
Saurabh Gupta Design Portfolio 2002-08
SharePoint & ERM
Now that I have CRM, what else can I do with it?
Business Computing in Future with Voice
Ad

Similar to Private cloud forefront identity manager 2010 (adam bresson) (20)

PPT
Microsoft Unified Communications - Overview Presentation
PPTX
Uc Microsoft Lync
PDF
emediaIT - Unified Communications - 2011.09.01
PPT
Tech Executives Risk Mgmt And It Gov Frm Iam Persp Nov13
PPTX
Lync Server Notes from the Field: Options for Deployment
PDF
IDM & IAM 2012
PPTX
Supporting architecture for office 365 spo
PPSX
Lync 2013 business value compact
PPTX
Adfs azure
PPTX
How to provide AD, ADFS, DirSync in Windows Azure and hook it up with Office 365
PPSX
Credexo IDM
PPTX
PDF
DirectAccess
PPTX
Unify² Polycom-Microsoft UCC Portfolio
PDF
Office 365: Planning and Automating for Hybrid Identity Scenarios in the Clou...
PDF
Reference architecture for community clouds
PPTX
Deployment Planning for Success - #SPSBend
PPTX
Consumerization of IT MSL Jumpstart Keynote
PDF
SharePoint 2013-design-sample-extranet
PDF
SharePoint Saturday - Putting Paper to Work
Microsoft Unified Communications - Overview Presentation
Uc Microsoft Lync
emediaIT - Unified Communications - 2011.09.01
Tech Executives Risk Mgmt And It Gov Frm Iam Persp Nov13
Lync Server Notes from the Field: Options for Deployment
IDM & IAM 2012
Supporting architecture for office 365 spo
Lync 2013 business value compact
Adfs azure
How to provide AD, ADFS, DirSync in Windows Azure and hook it up with Office 365
Credexo IDM
DirectAccess
Unify² Polycom-Microsoft UCC Portfolio
Office 365: Planning and Automating for Hybrid Identity Scenarios in the Clou...
Reference architecture for community clouds
Deployment Planning for Success - #SPSBend
Consumerization of IT MSL Jumpstart Keynote
SharePoint 2013-design-sample-extranet
SharePoint Saturday - Putting Paper to Work
Ad

More from Harold Wong (20)

PPTX
System Center 2012 SP1 Overview and Window Azure IaaS
PPTX
Upgrading from Windows Server 2008 / 2008 R2 to Windows Server 2012
PPTX
Windows 8 Deployment
PPTX
FY13 Q2 IT Camp - Windows 8 Overview
PPTX
TechMentor 2012: Deploying Windows Server 2012 Server Core
PPTX
TechMentor 2012: What's new in Windows Server 2012 and Hyper-V
PPTX
IT Camp - Vision Solutions Presentation
PPTX
Windows Server 2012 Beta Storage Overview
PPTX
IT Camp Windows Server 2012 Beta Hyper-V Overview
PPTX
FI-B328 How to Build a Microsoft Private Cloud Lab in 1,000 Tiny Steps
PPTX
It camp veeam presentation (no videos)
PPTX
Cloud Intelligence - Get Your Head Out of the Clouds
PPTX
Cloud Intelligence - Build a Private Cloud in a 1,000 Easy Steps
PPTX
IT Camp Opening - Los Angeles
PPTX
IT Camp Opening - Phoenix / Tempe
PPTX
IT Camp - Server Migration Overview
PPTX
Private cloud 201 how to build a private cloud
PPTX
Get ready for tomorrow, today!
PPTX
Lync 2010 Conferencing Deep Dive
PPTX
Lync 2010 Voice Deployment
System Center 2012 SP1 Overview and Window Azure IaaS
Upgrading from Windows Server 2008 / 2008 R2 to Windows Server 2012
Windows 8 Deployment
FY13 Q2 IT Camp - Windows 8 Overview
TechMentor 2012: Deploying Windows Server 2012 Server Core
TechMentor 2012: What's new in Windows Server 2012 and Hyper-V
IT Camp - Vision Solutions Presentation
Windows Server 2012 Beta Storage Overview
IT Camp Windows Server 2012 Beta Hyper-V Overview
FI-B328 How to Build a Microsoft Private Cloud Lab in 1,000 Tiny Steps
It camp veeam presentation (no videos)
Cloud Intelligence - Get Your Head Out of the Clouds
Cloud Intelligence - Build a Private Cloud in a 1,000 Easy Steps
IT Camp Opening - Los Angeles
IT Camp Opening - Phoenix / Tempe
IT Camp - Server Migration Overview
Private cloud 201 how to build a private cloud
Get ready for tomorrow, today!
Lync 2010 Conferencing Deep Dive
Lync 2010 Voice Deployment

Recently uploaded (20)

PPTX
Detection-First SIEM: Rule Types, Dashboards, and Threat-Informed Strategy
PDF
Advanced methodologies resolving dimensionality complications for autism neur...
PDF
Encapsulation_ Review paper, used for researhc scholars
PPT
Teaching material agriculture food technology
PDF
7 ChatGPT Prompts to Help You Define Your Ideal Customer Profile.pdf
PDF
Diabetes mellitus diagnosis method based random forest with bat algorithm
PPTX
Understanding_Digital_Forensics_Presentation.pptx
PPTX
KOM of Painting work and Equipment Insulation REV00 update 25-dec.pptx
PPTX
Cloud computing and distributed systems.
PDF
KodekX | Application Modernization Development
PPTX
Big Data Technologies - Introduction.pptx
PDF
Reach Out and Touch Someone: Haptics and Empathic Computing
DOCX
The AUB Centre for AI in Media Proposal.docx
PDF
How UI/UX Design Impacts User Retention in Mobile Apps.pdf
PDF
Build a system with the filesystem maintained by OSTree @ COSCUP 2025
PPTX
20250228 LYD VKU AI Blended-Learning.pptx
PDF
Encapsulation theory and applications.pdf
PDF
Bridging biosciences and deep learning for revolutionary discoveries: a compr...
PDF
TokAI - TikTok AI Agent : The First AI Application That Analyzes 10,000+ Vira...
PDF
Dropbox Q2 2025 Financial Results & Investor Presentation
Detection-First SIEM: Rule Types, Dashboards, and Threat-Informed Strategy
Advanced methodologies resolving dimensionality complications for autism neur...
Encapsulation_ Review paper, used for researhc scholars
Teaching material agriculture food technology
7 ChatGPT Prompts to Help You Define Your Ideal Customer Profile.pdf
Diabetes mellitus diagnosis method based random forest with bat algorithm
Understanding_Digital_Forensics_Presentation.pptx
KOM of Painting work and Equipment Insulation REV00 update 25-dec.pptx
Cloud computing and distributed systems.
KodekX | Application Modernization Development
Big Data Technologies - Introduction.pptx
Reach Out and Touch Someone: Haptics and Empathic Computing
The AUB Centre for AI in Media Proposal.docx
How UI/UX Design Impacts User Retention in Mobile Apps.pdf
Build a system with the filesystem maintained by OSTree @ COSCUP 2025
20250228 LYD VKU AI Blended-Learning.pptx
Encapsulation theory and applications.pdf
Bridging biosciences and deep learning for revolutionary discoveries: a compr...
TokAI - TikTok AI Agent : The First AI Application That Analyzes 10,000+ Vira...
Dropbox Q2 2025 Financial Results & Investor Presentation

Private cloud forefront identity manager 2010 (adam bresson)

  • 1. JOURNEY TO THE CLOUD FIM 2010 Used for Management of AD the core of your Identity in the Private Cloud
  • 2. Cloud Security Concerns • Security is the number 1 concern for cloud adoption • 75% responded 4 or 5 (on 1 to 5 scale) * • Key security issues: • Isolation of tenants from each other & hosting infrastructure • Compute and network layers • Authentication / Authorization / Auditing of access to cloud services • Unauthorized access / DoS due to weak (or mis)configuration * Source: IDC Enterprise Panel
  • 3. Three Pillars Authentication Authorization Attributes Identity Management Platform
  • 5. Typical Cloud ID Journey Authentication Authorization Attributes Federated Islands of Silos Identity (Islands of Identity)
  • 6. A Better Journey Authentication Authorization Attributes Federated Islands of Silos Identity Identity Management Platform (Islands of Identity)
  • 7. What is Forefront Identity Manager Self-Service integration Windows Log On FIM Portal Manages Active Directory LOB - secure delegation Applications of administration AD FS login across clouds - enable access to private cloud Databases Integrated login to applications Directories Secure the Private Cloud
  • 8. Common Identity across clouds Private Cloud HR System FirstName Terry LastName Adams Title Sales Manager FirstName Terry Exchange Dept Sales LastName Adams SharePoint Mgr: Melissa Meyers Title Sales Manager Web EmplID 123 Dept Sales Sites Line of Group membership and user Mgr: Melissa Meyers Business attributes generated Apps File / Print LoginID Tadams Integrated Workflow Phone 555-1212 and federated Email Tadams@litware.com common FIM 2010 identity Public Cloud Groups Melissa’s Directs All in Sales PaaS Phone Sales App Owners SaaS Firstname Terry LastName Adams AD Windows Azure Office 36 Phone 555-1234 Email LoginID Tadams Email tadams@litware.com
  • 9. Private Cloud Enabled Identity All Microsoft solutions for private cloud leverage a single identity store to authenticate users with Microsoft® Active Directory® across physical and virtual systems.  Active Directory System Center Virtual Forefront Identity Machine Manager Manager o Single identity store to authenticate users Forefront™ Security Solutions o Support across physical and Active Directory virtual systems Virtualization o Federated Identity Hardware Presentation Application  Forefront Identity Manager Hyper-V™ Terminal Microsoft o Easy user provisioning Services App. Virt. o Identity synchronization o Simplified management of Network Access Protection cloud resources Server and Domain Isolation
  • 10. Solution Example – Enhancing Private Cloud with Identity • Hyper-V and SC Virtual Machine Manager uses roles • Roles can contain users or groups from AD • Delegation of datacenter management • Forefront Identity Manager securely manages membership in AD groups Private Cloud Roles in Leverage AD Manage AD Self Service Hyper-V and Groups in Groups in FIM secure and System Center roles compliant
  • 11. Solution Example- Enhancing Private Cloud with Identity Hyper-V Authorization Manager + Common identity in Private Cloud • Default role allows access to all operations • Additional roles with desired rights can be created • 33 different operations OOB grouped under • Hyper-V Service Operations • Hyper-V Networks Operations • Hyper-V Virtual Machine Operations
  • 12. Solution Example - Enhancing Private Cloud with Identity Virtual Machine Manager + Common identity in Private Cloud • The Administrator profile • Complete administrative access to all the hosts, virtual machines, and library servers in VMM 2008 • The Delegated Administrator profile • Grants administrative access to a defined set of host groups and library servers • The Self-Service User profile • Administrative access to a defined set of virtual machines through the Web-based Virtual Machine Manager Self-Service Portal • Additional delegation capabilities in Self service portal
  • 13. FIM (Helping) with The Cloud Oh, alright then Can I have Admin access to the cloud app? Request Approve User
  • 14. EVERY JOURNEY NEEDS A HISTORY Authentication Authorization Attributes Audit Federated Islands of Silos Identity Identity Management Platform (Islands of Identity)
  • 15. TO THE CLOUD! • Using Hyper-V as an infrastructure for Private Cloud is great for server optimization but, without an IAM architecture in place, this is just moving around the administrative problems. • FIM provides a compliant and well managed AD. Compliance here is about automation of changing access permissions, making sure users have the right access, reporting. • Active Directory provides the common identity platform for classic datacenter hosted systems, to private cloud and also paves the way to enabling use of public cloud resources.