SlideShare a Scribd company logo
Securing Access to SaaS Apps with WSO2
Identity Server​
June 25, 2017
Ishara Karunarathna
Farasath Ahamed
1
2017 Summer School Webinar Series
2
About WSO2
▪ All WSO2 products 100% free and open source
▪ Licensed under Apache 2.0
▪ Based on WSO2 Carbon platform
▪ Componentized, modular architecture
▪ Founded in 2005
3
WSO2 Platform
4
▪ Currently in its 5th generation
▪ Latest release - WSO2 Identity Server 5.3.0
▪ Addresses critical IAM needs both in customer IAM and workforce IAM
spaces
▪ Extensive support for open standards - no vendor locking
▪ Large scale deployments over millions of users
▪ Rich eco system with 40+ connectors
(https://store.wso2.com/store/assets/isconnector/list)
▪ Support for multi-tenancy
▪ Extensible product architecture to address complex IAM needs
About WSO2 Identity Server
5
Securing Access to
SaaS Apps with
WSO2 Identity
Server
6
Agenda
▪ SaaS apps, Why?
▪ Business benefits with SaaS apps
▪ IAM challenges with SaaS integration
▪ IAM Solution Patterns for SaaS Apps
▪ Q&A
7
“Software-as-a-Service (SaaS) is expected to
increase 20.1%, reaching $46.3B in 2017”
SaaS Apps, Why?
8
- Gartner -
▪ Efficiency, velocity, and agility
▪ Cost-effective
▪ Better collaboration
Business benefits with SaaS apps
9
IAM Challenges
With
SaaS applications
10
"Security is the No. 1 reason preventing firms from
moving to SaaS,"
What prevents you from moving to SaaS
11
▪ Identity and Access Management
▪ Application and data Management
▪ Logging and monitoring
SaaS Security Concerns
12
▪ Identity LifeCycle Management
▪ User Authentication
▪ User Authorization
▪ Single Sign-On
▪ Analytics
IAM Challenges with SaaS Apps
13
▪ Error-Prone user provisioning and deprovisioning
▪ Overhead of User administration
▪ Self service and Identity verification
▪ Different administration models for different applications
Identity LifeCycle Management
14
▪ User password fatigue
▪ Strong multifactor authentication
▪ Elevated authentication support
▪ Adaptive authentication
▪ BYOID
User Authentication
15
▪ Centralized Authorization
▪ Role based access control
▪ Granular permissions
▪ Access delegation
User Authorization
16
▪ SIngle authentication session for multiple application logins
▪ Identity Federation
▪ Protocol bridging
▪ Seamless application integration
Single Sign-On
17
▪ Fraud detection
▪ Understanding user behavior
▪ Predicting future needs
Analytics
18
▪ Use existing infrastructure wherever and whenever possible
▪ Avoid proprietary mechanisms go, for Open Standards
▪ Minimise sensitive user data in the cloud
▪ Right balance between Security vs Convenience
▪ Requires a cultural changes to move to new platform
SaaS IAM Best Practices
19
IAM Solution Patterns
for
SaaS Apps
20
Identity Provisioning
21
Rule/Workflow based Provisioning
22
Just In Time Provisioning
23
Claim/Role mapping
24
Single Sign On using multiple protocols
25
Single Sign On using multiple protocols
26
Multi Factor Authentication
27
Multi Factor Authentication
28
Engage Authorization policies in Authentication
29
Adaptive Authentication
30
Federated Authentication
31
Monitoring and Analytics
32
Q&A
33
What next?
34
OPEN TECHNOLOGY FOR YOUR AGILE DIGITAL BUSINESS
THANK YOU
35

More Related Content

PDF
Identity Federation Patterns with WSO2 Identity Server​
PPTX
Identity and Access Management in the Era of Digital Transformation
PDF
Digital Identities in the Internet of Things - Securely Manage Devices at Scale
PDF
T-Systems. Automating ForgeRock Full Stack Deployments to a Magenta Cloud.
PPTX
Identity Live Paris 2017 | Ian Sorbello, HSBC
PPTX
Identity Live London 2017 | Kenneth May
PPTX
2015 Identity Summit - CTO Innovation Center
PPTX
Identity Live Sydney 2017 - Tim Sheedy
Identity Federation Patterns with WSO2 Identity Server​
Identity and Access Management in the Era of Digital Transformation
Digital Identities in the Internet of Things - Securely Manage Devices at Scale
T-Systems. Automating ForgeRock Full Stack Deployments to a Magenta Cloud.
Identity Live Paris 2017 | Ian Sorbello, HSBC
Identity Live London 2017 | Kenneth May
2015 Identity Summit - CTO Innovation Center
Identity Live Sydney 2017 - Tim Sheedy

What's hot (20)

PPTX
McKesson Case Study: Pharmacy Systems & Automation
PPTX
Identity Gateway with the ForgeRock Identity Platform - So What’s New?
PPTX
2015 Identity Summit - Stepping Up to New Data Protection Challenges
PDF
GDPR & Customer IAM: The Real Winners Won’t Stop At Compliance
PPTX
9.35am robert humphrey
PPTX
HSBC - ForgeRock Identity Summit 2017 Dusseldorf
PPTX
Identity Live Paris 2017 | Monetising Digital Customer Relationships
PPTX
apidays LIVE Paris 2021 - How password managers are built for Privacy and Sec...
PPTX
Identity Live Sydney 2017 - Ian Sorbello
PPTX
Webinar: ForgeRock Identity Platform Preview (Dec 2015)
PDF
Silo Busters- The Value of User and Data Centricity beyond IoT Devices (Ident...
PDF
Implications of GDPR in Conjunction with UMA
PDF
ForgeRock and Trusona - Simplifying the Multi-factor User Experience
PDF
Go Beyond PSD2 Compliance with Digital Identity
PDF
ForgeRock Platform Release - Summer 2016
PDF
apidays LIVE Paris 2021 - Identification & Authentication for Individuals wit...
PPT
ForgeRock Open Identity Stack Summit - Kick-off by Mike Ellis
PPTX
Identity Live Sydney 2017 - Michael Dowling
PPTX
2015 Identity Summit - The Identity Broker as Driver for Growth
PDF
Security On The Edge - A New Way To Think About Securing the Internet of Things
McKesson Case Study: Pharmacy Systems & Automation
Identity Gateway with the ForgeRock Identity Platform - So What’s New?
2015 Identity Summit - Stepping Up to New Data Protection Challenges
GDPR & Customer IAM: The Real Winners Won’t Stop At Compliance
9.35am robert humphrey
HSBC - ForgeRock Identity Summit 2017 Dusseldorf
Identity Live Paris 2017 | Monetising Digital Customer Relationships
apidays LIVE Paris 2021 - How password managers are built for Privacy and Sec...
Identity Live Sydney 2017 - Ian Sorbello
Webinar: ForgeRock Identity Platform Preview (Dec 2015)
Silo Busters- The Value of User and Data Centricity beyond IoT Devices (Ident...
Implications of GDPR in Conjunction with UMA
ForgeRock and Trusona - Simplifying the Multi-factor User Experience
Go Beyond PSD2 Compliance with Digital Identity
ForgeRock Platform Release - Summer 2016
apidays LIVE Paris 2021 - Identification & Authentication for Individuals wit...
ForgeRock Open Identity Stack Summit - Kick-off by Mike Ellis
Identity Live Sydney 2017 - Michael Dowling
2015 Identity Summit - The Identity Broker as Driver for Growth
Security On The Edge - A New Way To Think About Securing the Internet of Things
Ad

Similar to Securing Access to SaaS Apps with WSO2 Identity Server (20)

PPTX
Synergies across APIs and IAM
PDF
CA Security - Deloitte IAM Summit - Vasu
PDF
Cloud Customer Architecture for Securing Workloads on Cloud Services
PDF
Hybrid IAM: Fuelling Agility in the Cloud Transformation Journey | Gartner IA...
PDF
Navigating Identity and Access Management in the Modern Enterprise
PDF
Addressing Integration needs in the education industry with the WSO2 Platform
PPT
Six Steps To Build A Successful API
PPT
Six Steps to Build Successful APIs
PDF
Webinar: Deep Diving Into the KuppingerCole IDaaS Leadership Compass
PDF
API Management within a Microservice Architecture
PPTX
API Management Within a Microservices Architecture
PDF
Cloud Customer Architecture for API Management
PDF
A Study in Borderless Over Perimeter
PDF
APIs from the Edge to the Mesh
PDF
Cloud Modernization and Data as a Service Option
PDF
Benefits of Using Open Source IAM
PDF
WSO2CON 2024 - Unlocking the Identity: Embracing CIAM 2.0 for a Competitive A...
PDF
Introducing The WSO2 Platform
PPTX
Digital Transformation with Mobile Connect: Enhancing your Customer Experience
PPTX
WSO2- OSC Korea - Accelerating Digital Businesses with APIs
Synergies across APIs and IAM
CA Security - Deloitte IAM Summit - Vasu
Cloud Customer Architecture for Securing Workloads on Cloud Services
Hybrid IAM: Fuelling Agility in the Cloud Transformation Journey | Gartner IA...
Navigating Identity and Access Management in the Modern Enterprise
Addressing Integration needs in the education industry with the WSO2 Platform
Six Steps To Build A Successful API
Six Steps to Build Successful APIs
Webinar: Deep Diving Into the KuppingerCole IDaaS Leadership Compass
API Management within a Microservice Architecture
API Management Within a Microservices Architecture
Cloud Customer Architecture for API Management
A Study in Borderless Over Perimeter
APIs from the Edge to the Mesh
Cloud Modernization and Data as a Service Option
Benefits of Using Open Source IAM
WSO2CON 2024 - Unlocking the Identity: Embracing CIAM 2.0 for a Competitive A...
Introducing The WSO2 Platform
Digital Transformation with Mobile Connect: Enhancing your Customer Experience
WSO2- OSC Korea - Accelerating Digital Businesses with APIs
Ad

More from WSO2 (20)

PDF
Demystifying CMS-0057-F - Compliance Made Seamless with WSO2
PDF
Quantum Threats Are Closer Than You Think – Act Now to Stay Secure
PDF
Modern Platform Engineering with Choreo - The AI-Native Internal Developer Pl...
PDF
Application Modernization with Choreo - The AI-Native Internal Developer Plat...
PDF
Build Smarter, Deliver Faster with Choreo - An AI Native Internal Developer P...
PDF
Platformless Modernization with Choreo.pdf
PDF
Application Modernization with Choreo for the BFSI Sector
PDF
Choreo - The AI-Native Internal Developer Platform as a Service: Overview
PDF
[Roundtable] Choreo - The AI-Native Internal Developer Platform as a Service
PPTX
WSO2Con 2025 - Building AI Applications in the Enterprise (Part 1)
PPTX
WSO2Con 2025 - Building Secure Business Customer and Partner Experience (B2B)...
PPTX
WSO2Con 2025 - Building Secure Customer Experience Apps
PPTX
WSO2Con 2025 - AI-Driven API Design, Development, and Consumption with Enhanc...
PPTX
WSO2Con 2025 - AI-Driven API Design, Development, and Consumption with Enhanc...
PPTX
WSO2Con 2025 - Unified Management of Ingress and Egress Across Multiple API G...
PPTX
WSO2Con 2025 - How an Internal Developer Platform Lets Developers Focus on Code
PPTX
WSO2Con 2025 - Architecting Cloud-Native Applications
PDF
Mastering Intelligent Digital Experiences with Platformless Modernization
PDF
Accelerate Enterprise Software Engineering with Platformless
PDF
WSO2Con2024 - WSO2's IAM Vision: Identity-Led Digital Transformation
Demystifying CMS-0057-F - Compliance Made Seamless with WSO2
Quantum Threats Are Closer Than You Think – Act Now to Stay Secure
Modern Platform Engineering with Choreo - The AI-Native Internal Developer Pl...
Application Modernization with Choreo - The AI-Native Internal Developer Plat...
Build Smarter, Deliver Faster with Choreo - An AI Native Internal Developer P...
Platformless Modernization with Choreo.pdf
Application Modernization with Choreo for the BFSI Sector
Choreo - The AI-Native Internal Developer Platform as a Service: Overview
[Roundtable] Choreo - The AI-Native Internal Developer Platform as a Service
WSO2Con 2025 - Building AI Applications in the Enterprise (Part 1)
WSO2Con 2025 - Building Secure Business Customer and Partner Experience (B2B)...
WSO2Con 2025 - Building Secure Customer Experience Apps
WSO2Con 2025 - AI-Driven API Design, Development, and Consumption with Enhanc...
WSO2Con 2025 - AI-Driven API Design, Development, and Consumption with Enhanc...
WSO2Con 2025 - Unified Management of Ingress and Egress Across Multiple API G...
WSO2Con 2025 - How an Internal Developer Platform Lets Developers Focus on Code
WSO2Con 2025 - Architecting Cloud-Native Applications
Mastering Intelligent Digital Experiences with Platformless Modernization
Accelerate Enterprise Software Engineering with Platformless
WSO2Con2024 - WSO2's IAM Vision: Identity-Led Digital Transformation

Recently uploaded (20)

PDF
Mobile App Security Testing_ A Comprehensive Guide.pdf
PDF
KodekX | Application Modernization Development
PDF
Peak of Data & AI Encore- AI for Metadata and Smarter Workflows
PPTX
Understanding_Digital_Forensics_Presentation.pptx
PDF
Diabetes mellitus diagnosis method based random forest with bat algorithm
PPT
“AI and Expert System Decision Support & Business Intelligence Systems”
PDF
Reach Out and Touch Someone: Haptics and Empathic Computing
PDF
Build a system with the filesystem maintained by OSTree @ COSCUP 2025
PPTX
sap open course for s4hana steps from ECC to s4
DOCX
The AUB Centre for AI in Media Proposal.docx
PDF
Building Integrated photovoltaic BIPV_UPV.pdf
PPTX
20250228 LYD VKU AI Blended-Learning.pptx
PDF
Review of recent advances in non-invasive hemoglobin estimation
PPT
Teaching material agriculture food technology
PPTX
Programs and apps: productivity, graphics, security and other tools
PDF
Optimiser vos workloads AI/ML sur Amazon EC2 et AWS Graviton
PDF
Advanced methodologies resolving dimensionality complications for autism neur...
PDF
NewMind AI Weekly Chronicles - August'25 Week I
PPTX
MYSQL Presentation for SQL database connectivity
PDF
cuic standard and advanced reporting.pdf
Mobile App Security Testing_ A Comprehensive Guide.pdf
KodekX | Application Modernization Development
Peak of Data & AI Encore- AI for Metadata and Smarter Workflows
Understanding_Digital_Forensics_Presentation.pptx
Diabetes mellitus diagnosis method based random forest with bat algorithm
“AI and Expert System Decision Support & Business Intelligence Systems”
Reach Out and Touch Someone: Haptics and Empathic Computing
Build a system with the filesystem maintained by OSTree @ COSCUP 2025
sap open course for s4hana steps from ECC to s4
The AUB Centre for AI in Media Proposal.docx
Building Integrated photovoltaic BIPV_UPV.pdf
20250228 LYD VKU AI Blended-Learning.pptx
Review of recent advances in non-invasive hemoglobin estimation
Teaching material agriculture food technology
Programs and apps: productivity, graphics, security and other tools
Optimiser vos workloads AI/ML sur Amazon EC2 et AWS Graviton
Advanced methodologies resolving dimensionality complications for autism neur...
NewMind AI Weekly Chronicles - August'25 Week I
MYSQL Presentation for SQL database connectivity
cuic standard and advanced reporting.pdf

Securing Access to SaaS Apps with WSO2 Identity Server