SlideShare a Scribd company logo
SharePoint Authentication and Authorization
Scott
Hoag

ciphertxt
Dan
Usher

usher
Jason
Himmelstein

sharepointlhorn
introductions
a few ground rules…
SharePoint Authentication and Authorization
Security
http://xkcd.com/109/
SharePoint Authentication and Authorization
SharePoint Authentication and Authorization
SharePoint Authentication and Authorization
SharePoint Authentication and Authorization
SharePoint Authentication and Authorization
SharePoint Authentication and Authorization
SharePoint Authentication and Authorization
SharePoint Authentication and Authorization
SharePoint Authentication and Authorization
SharePoint Authentication and Authorization
authorizing
                   authority

authority
authority

       authority
SharePoint Authentication and Authorization
SharePoint Authentication and Authorization
http://go.spdan.com/cba
SharePoint Authentication and Authorization
http://go.spdan.com/claimsencoding
ASP.NET Authentication




         Source: http://go.spdan.com/iisauth
Identity Provider                    SharePoint 2010
 Security Token Service                     aka RP
       aka IP-STS




1.   Resource Requested
2.   AuthN Request / Redirect
3.   AuthN Request
4.   Security Token
5.   Security Token Request
6.   Service Token
7.   Resource Request w/Service Token
8.   Resource Sent
Side Story




             SharePint Anyone?
SharePoint Authentication and Authorization
SharePoint Authentication and Authorization
SharePoint Authentication and Authorization
SharePoint Authentication and Authorization
SharePoint Authentication and Authorization
https://sts.domain.com
SharePoint Authentication and Authorization
Web Application / Site Collection               Anonymous


Secured Site / Site Collection / Content
                                                    Authentication

         Content Repository
                                                  Is In Site Group?
              Content




                                   Does user have claim attribute?
SharePoint Authentication and Authorization
Real World
SharePoint Authentication and Authorization
Questions / Evals
jase@sharepointlonghorn.co
dan@spdan.com            m
@usher                   @sharepointlhorn
www.sharepointdan.com    www.sharepointlonghorn.com



Scott.hoag@spdelta.com   liamcleary@msn.com
@ciphertxt               @helloitsliam
http://psconfig.com      www.helloitsliam.com

More Related Content

PPT
Attacking Web Applications
PPTX
Web Vulnerabilities - Building Basic Security Awareness
PDF
In graph we trust: Microservices, GraphQL and security challenges
PDF
Wakanda and the top 5 security risks - JS.everyrwhere(2012) Europe
PPTX
A2 - broken authentication and session management(OWASP thailand chapter Apri...
PPTX
Unmasking You
PDF
Pentesting RESTful webservices
PPTX
Web application security: Threats & Countermeasures
Attacking Web Applications
Web Vulnerabilities - Building Basic Security Awareness
In graph we trust: Microservices, GraphQL and security challenges
Wakanda and the top 5 security risks - JS.everyrwhere(2012) Europe
A2 - broken authentication and session management(OWASP thailand chapter Apri...
Unmasking You
Pentesting RESTful webservices
Web application security: Threats & Countermeasures

Viewers also liked (7)

PPTX
Hampton Road SQL and SharePoint User Group - SharePoint 2013 a Brief Capabili...
PDF
SharePoint Worst Practices - SPSRIC
PDF
2014-04-05 - SPSPhilly - Getting Started with Office 365
PDF
2014-05-17 SPS Baltimore - Worst Practices of SharePoint
PDF
Pitfalls of Migrating to SharePoint 2010 #SPSVB
PDF
2014-02-06 - Getting Started with Office 365
PDF
2014-04-05 - SPSPhilly - Authentication and Authorization
Hampton Road SQL and SharePoint User Group - SharePoint 2013 a Brief Capabili...
SharePoint Worst Practices - SPSRIC
2014-04-05 - SPSPhilly - Getting Started with Office 365
2014-05-17 SPS Baltimore - Worst Practices of SharePoint
Pitfalls of Migrating to SharePoint 2010 #SPSVB
2014-02-06 - Getting Started with Office 365
2014-04-05 - SPSPhilly - Authentication and Authorization
Ad

Similar to SharePoint Authentication and Authorization (20)

PPTX
Authentication, Authorization, and Identity – More than meets the eye…
PPTX
SharePoint Saturday Utah - Do you claim to be from the Azure Sky?
PPTX
SharePoint Authentication And Authorization SPTechCon San Francisco
PPTX
SharePoint Saturday Austin - Share point authentication and authorization
PPTX
Understanding SharePoint Apps, authentication and authorization infrastructur...
PPTX
SPSBE 2013 Claims for devs
PPTX
SPSNYC - Authentication, Authorization, and Identity – More than meets the eye…
PPTX
DD109 Claims Based AuthN in SharePoint 2010
PDF
SharePoint Saturday The Conference DC - Are you who you say you are share poi...
PDF
Introduction to claims based authentication in share point 2010
PDF
Claims based authentication in SharePoint 2010 - SharePoint Saturday Vietnam
PPTX
Share point security 101 sps-ottawa 2012 - antonio maio
PPTX
Claim Based Authentication in SharePoint 2010 for Community Day 2011
PPTX
SharePoint 2010 - Tips and Tricks of the Trade - Avoiding Administrative Blun...
PPTX
SharePoint 2010 - Tips and Tricks of the Trade - Avoiding Administrative Blun...
PPTX
Claims Based Authentication A Beginners Guide
PPTX
SharePoint 2010 Extranets and Authentication: How will SharePoint 2010 connec...
PPTX
Claims Based Identity In Share Point 2010
PPTX
How to deploy SharePoint 2010 to external users?
PPTX
Securing SharePoint Apps with OAuth
Authentication, Authorization, and Identity – More than meets the eye…
SharePoint Saturday Utah - Do you claim to be from the Azure Sky?
SharePoint Authentication And Authorization SPTechCon San Francisco
SharePoint Saturday Austin - Share point authentication and authorization
Understanding SharePoint Apps, authentication and authorization infrastructur...
SPSBE 2013 Claims for devs
SPSNYC - Authentication, Authorization, and Identity – More than meets the eye…
DD109 Claims Based AuthN in SharePoint 2010
SharePoint Saturday The Conference DC - Are you who you say you are share poi...
Introduction to claims based authentication in share point 2010
Claims based authentication in SharePoint 2010 - SharePoint Saturday Vietnam
Share point security 101 sps-ottawa 2012 - antonio maio
Claim Based Authentication in SharePoint 2010 for Community Day 2011
SharePoint 2010 - Tips and Tricks of the Trade - Avoiding Administrative Blun...
SharePoint 2010 - Tips and Tricks of the Trade - Avoiding Administrative Blun...
Claims Based Authentication A Beginners Guide
SharePoint 2010 Extranets and Authentication: How will SharePoint 2010 connec...
Claims Based Identity In Share Point 2010
How to deploy SharePoint 2010 to external users?
Securing SharePoint Apps with OAuth
Ad

More from Dan Usher (20)

PDF
SPS Pittsburgh - Getting Started with Office 365
PDF
SPS NYC - Getting started with Office 365 for IT Pros
PDF
2014 09-20 - SPSNJ - Worst Practices of SharePoint
PDF
2014 09-20 - SPSNJ - Getting Started with Office 365
PDF
SPTechCon 2014 - Boston - Worst practices of SharePoint
PDF
SPTechCon - Boston 2014 - Getting started with Office 365
PPTX
2014 08-15 - Getting Started with Office 365 - Office 365 Ramp Up
PPTX
SPSNYC 2014 - Authentication and Authorization
PPTX
2014 05-19 - getting started with office 365.release
PDF
2014-005-17 SPS Baltimore - Getting Started with Office 365
PPTX
SharePoint Intersections - SP11 - SharePoint and IaaS - The OnPrem in the Cloud
PPTX
SharePoint Intersections - SP10 - Getting Started with Office 365 - Identity,...
PPTX
SharePoint Intersections - SP09 - Introduction to SharePoint 2013 for IT Pros
PDF
2014-03-20 - Baltimore SharePoint Users Group - Getting Started with Office 365
PDF
2014 03-19 - CapArea.net SSIG - Getting Started with Office 365
PDF
2014-03-13 - Getting Started with Office 365 at SUGDC
PDF
2014 02-26 - Princeton SUG presents - Getting Started with Office 365
PDF
2013-09-12 - SUGDC - Office 365 and Hybrid Solutions
PDF
2013-07-24 - CapArea.NET SSIG - SharePoint 2013, A Brief Capability Overview ...
PDF
2014-02-22 - IT Pro Camp - SharePoint 2013, A Brief Overview of Capability
SPS Pittsburgh - Getting Started with Office 365
SPS NYC - Getting started with Office 365 for IT Pros
2014 09-20 - SPSNJ - Worst Practices of SharePoint
2014 09-20 - SPSNJ - Getting Started with Office 365
SPTechCon 2014 - Boston - Worst practices of SharePoint
SPTechCon - Boston 2014 - Getting started with Office 365
2014 08-15 - Getting Started with Office 365 - Office 365 Ramp Up
SPSNYC 2014 - Authentication and Authorization
2014 05-19 - getting started with office 365.release
2014-005-17 SPS Baltimore - Getting Started with Office 365
SharePoint Intersections - SP11 - SharePoint and IaaS - The OnPrem in the Cloud
SharePoint Intersections - SP10 - Getting Started with Office 365 - Identity,...
SharePoint Intersections - SP09 - Introduction to SharePoint 2013 for IT Pros
2014-03-20 - Baltimore SharePoint Users Group - Getting Started with Office 365
2014 03-19 - CapArea.net SSIG - Getting Started with Office 365
2014-03-13 - Getting Started with Office 365 at SUGDC
2014 02-26 - Princeton SUG presents - Getting Started with Office 365
2013-09-12 - SUGDC - Office 365 and Hybrid Solutions
2013-07-24 - CapArea.NET SSIG - SharePoint 2013, A Brief Capability Overview ...
2014-02-22 - IT Pro Camp - SharePoint 2013, A Brief Overview of Capability

Recently uploaded (20)

PPTX
A Presentation on Artificial Intelligence
PDF
cuic standard and advanced reporting.pdf
PPTX
Spectroscopy.pptx food analysis technology
PDF
Per capita expenditure prediction using model stacking based on satellite ima...
PDF
Reach Out and Touch Someone: Haptics and Empathic Computing
PDF
Approach and Philosophy of On baking technology
PDF
NewMind AI Weekly Chronicles - August'25-Week II
PDF
Architecting across the Boundaries of two Complex Domains - Healthcare & Tech...
PDF
gpt5_lecture_notes_comprehensive_20250812015547.pdf
PDF
TokAI - TikTok AI Agent : The First AI Application That Analyzes 10,000+ Vira...
PPTX
Digital-Transformation-Roadmap-for-Companies.pptx
PPTX
VMware vSphere Foundation How to Sell Presentation-Ver1.4-2-14-2024.pptx
PPTX
Machine Learning_overview_presentation.pptx
PDF
Empathic Computing: Creating Shared Understanding
PDF
Electronic commerce courselecture one. Pdf
PDF
Build a system with the filesystem maintained by OSTree @ COSCUP 2025
PDF
Network Security Unit 5.pdf for BCA BBA.
PDF
7 ChatGPT Prompts to Help You Define Your Ideal Customer Profile.pdf
PDF
Encapsulation theory and applications.pdf
PPTX
20250228 LYD VKU AI Blended-Learning.pptx
A Presentation on Artificial Intelligence
cuic standard and advanced reporting.pdf
Spectroscopy.pptx food analysis technology
Per capita expenditure prediction using model stacking based on satellite ima...
Reach Out and Touch Someone: Haptics and Empathic Computing
Approach and Philosophy of On baking technology
NewMind AI Weekly Chronicles - August'25-Week II
Architecting across the Boundaries of two Complex Domains - Healthcare & Tech...
gpt5_lecture_notes_comprehensive_20250812015547.pdf
TokAI - TikTok AI Agent : The First AI Application That Analyzes 10,000+ Vira...
Digital-Transformation-Roadmap-for-Companies.pptx
VMware vSphere Foundation How to Sell Presentation-Ver1.4-2-14-2024.pptx
Machine Learning_overview_presentation.pptx
Empathic Computing: Creating Shared Understanding
Electronic commerce courselecture one. Pdf
Build a system with the filesystem maintained by OSTree @ COSCUP 2025
Network Security Unit 5.pdf for BCA BBA.
7 ChatGPT Prompts to Help You Define Your Ideal Customer Profile.pdf
Encapsulation theory and applications.pdf
20250228 LYD VKU AI Blended-Learning.pptx

SharePoint Authentication and Authorization