World®
’16
WAM	and	Federation:	Two	Great	
Tastes	That	Taste	Great	Together
Aaron	Berman	– WW	VP,	Single	Sign-on	&	Directory	Solutions
CA	Technologies
SCT44T
SECURITY
1 ©	2016	CA.	ALL	RIGHTS	RESERVED.@CAWORLD				#CAWORLD
©	2016	CA.	All	rights	reserved.	All	trademarks	referenced	herein	belong	to	their	respective	companies.
The	content	provided	in	this CA	World	2016	presentation	is	intended	for	informational	purposes	only	and	does	not	form	any	type	of	
warranty. The information	provided	by	a	CA	partner	and/or	CA	customer	has	not	been	reviewed	for	accuracy	by	CA.	
For	Informational	Purposes	Only	
Terms	of	this	Presentation
2 ©	2016	CA.	ALL	RIGHTS	RESERVED.@CAWORLD				#CAWORLD
Abstract
WAM	&	Federation:	Two	Great	Tastes	that	Taste	Great	Together
Choosing	the	right	approach	to	meet	your	needs	is	critical.	Choosing	the	
wrong	approach	can	cause	problems	like	increased	integration	costs	and	
project	delays.	Learn	about	the	differences	between	federated	models	
and	PEP/PDP	access	management	models	for	session	security	and	
user	experience.
Aaron	
Berman
CA	Technologies
WW	VP,	Single	Sign-On	
&	Directory	Solutions
3 ©	2016	CA.	ALL	RIGHTS	RESERVED.@CAWORLD				#CAWORLD
Single	Sign-on	Can	Mean	Many	Different	Things
§ Getting	an	identity from	one	application	to	another
§ Maintaining	a	secure	session	across	multiple	applications
§ Only	allowing	the	correct users	access
§ Security controls	for	the	session
§ Knowing	what	actions users	are	doing
§ URL	filtering	to	keep	bad	requests	out
4 ©	2016	CA.	ALL	RIGHTS	RESERVED.@CAWORLD				#CAWORLD
Two	Approaches	to	Meet	Different	Needs
§ Policy	enforcement	points	to	intercept	and	
examine	each	request	
§ Shared	session	across	multiple	applications
WEB	ACCESS	MANAGEMENT
§ Identity	passed	from	identity	provider	
to	applications
§ Claims	approach	to	SSO
§ Application	remains	in	control	of	own	
security	policies
OPEN	STANDARDS
TIGHTLY	COUPLED LOOSELY	COUPLED
5 ©	2016	CA.	ALL	RIGHTS	RESERVED.@CAWORLD				#CAWORLD
Choosing	the	Wrong	Approach	Can	Cause	Problems
§ Increased	integration	costs
§ Use	of	workarounds	to	meet	requirements
§ Customization
§ Project	Delays
Image	taken	from	https://hikingartist.com/thrive/nail-screw/
Choosing	the	right	approach to	
meet	your	needs	is	critical
6 ©	2016	CA.	ALL	RIGHTS	RESERVED.@CAWORLD				#CAWORLD
Decision	Guidelines
§ On	Premise	or	PaaS	applications
§ Simple	cross	application	linking
§ Enforcement	of	user	authorization
§ Audit	/	Timeout	/	Session	Security	
WEB	ACCESS	MANAGEMENT
§ Third	Party	sites
§ Applications	have	a	native	integration
§ Remote	locations
§ Only	concerned	with	passing	identity	
OPEN	STANDARDS
7 ©	2016	CA.	ALL	RIGHTS	RESERVED.@CAWORLD				#CAWORLD
SAML
SSO	Approaches	Can	be	Combined…
SAML	to	an	Internal	Application	While	Maintaining	URL	Filtering
End	User SSO	Gateway
SSO	Session Application	session
Application
Session	Linker
8 ©	2016	CA.	ALL	RIGHTS	RESERVED.@CAWORLD				#CAWORLD
OAUTH
…and	Integrated
Inbound	Social	Sign-on	Data	Passed	to	Applications	Without	Account	Creation
End	User SSO	Gateway
Social	Media
Application	2
Application	1
SSO
CA	Directory
Session	Store
SSO	Policy	Server
Identity	Data
9 ©	2016	CA.	ALL	RIGHTS	RESERVED.@CAWORLD				#CAWORLD
CA	Single	Sign-on	Offers	Both	Options
Unlimited	web	server	agents
Unlimited	gateways
Unlimited	standards	based	SSO	for	all	licensed	users
CA	Single	
Sign-On	
Features
Deploying	a	single	solution	for	all	SSO	needs	reduces	IT	spend	and	
Integration	costs
10 ©	2016	CA.	ALL	RIGHTS	RESERVED.@CAWORLD				#CAWORLD
Summary
Choose the	right	
approach	to	meet	
your	business	
needs
WAM	and	Open	
Standards	do	not	
contradict they	
compliment
Combine	WAM and	Open	
standards	together
11 ©	2016	CA.	ALL	RIGHTS	RESERVED.@CAWORLD				#CAWORLD
Recommended	Sessions
SESSION	# TITLE DATE/TIME
SCT915 Data	Breach	Digest,	John	Grimm 11/16/2016	at	12:45	pm
SCT45T How	Fast	Is	Your	Directory? 11/16/2016	at	4:30	pm
SCX205 CA	SSO,	AA	Roadmap 11/18/2016	at	1:45	pm
12 ©	2016	CA.	ALL	RIGHTS	RESERVED.@CAWORLD				#CAWORLD
Don’t	Miss	Our	INTERACTIVE
Security	Demo	Experience!
SNEAK
PEEK!
12 ©	2016	CA.	ALL	RIGHTS	RESERVED.@CAWORLD				#CAWORLD
@CAWORLD					#CAWORLD ©	2016	CA.	All	RIGHTS	RESERVED.13 @CAWORLD					#CAWORLD
Security
For	more	information	on	Security,	please	visit:	
http://cainc.to/EtfYyw

More Related Content

PDF
Securely Enabling the Digital Age
PDF
Tech Talk: Want to get in on the Secret? How fast is your Directory?
PDF
Tech Talk: Make life easy for your users with a hybrid application launchpad
PDF
Introduction to Identity-as-a-Service and Secure Access to SaaS
PDF
Convenience and Security for banking customers with CA Advanced Authentication
PDF
Pre-Con Ed: Knock, Knock, the IoT Wants to Come In
PDF
Pre-Con Ed: Governance of Privileged Identities—Key to Breach Prevention
PDF
Pre-Con Ed: Who's minding the SSO store?
Securely Enabling the Digital Age
Tech Talk: Want to get in on the Secret? How fast is your Directory?
Tech Talk: Make life easy for your users with a hybrid application launchpad
Introduction to Identity-as-a-Service and Secure Access to SaaS
Convenience and Security for banking customers with CA Advanced Authentication
Pre-Con Ed: Knock, Knock, the IoT Wants to Come In
Pre-Con Ed: Governance of Privileged Identities—Key to Breach Prevention
Pre-Con Ed: Who's minding the SSO store?

What's hot (20)

PDF
Pre-Con Ed (Lab): Making CA Identity Suite Deployment Incredibly Easy
PDF
Tech Talk: Governing your Privileged Users – A Key Step Towards Reducing the ...
PDF
Identity and Access Management Survey: Current Market Challenges and Solutions
PDF
Pre-Con Ed: Privileged Access Management for Hybrid Enterprises
PDF
Tech Talk: Real-time Identity Analytics – Improving Performance through Incre...
PDF
Pre-Con Ed: How to IAM-Enable Your Office 365 Environment
PDF
Digital transformation in financial services through trusted digital relation...
PDF
Introducing New Identity as a Service
PDF
Critical Considerations for Mobile and IoT Strategy
PDF
Tech Tak: Threat Analytics for Privileged Access Management
PDF
TechTalk: Sometimes Less is More –Visualization Can Reduce your Test Data whi...
PDF
Tech Talk: Privileged Account Management Maturity Model
PDF
Streamlining Your CA Identity Suite Deployment
PDF
Securing Mobile Payments: Applying Lessons Learned in the Real World
PDF
Pre-Con Ed (Lab): CA Identity Suite—Raising the Bar on User Productivity and ...
PDF
Pre-Con Ed: Multiple Implementation and Access Models for CA SSO
PDF
Tech Talk: Defense In Depth Privileged Access Management for Hybrid Enterprises
PDF
Tech Talk: Forty2.io: Leveraging Machine Learning to Protect Your Web Applica...
PDF
Modern System Intelligence: Making the Data Do the Work
PDF
The answer is Forty2 - How analytics-backed bot mitigation helped Insilicum
Pre-Con Ed (Lab): Making CA Identity Suite Deployment Incredibly Easy
Tech Talk: Governing your Privileged Users – A Key Step Towards Reducing the ...
Identity and Access Management Survey: Current Market Challenges and Solutions
Pre-Con Ed: Privileged Access Management for Hybrid Enterprises
Tech Talk: Real-time Identity Analytics – Improving Performance through Incre...
Pre-Con Ed: How to IAM-Enable Your Office 365 Environment
Digital transformation in financial services through trusted digital relation...
Introducing New Identity as a Service
Critical Considerations for Mobile and IoT Strategy
Tech Tak: Threat Analytics for Privileged Access Management
TechTalk: Sometimes Less is More –Visualization Can Reduce your Test Data whi...
Tech Talk: Privileged Account Management Maturity Model
Streamlining Your CA Identity Suite Deployment
Securing Mobile Payments: Applying Lessons Learned in the Real World
Pre-Con Ed (Lab): CA Identity Suite—Raising the Bar on User Productivity and ...
Pre-Con Ed: Multiple Implementation and Access Models for CA SSO
Tech Talk: Defense In Depth Privileged Access Management for Hybrid Enterprises
Tech Talk: Forty2.io: Leveraging Machine Learning to Protect Your Web Applica...
Modern System Intelligence: Making the Data Do the Work
The answer is Forty2 - How analytics-backed bot mitigation helped Insilicum
Ad

Similar to Tech Talk: Web Access Management and Federation – Two Great Tastes that Taste Good Together (20)

PDF
Tech Talk: Federate to an SAML-Enabled App in Minutes
PDF
Enabling a Hybrid Enterprise Application Launch Pad
PDF
Pre-Con Ed: Your Voice Counts! Customer Driven Requirements for CA Workload A...
PDF
Pre-Con Ed: Streamline Agile Workload Automation Processes for a Repeatable a...
PDF
Pre-Con Ed: CA Live API Creator:  Learn How to Integrate Data From Enterprise...
PDF
Pre-Con Ed: CA API Gateway: How to Deploy Your Gateway Across Multiple Enviro...
PDF
Tech Vision: Next-Generation Performance Testing With BlazeMeter, Service Vir...
PDF
CA Datacom®/AD Installation/Upgrade and Maintenance
PDF
Pre-Con Ed: Where's the Data? How CA's DevTest Solutions Work Together to Lev...
PDF
Pre-Con Ed: Test Data Management and Compliance: Is your Test Data Ready for ...
PDF
Implementation and Use of Generic VTAM Resources with Parallel SYSPLEX Features
PDF
Pre-Con Ed: Predicting the Fire with Operational Intelligence
PDF
Hands-On Lab: Tune CA Performance Management for an Optimal Network Performan...
PDF
Roadmap Session: Achieve DevOps on the Mainframe for Faster Time to Market
PDF
Pre-Con Ed: An Overview of How CA Test Data Manager Helps Deliver Rigorously ...
PDF
Tracking Message Flows in DataPower With CA APM
PDF
Case Study: GM Financial Builds a Sustainable, Holistic, Continuous Delivery ...
PDF
Technology Primer: Monitor a Website in Minutes Using Shortcuts for Customer ...
PDF
Tech Talk: CA Agile Central Made Easy
PDF
Pre-Con Ed: CA Live API Creator: How to Integrate Enterprise Data for Mobile ...
Tech Talk: Federate to an SAML-Enabled App in Minutes
Enabling a Hybrid Enterprise Application Launch Pad
Pre-Con Ed: Your Voice Counts! Customer Driven Requirements for CA Workload A...
Pre-Con Ed: Streamline Agile Workload Automation Processes for a Repeatable a...
Pre-Con Ed: CA Live API Creator:  Learn How to Integrate Data From Enterprise...
Pre-Con Ed: CA API Gateway: How to Deploy Your Gateway Across Multiple Enviro...
Tech Vision: Next-Generation Performance Testing With BlazeMeter, Service Vir...
CA Datacom®/AD Installation/Upgrade and Maintenance
Pre-Con Ed: Where's the Data? How CA's DevTest Solutions Work Together to Lev...
Pre-Con Ed: Test Data Management and Compliance: Is your Test Data Ready for ...
Implementation and Use of Generic VTAM Resources with Parallel SYSPLEX Features
Pre-Con Ed: Predicting the Fire with Operational Intelligence
Hands-On Lab: Tune CA Performance Management for an Optimal Network Performan...
Roadmap Session: Achieve DevOps on the Mainframe for Faster Time to Market
Pre-Con Ed: An Overview of How CA Test Data Manager Helps Deliver Rigorously ...
Tracking Message Flows in DataPower With CA APM
Case Study: GM Financial Builds a Sustainable, Holistic, Continuous Delivery ...
Technology Primer: Monitor a Website in Minutes Using Shortcuts for Customer ...
Tech Talk: CA Agile Central Made Easy
Pre-Con Ed: CA Live API Creator: How to Integrate Enterprise Data for Mobile ...
Ad

More from CA Technologies (20)

PPTX
CA Mainframe Resource Intelligence
PDF
Mainframe as a Service: Sample a Buffet of IBM z/OS® Platform Excellence
PDF
Case Study: How CA Went From 40 Days to Three Days Building Crystal-Clear Tes...
PDF
Case Study: How The Home Depot Built Quality Into Software Development
PDF
Pre-Con Ed: Privileged Identity Governance: Are You Certifying Privileged Use...
PDF
Case Study: Privileged Access in a World on Time
PDF
Case Study: How SGN Used Attack Path Mapping to Control Privileged Access in ...
PDF
Case Study: Putting Citizens at The Center of Digital Government
PDF
Making Security Work—Implementing a Transformational Security Program
PDF
Keynote: Making Security a Competitive Advantage
PDF
Emerging Managed Services Opportunities in Identity and Access Management
PDF
The Unmet Demand for Premium Cloud Monitoring Services—and How Service Provid...
PDF
Leveraging Monitoring Governance: How Service Providers Can Boost Operational...
PDF
The Next Big Service Provider Opportunity—Beyond Infrastructure: Architecting...
PDF
Application Experience Analytics Services: The Strategic Digital Transformati...
PDF
Application Experience Analytics Services: The Strategic Digital Transformati...
PDF
Strategic Direction Session: Deliver Next-Gen IT Ops with CA Mainframe Operat...
PDF
Strategic Direction Session: Enhancing Data Privacy with Data-Centric Securit...
PDF
Blockchain: Strategies for Moving From Hype to Realities of Deployment
PDF
Establish Digital Trust as the Currency of Digital Enterprise
CA Mainframe Resource Intelligence
Mainframe as a Service: Sample a Buffet of IBM z/OS® Platform Excellence
Case Study: How CA Went From 40 Days to Three Days Building Crystal-Clear Tes...
Case Study: How The Home Depot Built Quality Into Software Development
Pre-Con Ed: Privileged Identity Governance: Are You Certifying Privileged Use...
Case Study: Privileged Access in a World on Time
Case Study: How SGN Used Attack Path Mapping to Control Privileged Access in ...
Case Study: Putting Citizens at The Center of Digital Government
Making Security Work—Implementing a Transformational Security Program
Keynote: Making Security a Competitive Advantage
Emerging Managed Services Opportunities in Identity and Access Management
The Unmet Demand for Premium Cloud Monitoring Services—and How Service Provid...
Leveraging Monitoring Governance: How Service Providers Can Boost Operational...
The Next Big Service Provider Opportunity—Beyond Infrastructure: Architecting...
Application Experience Analytics Services: The Strategic Digital Transformati...
Application Experience Analytics Services: The Strategic Digital Transformati...
Strategic Direction Session: Deliver Next-Gen IT Ops with CA Mainframe Operat...
Strategic Direction Session: Enhancing Data Privacy with Data-Centric Securit...
Blockchain: Strategies for Moving From Hype to Realities of Deployment
Establish Digital Trust as the Currency of Digital Enterprise

Recently uploaded (20)

PPT
Module 1.ppt Iot fundamentals and Architecture
PDF
sustainability-14-14877-v2.pddhzftheheeeee
PDF
Zenith AI: Advanced Artificial Intelligence
PDF
Five Habits of High-Impact Board Members
PPTX
Benefits of Physical activity for teenagers.pptx
PDF
Getting Started with Data Integration: FME Form 101
PDF
A contest of sentiment analysis: k-nearest neighbor versus neural network
PDF
ENT215_Completing-a-large-scale-migration-and-modernization-with-AWS.pdf
PDF
Hybrid horned lizard optimization algorithm-aquila optimizer for DC motor
PDF
Enhancing emotion recognition model for a student engagement use case through...
PPTX
O2C Customer Invoices to Receipt V15A.pptx
PDF
CloudStack 4.21: First Look Webinar slides
PDF
Microsoft Solutions Partner Drive Digital Transformation with D365.pdf
PDF
A comparative study of natural language inference in Swahili using monolingua...
PPTX
Chapter 5: Probability Theory and Statistics
PDF
Assigned Numbers - 2025 - Bluetooth® Document
PDF
From MVP to Full-Scale Product A Startup’s Software Journey.pdf
PPTX
Web Crawler for Trend Tracking Gen Z Insights.pptx
PDF
STKI Israel Market Study 2025 version august
PDF
A review of recent deep learning applications in wood surface defect identifi...
Module 1.ppt Iot fundamentals and Architecture
sustainability-14-14877-v2.pddhzftheheeeee
Zenith AI: Advanced Artificial Intelligence
Five Habits of High-Impact Board Members
Benefits of Physical activity for teenagers.pptx
Getting Started with Data Integration: FME Form 101
A contest of sentiment analysis: k-nearest neighbor versus neural network
ENT215_Completing-a-large-scale-migration-and-modernization-with-AWS.pdf
Hybrid horned lizard optimization algorithm-aquila optimizer for DC motor
Enhancing emotion recognition model for a student engagement use case through...
O2C Customer Invoices to Receipt V15A.pptx
CloudStack 4.21: First Look Webinar slides
Microsoft Solutions Partner Drive Digital Transformation with D365.pdf
A comparative study of natural language inference in Swahili using monolingua...
Chapter 5: Probability Theory and Statistics
Assigned Numbers - 2025 - Bluetooth® Document
From MVP to Full-Scale Product A Startup’s Software Journey.pdf
Web Crawler for Trend Tracking Gen Z Insights.pptx
STKI Israel Market Study 2025 version august
A review of recent deep learning applications in wood surface defect identifi...

Tech Talk: Web Access Management and Federation – Two Great Tastes that Taste Good Together