SlideShare une entreprise Scribd logo
1  sur  55
Télécharger pour lire hors ligne
Extranet Identity Management and Authentication for SharePoint On Premise, Office 365 and Beyond 
Presented by Peter Carson 
President, Envision IT 
October 22, 2014
Peter Carson 
•President, Envision IT 
•SharePoint MVP 
•Virtual Technical Specialist, Microsoft Canada 
•peter@envisionit.com 
•http://blog.petercarson.ca 
•www.envisionit.com 
•Twitter @carsonpeter 
•VP Toronto SharePoint User Group
Hugh Davidson 
Business Development Manager, Product Sales 
•e: hdavidson@envisionit.com 
•p: (905) 812-3009 x222
Denesh Sohan 
Director of Products 
•e: dsohan@envisionit.com 
•p: (905) 812-3009 x298
Corey Thokle 
Project Manager 
•e: cthokle@envisionit.com 
•p: (905) 812 3009 ext.248
Agenda 
•Envision IT Overview 
•Extranet Scenarios 
•Extranet User Manager Overview 
•SharePoint On Premises Demo 
•Federation 
•Office 365 Demo 
•Wrap-Up and Q&A
Focused on complex SharePoint solutions, Envision IT is the “go-to” partner for Microsoft SharePoint, building integrated public web sites, Intranets, Extranets, and web applications that leverage your existing systems anywhere over the Internet. 
Envision IT Services Overview
Public Web Sites 
We create interactive, content-rich customer-facing web sites that are able to grow and transform with changing needs
Collaboration Portals 
Our Collaboration Portals provide a secure space for teams to share knowledge and resources
Intranets 
Our Intranet Sites connect people to information, expertise and key business applications, and SharePoint provides a broad set of Enterprise Content Management features
Extranets 
Envision IT has a wealth of experience building Corporate Extranets that allow you to securely connect with customers and partners
What is an Extranet 
•An Extranetis a web site that is accessible to users outside of the corporate network, which allowsorganizations to share information and collaborate with their customers, partners, and/or vendors in a secure and easy-to-use environment 
•The Extranet may be added as amodule into the Intranet site to only allow external users into specific sub-sites of the Intranet
Poll 1 
Which Version of SharePoint are you currently using? 
•SharePoint Server 2013 
•Office 365 
•SharePoint Server 2010 
•SharePoint Foundation (2010 or 2013) 
•MOSS 2007 or WSS 3.0
Poll 2 
How do you use SharePoint today? 
•Internal collaboration 
•Internal web publishing (Intranet) 
•Extranets 
•Public facing website
Extranet Scenarios
SharePoint On Premise Authentication Options 
Windows Authentication 
Active Directory 
Windows Claims 
Or 
Classic Mode 
.NET Providers 
Forms-Based Authentication 
AD 
SQL 
Claims 
Relying Party 
Federated Identity 
Trusted Identity Provider 
AD 
User Store 
Claims
Office 365 Authentication Options 
Windows Azure Active Directory 
No Integration 
Cloud Identity 
Windows Azure Active Directory 
Integration with no 
federation 
Directory and Password 
Synchronization 
DirSync and Password Sync 
On Premise Identity 
Windows Azure Active Directory 
Single federated identity 
and credentials 
Federated Identity 
On Premise Identity 
Federation User Sync
SharePoint Extranets -OOTB 
•On premises SharePoint can be published externally through SSL 
•Unless an additional reverse proxy is used, the login experience is very basic 
•No forgotten password, change password, or self-registration 
•IT needs to setup and manage external users 
•No mechanism for getting credentials to users
SharePoint Extranets –Office 365 
•Up to 10,000 free external users in your Office 365 subscription through External Sharing 
•Must use the Microsoft login form 
•External users must have a Microsoft account, or be an Office 365 subscriber themselves 
•No control over what account is used to accept the invitation
SharePoint Extranets –Forms Based Authentication 
•Branded and friendly login form is possible 
•Requires custom development 
•Users can be stored outside of the corporate Active Directory 
•Installation is manual and requires re-configuring numerous configfiles on the SharePoint servers 
•Previous releases of Extranet User Manger (Version 2.6 and prior) addressed the login form, branding, installation, self- registration, forgotten password, and user management delegation issues
SharePoint Extranets -Federation 
•Supports SharePoint 2010 and 2013 on premises, and Office 365 
•Fully branded user experience 
•Friendly customizable login form 
•Login with email address 
•Automatic login for internal users 
•Customizable self-registration with approvals 
•Welcome email to set credentials 
•Forgotten password reset 
•Delegation of user management to business or externally 
•Delegated group management simplifies permissions 
•Supports single sign-on to other claims-aware applications 
•Improved governance over your Extranet
•Easy delegation of user management to business 
•Self-registration, approvals, forgotten password reset 
•Simplified login for both internal and external users 
Extranet User Manager
Main Components 
•Administration console 
Used by IT to configure EUM 
Used by the business to manage users and groups 
•End User 
Components that the Extranet users see 
Login, disclaimer, change password, forgotten password 
•Registration 
Allow users to self-register 
Support approval workflows
Pricing 
•Full pricing details available at www.envisionit.com/eum 
•Standard edition $8,000 USD per production farm 
No limits on the number of SharePoint web front ends 
Four hours of Premium Software Support 
•Enterprise Edition $13,000 USD 
Unlimited SSO authentication to claims aware applications 
Eight hours of Premium Software Support 
•20% annual Software Assurance provides all product updates 
•Devand QA farm licenses provided with up to date Software Assurance 
•Additional support packages available 
•Azure hosted monthly subscription plans coming next month
Registration
Registration Form Customizations
Approval Email
Approve the User
Welcome Email
Set Your Password
Login
Forgotten Password
Demo One –On Premises 
Registration through to Login
Demo Scenario 
•Sample site at https://productdemo13.envisionit.com 
•SharePoint 2013 on premises 
•AD FS for internal users 
•External users 
In a separate AD 
Authenticating through ThinktectureIdentity Server 
Managed with the Envision IT Extranet User Manager
Single Sign-On 
•https://productdemo13eum.envisionit.com 
Extranet User Manager 
Installed in its own IIS site outside of SharePoint 
•https://productdemo13sample.envisionit.com 
Sample ASP.NET 4.5 Visual Studio application 
Displays the claim information for the logged in user
Managing Your External Users with EUM 
•Supports SharePoint 2010 and 2013 on premises, and Office 365 
•Fully branded user experience 
•Friendly customizable login form 
•Login with email address 
•Automatic login for internal users 
•Customizable self-registration with approvals 
•Welcome email to set credentials 
•Forgotten password reset 
•Delegation of user management to business or externally 
•Delegated group management simplifies permissions 
•Supports single sign-on to other claims-aware applications 
•Improved governance over your Extranet
Technical Advantages 
•Fully supported by Microsoft with minimal changes to the SharePoint farm 
PowerShell script installs the required certificates into SharePoint 
•No open firewall ports from DMZ to internal required 
If internal users should be able to login externally without VPN, then ADFS needs to be published externally on port 443 
•External users can be stored in a separate DMZ AD, or in a SQL database 
•IT no longer needs to manage the external users, or reset their passwords
Poll 3 
When would you like us to follow up? 
•Right away 
•November / December 
•January
Single Sign-On and Federated Identities 
•Trusted Identity Provider does the authentication 
•Can be any SAML compliant provider 
Active Directory Federation Services 
ThinktectureIdentity Server 
owww.thinktecture.com 
Social identities 
•Can be AD, SQL, or other user repository under the hood 
•Relying parties (such as SharePoint) trust the SAML token and provide the authorization based off that identity 
•Provides Single Sign-On to multiple systems 
Can be any SAML claims compliant system, not just SharePoint
AD FS Servers 
Internal AD FS/DC Servers DMZ AD FS Proxies 
Web Application Proxy
AD FS Login Form 
•Internal users shouldn’t see this inside the network 
•Can be branded, within limits
Federation
Authentication Process 
Relying Party Identity Provider Active Directory 
Browse app 
Not authenticated 
Redirected to IP 
Authenticate 
User 
Query for user attributes 
Return SAML Security Token 
Return page 
and cookie 
Send Token 
ST 
ST 
RP trusts IP
Certificates 
• PKI SSL encryption is used for communication 
• Token can be self-signed by the Identity Provider 
• Token can also be encrypted with a self-signed certificate 
from the Identity Provider 
A Communication 
Signing 
Relying party Identity Provider 
ST 
Encryption ST 
B 
Public key of C C 
D Public key of D 
Root for B Root for A
Why Thinktectureover ADFS? 
•ThinktectureIdentity Server is embedded in Extranet User Manager 
•www.thinktecture.com/identityAndAccessControl 
•Open source allows any customization 
•Fully brandable(ADFS allows branding within very particular parameters) 
•Login with email address instead of AD username 
•Use SQL instead of AD as the underlying user repository 
•Ability to incorporate the home realm discovery into the login form
ezRealmHome Realm Discovery 
Internal IP Address? 
Internal email domain? 
No 
Yes 
Yes 
No
Demo Two –Office 365 
Registration through to Login
Demo Scenario 
•Sample site at https://eumdev.sharepoint.com 
•EUM installed at https://eum.eitdev.org 
•SharePoint Online in Office 365 
•AD FS for internal users 
•External users 
In a separate AD 
Authenticating through ThinktectureIdentity Server 
Managed with the Envision IT Extranet User Manager
Next Steps 
•Reach out to Hugh Davidson, Sales 
e: hdavidson@envisionit.com 
p: (905) 812-3009 x222 
•Installation Support on Premise 
•Minimum 30 day evaluation with all features enabled
Pricing 
•Full pricing details available at www.envisionit.com/eum 
•Standard edition $8,000 USD per production farm 
No limits on the number of SharePoint web front ends 
Four hours of Premium Software Support 
•Enterprise Edition $13,000 USD 
Unlimited SSO authentication to claims aware applications 
Eight hours of Premium Software Support 
•20% annual Software Assurance provides all product updates 
•Devand QA farm licenses provided with up to date Software Assurance 
•Additional support packages available
Product Roadmap 
•SQL User Store 
•Office 365 Support 
•Azure Support 
•Responsive design 
•Quick spin-up demo environment** 
•Multifactor Authentication 
•Social Identity Integration
Upcoming Events 
•ESPC Webinar –Oct 30th9am EST 
http://www.envisionit.com/products/events/ 
•CollabConToronto –November 24th–25th 
www.collabcon.org 
Use the discount code ENVISIONIT for a 10% discount
Links 
•www.envisionit.com 
•blog.petercarson.ca 
•www.envisionit.com/eum 
•Video and presentation deck will be at www.envisionit.com/events 
•Customer sites 
www.publichealthontario.ca 
www.bgccan.com 
www.g2gmarket.com 
www.redcrest.com.au 
www.transamerica.ca 
suppliers.kinross.com 
www.problemgambling.ca
Questions?

Contenu connexe

Tendances

SharePoint Saturday Austin - Share point authentication and authorization
SharePoint Saturday Austin - Share point authentication and authorizationSharePoint Saturday Austin - Share point authentication and authorization
SharePoint Saturday Austin - Share point authentication and authorizationLiam Cleary [MVP]
 
Oauth and SharePoint 2013 Provider Hosted apps
Oauth and SharePoint 2013 Provider Hosted appsOauth and SharePoint 2013 Provider Hosted apps
Oauth and SharePoint 2013 Provider Hosted appsJames Tramel
 
The Who, What, Why and How of Active Directory Federation Services (AD FS)
The Who, What, Why and How of Active Directory Federation Services (AD FS)The Who, What, Why and How of Active Directory Federation Services (AD FS)
The Who, What, Why and How of Active Directory Federation Services (AD FS)Jay Simcox
 
Preparing for Office 365
Preparing for Office 365Preparing for Office 365
Preparing for Office 365Jan Egil Ring
 
SharePoint, ADFS and Claims Auth
SharePoint, ADFS and Claims AuthSharePoint, ADFS and Claims Auth
SharePoint, ADFS and Claims AuthKashif Imran
 
Office 365-single-sign-on-with-adfs
Office 365-single-sign-on-with-adfsOffice 365-single-sign-on-with-adfs
Office 365-single-sign-on-with-adfsamitchachra
 
A Developer's Introduction to Azure Active Directory B2C
A Developer's Introduction to Azure Active Directory B2CA Developer's Introduction to Azure Active Directory B2C
A Developer's Introduction to Azure Active Directory B2CJohn Garland
 
SharePoint Saturday The Conference DC - How the client object model saved the...
SharePoint Saturday The Conference DC - How the client object model saved the...SharePoint Saturday The Conference DC - How the client object model saved the...
SharePoint Saturday The Conference DC - How the client object model saved the...Liam Cleary [MVP]
 
Con8836 leveraging the cloud to simplify your identity management implement...
Con8836   leveraging the cloud to simplify your identity management implement...Con8836   leveraging the cloud to simplify your identity management implement...
Con8836 leveraging the cloud to simplify your identity management implement...OracleIDM
 
How to deploy SharePoint 2010 to external users?
How to deploy SharePoint 2010 to external users?How to deploy SharePoint 2010 to external users?
How to deploy SharePoint 2010 to external users?rlsoft
 
T28 implementing adfs and hybrid share point
T28   implementing adfs and hybrid share point T28   implementing adfs and hybrid share point
T28 implementing adfs and hybrid share point Thorbjørn Værp
 
Extending Authentication and Authorization
Extending Authentication and AuthorizationExtending Authentication and Authorization
Extending Authentication and AuthorizationEdin Kapic
 
ESPC15 - Extending Authentication and Authorization
ESPC15 - Extending Authentication and AuthorizationESPC15 - Extending Authentication and Authorization
ESPC15 - Extending Authentication and AuthorizationEdin Kapic
 
Unified client management session from Microsoft partner boot camp
Unified client management session from Microsoft partner boot campUnified client management session from Microsoft partner boot camp
Unified client management session from Microsoft partner boot campOlav Tvedt
 
OFM AIA FP Implementation View and Case Study
OFM AIA FP Implementation View and Case StudyOFM AIA FP Implementation View and Case Study
OFM AIA FP Implementation View and Case StudySreenivasa Setty
 
Avoiding the Hidden Costs of Active Directory Federation Services (AD FS)
Avoiding the Hidden Costs of Active Directory Federation Services (AD FS)Avoiding the Hidden Costs of Active Directory Federation Services (AD FS)
Avoiding the Hidden Costs of Active Directory Federation Services (AD FS)Okta-Inc
 
SharePoint Saturday Kansas 2015 - Building Killer Office365 Public Sites
SharePoint Saturday Kansas 2015 - Building Killer Office365 Public SitesSharePoint Saturday Kansas 2015 - Building Killer Office365 Public Sites
SharePoint Saturday Kansas 2015 - Building Killer Office365 Public SitesBrian Culver
 

Tendances (20)

OAuth in SharePoint 2013
OAuth in SharePoint 2013OAuth in SharePoint 2013
OAuth in SharePoint 2013
 
SharePoint Saturday Austin - Share point authentication and authorization
SharePoint Saturday Austin - Share point authentication and authorizationSharePoint Saturday Austin - Share point authentication and authorization
SharePoint Saturday Austin - Share point authentication and authorization
 
Oauth and SharePoint 2013 Provider Hosted apps
Oauth and SharePoint 2013 Provider Hosted appsOauth and SharePoint 2013 Provider Hosted apps
Oauth and SharePoint 2013 Provider Hosted apps
 
The Who, What, Why and How of Active Directory Federation Services (AD FS)
The Who, What, Why and How of Active Directory Federation Services (AD FS)The Who, What, Why and How of Active Directory Federation Services (AD FS)
The Who, What, Why and How of Active Directory Federation Services (AD FS)
 
Preparing for Office 365
Preparing for Office 365Preparing for Office 365
Preparing for Office 365
 
SharePoint, ADFS and Claims Auth
SharePoint, ADFS and Claims AuthSharePoint, ADFS and Claims Auth
SharePoint, ADFS and Claims Auth
 
Office 365-single-sign-on-with-adfs
Office 365-single-sign-on-with-adfsOffice 365-single-sign-on-with-adfs
Office 365-single-sign-on-with-adfs
 
SharePoint 2013 and ADFS
SharePoint 2013 and ADFSSharePoint 2013 and ADFS
SharePoint 2013 and ADFS
 
Office 365 Identity Management options
Office 365 Identity Management options Office 365 Identity Management options
Office 365 Identity Management options
 
A Developer's Introduction to Azure Active Directory B2C
A Developer's Introduction to Azure Active Directory B2CA Developer's Introduction to Azure Active Directory B2C
A Developer's Introduction to Azure Active Directory B2C
 
SharePoint Saturday The Conference DC - How the client object model saved the...
SharePoint Saturday The Conference DC - How the client object model saved the...SharePoint Saturday The Conference DC - How the client object model saved the...
SharePoint Saturday The Conference DC - How the client object model saved the...
 
Con8836 leveraging the cloud to simplify your identity management implement...
Con8836   leveraging the cloud to simplify your identity management implement...Con8836   leveraging the cloud to simplify your identity management implement...
Con8836 leveraging the cloud to simplify your identity management implement...
 
How to deploy SharePoint 2010 to external users?
How to deploy SharePoint 2010 to external users?How to deploy SharePoint 2010 to external users?
How to deploy SharePoint 2010 to external users?
 
T28 implementing adfs and hybrid share point
T28   implementing adfs and hybrid share point T28   implementing adfs and hybrid share point
T28 implementing adfs and hybrid share point
 
Extending Authentication and Authorization
Extending Authentication and AuthorizationExtending Authentication and Authorization
Extending Authentication and Authorization
 
ESPC15 - Extending Authentication and Authorization
ESPC15 - Extending Authentication and AuthorizationESPC15 - Extending Authentication and Authorization
ESPC15 - Extending Authentication and Authorization
 
Unified client management session from Microsoft partner boot camp
Unified client management session from Microsoft partner boot campUnified client management session from Microsoft partner boot camp
Unified client management session from Microsoft partner boot camp
 
OFM AIA FP Implementation View and Case Study
OFM AIA FP Implementation View and Case StudyOFM AIA FP Implementation View and Case Study
OFM AIA FP Implementation View and Case Study
 
Avoiding the Hidden Costs of Active Directory Federation Services (AD FS)
Avoiding the Hidden Costs of Active Directory Federation Services (AD FS)Avoiding the Hidden Costs of Active Directory Federation Services (AD FS)
Avoiding the Hidden Costs of Active Directory Federation Services (AD FS)
 
SharePoint Saturday Kansas 2015 - Building Killer Office365 Public Sites
SharePoint Saturday Kansas 2015 - Building Killer Office365 Public SitesSharePoint Saturday Kansas 2015 - Building Killer Office365 Public Sites
SharePoint Saturday Kansas 2015 - Building Killer Office365 Public Sites
 

En vedette

Sa jka national tournament 31 may 2013
Sa jka national tournament 31 may 2013Sa jka national tournament 31 may 2013
Sa jka national tournament 31 may 2013WolfgangPhoenix
 
Sa jka national tournament result slides 1 june 2013
Sa jka national tournament result slides 1 june 2013Sa jka national tournament result slides 1 june 2013
Sa jka national tournament result slides 1 june 2013WolfgangPhoenix
 
Sa jka national tournament results 1 june
Sa jka national tournament results 1 juneSa jka national tournament results 1 june
Sa jka national tournament results 1 juneWolfgangPhoenix
 
CIS14: Case Study: Using a Federated Identity Service for Faster Application ...
CIS14: Case Study: Using a Federated Identity Service for Faster Application ...CIS14: Case Study: Using a Federated Identity Service for Faster Application ...
CIS14: Case Study: Using a Federated Identity Service for Faster Application ...CloudIDSummit
 
Top 10 Podcasts Every Salesperson Needs to be Listening To
Top 10 Podcasts Every Salesperson Needs to be Listening ToTop 10 Podcasts Every Salesperson Needs to be Listening To
Top 10 Podcasts Every Salesperson Needs to be Listening ToBrandon Redlinger
 
Study: The Future of VR, AR and Self-Driving Cars
Study: The Future of VR, AR and Self-Driving CarsStudy: The Future of VR, AR and Self-Driving Cars
Study: The Future of VR, AR and Self-Driving CarsLinkedIn
 

En vedette (6)

Sa jka national tournament 31 may 2013
Sa jka national tournament 31 may 2013Sa jka national tournament 31 may 2013
Sa jka national tournament 31 may 2013
 
Sa jka national tournament result slides 1 june 2013
Sa jka national tournament result slides 1 june 2013Sa jka national tournament result slides 1 june 2013
Sa jka national tournament result slides 1 june 2013
 
Sa jka national tournament results 1 june
Sa jka national tournament results 1 juneSa jka national tournament results 1 june
Sa jka national tournament results 1 june
 
CIS14: Case Study: Using a Federated Identity Service for Faster Application ...
CIS14: Case Study: Using a Federated Identity Service for Faster Application ...CIS14: Case Study: Using a Federated Identity Service for Faster Application ...
CIS14: Case Study: Using a Federated Identity Service for Faster Application ...
 
Top 10 Podcasts Every Salesperson Needs to be Listening To
Top 10 Podcasts Every Salesperson Needs to be Listening ToTop 10 Podcasts Every Salesperson Needs to be Listening To
Top 10 Podcasts Every Salesperson Needs to be Listening To
 
Study: The Future of VR, AR and Self-Driving Cars
Study: The Future of VR, AR and Self-Driving CarsStudy: The Future of VR, AR and Self-Driving Cars
Study: The Future of VR, AR and Self-Driving Cars
 

Similaire à Extranet Identity Management and Authentication for SharePoint On Premise, Office 365 and Beyond

Envision it SharePoint Extranet Webinar Series - Federation and Office 365
Envision it SharePoint Extranet Webinar Series - Federation and Office 365Envision it SharePoint Extranet Webinar Series - Federation and Office 365
Envision it SharePoint Extranet Webinar Series - Federation and Office 365Envision IT
 
Envision it SharePoint Extranet Webinar Series - Extranet User Provisioning
Envision it SharePoint Extranet Webinar Series  - Extranet User ProvisioningEnvision it SharePoint Extranet Webinar Series  - Extranet User Provisioning
Envision it SharePoint Extranet Webinar Series - Extranet User ProvisioningEnvision IT
 
Introduction to Azure AD and Azure AD B2C
Introduction to Azure AD and Azure AD B2CIntroduction to Azure AD and Azure AD B2C
Introduction to Azure AD and Azure AD B2CJoonas Westlin
 
Understanding Office 365’s Identity Solutions: Deep Dive - EPC Group
Understanding Office 365’s Identity Solutions: Deep Dive - EPC GroupUnderstanding Office 365’s Identity Solutions: Deep Dive - EPC Group
Understanding Office 365’s Identity Solutions: Deep Dive - EPC GroupEPC Group
 
How to Build a Structured Extranet Using Azure AD B2B
How to Build a Structured Extranet Using Azure AD B2BHow to Build a Structured Extranet Using Azure AD B2B
How to Build a Structured Extranet Using Azure AD B2BAndrew Oboro
 
Unstructured vs. Structured Extranets in office 365 Webinar - June 11, 2019
Unstructured vs. Structured Extranets in office 365 Webinar - June 11, 2019Unstructured vs. Structured Extranets in office 365 Webinar - June 11, 2019
Unstructured vs. Structured Extranets in office 365 Webinar - June 11, 2019Andrew Oboro
 
O365Con18 - Hybrid SharePoint Deep Dive - Thomas Vochten
O365Con18 - Hybrid SharePoint Deep Dive - Thomas VochtenO365Con18 - Hybrid SharePoint Deep Dive - Thomas Vochten
O365Con18 - Hybrid SharePoint Deep Dive - Thomas VochtenNCCOMMS
 
MindSurf 2013 - Improving Business Productivity with SharePoint 2013
MindSurf 2013 - Improving Business Productivity with SharePoint 2013MindSurf 2013 - Improving Business Productivity with SharePoint 2013
MindSurf 2013 - Improving Business Productivity with SharePoint 2013Don Donais
 
Sharepoint and office 365 hybrid configuration from A to Z #spstoronto 2015
Sharepoint and office 365 hybrid configuration from A to Z   #spstoronto 2015Sharepoint and office 365 hybrid configuration from A to Z   #spstoronto 2015
Sharepoint and office 365 hybrid configuration from A to Z #spstoronto 2015Nicolas Georgeault
 
Pre-built, Secure Identity Layer for Consumer Websites, B2B Portals and SaaS ...
Pre-built, Secure Identity Layer for Consumer Websites, B2B Portals and SaaS ...Pre-built, Secure Identity Layer for Consumer Websites, B2B Portals and SaaS ...
Pre-built, Secure Identity Layer for Consumer Websites, B2B Portals and SaaS ...Okta-Inc
 
Salesforce Identity: Connect and Collaborate Anywhere, Securely with Single S...
Salesforce Identity: Connect and Collaborate Anywhere, Securely with Single S...Salesforce Identity: Connect and Collaborate Anywhere, Securely with Single S...
Salesforce Identity: Connect and Collaborate Anywhere, Securely with Single S...Perficient, Inc.
 
Implementing and Managing Office 365 - Jacksonville IT Pro Camp 2017
Implementing and Managing Office 365  -  Jacksonville IT Pro Camp 2017Implementing and Managing Office 365  -  Jacksonville IT Pro Camp 2017
Implementing and Managing Office 365 - Jacksonville IT Pro Camp 2017Ben Stegink
 
04_Extending and Securing Enterprise Applications in Microsoft Azure_GAB2019
04_Extending and Securing Enterprise Applications in Microsoft Azure_GAB201904_Extending and Securing Enterprise Applications in Microsoft Azure_GAB2019
04_Extending and Securing Enterprise Applications in Microsoft Azure_GAB2019Kumton Suttiraksiri
 
SharePoint Authentication And Authorization SPTechCon San Francisco
SharePoint Authentication And Authorization SPTechCon San FranciscoSharePoint Authentication And Authorization SPTechCon San Francisco
SharePoint Authentication And Authorization SPTechCon San FranciscoLiam Cleary [MVP]
 
Practical Tips for Migrating SharePoint Customizations to Office 365
Practical Tips for Migrating SharePoint Customizations to Office 365Practical Tips for Migrating SharePoint Customizations to Office 365
Practical Tips for Migrating SharePoint Customizations to Office 365Haniel Croitoru
 
Moving to the cloud with Office 365
Moving to the cloud with Office 365Moving to the cloud with Office 365
Moving to the cloud with Office 365Ben Stegink
 
SPSVB - Office 365 and Cloud Identity - What Does It Mean for Me?
SPSVB - Office 365 and Cloud Identity - What Does It Mean for Me?SPSVB - Office 365 and Cloud Identity - What Does It Mean for Me?
SPSVB - Office 365 and Cloud Identity - What Does It Mean for Me?Scott Hoag
 
#spsuk: Understanding the Office 365 Architecture
#spsuk: Understanding the Office 365 Architecture#spsuk: Understanding the Office 365 Architecture
#spsuk: Understanding the Office 365 Architecturepearce.alex
 
Introduction and What’s new in SharePoint 2013
Introduction and What’s new in SharePoint 2013Introduction and What’s new in SharePoint 2013
Introduction and What’s new in SharePoint 2013MJ Ferdous
 
Configuring Hybrid Workloads for SharePoint 2013 and O365 by Neil Hodgkinson
Configuring Hybrid Workloads for SharePoint 2013 and O365 by Neil HodgkinsonConfiguring Hybrid Workloads for SharePoint 2013 and O365 by Neil Hodgkinson
Configuring Hybrid Workloads for SharePoint 2013 and O365 by Neil HodgkinsonEuropean SharePoint Conference
 

Similaire à Extranet Identity Management and Authentication for SharePoint On Premise, Office 365 and Beyond (20)

Envision it SharePoint Extranet Webinar Series - Federation and Office 365
Envision it SharePoint Extranet Webinar Series - Federation and Office 365Envision it SharePoint Extranet Webinar Series - Federation and Office 365
Envision it SharePoint Extranet Webinar Series - Federation and Office 365
 
Envision it SharePoint Extranet Webinar Series - Extranet User Provisioning
Envision it SharePoint Extranet Webinar Series  - Extranet User ProvisioningEnvision it SharePoint Extranet Webinar Series  - Extranet User Provisioning
Envision it SharePoint Extranet Webinar Series - Extranet User Provisioning
 
Introduction to Azure AD and Azure AD B2C
Introduction to Azure AD and Azure AD B2CIntroduction to Azure AD and Azure AD B2C
Introduction to Azure AD and Azure AD B2C
 
Understanding Office 365’s Identity Solutions: Deep Dive - EPC Group
Understanding Office 365’s Identity Solutions: Deep Dive - EPC GroupUnderstanding Office 365’s Identity Solutions: Deep Dive - EPC Group
Understanding Office 365’s Identity Solutions: Deep Dive - EPC Group
 
How to Build a Structured Extranet Using Azure AD B2B
How to Build a Structured Extranet Using Azure AD B2BHow to Build a Structured Extranet Using Azure AD B2B
How to Build a Structured Extranet Using Azure AD B2B
 
Unstructured vs. Structured Extranets in office 365 Webinar - June 11, 2019
Unstructured vs. Structured Extranets in office 365 Webinar - June 11, 2019Unstructured vs. Structured Extranets in office 365 Webinar - June 11, 2019
Unstructured vs. Structured Extranets in office 365 Webinar - June 11, 2019
 
O365Con18 - Hybrid SharePoint Deep Dive - Thomas Vochten
O365Con18 - Hybrid SharePoint Deep Dive - Thomas VochtenO365Con18 - Hybrid SharePoint Deep Dive - Thomas Vochten
O365Con18 - Hybrid SharePoint Deep Dive - Thomas Vochten
 
MindSurf 2013 - Improving Business Productivity with SharePoint 2013
MindSurf 2013 - Improving Business Productivity with SharePoint 2013MindSurf 2013 - Improving Business Productivity with SharePoint 2013
MindSurf 2013 - Improving Business Productivity with SharePoint 2013
 
Sharepoint and office 365 hybrid configuration from A to Z #spstoronto 2015
Sharepoint and office 365 hybrid configuration from A to Z   #spstoronto 2015Sharepoint and office 365 hybrid configuration from A to Z   #spstoronto 2015
Sharepoint and office 365 hybrid configuration from A to Z #spstoronto 2015
 
Pre-built, Secure Identity Layer for Consumer Websites, B2B Portals and SaaS ...
Pre-built, Secure Identity Layer for Consumer Websites, B2B Portals and SaaS ...Pre-built, Secure Identity Layer for Consumer Websites, B2B Portals and SaaS ...
Pre-built, Secure Identity Layer for Consumer Websites, B2B Portals and SaaS ...
 
Salesforce Identity: Connect and Collaborate Anywhere, Securely with Single S...
Salesforce Identity: Connect and Collaborate Anywhere, Securely with Single S...Salesforce Identity: Connect and Collaborate Anywhere, Securely with Single S...
Salesforce Identity: Connect and Collaborate Anywhere, Securely with Single S...
 
Implementing and Managing Office 365 - Jacksonville IT Pro Camp 2017
Implementing and Managing Office 365  -  Jacksonville IT Pro Camp 2017Implementing and Managing Office 365  -  Jacksonville IT Pro Camp 2017
Implementing and Managing Office 365 - Jacksonville IT Pro Camp 2017
 
04_Extending and Securing Enterprise Applications in Microsoft Azure_GAB2019
04_Extending and Securing Enterprise Applications in Microsoft Azure_GAB201904_Extending and Securing Enterprise Applications in Microsoft Azure_GAB2019
04_Extending and Securing Enterprise Applications in Microsoft Azure_GAB2019
 
SharePoint Authentication And Authorization SPTechCon San Francisco
SharePoint Authentication And Authorization SPTechCon San FranciscoSharePoint Authentication And Authorization SPTechCon San Francisco
SharePoint Authentication And Authorization SPTechCon San Francisco
 
Practical Tips for Migrating SharePoint Customizations to Office 365
Practical Tips for Migrating SharePoint Customizations to Office 365Practical Tips for Migrating SharePoint Customizations to Office 365
Practical Tips for Migrating SharePoint Customizations to Office 365
 
Moving to the cloud with Office 365
Moving to the cloud with Office 365Moving to the cloud with Office 365
Moving to the cloud with Office 365
 
SPSVB - Office 365 and Cloud Identity - What Does It Mean for Me?
SPSVB - Office 365 and Cloud Identity - What Does It Mean for Me?SPSVB - Office 365 and Cloud Identity - What Does It Mean for Me?
SPSVB - Office 365 and Cloud Identity - What Does It Mean for Me?
 
#spsuk: Understanding the Office 365 Architecture
#spsuk: Understanding the Office 365 Architecture#spsuk: Understanding the Office 365 Architecture
#spsuk: Understanding the Office 365 Architecture
 
Introduction and What’s new in SharePoint 2013
Introduction and What’s new in SharePoint 2013Introduction and What’s new in SharePoint 2013
Introduction and What’s new in SharePoint 2013
 
Configuring Hybrid Workloads for SharePoint 2013 and O365 by Neil Hodgkinson
Configuring Hybrid Workloads for SharePoint 2013 and O365 by Neil HodgkinsonConfiguring Hybrid Workloads for SharePoint 2013 and O365 by Neil Hodgkinson
Configuring Hybrid Workloads for SharePoint 2013 and O365 by Neil Hodgkinson
 

Dernier

GenCyber Cyber Security Day Presentation
GenCyber Cyber Security Day PresentationGenCyber Cyber Security Day Presentation
GenCyber Cyber Security Day PresentationMichael W. Hawkins
 
Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024The Digital Insurer
 
A Call to Action for Generative AI in 2024
A Call to Action for Generative AI in 2024A Call to Action for Generative AI in 2024
A Call to Action for Generative AI in 2024Results
 
Breaking the Kubernetes Kill Chain: Host Path Mount
Breaking the Kubernetes Kill Chain: Host Path MountBreaking the Kubernetes Kill Chain: Host Path Mount
Breaking the Kubernetes Kill Chain: Host Path MountPuma Security, LLC
 
Tata AIG General Insurance Company - Insurer Innovation Award 2024
Tata AIG General Insurance Company - Insurer Innovation Award 2024Tata AIG General Insurance Company - Insurer Innovation Award 2024
Tata AIG General Insurance Company - Insurer Innovation Award 2024The Digital Insurer
 
Boost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivityBoost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivityPrincipled Technologies
 
IAC 2024 - IA Fast Track to Search Focused AI Solutions
IAC 2024 - IA Fast Track to Search Focused AI SolutionsIAC 2024 - IA Fast Track to Search Focused AI Solutions
IAC 2024 - IA Fast Track to Search Focused AI SolutionsEnterprise Knowledge
 
Understanding Discord NSFW Servers A Guide for Responsible Users.pdf
Understanding Discord NSFW Servers A Guide for Responsible Users.pdfUnderstanding Discord NSFW Servers A Guide for Responsible Users.pdf
Understanding Discord NSFW Servers A Guide for Responsible Users.pdfUK Journal
 
Automating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps ScriptAutomating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps Scriptwesley chun
 
Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)wesley chun
 
A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)Gabriella Davis
 
Factors to Consider When Choosing Accounts Payable Services Providers.pptx
Factors to Consider When Choosing Accounts Payable Services Providers.pptxFactors to Consider When Choosing Accounts Payable Services Providers.pptx
Factors to Consider When Choosing Accounts Payable Services Providers.pptxKatpro Technologies
 
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...apidays
 
Handwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed textsHandwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed textsMaria Levchenko
 
Finology Group – Insurtech Innovation Award 2024
Finology Group – Insurtech Innovation Award 2024Finology Group – Insurtech Innovation Award 2024
Finology Group – Insurtech Innovation Award 2024The Digital Insurer
 
08448380779 Call Girls In Friends Colony Women Seeking Men
08448380779 Call Girls In Friends Colony Women Seeking Men08448380779 Call Girls In Friends Colony Women Seeking Men
08448380779 Call Girls In Friends Colony Women Seeking MenDelhi Call girls
 
Scaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organizationScaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organizationRadu Cotescu
 
Workshop - Best of Both Worlds_ Combine KG and Vector search for enhanced R...
Workshop - Best of Both Worlds_ Combine  KG and Vector search for  enhanced R...Workshop - Best of Both Worlds_ Combine  KG and Vector search for  enhanced R...
Workshop - Best of Both Worlds_ Combine KG and Vector search for enhanced R...Neo4j
 
2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...Martijn de Jong
 
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptxEIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptxEarley Information Science
 

Dernier (20)

GenCyber Cyber Security Day Presentation
GenCyber Cyber Security Day PresentationGenCyber Cyber Security Day Presentation
GenCyber Cyber Security Day Presentation
 
Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024
 
A Call to Action for Generative AI in 2024
A Call to Action for Generative AI in 2024A Call to Action for Generative AI in 2024
A Call to Action for Generative AI in 2024
 
Breaking the Kubernetes Kill Chain: Host Path Mount
Breaking the Kubernetes Kill Chain: Host Path MountBreaking the Kubernetes Kill Chain: Host Path Mount
Breaking the Kubernetes Kill Chain: Host Path Mount
 
Tata AIG General Insurance Company - Insurer Innovation Award 2024
Tata AIG General Insurance Company - Insurer Innovation Award 2024Tata AIG General Insurance Company - Insurer Innovation Award 2024
Tata AIG General Insurance Company - Insurer Innovation Award 2024
 
Boost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivityBoost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivity
 
IAC 2024 - IA Fast Track to Search Focused AI Solutions
IAC 2024 - IA Fast Track to Search Focused AI SolutionsIAC 2024 - IA Fast Track to Search Focused AI Solutions
IAC 2024 - IA Fast Track to Search Focused AI Solutions
 
Understanding Discord NSFW Servers A Guide for Responsible Users.pdf
Understanding Discord NSFW Servers A Guide for Responsible Users.pdfUnderstanding Discord NSFW Servers A Guide for Responsible Users.pdf
Understanding Discord NSFW Servers A Guide for Responsible Users.pdf
 
Automating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps ScriptAutomating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps Script
 
Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)
 
A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)
 
Factors to Consider When Choosing Accounts Payable Services Providers.pptx
Factors to Consider When Choosing Accounts Payable Services Providers.pptxFactors to Consider When Choosing Accounts Payable Services Providers.pptx
Factors to Consider When Choosing Accounts Payable Services Providers.pptx
 
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
 
Handwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed textsHandwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed texts
 
Finology Group – Insurtech Innovation Award 2024
Finology Group – Insurtech Innovation Award 2024Finology Group – Insurtech Innovation Award 2024
Finology Group – Insurtech Innovation Award 2024
 
08448380779 Call Girls In Friends Colony Women Seeking Men
08448380779 Call Girls In Friends Colony Women Seeking Men08448380779 Call Girls In Friends Colony Women Seeking Men
08448380779 Call Girls In Friends Colony Women Seeking Men
 
Scaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organizationScaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organization
 
Workshop - Best of Both Worlds_ Combine KG and Vector search for enhanced R...
Workshop - Best of Both Worlds_ Combine  KG and Vector search for  enhanced R...Workshop - Best of Both Worlds_ Combine  KG and Vector search for  enhanced R...
Workshop - Best of Both Worlds_ Combine KG and Vector search for enhanced R...
 
2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...
 
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptxEIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
 

Extranet Identity Management and Authentication for SharePoint On Premise, Office 365 and Beyond

  • 1. Extranet Identity Management and Authentication for SharePoint On Premise, Office 365 and Beyond Presented by Peter Carson President, Envision IT October 22, 2014
  • 2. Peter Carson •President, Envision IT •SharePoint MVP •Virtual Technical Specialist, Microsoft Canada •peter@envisionit.com •http://blog.petercarson.ca •www.envisionit.com •Twitter @carsonpeter •VP Toronto SharePoint User Group
  • 3. Hugh Davidson Business Development Manager, Product Sales •e: hdavidson@envisionit.com •p: (905) 812-3009 x222
  • 4. Denesh Sohan Director of Products •e: dsohan@envisionit.com •p: (905) 812-3009 x298
  • 5. Corey Thokle Project Manager •e: cthokle@envisionit.com •p: (905) 812 3009 ext.248
  • 6. Agenda •Envision IT Overview •Extranet Scenarios •Extranet User Manager Overview •SharePoint On Premises Demo •Federation •Office 365 Demo •Wrap-Up and Q&A
  • 7.
  • 8. Focused on complex SharePoint solutions, Envision IT is the “go-to” partner for Microsoft SharePoint, building integrated public web sites, Intranets, Extranets, and web applications that leverage your existing systems anywhere over the Internet. Envision IT Services Overview
  • 9. Public Web Sites We create interactive, content-rich customer-facing web sites that are able to grow and transform with changing needs
  • 10. Collaboration Portals Our Collaboration Portals provide a secure space for teams to share knowledge and resources
  • 11. Intranets Our Intranet Sites connect people to information, expertise and key business applications, and SharePoint provides a broad set of Enterprise Content Management features
  • 12. Extranets Envision IT has a wealth of experience building Corporate Extranets that allow you to securely connect with customers and partners
  • 13. What is an Extranet •An Extranetis a web site that is accessible to users outside of the corporate network, which allowsorganizations to share information and collaborate with their customers, partners, and/or vendors in a secure and easy-to-use environment •The Extranet may be added as amodule into the Intranet site to only allow external users into specific sub-sites of the Intranet
  • 14. Poll 1 Which Version of SharePoint are you currently using? •SharePoint Server 2013 •Office 365 •SharePoint Server 2010 •SharePoint Foundation (2010 or 2013) •MOSS 2007 or WSS 3.0
  • 15. Poll 2 How do you use SharePoint today? •Internal collaboration •Internal web publishing (Intranet) •Extranets •Public facing website
  • 17. SharePoint On Premise Authentication Options Windows Authentication Active Directory Windows Claims Or Classic Mode .NET Providers Forms-Based Authentication AD SQL Claims Relying Party Federated Identity Trusted Identity Provider AD User Store Claims
  • 18. Office 365 Authentication Options Windows Azure Active Directory No Integration Cloud Identity Windows Azure Active Directory Integration with no federation Directory and Password Synchronization DirSync and Password Sync On Premise Identity Windows Azure Active Directory Single federated identity and credentials Federated Identity On Premise Identity Federation User Sync
  • 19. SharePoint Extranets -OOTB •On premises SharePoint can be published externally through SSL •Unless an additional reverse proxy is used, the login experience is very basic •No forgotten password, change password, or self-registration •IT needs to setup and manage external users •No mechanism for getting credentials to users
  • 20. SharePoint Extranets –Office 365 •Up to 10,000 free external users in your Office 365 subscription through External Sharing •Must use the Microsoft login form •External users must have a Microsoft account, or be an Office 365 subscriber themselves •No control over what account is used to accept the invitation
  • 21. SharePoint Extranets –Forms Based Authentication •Branded and friendly login form is possible •Requires custom development •Users can be stored outside of the corporate Active Directory •Installation is manual and requires re-configuring numerous configfiles on the SharePoint servers •Previous releases of Extranet User Manger (Version 2.6 and prior) addressed the login form, branding, installation, self- registration, forgotten password, and user management delegation issues
  • 22. SharePoint Extranets -Federation •Supports SharePoint 2010 and 2013 on premises, and Office 365 •Fully branded user experience •Friendly customizable login form •Login with email address •Automatic login for internal users •Customizable self-registration with approvals •Welcome email to set credentials •Forgotten password reset •Delegation of user management to business or externally •Delegated group management simplifies permissions •Supports single sign-on to other claims-aware applications •Improved governance over your Extranet
  • 23. •Easy delegation of user management to business •Self-registration, approvals, forgotten password reset •Simplified login for both internal and external users Extranet User Manager
  • 24. Main Components •Administration console Used by IT to configure EUM Used by the business to manage users and groups •End User Components that the Extranet users see Login, disclaimer, change password, forgotten password •Registration Allow users to self-register Support approval workflows
  • 25. Pricing •Full pricing details available at www.envisionit.com/eum •Standard edition $8,000 USD per production farm No limits on the number of SharePoint web front ends Four hours of Premium Software Support •Enterprise Edition $13,000 USD Unlimited SSO authentication to claims aware applications Eight hours of Premium Software Support •20% annual Software Assurance provides all product updates •Devand QA farm licenses provided with up to date Software Assurance •Additional support packages available •Azure hosted monthly subscription plans coming next month
  • 32. Login
  • 34. Demo One –On Premises Registration through to Login
  • 35. Demo Scenario •Sample site at https://productdemo13.envisionit.com •SharePoint 2013 on premises •AD FS for internal users •External users In a separate AD Authenticating through ThinktectureIdentity Server Managed with the Envision IT Extranet User Manager
  • 36. Single Sign-On •https://productdemo13eum.envisionit.com Extranet User Manager Installed in its own IIS site outside of SharePoint •https://productdemo13sample.envisionit.com Sample ASP.NET 4.5 Visual Studio application Displays the claim information for the logged in user
  • 37. Managing Your External Users with EUM •Supports SharePoint 2010 and 2013 on premises, and Office 365 •Fully branded user experience •Friendly customizable login form •Login with email address •Automatic login for internal users •Customizable self-registration with approvals •Welcome email to set credentials •Forgotten password reset •Delegation of user management to business or externally •Delegated group management simplifies permissions •Supports single sign-on to other claims-aware applications •Improved governance over your Extranet
  • 38. Technical Advantages •Fully supported by Microsoft with minimal changes to the SharePoint farm PowerShell script installs the required certificates into SharePoint •No open firewall ports from DMZ to internal required If internal users should be able to login externally without VPN, then ADFS needs to be published externally on port 443 •External users can be stored in a separate DMZ AD, or in a SQL database •IT no longer needs to manage the external users, or reset their passwords
  • 39. Poll 3 When would you like us to follow up? •Right away •November / December •January
  • 40. Single Sign-On and Federated Identities •Trusted Identity Provider does the authentication •Can be any SAML compliant provider Active Directory Federation Services ThinktectureIdentity Server owww.thinktecture.com Social identities •Can be AD, SQL, or other user repository under the hood •Relying parties (such as SharePoint) trust the SAML token and provide the authorization based off that identity •Provides Single Sign-On to multiple systems Can be any SAML claims compliant system, not just SharePoint
  • 41. AD FS Servers Internal AD FS/DC Servers DMZ AD FS Proxies Web Application Proxy
  • 42. AD FS Login Form •Internal users shouldn’t see this inside the network •Can be branded, within limits
  • 44. Authentication Process Relying Party Identity Provider Active Directory Browse app Not authenticated Redirected to IP Authenticate User Query for user attributes Return SAML Security Token Return page and cookie Send Token ST ST RP trusts IP
  • 45. Certificates • PKI SSL encryption is used for communication • Token can be self-signed by the Identity Provider • Token can also be encrypted with a self-signed certificate from the Identity Provider A Communication Signing Relying party Identity Provider ST Encryption ST B Public key of C C D Public key of D Root for B Root for A
  • 46. Why Thinktectureover ADFS? •ThinktectureIdentity Server is embedded in Extranet User Manager •www.thinktecture.com/identityAndAccessControl •Open source allows any customization •Fully brandable(ADFS allows branding within very particular parameters) •Login with email address instead of AD username •Use SQL instead of AD as the underlying user repository •Ability to incorporate the home realm discovery into the login form
  • 47. ezRealmHome Realm Discovery Internal IP Address? Internal email domain? No Yes Yes No
  • 48. Demo Two –Office 365 Registration through to Login
  • 49. Demo Scenario •Sample site at https://eumdev.sharepoint.com •EUM installed at https://eum.eitdev.org •SharePoint Online in Office 365 •AD FS for internal users •External users In a separate AD Authenticating through ThinktectureIdentity Server Managed with the Envision IT Extranet User Manager
  • 50. Next Steps •Reach out to Hugh Davidson, Sales e: hdavidson@envisionit.com p: (905) 812-3009 x222 •Installation Support on Premise •Minimum 30 day evaluation with all features enabled
  • 51. Pricing •Full pricing details available at www.envisionit.com/eum •Standard edition $8,000 USD per production farm No limits on the number of SharePoint web front ends Four hours of Premium Software Support •Enterprise Edition $13,000 USD Unlimited SSO authentication to claims aware applications Eight hours of Premium Software Support •20% annual Software Assurance provides all product updates •Devand QA farm licenses provided with up to date Software Assurance •Additional support packages available
  • 52. Product Roadmap •SQL User Store •Office 365 Support •Azure Support •Responsive design •Quick spin-up demo environment** •Multifactor Authentication •Social Identity Integration
  • 53. Upcoming Events •ESPC Webinar –Oct 30th9am EST http://www.envisionit.com/products/events/ •CollabConToronto –November 24th–25th www.collabcon.org Use the discount code ENVISIONIT for a 10% discount
  • 54. Links •www.envisionit.com •blog.petercarson.ca •www.envisionit.com/eum •Video and presentation deck will be at www.envisionit.com/events •Customer sites www.publichealthontario.ca www.bgccan.com www.g2gmarket.com www.redcrest.com.au www.transamerica.ca suppliers.kinross.com www.problemgambling.ca