ラベル TechEd の投稿を表示しています。 すべての投稿を表示
ラベル TechEd の投稿を表示しています。 すべての投稿を表示

2011年6月7日火曜日

TechEd 2011 Japan の延期と TechEd 2011 North America の Identity 系セッションまとめ

例年であればそろそろ夏の最大イベント:TechEd の話題が出てくる頃なのですが、今年は流石にすんなりとはいかないようです。

- TechEd Japan 開催延期のお知らせ
http://www.microsoft.com/japan/teched/2011/default.aspx


とは言え、Office365の正式リリースが 6/28 に決定したり、と世間は動いているので先月(5/15-19)にアトランタで開催されていた TechEd 2011 North America のセッションから Identity 関連のセッションを抜き出してみました。
ほとんどのセッションのスライドと動画がダウンロードできるので来年前半の TechEd Japan の開催が待ちきれない人はあらかじめ資料を見ておくと良いかもしれません。

さすが本国、ということでおなじみの Vittorio や Mark Wahl もたくさんセッションを担当しています。

Impact of Cloning and Virtualization on Active Directory Domain Services
http://channel9.msdn.com/Events/TechEd/NorthAmerica/2011/SIM406

Identity & Access and Cloud: Better Together
http://channel9.msdn.com/Events/TechEd/NorthAmerica/2011/SIM205

Active Directory Federation Services 2.0 Deep Dive: Deploying a Highly Available Infrastructure
http://channel9.msdn.com/Events/TechEd/NorthAmerica/2011/SIM401

Microsoft Identity and Access Strategy
http://channel9.msdn.com/Events/TechEd/NorthAmerica/2011/SIM203

Cross-Organization Collaboration Using Microsoft SharePoint 2010 and Active Directory Federation Services 2.0
http://channel9.msdn.com/Events/TechEd/NorthAmerica/2011/SIM319

Developer's View on Single Sign-On for Applications Using Windows Azure
http://channel9.msdn.com/Events/TechEd/NorthAmerica/2011/SIM322

Using Windows Azure Access Control Service 2.0 with Your Cloud Application
http://channel9.msdn.com/Events/TechEd/NorthAmerica/2011/SIM324

Technical Overview of Microsoft Forefront Identity Manager 2010 R2
http://channel9.msdn.com/Events/TechEd/NorthAmerica/2011/SIM332

Preparing Identities for Cloud Services with Microsoft Forefront Identity Manager
http://channel9.msdn.com/Events/TechEd/NorthAmerica/2011/SIM358

Active Directory Federation Services,Part 1: How Do They Really Work?
http://channel9.msdn.com/Events/TechEd/NorthAmerica/2011/SIM402

Active Directory Federation Services,Part 2: Building Federated Identity Solutions
http://channel9.msdn.com/Events/TechEd/NorthAmerica/2011/SIM403

Optimizing Microsoft Forefront Identity Manager 2010
http://channel9.msdn.com/Events/TechEd/NorthAmerica/2011/SIM315

Using Active Directory with Microsoft Office 365
http://channel9.msdn.com/Events/TechEd/NorthAmerica/2011/SIM320

User Identity and Authentication for Desktop and Phone Applications
http://channel9.msdn.com/Events/TechEd/NorthAmerica/2011/SIM323

Deep Dive Windows Identity Foundation for Developers
http://channel9.msdn.com/Events/TechEd/NorthAmerica/2011/SIM325

2011年5月17日火曜日

WIF Extension for SAML 2.0 Protocol の CTP 版リリース

twitter の time line を見ていると北米の TechEd が盛り上がっていそうですね。AD FSや ACS 関係のアップデートなどの情報も出てくるのかどうか、、、非常に楽しみです。

さてそんな中、これまで ws-federation にだけ対応していた Windows Identity Foundation ( WIF ) の SAML 2.0 プロトコル対応版の CTP がアナウンスされました。( SAML SP-Lite に対応)

-WIF チームの blog

-おなじみ Vittorio 氏の blog


これを使えば 3rd パーティの SAML IdP にネイティブで対応する Relying Party が簡単に作れるようになるはずです。これで一部マイクロソフトの黒歴史?とのうわさもある ws-federation だけでなく 別途既に CTP リリースされている OAuth 対応版と合わせて、よりスタンダードに歩み寄る流れが加速するんでしょうか?


【参考】現状リリースされている WIF の Extension CTP
・U-Prove
・OAuth
・SAML 2.0

2010年11月24日水曜日

Office365のアイデンティティ管理

先日MVP OpenDayというクローズなイベントがあり、色々と話を聴いたのですが流石にNDAが多くblogにかけないものばかりですので、ここでは現状TechEd Europeなどで公開されている情報を。

マイクロソフトが提供するSaaSであるBPOSが次期リリースよりOffice365という名称になるのはある程度周知の事実かと思います。
提供されるサービス自体ももちろん色々とエンハンスされていますが、ここではアイデンティティ管理に関する機能に着目してみます。(ネタ元は殆どTechEd Europeです)


■Office365におけるアイデンティティ管理

まず、Office365のエディションとそのアイデンティティ管理に関する特徴を見てみます。
参考サイト:http://office365.microsoft.com/en-US/office365-beta.aspx

Office365のエディションとして提供されるのは大きく分けると
・Office365 for small business
・Office365 for enterprises
・Office365 for education
の3種類です。

また、アイデンティティ管理については以下の3つのパターンが存在します。
1.MS OnlineIDのみ
2.MS OnlineID + DirSync
3.Federated ID + DirSync














これらのうち、1番目と2番目については以前のBPOSと変わらないので新しいオプションである3番目のフェデレーション+ディレクトリ同期について見ていきますが、この機能(フェデレーション)はfor enterpriseとfor educationについてのみサポートされます。


■フェデレーションの構成
基本的には、AD FS2.0とOffice365側にあるFederation Provider(Microsoft Federation Gateway / MFG)を使ってOffice365上のアイデンティティ情報とオンプレミス(Active Directory)のアイデンティティのひも付けを行う(フェデレーション)という考え方です。
この際Office365側のアイデンティティストアとオンプレミスのアイデンティティストア(Active Directory)の情報の同期を行うのがDirSyncというツール、というわけです。
また、フェデレーションについてはブラウザを使う場合はPassiveプロファイルが使えますが、Outlook等のリッチクライアントを使う場合はActiveプロファイルでのアクセス(自らがIdPのエンドポイントをあらかじめ知っている必要がある)を行うため、初回のみService Connectorというツールのインストールが必要になります。

関連するコンポーネントをまとめると以下のようになります。
コンポーネント役割
AD FS2.0 / MFGフェデレーションを行う
DirSyncオンプレミスのアイデンティティストアとオンライン(Office365)のアイデンティティストアの情報を同期する
Service Connectorリッチクライアント(Outlook等)へのActive SSO設定を行う














ちなみにMFGは現段階ではSAML2.0をサポートしていないので、オンプレミスのフェデレーションサーバにAD FS2.0以外を持ってくる場合は注意が必要です。(AD FS2.0以外を使う構成がサポートされるかどうかはわかりませんが)

ちなみにBPOSにおいては各クライアントにサインインツールをインストールして擬似的なシングルサインオンを実現していましたが、Office365においては非推奨となっています。(継続的に使えるのかどうかは不明です)













■ディレクトリ同期ツール(DirSync)
仕組み自体はBPOSのころと変わりませんが、このツールのバージョンもVersion 2に上がっており、例えば大きいところではセキュリティグループの同期などもサポートしています。













ちなみにこのツールはILM2007をベースとして構成されているツールなのですが、今後はこのような独立したツールとしてではなく、FIM2010用の管理エージェントとしても提供される見込みです。そうなるとある程度カスタマイズの余地も出てきますし64bit環境メリットもフルに活用することが可能になると思われます。













いずれにしてもbeta版の一般公開はしばらく先の様なので、実際の動きについては継続的に情報を収集していく必要がありそうです。
とりあえずbeta利用の応募は先のサイトからも可能なので、応募はしてみました。待ち行列に入っているようですが・・・

■参考セッション(TechEd Europe)
・COS301 - Microsoft Office 365 Directory Synchronization
・COS302 - Office 365: Identity and Access Solutions

2010年11月9日火曜日

TechEd Europe 2010 の Identity系セッション

TechEd Europe 2010がが今週(11/8-12)でベルリンで開催されています。
















さすがに日本での開催とは規模が違い、多くのIdentity関連のセッションが用意されています。
少しピックアップしてみました。これからセッション資料やビデオなども公開されるようなので公開されたら見て紹介してみたいと思います。
Office365のAD FS2.0を使ったフェデレーションなんかは今後日本でもニーズが出てきそうなので要チェックかと思います。

ARC303 - Architecting Claims-Aware Applications (with the Windows Identity Foundation and Active Directory Federation Services)
Claims, Tokens and (possibly) Federation are the new ways to model authentication, access control and personalization for distributed applications. The possibilities for these technologies are vast, but there are some well-established patterns to fit typical security scenarios. These include guidelines for the usage of claims, identity providers, resource security token services, federation gateways and multi-tenancy. This talk walks you through common application architectures and illustrates how to use the Windows Identity Foundation (WIF) and Active Directory Federation Services (ADFS) to tap into the power of claims-based security

COS302 - Office 365: Identity and Access Solutions
This session provides a preview of the identity and access solutions in the next generation of the Business Productivity Online Standard Suite (Office 365). The session will focus on how authentication works for both web apps and rich client apps, how to enable single sign-on (SSO) using corporate AD credentials and AD FS 2.0 to Office 365 services, and the different SSO deployment options for Office 365 services.

OFS308 - Deploying Microsoft SharePoint Server 2010 with Claims Authentication
This session will walk you step-by-step through the process of configuring a SharePoint web application to use SAML claims and ADFS v2. It will cover some basic usage scenarios, and describe specifically how they impact sites using SAML claims and how to implement common changes in a SAML claims environment. The session will also include some basic troubleshooting steps to help you understand why users may not be able to log on to a SAML claims site

SIA203-IS - Interactive Discussion on Identity Futures with Microsoft Program Managers
What does Identity mean to you? Do you want to influence the future of Microsoft's Identity offerings? This highly interactive, discussion-based session provides a unique opportunity to share real-world requirements and understand how your priorities align with those of other TechEd attendees. Members of Microsoft's Identity and Access product team will be on hand to absorb your feedback first-hand, and to guide participants through a fast-paced discussion covering a wide range of topics

SIA301-IS - Under the Hood: What Really Happens During Critical Active Directory Operations
Come and discuss critical Active Directory-Operations. Are you fully aware what “critical” operations in AD really do? In this interactive session we will talk about those operations, understanding what they are doing and how to distinguish whether operations are critical to your environment or not. Ulf has been working in the field for more than 13 years, and has a lot of notes and examples to share. We will talk about how to approach challenges, and study scenarios that show how other companies managed the associated risks and prepared for rollbacks. We have some common scenarios for everyone but please bring your own questions as well, as we want this talk to be as interactive as possible

SIA303-LNC - Common Identity Across On-premises, Private and Public Cloud
See how Forefront Identity Manager is used to provide self-service delegated management of on-premises and private cloud datacenter resources. You will learn how Forefront Identity Manager, Active Directory Federation Services and Windows Identity Foundation are being integrated to provision users and provide access to application services in the cloud (Azure and BPOS), and also how to configure FIM to ensure that quality identity data is available to these applications, and how users can perform self-service claims management

SIA305 - Windows Identity Foundation and Windows Azure for Developers
Claims-based identity provides an open and interoperable approach to identity and access control that can be applied consistently, both on-premises and in the cloud. Come to this session to learn about how Windows Identity Foundation can be used to secure your Web Roles hosted in Windows Azure, how you can take advantage of existing on-premises identities, and how to make the best of features in our cloud offering, such as certificate management and staged environments. This is an ideal session for developers

SIA306 - A Dozen Years AD - Discuss Previous and Future Design Decisions
Active Directory has evolved over the years, along with security recommendations and best practices. But has our corporate design changed that much? Is it required? What should we change, and what should we retain? Ulf B. Simon-Weidner is a long standing, internationally recognized expert in Active Directory, and in this session he will discuss Active Directory Designs of the past, present and future

SIA311 - Deploying and Managing Forefront Identity Manager 2010
Forefront Identity Manager 2010 is a powerful product that includes many features across multiple platforms. Deploying and managing FIM requires broad domain knowledge in technologies like Active Directory, SharePoint, Exchange, SQL, Windows Communication Foundation, Workflow Foundation and ILM 2007. This session covers the basic approaches, “tips and tricks”, and common problems faced by customers. It includes best practices for managing and deploying FIM, based on the knowledge and experience of the product team and work done with Microsoft IT. This is the session for attendees who plan to deploy, configure or administer FIM

SIA313 - Cloud Security: The Practical Meaning of Security, Identity and Access Revealed!
The CLOUD is coming. But let’s face it, you must have asked yourself if it possible to hack the claims? How can we prevent this? One thing is sure: moving from on-premises applications to the cloud is like moving from a home generator to the electricity grid. We put our trust in the external identity providers, but are we really sure that all of the security issues have been addressed? We focus on the application in the cloud, but is this really the application that we need to protect? New solutions bring new possible attack vectors, and not only from the outside! Come and see what can happen when the users, or even the administrators, become the bad guys.During this intensive and extremely practical session, presenters will guide you through the threats and challenges related to the industry standard- based services delivered by ADFS v2. Only real-life scenarios! Many practical demos!

SIA316 - Exploring the Possibilities of Forefront Identity Manager 2010: Meeting Business Requirements Through Customization
Forefront Identity Manager 2010 provides a sophisticated platform for enforcing policy in an organization. Often it is necessary to extend FIM to enable some business policies, and this is your opportunity to learn about techniques for extending FIM to meet your specific business requirements. This session introduces the recommended patterns for creating custom web service clients and workflow activities, and includes code examples for each that accomplish common scenarios, such as group management and authorization workflows. The session is designed for developers who are already familiar with FIM, and plan to extend FIM.

SIA318 - Windows Identity Foundation in the Real World
Are you wondering how customers are adopting Windows Identity Foundation (WIF) in the real world? What challenges do they face? What solutions are they implementing? This session presents a series of best practices collected, and lessons learned, during the implementation of large WIF solutions in the real world. We have included a series of practical demonstrations that illustrate how to address important aspects of WIF-based solutions, such as monitoring, scalability, testing, and claim and record management, among many others. Additionally, we will present three case studies that demonstrate how customers are leveraging these solutions to facilitate the implementation of WIF in the enterprise.

SIA320 - Impact of Cloning and Virtualization on Active Directory Domain Services
Customers are looking to further virtualize their environments: file servers, web servers, DNS servers and even their domain controllers. It is clear that virtualization provides many benefits in areas such as deployment, disaster-recovery and lowering TCO. However, while virtualization offers many powerful capabilities and greatly simplifies repetitive tasks, it is a technology that must be handled with care when used in conjunction with Active Directory. In this session we will review fundamental concepts within Active Directory and the impact of cloning & virtualization upon domain controllers, domain members and Windows in general. We will also discuss how to best leverage virtualization, and how to both mitigate problems and to avoid occurrences in the first place.

SIA321 - Explore Secure Collaboration Using Identity Federation in Forefront UAG Service Pack 1
Supercharge your federation solution with Forefront UAG SP1! Learn how UAG can simplify migration to a claims-aware environment, enabling secure, seamless access to all your applications. We will cover what is new in UAG SP1 and look at secure collaboration scenarios and federation via AD FS 2.0. We will demonstrate federation with legacy applications, by translating claims to Kerberos, and enforcing authorization at the edge level

SIA402 - Active Directory Federation Services - How do they really work?
Secure applications must be able to “trust” the identity of users who are accessing the resources. It is simple to establish that trust when Active Directory Windows authentication is used. And if the application needs further identity information about the user in order to qualify its response, the additional properties can be read from the Active Directory. When the application resides outside your realm, maybe in the Cloud or within a partner organization, how do we establish trust? This is where Active Directory Federation Services (ADFS) provides a method of linking trust between disparate parties. One organization authenticates the user and creates an industry standard token that contains the Identity of the user in the form of claims. The receiving organization accepts the user’s identity and responds with the appropriate resources because of the established trust. Come to this deep dive, demo rich session and learn how to setup and leverage the true power of ADFS v2

SIA403 - How to (un)Destroy your Active Directory
As a consultant with 10 years of experience in troubleshooting ADDS and as MVP for Directory Services, I prepared an ADDS with the top 10 errors - all at the same time. During this session we will fix it step-by-step, while explaining the reason why this happened and how it can be avoided next time

2010年11月8日月曜日

PDC2010でのアイデンティティ関連セッション

少し時間が経ってしまいましたが先日のPDC2010のアイデンティティ関係のセッション(といっても一つだけでしたが)の概要を紹介したいと思います。

セッションはおなじみのVittorio Bertocciによるもので
Identity & Access Control in the Cloud
というタイトルのものです。
PDCのオフィシャルサイトで動画とスライドが公開されています。(同時通訳も公開されているので日本語でも聞くことができます。たぶん英語で聞いたほうがわかりやすいとは思いますが・・・。後、動画を見るとわかりますがタブレットでスライドにリアルタイムで絵をかきながらプレゼンを進めていたり、デモが多いのでスライドだけをダウンロードしても何もわからないと思います)

内容ですが、メインテーマは「アプリケーションをクラウドに移行するにあたって認証やアイデンティティをどうするか?」というもので、以下のステップで解説をしています。
1.オンプレミス・アプリケーションの認証
2.Windows Azure上のアプリケーションの認証
3.複数の企業が存在する場合
4.ソーシャルプロバイダで認証
5.他のアプリケーション用の認証
6.モバイルの例


それぞれを簡単に解説します。
1.オンプレミス・アプリケーションの認証
  自社内にデータセンタがあり、アプリケーションがある
  本人認証はActive Directoryを使うことによりアプリケーションから分離できる













2.Windows Azure上のアプリケーションの認証
  アプリケーションをWindows Azure上に持っていく
  STS(AD FS2.0)をDirectoryの上に乗せる=IdPとなる
  Claim-Basedという考え方が必要となる
  アプリケーション側にClaimを解釈する仕組み(Windows Identity Foundation=WIF













3.複数の企業が存在する場合
  HomeRealm Discoveryが必要になる
  →IdPのリストを表示することで対応する
  企業ごとにIdPを持っているのでトークンのフォーマットが異なる
  →中間にFederation Providerを配置し、トークンの変換を行う
   Microsoftが用意したのがAppFabric Access Control Service(ACS)である














4.ソーシャルプロバイダで認証
  Facebook、Google、WindowsLive、Yahoo!を例として取り上げる
  課題は、それぞれプロトコルが違う(facebook api,openid,live api...)ことである
  WIFのようなライブラリが個々のプロトコル(しかも頻繁に変わる)をサポートするのではなく、Federation Providerでプロトコルを変換する














5.他のアプリケーション用の認証
  OAuthの話
  ACSが呼び出し元となるFacebook上のアプリケーションにアクセストークンを渡す
  Facebook上のアプリケーションがAzure上のアプリケーションにトークンを渡すことでリソースを利用する













6.モバイルの例
  モバイル(Windows Phone7)上で動くSilverlightアプリケーションの認証をACS経由でFacebookで行い、Azure上のサービスを利用する
















尚、スライド上で出てくるデモについては今週ベルリンで開催されるTechEd Europeでさらに詳細に解説されるようです。
また、Windows Phone7でのデモについてはVittorioのblogで公開されています。



全体を通じて感じたことですが、PDCというDeveloper対象のイベントの性質上もあるのかも知れませんが、Identity Federationの訴求ポイントが「ソーシャルプロバイダとの連携機能を持つACSを使ったAzure上のアプリケーションを開発することにより、5億人もいるFacebookユーザをターゲットすることができる」というビジネスチャンスの拡大にあった点が印象的でした。













現状日本においてはIdentity FederationはあくまでIT管理者をターゲットに「いかにセキュアに自社のアプリケーションをクラウドに持っていくか」という点が訴求ポイントになっていることが多いと思われる中でこれは非常に印象が強かったポイントでした。(しかもマイクロソフトが公式に発言している点で)
日本では「クラウド上でアプリケーションを展開する」という段階のハードルをまずは超える必要があるからだと思われますが、新しいACSのリリースされるタイミングで同様の考え方も広がってくると面白いと思います。

2010年8月30日月曜日

[Silverlight+WIF+ADFS2.0] TechEd Japan 2010 BoF-09の資料公開など

先週8/25-27でTechEd Japan 2010に参加してきました。
今回は単なる聴講だけではなく、BoF (Birds of Feather) とLT (Lightning Talk) にも軽く参加させてもらいました。

LTはいずれマイクロソフトのサイトで資料公開されると思いますが、BoFについては資料は公開されないそうなので、こちらで公開しておきます。Silverlight Squareの@hr_saoさんとのコラボです。



内容を簡単に紹介しておくと、SilverlightアプリケーションからWIFを使って外部システム(ADFS2.0等)で認証を行うには、という話です。

利用シーンとして企業間のアプリケーション共有を想定しており、

・アプリケーションオーナーとなる企業から利用者となる企業のID管理をしたくない
 (これまではアプリケーションオーナーが全利用者のIDを管理していたが、本当は他の企業のユーザの管理はしたくない・・・)
 →WIF+ADFS、ADFSのIdP連携

・利用者はブラウザ特有のオペレーションではなく、もっとリッチなインターフェイスでアプリケーションを使いたい
 →Silverlightアプリケーションを使う(デモではインブラウザーを見せましたが、本当はブラウザ外実行をお見せしたかったです。今回は時間切れです。。。)

というシナリオでデモをしました。

詳細はスライドを見ていただければと思いますが、実際に環境を作る際に苦労したのはSilverlightから直接WIFを呼ぶことができないため、WCFのサービスでWIFをラッピングする仕掛けを作って、Silverlightからはそのサービスを呼び出す形にする必要があった点です。

まぁWIFの実装を含め細かい話はこの本にちょっと期待してます。



次にLTですが、資料は公開される見通しですが実はあんまり資料をベースに話をしていないので、ざっくり内容を。
テーマは「Azure上のアプリケーションへのシングルサインオン」ということでWindows Azure上にデプロイしたWIFを使ったアプリケーションとGoogle Apps (GMail)のSSOのデモと、逆にAppFabric Access Control Service (新しい方)を使ってWindows Azure上にデプロイしたWIFアプリケーションからGoogleの認証システムを使う、という2つのデモを紹介しました。
一つ目のデモはできればPCを使わずに、と思っていたのでDell StreakというAndroid OSで動く端末を使いたかったのですが、プロジェクターへの投影の関係で事前に撮影したムービーを紹介しました。

[ムービー]


一応資料も。



こちら(LT)では@tatsuakisakaiさん特別賞?として、「Windows Azureアプリケーション開発入門」をいただきました。



何にせよ非常に充実した3日間でした。
オンラインでは知っている人に初めてオフラインでお会い出来たりしましたし。

あと、BoFのセッションでもお話ししましたが今後はブラウザ外実行しているSilverlightの認証についても試してみたいので、本Blogでも情報のアップデートをしていきたいと思います。

2010年8月17日火曜日

TechEd2010 見どころセッション

いよいよTechEdが来週に迫ってきました。今年はクラウド一色と言っていいほどAzureやOnline Servicesのセッションが目白押しです。

中でもクラウド x アイデンティティ = フェデレーションということでAD FS 2.0関連のセッションは個人的には要注目だと思っています。

■AD FS 2.0関連のテクニカルセッション

8/25 15:20~16:30
T1-304 次期 Microsoft Online Services の ID およびアクセス管理 ~ AD FS 2.0 によるシングル サインオンの実現 1 ~

8/26 16:55~18:05
T3-304 AD FS 2.0 のアーキテクチャと Windows Azure 連携の実装 ~ AD FS 2.0 によるシングル サインオンの実現 2 ~


また、一つだけですがFIM関連のセッションもあります。AD FSなどのIdPの情報鮮度を保つためには重要な機能です。

■FIM関連のテクニカルセッション

8/27 16:55~18:05
T3-302 ポリシー ベースで ID 管理を実現する! ~ Forefront Identity Manager 2010 実践的構築手法 ~



後、僭越ながら私もBoF(Birds of a Feather)とLT(ライトニング・トーク)で登壇させていただきます。いずれもAD FS 2.0とWIF(Windows Identity Foundation)関連ですが、デモも交えていろいろとお見せできれば、と思っています。

■BoF (Birds of a Feather)

8/27 10:55~12:05
BOF-09 Silverlight と WIF (Windows Identity Foundation) のアプリケーション連携

Silverlightアプリケーションの認証を外部AD FS2.0で実施するにあたり WIF をどのように使うか?という点を実際のコードや環境を交えて解説したいと思います。
ポイントは IdP を2つ用意して異なる企業間での認証連携を行うところ、および意外と面倒くさいSilverlightアプリケーションの認証の解説だと思っています。

ちなみにSilverlightSquare@hr_saoさんとのコラボです。

■LT (ライトニング・トーク)

8/27 16:55~18:05
LT-03 Azure 上のアプリケーションとのシングル サインオン!

こちらは本blogでも紹介したネタ(これこれ)をベースにデモを中心に動きを解説したいと思います。
出来ればWindowsクライアントじゃない端末を使ってデモが出来れば、、と色々と画策中です。

2010年6月23日水曜日

TechEd North Americaのセッション資料

6月7日~10日に北米ニューオーリンズで開催されていたMicrosoft TechEdの資料が公開されてます。
さすがに日本とは比べ物にならないくらいのボリュームです。

とりあえずセッションの中からADFS2.0関連、FIM2010関連のものをピックアップして斜め読みをしてみました。


セッションコードタイトル概要(自分メモ)
COS206Microsoft Business Productivity Online Standard Suite (BPOS) v.Next: Identity and Access SolutionsBPOSへのFederation
・OnlineID
・OnlineID+DirSync
・FederatedID+DirSync
OSP311From N to Z: Authentication and Authorization in Microsoft SharePoint Server 2010@SPIdentity
MVP for MOSS
MOSS2010+ADFS2.0
SIA201Understanding Claims-Based Applications: An Overview of Active Directory Federation Services (AD FS) 2.0 and Windows Identity FoundationDavid Chappell
ADFS2.0+WIF+CardSpace2.0のオーバービュー
SIA302Identity and Access Management: Centralizing Application Authorization Using Active Directory Federation Services 2.0MSIT
BPOS連携などのオーバービュー
SIA303Identity and Access Management: Windows Identity Foundation and Windows AzureVittorio Bertocci
Azure上にWIFを使ったアプリケーションをデプロイする際の具体的なTIPSなど
SIA304Identity and Access Management: Windows Identity Foundation OverviewVittorio Bertocci
WIFの概要
SIA305Top 3 Security and Privacy Challenges in Identity Infrastructures and How to Overcome Them with U-Prove U-Prove
概要の説明とCTP
SIA307Identity and Access Management: Deploying Microsoft Forefront Identity Manager 2010 Certificate ManagementFIM2010 CLM
SIA318Microsoft Forefront Identity Manager 2010 Deploying FIMFIM2010のデプロイ
SIA319Forefront Identity Manager 2010: In Production本番環境におけるFIM2010の運用
SIA321Business Ready Security: Exploring the Identity and Access Management Solution Business Ready Securityのオーバービュー
SIA326Identity and Access Management: Single Sign-on Across Organizations and the Cloud - Active Directory Federation Services 2.0 Architecture DrilldownADFS2.0のデプロイ
SIA327Identity and Access Management: Managing Active Directory Using Microsoft Forefront Identity Manager FIM2010の概要



8月の日本開催のセッション予定を見ているとADFS2.0、FIM2010それぞれ1つずつという状態なので、ちょっとさみしい感じです。


とは言え濃い内容になっていることに期待!と言ったところでしょうか。