who am I?
Dan
Usher

#bb
what about this guy?

#ct
about you
housekeeping
• Phones silenced, phasers set to stun
• Ask questions
• Please remember to turn in your filled out
bingo cards and event evaluations for prizes.
• SharePint is sponsored by Slalom at Whiskey
Trader (Between 55th and 56th on 6th Avenue).
• Follow SharePoint Saturday New York City on
Twitter @spsnyc and hashtag #spsnyc
• Do not feed Scott donuts…
#bb
#bb
Security
http://xkcd.com/1240/

#ct
#ct
#bb
#ct
#bb
#bb
#ct
• The act of authorizing.
• Permission or power granted by an authority;
•
•
•
•

sanction.
To give authority or official power to.
To give authority for; formally sanction (an act
or proceeding).
To establish by authority or usage.
Sometimes we call it AuthZ.

#ct
#ct
#bb
#bb
#bb
http://go.spdan.com/cba

#bb
#ct
#ct
#bb
#ct

http://go.spdan.com/claimsencoding
#bb

Source: http://go.spdan.com/iisauth

ASP.NET Authentication
Identity Provider
Security Token Service
aka IP-STS

1.
2.
3.
4.
5.
6.
7.
8.

SharePoint 2010
aka RP

Resource Requested
AuthN Request / Redirect
AuthN Request
Security Token
Security Token Request
Service Token
Resource Request w/Service Token
Resource Sent

#bb
#bb
#ct
#ct
#ct
#ct
#bb
#bb
#bb
https://sts.domain.com

#ct
#ct
#bb
#bb
#bb
Web Application / Site Collection
Secured Site / Site Collection / Content

Anonymous

Authentication

Content Repository
Is In Site Group?
Content

Does user have claim attribute?

#ct
#ct
Real World
#bb
#ct
Usher_Daniel@bah.com
@binarybrewery
www.sharepointdan.com

scott.hoag@appliedis.com
@ciphertxt
http://psconfig.com

SPSNYC - Authentication, Authorization, and Identity – More than meets the eye…