SPS Philly
Platinum
Gold
Silver Web
SharePointUser Group
• SharePoint
• End Users
• Administrators
• Architects
• Developers
• IT Pros
• Meetings: 2nd Tuesday of the month, MicrosoftMalvern, 5:30-8 pm
WEB: www.TriStateSharePoint.org
EMAIL: info@TriStateSharePoint.org
TWITTER: @tristateSP
Dan Usher
Lead Associate
Booz Allen Hamilton
usher_daniel@bah.com
http://www.sharepointdan.com
http://www.yammer.com/spyam
http://go.spdan.com/kerberos2010
http://go.spdan.com/kerberos2013
http://go.spdan.com/multihopwinrm
http://xkcd.com/1240/
Security in General
Security in General
Anonymous
Authentication
Is In Site Group?
Does user have claim attribute?
Web Application / Site Collection
Secured Site / Site Collection / Content
Content Repository
Content
Source:http://go.spdan.com/iisauth
ASP.NETAuthentication
•
•
•
•
•
•
http://go.spdan.com/cba
http://go.spdan.com/cba
http://go.spdan.com/claimsencoding
http://go.spdan.com/claimsencoding
1. Resource Requested
2. AuthN Request / Redirect
3. AuthN Request
4. Security Token
5. Security Token Request
6. Service Token
7. Resource Request w/Service Token
8. Resource Sent
Identity Provider
Security Token Service
aka IP-STS
SharePoint 2010
aka RP
https://sts.domain.com
•
•
•
•
•
•
Usher_Daniel@bah.com
@binarybrewery
www.sharepointdan.com

2014-04-05 - SPSPhilly - Authentication and Authorization