SlideShare a Scribd company logo
Binh Thanh Nguyen
Solutions Architect and Project Manager
Bamboo Solutions Corporation Vietnam
• Identity and Identity Providers
• Authentication and Authorization
• Identity challenges in SharePoint 2007
• Claims-Based Identity
• Claims-Based Authentication in
  Microsoft SharePoint 2010
• Demo
• Q&A
• What is Identity?
  – A set of attributes to describe a user
• What is Identity Providers?
  – Composed of attributes/identifiers
• Examples:
  – Active Directory, Directory Services
• What is Authentication (AuthN)?
  – Authentication is the process of
    identification and validation of a
    user's identity
• What is Authorization (AuthZ)?
  – Determines whether that identity
    has access to a particular resource
    such as sites, content, and other
    features the user can access.
• Authentication is intertwined within
  SharePoint 2007
• Very Complex in doing the
  configuration
• Access control only through
  attribute providers

So… What is the SOLUTIONS ???
• What is Claims?    Issuer: Police
                     Dept.
                                      Issuer: VN
                                      Railway
  – Information      Full Name        Name

    about the user   ID Number        Frequent flyer
                                      number
    … such as Full   Address          Train number

    name, e-mail,    Regional         Bus

    age, group,      Date of birth    Seat number

    etc.
                     Date of issue    Date of issue
                     Sex

                     Picture
Request ID Card


        ID Card
                  Trust




      ID Card

       Ticket


      Ticket
• The service component that builds, signs,
  and issues security tokens.
• Supports multiple credential types
• Identity Provider STS (IP-STS) and a Relying
  Party STS(RP-STS).
   – An IP-STS is an STS that issues tokens that
     can be used to request service tokens
     from RP-STSs.
   – An RP-STS can also consume other types of
     tokens (or credentials), for example an NT
     token that comes from the domain
     controller or the (KDC)
• STSs can be chained
• SharePoint STS is always relying party STS
  Built on Windows Identity Foundation
  (WIF)
• Multiple authentication types
• Identity Provider neutral
   – Configured via Central Admin or
     PowerShell
• Delegation of user identity between
  applications.
Send Cookie
 Send token
 Issue token
Send token
Issue token
 Authenticate
Browser                         Issuer
           Get /                         Active Directory

           302
                    AuthN

                   SAML Token

    Post
                        Process Token
          Cookie

      Cookie

           302          Process Claims
-Classic   -Claims
• Support existing identity infrastructure
   – Active Directory
   – LDAP, SQL
   – WebSSO and Identity Management Systems
• Multiple authentication methods per
  SharePoint Web Application
• Enable automatic, secure identity delegation
   – Cross-machines & cross-farm
• Support “no-credential” connections to
  External web services
• Standards-based and Interoperable
Configure claims-based authentication
       using Windows Live ID
• MSDN and Technet:
  – http://technet.microsoft.com/en-
    us/library/ff973117.aspx#section3
  – http://blogs.technet.com/b/ritaylor/archive/20
    09/06/03/claims-based-authentication-an-
    overview.aspx
  – http://technet.microsoft.com/en-
    us/sharepoint/ff678022.aspx#lesson2
  – http://blogs.msdn.com/b/russmax/archive/201
    0/05/27/understanding-sharepoint-2010-
    claims-authentication.aspx
• Microsoft PDC:
  – http://www.microsoftpdc.com/2009/SVC26
THANK YOU!

More Related Content

Viewers also liked

All about Ribbon in SharePoint 2010 - SharePoint Saturday Vietnam
All about Ribbon in SharePoint 2010 - SharePoint Saturday VietnamAll about Ribbon in SharePoint 2010 - SharePoint Saturday Vietnam
All about Ribbon in SharePoint 2010 - SharePoint Saturday Vietnam
Officience
 
Evaluation question 1
Evaluation question 1 Evaluation question 1
Evaluation question 1
Rebeccahartx
 
Olimpiade Biologi Pengamatan Mikroskopis
Olimpiade Biologi Pengamatan MikroskopisOlimpiade Biologi Pengamatan Mikroskopis
Olimpiade Biologi Pengamatan Mikroskopis
Rohmad Joni Pranoto
 
Test shot analysis
Test shot analysis Test shot analysis
Test shot analysis
Rebeccahartx
 
Oh my Gov
Oh my GovOh my Gov
Oh my Gov
EGOV
 
Soal latihan UTS Praktikum Keanekaragaman Tumbuhan
Soal latihan UTS Praktikum Keanekaragaman TumbuhanSoal latihan UTS Praktikum Keanekaragaman Tumbuhan
Soal latihan UTS Praktikum Keanekaragaman Tumbuhan
Rohmad Joni Pranoto
 
Program wanamina indonesia
Program wanamina indonesiaProgram wanamina indonesia
Program wanamina indonesia
Rohmad Joni Pranoto
 
Toksisitas Makanan/Food Toxicity
Toksisitas Makanan/Food ToxicityToksisitas Makanan/Food Toxicity
Toksisitas Makanan/Food Toxicity
Rohmad Joni Pranoto
 
Hálozatok
HálozatokHálozatok
Hálozatok
Róbert Moór
 
Photoshoot analysis
Photoshoot analysisPhotoshoot analysis
Photoshoot analysis
Rebeccahartx
 
Presentazione premio egov su tecnologia in pa
Presentazione premio egov su tecnologia in paPresentazione premio egov su tecnologia in pa
Presentazione premio egov su tecnologia in paEGOV
 
Vector
VectorVector
Digitális óravázlat
Digitális óravázlatDigitális óravázlat
Digitális óravázlat
Róbert Moór
 
Lotus Notes to SharePoint Migration
Lotus Notes to SharePoint MigrationLotus Notes to SharePoint Migration
Lotus Notes to SharePoint Migration
Officience
 

Viewers also liked (14)

All about Ribbon in SharePoint 2010 - SharePoint Saturday Vietnam
All about Ribbon in SharePoint 2010 - SharePoint Saturday VietnamAll about Ribbon in SharePoint 2010 - SharePoint Saturday Vietnam
All about Ribbon in SharePoint 2010 - SharePoint Saturday Vietnam
 
Evaluation question 1
Evaluation question 1 Evaluation question 1
Evaluation question 1
 
Olimpiade Biologi Pengamatan Mikroskopis
Olimpiade Biologi Pengamatan MikroskopisOlimpiade Biologi Pengamatan Mikroskopis
Olimpiade Biologi Pengamatan Mikroskopis
 
Test shot analysis
Test shot analysis Test shot analysis
Test shot analysis
 
Oh my Gov
Oh my GovOh my Gov
Oh my Gov
 
Soal latihan UTS Praktikum Keanekaragaman Tumbuhan
Soal latihan UTS Praktikum Keanekaragaman TumbuhanSoal latihan UTS Praktikum Keanekaragaman Tumbuhan
Soal latihan UTS Praktikum Keanekaragaman Tumbuhan
 
Program wanamina indonesia
Program wanamina indonesiaProgram wanamina indonesia
Program wanamina indonesia
 
Toksisitas Makanan/Food Toxicity
Toksisitas Makanan/Food ToxicityToksisitas Makanan/Food Toxicity
Toksisitas Makanan/Food Toxicity
 
Hálozatok
HálozatokHálozatok
Hálozatok
 
Photoshoot analysis
Photoshoot analysisPhotoshoot analysis
Photoshoot analysis
 
Presentazione premio egov su tecnologia in pa
Presentazione premio egov su tecnologia in paPresentazione premio egov su tecnologia in pa
Presentazione premio egov su tecnologia in pa
 
Vector
VectorVector
Vector
 
Digitális óravázlat
Digitális óravázlatDigitális óravázlat
Digitális óravázlat
 
Lotus Notes to SharePoint Migration
Lotus Notes to SharePoint MigrationLotus Notes to SharePoint Migration
Lotus Notes to SharePoint Migration
 

Similar to Introduction to claims based authentication in share point 2010

Claim Based Authentication in SharePoint 2010 for Community Day 2011
Claim Based Authentication in SharePoint 2010 for Community Day 2011Claim Based Authentication in SharePoint 2010 for Community Day 2011
Claim Based Authentication in SharePoint 2010 for Community Day 2011
Joris Poelmans
 
SharePoint, ADFS and Claims Auth
SharePoint, ADFS and Claims AuthSharePoint, ADFS and Claims Auth
SharePoint, ADFS and Claims Auth
Kashif Imran
 
Envision it SharePoint Extranet Webinar Series - Federation and SharePoint On...
Envision it SharePoint Extranet Webinar Series - Federation and SharePoint On...Envision it SharePoint Extranet Webinar Series - Federation and SharePoint On...
Envision it SharePoint Extranet Webinar Series - Federation and SharePoint On...
Envision IT
 
SPSBE 2013 Claims for devs
SPSBE 2013 Claims for devsSPSBE 2013 Claims for devs
SPSBE 2013 Claims for devs
Steven Van de Craen
 
SharePoint Saturday Utah - Do you claim to be from the Azure Sky?
SharePoint Saturday Utah - Do you claim to be from the Azure Sky?SharePoint Saturday Utah - Do you claim to be from the Azure Sky?
SharePoint Saturday Utah - Do you claim to be from the Azure Sky?
Liam Cleary [MVP]
 
SharePointFest 2013 Washington DC - SPT 103 - SharePoint 2013 Extranets: How ...
SharePointFest 2013 Washington DC - SPT 103 - SharePoint 2013 Extranets: How ...SharePointFest 2013 Washington DC - SPT 103 - SharePoint 2013 Extranets: How ...
SharePointFest 2013 Washington DC - SPT 103 - SharePoint 2013 Extranets: How ...
Brian Culver
 
SharePoint Saturday The Conference DC - Are you who you say you are share poi...
SharePoint Saturday The Conference DC - Are you who you say you are share poi...SharePoint Saturday The Conference DC - Are you who you say you are share poi...
SharePoint Saturday The Conference DC - Are you who you say you are share poi...
Liam Cleary [MVP]
 
Federated and fabulous identity
Federated and fabulous identityFederated and fabulous identity
Federated and fabulous identity
Andre N. Klingsheim
 
Understanding SharePoint Apps, authentication and authorization infrastructur...
Understanding SharePoint Apps, authentication and authorization infrastructur...Understanding SharePoint Apps, authentication and authorization infrastructur...
Understanding SharePoint Apps, authentication and authorization infrastructur...
SPC Adriatics
 
SharePoint Saturday Austin - Share point authentication and authorization
SharePoint Saturday Austin - Share point authentication and authorizationSharePoint Saturday Austin - Share point authentication and authorization
SharePoint Saturday Austin - Share point authentication and authorization
Liam Cleary [MVP]
 
SharePoint 2010, Claims-Based Identity, Facebook, and the Cloud
SharePoint 2010, Claims-Based Identity, Facebook, and the CloudSharePoint 2010, Claims-Based Identity, Facebook, and the Cloud
SharePoint 2010, Claims-Based Identity, Facebook, and the Cloud
Danny Jessee
 
Claims Based Authentication in SharePoint 2010
Claims Based Authentication in SharePoint 2010Claims Based Authentication in SharePoint 2010
Claims Based Authentication in SharePoint 2010
Jonathan Schultz
 
SharePoint 2010, Claims-Based Identity, Facebook, and the Cloud
SharePoint 2010, Claims-Based Identity, Facebook, and the CloudSharePoint 2010, Claims-Based Identity, Facebook, and the Cloud
SharePoint 2010, Claims-Based Identity, Facebook, and the Cloud
Danny Jessee
 
NIC 2014 Modern Authentication for the Cloud Era
NIC 2014 Modern Authentication for the Cloud EraNIC 2014 Modern Authentication for the Cloud Era
NIC 2014 Modern Authentication for the Cloud Era
Morgan Simonsen
 
Presentation
PresentationPresentation
Presentation
Laxman Kumar
 
The Who, What, Why and How of Active Directory Federation Services (AD FS)
The Who, What, Why and How of Active Directory Federation Services (AD FS)The Who, What, Why and How of Active Directory Federation Services (AD FS)
The Who, What, Why and How of Active Directory Federation Services (AD FS)
Jay Simcox
 
Claims-Based Identity in SharePoint 2010
Claims-Based Identity in SharePoint 2010Claims-Based Identity in SharePoint 2010
Claims-Based Identity in SharePoint 2010
Danny Jessee
 
Claims-Based Identity, Facebook, and the Cloud
Claims-Based Identity, Facebook, and the CloudClaims-Based Identity, Facebook, and the Cloud
Claims-Based Identity, Facebook, and the Cloud
Danny Jessee
 
SharePoint 2010, Claims-Based Identity, Facebook, and the Cloud
SharePoint 2010, Claims-Based Identity, Facebook, and the CloudSharePoint 2010, Claims-Based Identity, Facebook, and the Cloud
SharePoint 2010, Claims-Based Identity, Facebook, and the Cloud
Danny Jessee
 
Early Adopting Java WSIT-Experiences with Windows CardSpace
Early Adopting Java WSIT-Experiences with Windows CardSpaceEarly Adopting Java WSIT-Experiences with Windows CardSpace
Early Adopting Java WSIT-Experiences with Windows CardSpace
Oliver Pfaff
 

Similar to Introduction to claims based authentication in share point 2010 (20)

Claim Based Authentication in SharePoint 2010 for Community Day 2011
Claim Based Authentication in SharePoint 2010 for Community Day 2011Claim Based Authentication in SharePoint 2010 for Community Day 2011
Claim Based Authentication in SharePoint 2010 for Community Day 2011
 
SharePoint, ADFS and Claims Auth
SharePoint, ADFS and Claims AuthSharePoint, ADFS and Claims Auth
SharePoint, ADFS and Claims Auth
 
Envision it SharePoint Extranet Webinar Series - Federation and SharePoint On...
Envision it SharePoint Extranet Webinar Series - Federation and SharePoint On...Envision it SharePoint Extranet Webinar Series - Federation and SharePoint On...
Envision it SharePoint Extranet Webinar Series - Federation and SharePoint On...
 
SPSBE 2013 Claims for devs
SPSBE 2013 Claims for devsSPSBE 2013 Claims for devs
SPSBE 2013 Claims for devs
 
SharePoint Saturday Utah - Do you claim to be from the Azure Sky?
SharePoint Saturday Utah - Do you claim to be from the Azure Sky?SharePoint Saturday Utah - Do you claim to be from the Azure Sky?
SharePoint Saturday Utah - Do you claim to be from the Azure Sky?
 
SharePointFest 2013 Washington DC - SPT 103 - SharePoint 2013 Extranets: How ...
SharePointFest 2013 Washington DC - SPT 103 - SharePoint 2013 Extranets: How ...SharePointFest 2013 Washington DC - SPT 103 - SharePoint 2013 Extranets: How ...
SharePointFest 2013 Washington DC - SPT 103 - SharePoint 2013 Extranets: How ...
 
SharePoint Saturday The Conference DC - Are you who you say you are share poi...
SharePoint Saturday The Conference DC - Are you who you say you are share poi...SharePoint Saturday The Conference DC - Are you who you say you are share poi...
SharePoint Saturday The Conference DC - Are you who you say you are share poi...
 
Federated and fabulous identity
Federated and fabulous identityFederated and fabulous identity
Federated and fabulous identity
 
Understanding SharePoint Apps, authentication and authorization infrastructur...
Understanding SharePoint Apps, authentication and authorization infrastructur...Understanding SharePoint Apps, authentication and authorization infrastructur...
Understanding SharePoint Apps, authentication and authorization infrastructur...
 
SharePoint Saturday Austin - Share point authentication and authorization
SharePoint Saturday Austin - Share point authentication and authorizationSharePoint Saturday Austin - Share point authentication and authorization
SharePoint Saturday Austin - Share point authentication and authorization
 
SharePoint 2010, Claims-Based Identity, Facebook, and the Cloud
SharePoint 2010, Claims-Based Identity, Facebook, and the CloudSharePoint 2010, Claims-Based Identity, Facebook, and the Cloud
SharePoint 2010, Claims-Based Identity, Facebook, and the Cloud
 
Claims Based Authentication in SharePoint 2010
Claims Based Authentication in SharePoint 2010Claims Based Authentication in SharePoint 2010
Claims Based Authentication in SharePoint 2010
 
SharePoint 2010, Claims-Based Identity, Facebook, and the Cloud
SharePoint 2010, Claims-Based Identity, Facebook, and the CloudSharePoint 2010, Claims-Based Identity, Facebook, and the Cloud
SharePoint 2010, Claims-Based Identity, Facebook, and the Cloud
 
NIC 2014 Modern Authentication for the Cloud Era
NIC 2014 Modern Authentication for the Cloud EraNIC 2014 Modern Authentication for the Cloud Era
NIC 2014 Modern Authentication for the Cloud Era
 
Presentation
PresentationPresentation
Presentation
 
The Who, What, Why and How of Active Directory Federation Services (AD FS)
The Who, What, Why and How of Active Directory Federation Services (AD FS)The Who, What, Why and How of Active Directory Federation Services (AD FS)
The Who, What, Why and How of Active Directory Federation Services (AD FS)
 
Claims-Based Identity in SharePoint 2010
Claims-Based Identity in SharePoint 2010Claims-Based Identity in SharePoint 2010
Claims-Based Identity in SharePoint 2010
 
Claims-Based Identity, Facebook, and the Cloud
Claims-Based Identity, Facebook, and the CloudClaims-Based Identity, Facebook, and the Cloud
Claims-Based Identity, Facebook, and the Cloud
 
SharePoint 2010, Claims-Based Identity, Facebook, and the Cloud
SharePoint 2010, Claims-Based Identity, Facebook, and the CloudSharePoint 2010, Claims-Based Identity, Facebook, and the Cloud
SharePoint 2010, Claims-Based Identity, Facebook, and the Cloud
 
Early Adopting Java WSIT-Experiences with Windows CardSpace
Early Adopting Java WSIT-Experiences with Windows CardSpaceEarly Adopting Java WSIT-Experiences with Windows CardSpace
Early Adopting Java WSIT-Experiences with Windows CardSpace
 

Introduction to claims based authentication in share point 2010

  • 1.
  • 2. Binh Thanh Nguyen Solutions Architect and Project Manager Bamboo Solutions Corporation Vietnam
  • 3. • Identity and Identity Providers • Authentication and Authorization • Identity challenges in SharePoint 2007 • Claims-Based Identity • Claims-Based Authentication in Microsoft SharePoint 2010 • Demo • Q&A
  • 4.
  • 5. • What is Identity? – A set of attributes to describe a user
  • 6. • What is Identity Providers? – Composed of attributes/identifiers • Examples: – Active Directory, Directory Services
  • 7.
  • 8. • What is Authentication (AuthN)? – Authentication is the process of identification and validation of a user's identity • What is Authorization (AuthZ)? – Determines whether that identity has access to a particular resource such as sites, content, and other features the user can access.
  • 9.
  • 10. • Authentication is intertwined within SharePoint 2007 • Very Complex in doing the configuration • Access control only through attribute providers So… What is the SOLUTIONS ???
  • 11.
  • 12. • What is Claims? Issuer: Police Dept. Issuer: VN Railway – Information Full Name Name about the user ID Number Frequent flyer number … such as Full Address Train number name, e-mail, Regional Bus age, group, Date of birth Seat number etc. Date of issue Date of issue Sex Picture
  • 13. Request ID Card ID Card Trust ID Card Ticket Ticket
  • 14.
  • 15. • The service component that builds, signs, and issues security tokens. • Supports multiple credential types • Identity Provider STS (IP-STS) and a Relying Party STS(RP-STS). – An IP-STS is an STS that issues tokens that can be used to request service tokens from RP-STSs. – An RP-STS can also consume other types of tokens (or credentials), for example an NT token that comes from the domain controller or the (KDC) • STSs can be chained
  • 16. • SharePoint STS is always relying party STS Built on Windows Identity Foundation (WIF) • Multiple authentication types • Identity Provider neutral – Configured via Central Admin or PowerShell • Delegation of user identity between applications.
  • 17. Send Cookie Send token Issue token Send token Issue token Authenticate
  • 18. Browser Issuer Get / Active Directory 302 AuthN SAML Token Post Process Token Cookie Cookie 302 Process Claims
  • 19. -Classic -Claims
  • 20.
  • 21. • Support existing identity infrastructure – Active Directory – LDAP, SQL – WebSSO and Identity Management Systems • Multiple authentication methods per SharePoint Web Application • Enable automatic, secure identity delegation – Cross-machines & cross-farm • Support “no-credential” connections to External web services • Standards-based and Interoperable
  • 22. Configure claims-based authentication using Windows Live ID
  • 23.
  • 24. • MSDN and Technet: – http://technet.microsoft.com/en- us/library/ff973117.aspx#section3 – http://blogs.technet.com/b/ritaylor/archive/20 09/06/03/claims-based-authentication-an- overview.aspx – http://technet.microsoft.com/en- us/sharepoint/ff678022.aspx#lesson2 – http://blogs.msdn.com/b/russmax/archive/201 0/05/27/understanding-sharepoint-2010- claims-authentication.aspx • Microsoft PDC: – http://www.microsoftpdc.com/2009/SVC26