SlideShare a Scribd company logo
1 of 39
Download to read offline
© Strata Identity Inc. 2019. All Rights Reserved. Patents Pending.© Strata Identity Inc. 2019. All Rights Reserved. Patents Pending.
Eric Leach
Chief Product Officer
Strata Identity, Inc.
Strata
Migrating and
Modernizing Identity
on the Path to Multi
Cloud
© Strata Identity Inc. 2019. All Rights Reserved. Patents Pending.
2
Redefining Identity For Multi Cloud World
ABOUT STRATA
Strata is an identity management services
provider focused on modernizing and migrating
identity to multi cloud and hybrid.
Our team has more than 110 years of combined
identity experience from Oracle, Salesforce,
Securant, Symplified, Ping, Auth0, JumpCloud,
PWC, and Thor.
Strata Identity
Eric Leach
CPO & Cofounder
• Eric brings 20+ years of experience developing and
delivering innovative solutions for identity
management.
• Most recently Eric was VP Product Management of
Oracle’s global identity portfolio.
• Eric built Salesforce’s Shield data security product
into a $500M business.
• Eric got his start in identity at Sun, where he
delivered the industry’s first commercial opensource
identity product, OpenSSO.
Intro
© Strata Identity Inc. 2019. All Rights Reserved. Patents Pending.
3
Agenda
1. What’s Going on with Identity?
2. What We Learned
3. Why Modernize?
4. Lift and Shift or Move and Improve?
5. Becoming Cloud Native
6. Identity for Multi Cloud
7. Extending Cloud Native Identity to Hybrid
8. Putting it all Together
© Strata Identity Inc. 2019. All Rights Reserved. Patents Pending.
4
What’s Going on with Identity?
© Strata Identity Inc. 2019. All Rights Reserved. Patents Pending.
5
A Hypothesis: customers are staring down three
IAM challenges
1. Moving to the cloud requires
modern identity systems.
2. Customers are universally
adopting multiple clouds.
3. Legacy IAM systems are aging
out and reaching end of life.
© Strata Identity Inc. 2019. All Rights Reserved. Patents Pending.
6
Using Lean Customer Development
To validate or disprove a hypothesis, you must first understand:
• Who are your customers
• What problems they are facing
• What are their current behaviors
Test your hypotheses by setting aside preconceived ideas and asking
simple, open-ended questions and then listening quietly and patiently.
© Strata Identity Inc. 2019. All Rights Reserved. Patents Pending.
7
We Asked Questions Like…
Q: Who owns identity in your enterprise?
A: The team in IT that traditionally owned IAM
B: The team(s) responsible for managing our cloud platform(s)
C: The business owner(s) that fund our SaaS app(s)
D: All three
E: I don’t know
© Strata Identity Inc. 2019. All Rights Reserved. Patents Pending.
8
We Asked Questions Like…
Q: Who owns identity in your enterprise?
A: The team in IT that traditionally owned IAM 65%
B: The team(s) responsible for managing our cloud platform(s) 9%
C: The business owner(s) that fund our SaaS app(s) 0%
D: All three 27%
E: I don’t know 0%
© Strata Identity Inc. 2019. All Rights Reserved. Patents Pending.
9
Using Lean Customer Development
Full disclosure: these are our practices, not our ideas.
Shout out to Cindy Alvarez. You should read her book.
https://www.cindyalvarez.com/lean-customer-development/
© Strata Identity Inc. 2019. All Rights Reserved. Patents Pending.
10
What We Learned
© Strata Identity Inc. 2019. All Rights Reserved. Patents Pending.
11
Most enterprises have
3+ cloud IaaS platforms
Most have private and
public clouds
Digital transformation is
driving this shift
SAML is focused on SSO
and Authentication
Identity data still needs
to be synchronized
No Identity Metadata
No Identity Lifecycle
No IGA
Need to deploy CSP
identity to use IaaS
platform, or SaaS App
(Office 365)
No visibility across silos
Fragmented across
clouds and across stack
Politics
Security
Economics
Migration Costs
M&A Integration
End of life 2020
Expertise hard to find
Compliance issues
Not compatible with
cloud native
architecture
SAML and
Federated
SSO Doesn’t
Address
Identity Data
Centralizing
Identities Is
Impossible
Legacy
Identity
Software is
Reaching
End of Life
Identity Silos
Are
Propagating
Multiple Clouds
Drives Multiple
Identity
Challenges
A Pattern of Recurring Pain Points
© Strata Identity Inc. 2019. All Rights Reserved. Patents Pending.
12
Migration and Modernization Use Cases
Move on premises legacy IAM to run on public cloud
IaaS. Retire on premises infrastructure. Low risk but
limited benefits.
Lift and Shift
Move and Improve
Start the process of adopting some cloud native
identity services. Identify so-called strangler patterns
to retire legacy products and/or features.
Hybrid SSO
Extend IDaaS to on premises apps, migrate users,
configurations, and policies from legacy IAM to cloud
and associated on premises gateways.
Cloud Native Identity Services
Begin adopting built in cloud native identity services.
Map to native architecture patterns, tools, and
modern DevOps practices.
Multi Cloud Identity
Define and apply basic patterns for identity services
across multiple public and private cloud platforms.
Establish clear ownership of shared responsibilities.
© Strata Identity Inc. 2019. All Rights Reserved. Patents Pending.
13
Hybrid Multiple Directories Multiple Policies
OAuth, OIDC, JWT
SCIM, Cookie Based,
HTTP Headers
On-Prem Reverse Proxy Yes
Multi Cloud Multiple Directories Multiple Policies
OAuth, OIDC, JWT
SCIM, SAML
Cloud Proxies Yes
Cloud Native Cloud Directory CSP / IDaaS
OAuth, OIDC, JWT
SCIM, SAML
Cloud Proxy Yes
Move & Improve Simple AD AWS Cognito
OAuth, OIDC, JWT
SCIM, Cookie Based, HTTP
Headers
Cloud Proxy Yes
Lift & Shift Active Directory SiteMinder Cookies & Header Agents or Proxy No
Baseline Active Directory SiteMinder Cookies & Header Agents or Proxy No
Identities Policies Sessions
Integration &
Enforcement
DevOps
A Cloud Identity Maturity Model
© Strata Identity Inc. 2019. All Rights Reserved. Patents Pending.
14
Why Modernize
© Strata Identity Inc. 2019. All Rights Reserved. Patents Pending.
15
Legacy Identity Characteristics vs Cloud Requirements
Legacy IAM Cloud
Deployment Model
• Pre-deployed servers for peak capacity
• Bare OS, some virtualization
• Individually edited config files
• Autoscaling
• Containers and orchestrators
• Declarative, immutable configuration
Integration Model
• Static agents for web, Java, .Net apps
• Proprietary APIs
• Proprietary cookies or HTTP Headers
• Sidecars and Nginx proxies
• Opensource tools and documented APIs
• Standards based tokens
User Model
• Single, consolidated user directory
• Distributed directories per cloud
Policy Model
• Static policy evaluation
• Custom deployed MFA
• Adaptive authentication and authorization
• Strong authentication by default
© Strata Identity Inc. 2019. All Rights Reserved. Patents Pending.
16
How Identity Is Delivered
To Apps In Legacy
Deployments
© Strata Identity Inc. 2019. All Rights Reserved. Patents Pending.
17
Benefits of Identity Migration and Modernization
Become Cloud Native Save Money Get More Done Faster
Break Lock-In Future Proof Investments Leap To The Cloud
• Adopt cloud native architectures with
an identity capability to match.
• Move to the cloud while extending your
existing identity and policies.
• Focus on digital transformation and
don’t worry about infrastructure.
• Migrating off old technology will save
you operational costs, legacy licensing &
maintenance costs, and infrastructure
expense.
• Automated migration saves you time
and money.
• Look for ways to turn migrations from
complex, multi-quarter initiatives into
quick software powered projects. Knock
off your migration tasks quickly.
• Consider externally sourcing experts so
you don’t have to find and hire rare
talent.
• API abstraction layers give you the
freedom to use the identity system of
your choice.
• Replicate identities, policies,
configurations across platforms.
• Leverage your existing investments in
the cloud through hybrid configurations.
• Extend value-producing apps and
systems to the cloud.
• Sync identities and policies to keep your
hybrid environments orchestrated.
• Determine whether you can make the
jump straight to cloud native.
• Use an incremental migration approach
or move everything straight to a cloud
native design.
© Strata Identity Inc. 2019. All Rights Reserved. Patents Pending.
18
Lift & Shift or Move & Improve
© Strata Identity Inc. 2019. All Rights Reserved. Patents Pending.
19
Migration and Modernization Use Cases
Move on premises legacy IAM to run on public cloud
IaaS. Retire on premises infrastructure. Low risk but
limited benefits.
Lift and Shift
Move and Improve
Start the process of adopting some cloud native
identity services. Identify so-called strangler patterns
to retire legacy products and/or features.
Hybrid SSO
Extend IDaaS to on premises apps, migrate users,
configurations, and policies from legacy IAM to cloud
and associated on premises gateways.
Cloud Native Identity Services
Begin adopting built in cloud native identity services.
Map to native architecture patterns, tools, and
modern DevOps practices.
Multi Cloud Identity
Define and apply basic patterns for identity services
across multiple public and private cloud platforms.
Establish clear ownership of shared responsibilities.
© Strata Identity Inc. 2019. All Rights Reserved. Patents Pending.
20
Virtualized Infrastructure
moves from on-premises
deployment to IaaS
service like AWS EC2,
GCP, Azure VM.
Lift and Shift:
Identity and Apps
to IaaS
© Strata Identity Inc. 2019. All Rights Reserved. Patents Pending.
21
Replace some
elements of
Infrastructure with
IaaS-provided services
like AWS Cognito,
Google Cloud Identity
and Azure AD.
Move and Improve:
Adopting Cloud
Native Identity
Services
© Strata Identity Inc. 2019. All Rights Reserved. Patents Pending.
22
Becoming Cloud Native
© Strata Identity Inc. 2019. All Rights Reserved. Patents Pending.
23
Migration and Modernization Use Cases
Move on premises legacy IAM to run on public cloud
IaaS. Retire on premises infrastructure. Low risk but
limited benefits.
Lift and Shift
Move and Improve
Start the process of adopting some cloud native
identity services. Identify so-called strangler patterns
to retire legacy products and/or features.
Hybrid SSO
Extend IDaaS to on premises apps, migrate users,
configurations, and policies from legacy IAM to cloud
and associated on premises gateways.
Cloud Native Identity Services
Begin adopting built in cloud native identity services.
Map to cloud native architecture patterns, tools, and
modern DevOps practices.
Multi Cloud Identity
Define and apply basic patterns for identity services
across multiple public and private cloud platforms.
Establish clear ownership of shared responsibilities.
© Strata Identity Inc. 2019. All Rights Reserved. Patents Pending.
24
Cloud Native
Identity and Apps
Implement a cloud native
containerized microservices
platform with native identity
microservices provided by cloud
service providers.
© Strata Identity Inc. 2019. All Rights Reserved. Patents Pending.
25
Identity for Multi Cloud
© Strata Identity Inc. 2019. All Rights Reserved. Patents Pending.
26
Migration and Modernization Use Cases
Move on premises legacy IAM to run on public cloud
IaaS. Retire on premises infrastructure. Low risk but
limited benefits.
Lift and Shift
Move and Improve
Start the process of adopting some cloud native
identity services. Identify so-called strangler patterns
to retire legacy products and/or features.
Hybrid SSO
Extend IDaaS to on premises apps, migrate users,
configurations, and policies from legacy IAM to cloud
and associated on premises gateways.
Cloud Native Identity Services
Begin adopting built in cloud native identity services.
Map to native architecture patterns, tools, and
modern DevOps practices.
Multi Cloud Identity
Define and apply basic patterns for identity services
across multiple public and private cloud platforms.
Establish clear ownership of shared responsibilities.
© Strata Identity Inc. 2019. All Rights Reserved. Patents Pending.
27
Multi Cloud Identity
Across Public and
Private Clouds
Seamless identity and application
integration across multiple public
and private clouds.
© Strata Identity Inc. 2019. All Rights Reserved. Patents Pending.
28
Extending Cloud Native to Hybrid
© Strata Identity Inc. 2019. All Rights Reserved. Patents Pending.
29
Migration and Modernization Use Cases
Move on premises legacy IAM to run on public cloud
IaaS. Retire on premises infrastructure. Low risk but
limited benefits.
Lift and Shift
Move and Improve
Start the process of adopting some cloud native
identity services. Identify so-called strangler patterns
to retire legacy products and/or features.
Hybrid SSO
Extend IDaaS to on premises apps, migrate users,
configurations, and policies from legacy IAM to cloud
and associated on premises gateways.
Cloud Native Identity Services
Begin adopting built in cloud native identity services.
Map to native architecture patterns, tools, and
modern DevOps practices.
Multi Cloud Identity
Define and apply basic patterns for identity services
across multiple public and private cloud platforms.
Establish clear ownership of shared responsibilities.
© Strata Identity Inc. 2019. All Rights Reserved. Patents Pending.
30
Cloud based IDaaS links
back to on-prem network
to leverage existing
directories and extend
SSO to on-prem apps.
Extending IDaaS
to Hybrid SSO
© Strata Identity Inc. 2019. All Rights Reserved. Patents Pending.
31
Putting It All Together
© Strata Identity Inc. 2019. All Rights Reserved. Patents Pending.
32
On A Journey to Modern Identity
Lift and
Shift
Move and
Improve
Hybrid SSOCloud Native
Identity
Services
Multi Cloud
Identity
© Strata Identity Inc. 2019. All Rights Reserved. Patents Pending.
33
On A Journey to Modern Identity
Lift and
Shift
Move and
Improve
Hybrid SSOCloud Native
Identity
Services
Multi Cloud
Identity
© Strata Identity Inc. 2019. All Rights Reserved. Patents Pending.
34
On A Journey to Modern Identity
Lift and
Shift
Move and
Improve
Hybrid SSOMulti Cloud
Identity
Cloud Native
Identity
Services
© Strata Identity Inc. 2019. All Rights Reserved. Patents Pending.
35
On A Journey to Modern Identity
Lift and
Shift
Move and
Improve
Hybrid SSOMulti Cloud
Identity
Cloud Native
Identity
Services
© Strata Identity Inc. 2019. All Rights Reserved. Patents Pending.
36
On A Journey to Modern Identity
Lift and
Shift
Move and
Improve
Hybrid SSOCloud Native
Identity
Services
Multi Cloud
Identity
© Strata Identity Inc. 2019. All Rights Reserved. Patents Pending.
37
On A Journey to Modern Identity
Lift and
Shift
Move and
Improve
Hybrid SSOCloud Native
Identity
Services
Multi Cloud
Identity
© Strata Identity Inc. 2019. All Rights Reserved. Patents Pending.
38
Takeaways: A Customer Perspective
“We are on this journey, but it has to be incremental. No big bangs!”
“We cannot afford lock in. We need unfettered access to innovation
on each of our cloud platforms.”
“There is a new identity model that is distributed, not centralized.”
© Strata Identity Inc. 2019. All Rights Reserved. Patents Pending.
Strata helps organizations move off legacy
identity systems and onto modern cloud
native identity systems across multiple clouds
Thank You!

More Related Content

What's hot

Aerohive Networks e ZScaler, le soluzioni tecnologiche per il nuovo ecosistem...
Aerohive Networks e ZScaler, le soluzioni tecnologiche per il nuovo ecosistem...Aerohive Networks e ZScaler, le soluzioni tecnologiche per il nuovo ecosistem...
Aerohive Networks e ZScaler, le soluzioni tecnologiche per il nuovo ecosistem...Miriade Spa
 
Webinar: Deep Diving Into the KuppingerCole IDaaS Leadership Compass
Webinar: Deep Diving Into the KuppingerCole IDaaS Leadership Compass Webinar: Deep Diving Into the KuppingerCole IDaaS Leadership Compass
Webinar: Deep Diving Into the KuppingerCole IDaaS Leadership Compass Ping Identity
 
Cloud Security: A New Perspective
Cloud Security: A New PerspectiveCloud Security: A New Perspective
Cloud Security: A New PerspectiveWen-Pai Lu
 
SWM_WP_MaturityModel_July15
SWM_WP_MaturityModel_July15SWM_WP_MaturityModel_July15
SWM_WP_MaturityModel_July15Mike Lemons
 
The New IT – Empowering Your Next Generation Workforce
The New IT – Empowering Your Next Generation WorkforceThe New IT – Empowering Your Next Generation Workforce
The New IT – Empowering Your Next Generation WorkforceCisco Canada
 
Cisco ucs overview ibm team 2014 v.2 - handout
Cisco ucs overview   ibm team 2014 v.2 - handoutCisco ucs overview   ibm team 2014 v.2 - handout
Cisco ucs overview ibm team 2014 v.2 - handoutSarmad Ibrahim
 
Open APIs + Software Competitions = Innovative & Creative Solutions
Open APIs + Software Competitions = Innovative & Creative SolutionsOpen APIs + Software Competitions = Innovative & Creative Solutions
Open APIs + Software Competitions = Innovative & Creative SolutionsCA API Management
 
Identity and Access Management from Microsoft and Razor Technology
Identity and Access Management from Microsoft and Razor TechnologyIdentity and Access Management from Microsoft and Razor Technology
Identity and Access Management from Microsoft and Razor TechnologyDavid J Rosenthal
 
5 Top Enterprises Making IAM a Priority
5 Top Enterprises Making IAM a Priority5 Top Enterprises Making IAM a Priority
5 Top Enterprises Making IAM a PriorityOkta-Inc
 
IBM Cloud OpenStack Services
IBM Cloud OpenStack ServicesIBM Cloud OpenStack Services
IBM Cloud OpenStack ServicesAshish Patel
 
Identity and Access Management Introduction
Identity and Access Management IntroductionIdentity and Access Management Introduction
Identity and Access Management IntroductionAidy Tificate
 
iSpaces - Investor overview (Fall 2012)
iSpaces - Investor overview (Fall 2012)iSpaces - Investor overview (Fall 2012)
iSpaces - Investor overview (Fall 2012)Alex Brotherbees
 
Catalyst 2015: Patrick Harding
Catalyst 2015: Patrick HardingCatalyst 2015: Patrick Harding
Catalyst 2015: Patrick HardingPing Identity
 
Bridging the Enterprise and the Cloud from Layer 7
Bridging the Enterprise and the Cloud from Layer 7Bridging the Enterprise and the Cloud from Layer 7
Bridging the Enterprise and the Cloud from Layer 7CA API Management
 
Cloud Governance Framework - Required Cloud Sourcing Capabilities
Cloud Governance Framework - Required Cloud Sourcing CapabilitiesCloud Governance Framework - Required Cloud Sourcing Capabilities
Cloud Governance Framework - Required Cloud Sourcing CapabilitiesSusanneT
 
Okta Digital Enterprise Report
Okta Digital Enterprise ReportOkta Digital Enterprise Report
Okta Digital Enterprise ReportOkta-Inc
 
The Context Aware Network A Holistic Approach to BYOD
The Context Aware Network A Holistic Approach to BYODThe Context Aware Network A Holistic Approach to BYOD
The Context Aware Network A Holistic Approach to BYODCisco Canada
 
Cloud security, Cloud security Access broker, CSAB's 4 pillar, deployment mode
Cloud security, Cloud security Access broker, CSAB's 4 pillar, deployment modeCloud security, Cloud security Access broker, CSAB's 4 pillar, deployment mode
Cloud security, Cloud security Access broker, CSAB's 4 pillar, deployment modeHimani Singh
 

What's hot (20)

PCI and the Cloud
PCI and the CloudPCI and the Cloud
PCI and the Cloud
 
Aerohive Networks e ZScaler, le soluzioni tecnologiche per il nuovo ecosistem...
Aerohive Networks e ZScaler, le soluzioni tecnologiche per il nuovo ecosistem...Aerohive Networks e ZScaler, le soluzioni tecnologiche per il nuovo ecosistem...
Aerohive Networks e ZScaler, le soluzioni tecnologiche per il nuovo ecosistem...
 
Webinar: Deep Diving Into the KuppingerCole IDaaS Leadership Compass
Webinar: Deep Diving Into the KuppingerCole IDaaS Leadership Compass Webinar: Deep Diving Into the KuppingerCole IDaaS Leadership Compass
Webinar: Deep Diving Into the KuppingerCole IDaaS Leadership Compass
 
Cloud Security: A New Perspective
Cloud Security: A New PerspectiveCloud Security: A New Perspective
Cloud Security: A New Perspective
 
SWM_WP_MaturityModel_July15
SWM_WP_MaturityModel_July15SWM_WP_MaturityModel_July15
SWM_WP_MaturityModel_July15
 
The New IT – Empowering Your Next Generation Workforce
The New IT – Empowering Your Next Generation WorkforceThe New IT – Empowering Your Next Generation Workforce
The New IT – Empowering Your Next Generation Workforce
 
Cisco ucs overview ibm team 2014 v.2 - handout
Cisco ucs overview   ibm team 2014 v.2 - handoutCisco ucs overview   ibm team 2014 v.2 - handout
Cisco ucs overview ibm team 2014 v.2 - handout
 
Open APIs + Software Competitions = Innovative & Creative Solutions
Open APIs + Software Competitions = Innovative & Creative SolutionsOpen APIs + Software Competitions = Innovative & Creative Solutions
Open APIs + Software Competitions = Innovative & Creative Solutions
 
IdM vs. IDaaS
IdM vs. IDaaSIdM vs. IDaaS
IdM vs. IDaaS
 
Identity and Access Management from Microsoft and Razor Technology
Identity and Access Management from Microsoft and Razor TechnologyIdentity and Access Management from Microsoft and Razor Technology
Identity and Access Management from Microsoft and Razor Technology
 
5 Top Enterprises Making IAM a Priority
5 Top Enterprises Making IAM a Priority5 Top Enterprises Making IAM a Priority
5 Top Enterprises Making IAM a Priority
 
IBM Cloud OpenStack Services
IBM Cloud OpenStack ServicesIBM Cloud OpenStack Services
IBM Cloud OpenStack Services
 
Identity and Access Management Introduction
Identity and Access Management IntroductionIdentity and Access Management Introduction
Identity and Access Management Introduction
 
iSpaces - Investor overview (Fall 2012)
iSpaces - Investor overview (Fall 2012)iSpaces - Investor overview (Fall 2012)
iSpaces - Investor overview (Fall 2012)
 
Catalyst 2015: Patrick Harding
Catalyst 2015: Patrick HardingCatalyst 2015: Patrick Harding
Catalyst 2015: Patrick Harding
 
Bridging the Enterprise and the Cloud from Layer 7
Bridging the Enterprise and the Cloud from Layer 7Bridging the Enterprise and the Cloud from Layer 7
Bridging the Enterprise and the Cloud from Layer 7
 
Cloud Governance Framework - Required Cloud Sourcing Capabilities
Cloud Governance Framework - Required Cloud Sourcing CapabilitiesCloud Governance Framework - Required Cloud Sourcing Capabilities
Cloud Governance Framework - Required Cloud Sourcing Capabilities
 
Okta Digital Enterprise Report
Okta Digital Enterprise ReportOkta Digital Enterprise Report
Okta Digital Enterprise Report
 
The Context Aware Network A Holistic Approach to BYOD
The Context Aware Network A Holistic Approach to BYODThe Context Aware Network A Holistic Approach to BYOD
The Context Aware Network A Holistic Approach to BYOD
 
Cloud security, Cloud security Access broker, CSAB's 4 pillar, deployment mode
Cloud security, Cloud security Access broker, CSAB's 4 pillar, deployment modeCloud security, Cloud security Access broker, CSAB's 4 pillar, deployment mode
Cloud security, Cloud security Access broker, CSAB's 4 pillar, deployment mode
 

Similar to Migrating Identity to Multi Cloud

Cloud DevSecOps masterclass: Lessons learned from a multi-year implementation...
Cloud DevSecOps masterclass: Lessons learned from a multi-year implementation...Cloud DevSecOps masterclass: Lessons learned from a multi-year implementation...
Cloud DevSecOps masterclass: Lessons learned from a multi-year implementation...Amazon Web Services
 
Developer Conference 2.1 - (Cloud) First Steps to the Cloud
Developer Conference 2.1 - (Cloud) First Steps to the CloudDeveloper Conference 2.1 - (Cloud) First Steps to the Cloud
Developer Conference 2.1 - (Cloud) First Steps to the CloudMicro Focus
 
APIsecure 2023 - For flex(ibility) sake, modernize your legacy APIs!, Topher ...
APIsecure 2023 - For flex(ibility) sake, modernize your legacy APIs!, Topher ...APIsecure 2023 - For flex(ibility) sake, modernize your legacy APIs!, Topher ...
APIsecure 2023 - For flex(ibility) sake, modernize your legacy APIs!, Topher ...apidays
 
Proven Practices for Office 365 Deployment, Security and Management
Proven Practices for Office 365 Deployment, Security and ManagementProven Practices for Office 365 Deployment, Security and Management
Proven Practices for Office 365 Deployment, Security and ManagementPerficient, Inc.
 
Migration to microsoft_azure_with_zscaler
Migration to microsoft_azure_with_zscalerMigration to microsoft_azure_with_zscaler
Migration to microsoft_azure_with_zscalerZscaler
 
Implementing Enterprise Identity and Access Management in a microservices wor...
Implementing Enterprise Identity and Access Management in a microservices wor...Implementing Enterprise Identity and Access Management in a microservices wor...
Implementing Enterprise Identity and Access Management in a microservices wor...Judy Breedlove
 
Modern Architectures
Modern ArchitecturesModern Architectures
Modern ArchitecturesSecureAuth
 
Enhancing Worker Digital Experience: A Hands-on Workshop for Partners
Enhancing Worker Digital Experience: A Hands-on Workshop for PartnersEnhancing Worker Digital Experience: A Hands-on Workshop for Partners
Enhancing Worker Digital Experience: A Hands-on Workshop for PartnersThousandEyes
 
Managing Identity without Boundaries
Managing Identity without BoundariesManaging Identity without Boundaries
Managing Identity without BoundariesPing Identity
 
Intel IT's Identity and Access Management Journey
Intel IT's Identity and Access Management JourneyIntel IT's Identity and Access Management Journey
Intel IT's Identity and Access Management JourneyIntel IT Center
 
Realise True Business Value .pdf
Realise True Business Value .pdfRealise True Business Value .pdf
Realise True Business Value .pdfThousandEyes
 
Are Your Appliance Security Solutions Ready For 2048-bit SSL Certificates ?
Are Your Appliance Security Solutions Ready For 2048-bit SSL Certificates ?Are Your Appliance Security Solutions Ready For 2048-bit SSL Certificates ?
Are Your Appliance Security Solutions Ready For 2048-bit SSL Certificates ?michaelbasoah
 
Realize True Business Value With ThousandEyes
Realize True Business Value With ThousandEyesRealize True Business Value With ThousandEyes
Realize True Business Value With ThousandEyesThousandEyes
 
Enterprise DevOps: Begin with Production-Ready Migration (ENT217-R1) - AWS re...
Enterprise DevOps: Begin with Production-Ready Migration (ENT217-R1) - AWS re...Enterprise DevOps: Begin with Production-Ready Migration (ENT217-R1) - AWS re...
Enterprise DevOps: Begin with Production-Ready Migration (ENT217-R1) - AWS re...Amazon Web Services
 
The Sky Is The Limit (CCC)
The Sky Is The Limit (CCC)The Sky Is The Limit (CCC)
The Sky Is The Limit (CCC)ITpreneurs
 
a_partner_overview_to_thousandeyes__v1_2_en1.pptx
a_partner_overview_to_thousandeyes__v1_2_en1.pptxa_partner_overview_to_thousandeyes__v1_2_en1.pptx
a_partner_overview_to_thousandeyes__v1_2_en1.pptxThousandEyes
 
DevSecOps: Integrating security into pipelines - SDD310 - AWS re:Inforce 2019
DevSecOps: Integrating security into pipelines - SDD310 - AWS re:Inforce 2019 DevSecOps: Integrating security into pipelines - SDD310 - AWS re:Inforce 2019
DevSecOps: Integrating security into pipelines - SDD310 - AWS re:Inforce 2019 Amazon Web Services
 

Similar to Migrating Identity to Multi Cloud (20)

Cloud DevSecOps masterclass: Lessons learned from a multi-year implementation...
Cloud DevSecOps masterclass: Lessons learned from a multi-year implementation...Cloud DevSecOps masterclass: Lessons learned from a multi-year implementation...
Cloud DevSecOps masterclass: Lessons learned from a multi-year implementation...
 
Developer Conference 2.1 - (Cloud) First Steps to the Cloud
Developer Conference 2.1 - (Cloud) First Steps to the CloudDeveloper Conference 2.1 - (Cloud) First Steps to the Cloud
Developer Conference 2.1 - (Cloud) First Steps to the Cloud
 
APIsecure 2023 - For flex(ibility) sake, modernize your legacy APIs!, Topher ...
APIsecure 2023 - For flex(ibility) sake, modernize your legacy APIs!, Topher ...APIsecure 2023 - For flex(ibility) sake, modernize your legacy APIs!, Topher ...
APIsecure 2023 - For flex(ibility) sake, modernize your legacy APIs!, Topher ...
 
Proven Practices for Office 365 Deployment, Security and Management
Proven Practices for Office 365 Deployment, Security and ManagementProven Practices for Office 365 Deployment, Security and Management
Proven Practices for Office 365 Deployment, Security and Management
 
Migration to microsoft_azure_with_zscaler
Migration to microsoft_azure_with_zscalerMigration to microsoft_azure_with_zscaler
Migration to microsoft_azure_with_zscaler
 
A journey to faster, repeatable data commercialization
A journey to faster, repeatable data commercializationA journey to faster, repeatable data commercialization
A journey to faster, repeatable data commercialization
 
Implementing Enterprise Identity and Access Management in a microservices wor...
Implementing Enterprise Identity and Access Management in a microservices wor...Implementing Enterprise Identity and Access Management in a microservices wor...
Implementing Enterprise Identity and Access Management in a microservices wor...
 
Modern Architectures
Modern ArchitecturesModern Architectures
Modern Architectures
 
Cloud the current future v6
Cloud   the current future v6Cloud   the current future v6
Cloud the current future v6
 
Enhancing Worker Digital Experience: A Hands-on Workshop for Partners
Enhancing Worker Digital Experience: A Hands-on Workshop for PartnersEnhancing Worker Digital Experience: A Hands-on Workshop for Partners
Enhancing Worker Digital Experience: A Hands-on Workshop for Partners
 
Managing Identity without Boundaries
Managing Identity without BoundariesManaging Identity without Boundaries
Managing Identity without Boundaries
 
Intel IT's Identity and Access Management Journey
Intel IT's Identity and Access Management JourneyIntel IT's Identity and Access Management Journey
Intel IT's Identity and Access Management Journey
 
Realise True Business Value .pdf
Realise True Business Value .pdfRealise True Business Value .pdf
Realise True Business Value .pdf
 
Are Your Appliance Security Solutions Ready For 2048-bit SSL Certificates ?
Are Your Appliance Security Solutions Ready For 2048-bit SSL Certificates ?Are Your Appliance Security Solutions Ready For 2048-bit SSL Certificates ?
Are Your Appliance Security Solutions Ready For 2048-bit SSL Certificates ?
 
Realize True Business Value With ThousandEyes
Realize True Business Value With ThousandEyesRealize True Business Value With ThousandEyes
Realize True Business Value With ThousandEyes
 
Smartscale Executive Summary
Smartscale Executive SummarySmartscale Executive Summary
Smartscale Executive Summary
 
Enterprise DevOps: Begin with Production-Ready Migration (ENT217-R1) - AWS re...
Enterprise DevOps: Begin with Production-Ready Migration (ENT217-R1) - AWS re...Enterprise DevOps: Begin with Production-Ready Migration (ENT217-R1) - AWS re...
Enterprise DevOps: Begin with Production-Ready Migration (ENT217-R1) - AWS re...
 
The Sky Is The Limit (CCC)
The Sky Is The Limit (CCC)The Sky Is The Limit (CCC)
The Sky Is The Limit (CCC)
 
a_partner_overview_to_thousandeyes__v1_2_en1.pptx
a_partner_overview_to_thousandeyes__v1_2_en1.pptxa_partner_overview_to_thousandeyes__v1_2_en1.pptx
a_partner_overview_to_thousandeyes__v1_2_en1.pptx
 
DevSecOps: Integrating security into pipelines - SDD310 - AWS re:Inforce 2019
DevSecOps: Integrating security into pipelines - SDD310 - AWS re:Inforce 2019 DevSecOps: Integrating security into pipelines - SDD310 - AWS re:Inforce 2019
DevSecOps: Integrating security into pipelines - SDD310 - AWS re:Inforce 2019
 

Recently uploaded

IAC 2024 - IA Fast Track to Search Focused AI Solutions
IAC 2024 - IA Fast Track to Search Focused AI SolutionsIAC 2024 - IA Fast Track to Search Focused AI Solutions
IAC 2024 - IA Fast Track to Search Focused AI SolutionsEnterprise Knowledge
 
Benefits Of Flutter Compared To Other Frameworks
Benefits Of Flutter Compared To Other FrameworksBenefits Of Flutter Compared To Other Frameworks
Benefits Of Flutter Compared To Other FrameworksSoftradix Technologies
 
Next-generation AAM aircraft unveiled by Supernal, S-A2
Next-generation AAM aircraft unveiled by Supernal, S-A2Next-generation AAM aircraft unveiled by Supernal, S-A2
Next-generation AAM aircraft unveiled by Supernal, S-A2Hyundai Motor Group
 
#StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024
#StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024#StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024
#StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024BookNet Canada
 
SIEMENS: RAPUNZEL – A Tale About Knowledge Graph
SIEMENS: RAPUNZEL – A Tale About Knowledge GraphSIEMENS: RAPUNZEL – A Tale About Knowledge Graph
SIEMENS: RAPUNZEL – A Tale About Knowledge GraphNeo4j
 
Snow Chain-Integrated Tire for a Safe Drive on Winter Roads
Snow Chain-Integrated Tire for a Safe Drive on Winter RoadsSnow Chain-Integrated Tire for a Safe Drive on Winter Roads
Snow Chain-Integrated Tire for a Safe Drive on Winter RoadsHyundai Motor Group
 
Artificial intelligence in the post-deep learning era
Artificial intelligence in the post-deep learning eraArtificial intelligence in the post-deep learning era
Artificial intelligence in the post-deep learning eraDeakin University
 
SQL Database Design For Developers at php[tek] 2024
SQL Database Design For Developers at php[tek] 2024SQL Database Design For Developers at php[tek] 2024
SQL Database Design For Developers at php[tek] 2024Scott Keck-Warren
 
Kotlin Multiplatform & Compose Multiplatform - Starter kit for pragmatics
Kotlin Multiplatform & Compose Multiplatform - Starter kit for pragmaticsKotlin Multiplatform & Compose Multiplatform - Starter kit for pragmatics
Kotlin Multiplatform & Compose Multiplatform - Starter kit for pragmaticscarlostorres15106
 
Tech-Forward - Achieving Business Readiness For Copilot in Microsoft 365
Tech-Forward - Achieving Business Readiness For Copilot in Microsoft 365Tech-Forward - Achieving Business Readiness For Copilot in Microsoft 365
Tech-Forward - Achieving Business Readiness For Copilot in Microsoft 3652toLead Limited
 
Transcript: #StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024
Transcript: #StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024Transcript: #StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024
Transcript: #StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024BookNet Canada
 
Unblocking The Main Thread Solving ANRs and Frozen Frames
Unblocking The Main Thread Solving ANRs and Frozen FramesUnblocking The Main Thread Solving ANRs and Frozen Frames
Unblocking The Main Thread Solving ANRs and Frozen FramesSinan KOZAK
 
AI as an Interface for Commercial Buildings
AI as an Interface for Commercial BuildingsAI as an Interface for Commercial Buildings
AI as an Interface for Commercial BuildingsMemoori
 
Human Factors of XR: Using Human Factors to Design XR Systems
Human Factors of XR: Using Human Factors to Design XR SystemsHuman Factors of XR: Using Human Factors to Design XR Systems
Human Factors of XR: Using Human Factors to Design XR SystemsMark Billinghurst
 
Maximizing Board Effectiveness 2024 Webinar.pptx
Maximizing Board Effectiveness 2024 Webinar.pptxMaximizing Board Effectiveness 2024 Webinar.pptx
Maximizing Board Effectiveness 2024 Webinar.pptxOnBoard
 
Install Stable Diffusion in windows machine
Install Stable Diffusion in windows machineInstall Stable Diffusion in windows machine
Install Stable Diffusion in windows machinePadma Pradeep
 
Beyond Boundaries: Leveraging No-Code Solutions for Industry Innovation
Beyond Boundaries: Leveraging No-Code Solutions for Industry InnovationBeyond Boundaries: Leveraging No-Code Solutions for Industry Innovation
Beyond Boundaries: Leveraging No-Code Solutions for Industry InnovationSafe Software
 
Azure Monitor & Application Insight to monitor Infrastructure & Application
Azure Monitor & Application Insight to monitor Infrastructure & ApplicationAzure Monitor & Application Insight to monitor Infrastructure & Application
Azure Monitor & Application Insight to monitor Infrastructure & ApplicationAndikSusilo4
 

Recently uploaded (20)

IAC 2024 - IA Fast Track to Search Focused AI Solutions
IAC 2024 - IA Fast Track to Search Focused AI SolutionsIAC 2024 - IA Fast Track to Search Focused AI Solutions
IAC 2024 - IA Fast Track to Search Focused AI Solutions
 
Benefits Of Flutter Compared To Other Frameworks
Benefits Of Flutter Compared To Other FrameworksBenefits Of Flutter Compared To Other Frameworks
Benefits Of Flutter Compared To Other Frameworks
 
Next-generation AAM aircraft unveiled by Supernal, S-A2
Next-generation AAM aircraft unveiled by Supernal, S-A2Next-generation AAM aircraft unveiled by Supernal, S-A2
Next-generation AAM aircraft unveiled by Supernal, S-A2
 
#StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024
#StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024#StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024
#StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024
 
SIEMENS: RAPUNZEL – A Tale About Knowledge Graph
SIEMENS: RAPUNZEL – A Tale About Knowledge GraphSIEMENS: RAPUNZEL – A Tale About Knowledge Graph
SIEMENS: RAPUNZEL – A Tale About Knowledge Graph
 
Snow Chain-Integrated Tire for a Safe Drive on Winter Roads
Snow Chain-Integrated Tire for a Safe Drive on Winter RoadsSnow Chain-Integrated Tire for a Safe Drive on Winter Roads
Snow Chain-Integrated Tire for a Safe Drive on Winter Roads
 
Artificial intelligence in the post-deep learning era
Artificial intelligence in the post-deep learning eraArtificial intelligence in the post-deep learning era
Artificial intelligence in the post-deep learning era
 
SQL Database Design For Developers at php[tek] 2024
SQL Database Design For Developers at php[tek] 2024SQL Database Design For Developers at php[tek] 2024
SQL Database Design For Developers at php[tek] 2024
 
Kotlin Multiplatform & Compose Multiplatform - Starter kit for pragmatics
Kotlin Multiplatform & Compose Multiplatform - Starter kit for pragmaticsKotlin Multiplatform & Compose Multiplatform - Starter kit for pragmatics
Kotlin Multiplatform & Compose Multiplatform - Starter kit for pragmatics
 
The transition to renewables in India.pdf
The transition to renewables in India.pdfThe transition to renewables in India.pdf
The transition to renewables in India.pdf
 
Tech-Forward - Achieving Business Readiness For Copilot in Microsoft 365
Tech-Forward - Achieving Business Readiness For Copilot in Microsoft 365Tech-Forward - Achieving Business Readiness For Copilot in Microsoft 365
Tech-Forward - Achieving Business Readiness For Copilot in Microsoft 365
 
Vulnerability_Management_GRC_by Sohang Sengupta.pptx
Vulnerability_Management_GRC_by Sohang Sengupta.pptxVulnerability_Management_GRC_by Sohang Sengupta.pptx
Vulnerability_Management_GRC_by Sohang Sengupta.pptx
 
Transcript: #StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024
Transcript: #StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024Transcript: #StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024
Transcript: #StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024
 
Unblocking The Main Thread Solving ANRs and Frozen Frames
Unblocking The Main Thread Solving ANRs and Frozen FramesUnblocking The Main Thread Solving ANRs and Frozen Frames
Unblocking The Main Thread Solving ANRs and Frozen Frames
 
AI as an Interface for Commercial Buildings
AI as an Interface for Commercial BuildingsAI as an Interface for Commercial Buildings
AI as an Interface for Commercial Buildings
 
Human Factors of XR: Using Human Factors to Design XR Systems
Human Factors of XR: Using Human Factors to Design XR SystemsHuman Factors of XR: Using Human Factors to Design XR Systems
Human Factors of XR: Using Human Factors to Design XR Systems
 
Maximizing Board Effectiveness 2024 Webinar.pptx
Maximizing Board Effectiveness 2024 Webinar.pptxMaximizing Board Effectiveness 2024 Webinar.pptx
Maximizing Board Effectiveness 2024 Webinar.pptx
 
Install Stable Diffusion in windows machine
Install Stable Diffusion in windows machineInstall Stable Diffusion in windows machine
Install Stable Diffusion in windows machine
 
Beyond Boundaries: Leveraging No-Code Solutions for Industry Innovation
Beyond Boundaries: Leveraging No-Code Solutions for Industry InnovationBeyond Boundaries: Leveraging No-Code Solutions for Industry Innovation
Beyond Boundaries: Leveraging No-Code Solutions for Industry Innovation
 
Azure Monitor & Application Insight to monitor Infrastructure & Application
Azure Monitor & Application Insight to monitor Infrastructure & ApplicationAzure Monitor & Application Insight to monitor Infrastructure & Application
Azure Monitor & Application Insight to monitor Infrastructure & Application
 

Migrating Identity to Multi Cloud

  • 1. © Strata Identity Inc. 2019. All Rights Reserved. Patents Pending.© Strata Identity Inc. 2019. All Rights Reserved. Patents Pending. Eric Leach Chief Product Officer Strata Identity, Inc. Strata Migrating and Modernizing Identity on the Path to Multi Cloud
  • 2. © Strata Identity Inc. 2019. All Rights Reserved. Patents Pending. 2 Redefining Identity For Multi Cloud World ABOUT STRATA Strata is an identity management services provider focused on modernizing and migrating identity to multi cloud and hybrid. Our team has more than 110 years of combined identity experience from Oracle, Salesforce, Securant, Symplified, Ping, Auth0, JumpCloud, PWC, and Thor. Strata Identity Eric Leach CPO & Cofounder • Eric brings 20+ years of experience developing and delivering innovative solutions for identity management. • Most recently Eric was VP Product Management of Oracle’s global identity portfolio. • Eric built Salesforce’s Shield data security product into a $500M business. • Eric got his start in identity at Sun, where he delivered the industry’s first commercial opensource identity product, OpenSSO. Intro
  • 3. © Strata Identity Inc. 2019. All Rights Reserved. Patents Pending. 3 Agenda 1. What’s Going on with Identity? 2. What We Learned 3. Why Modernize? 4. Lift and Shift or Move and Improve? 5. Becoming Cloud Native 6. Identity for Multi Cloud 7. Extending Cloud Native Identity to Hybrid 8. Putting it all Together
  • 4. © Strata Identity Inc. 2019. All Rights Reserved. Patents Pending. 4 What’s Going on with Identity?
  • 5. © Strata Identity Inc. 2019. All Rights Reserved. Patents Pending. 5 A Hypothesis: customers are staring down three IAM challenges 1. Moving to the cloud requires modern identity systems. 2. Customers are universally adopting multiple clouds. 3. Legacy IAM systems are aging out and reaching end of life.
  • 6. © Strata Identity Inc. 2019. All Rights Reserved. Patents Pending. 6 Using Lean Customer Development To validate or disprove a hypothesis, you must first understand: • Who are your customers • What problems they are facing • What are their current behaviors Test your hypotheses by setting aside preconceived ideas and asking simple, open-ended questions and then listening quietly and patiently.
  • 7. © Strata Identity Inc. 2019. All Rights Reserved. Patents Pending. 7 We Asked Questions Like… Q: Who owns identity in your enterprise? A: The team in IT that traditionally owned IAM B: The team(s) responsible for managing our cloud platform(s) C: The business owner(s) that fund our SaaS app(s) D: All three E: I don’t know
  • 8. © Strata Identity Inc. 2019. All Rights Reserved. Patents Pending. 8 We Asked Questions Like… Q: Who owns identity in your enterprise? A: The team in IT that traditionally owned IAM 65% B: The team(s) responsible for managing our cloud platform(s) 9% C: The business owner(s) that fund our SaaS app(s) 0% D: All three 27% E: I don’t know 0%
  • 9. © Strata Identity Inc. 2019. All Rights Reserved. Patents Pending. 9 Using Lean Customer Development Full disclosure: these are our practices, not our ideas. Shout out to Cindy Alvarez. You should read her book. https://www.cindyalvarez.com/lean-customer-development/
  • 10. © Strata Identity Inc. 2019. All Rights Reserved. Patents Pending. 10 What We Learned
  • 11. © Strata Identity Inc. 2019. All Rights Reserved. Patents Pending. 11 Most enterprises have 3+ cloud IaaS platforms Most have private and public clouds Digital transformation is driving this shift SAML is focused on SSO and Authentication Identity data still needs to be synchronized No Identity Metadata No Identity Lifecycle No IGA Need to deploy CSP identity to use IaaS platform, or SaaS App (Office 365) No visibility across silos Fragmented across clouds and across stack Politics Security Economics Migration Costs M&A Integration End of life 2020 Expertise hard to find Compliance issues Not compatible with cloud native architecture SAML and Federated SSO Doesn’t Address Identity Data Centralizing Identities Is Impossible Legacy Identity Software is Reaching End of Life Identity Silos Are Propagating Multiple Clouds Drives Multiple Identity Challenges A Pattern of Recurring Pain Points
  • 12. © Strata Identity Inc. 2019. All Rights Reserved. Patents Pending. 12 Migration and Modernization Use Cases Move on premises legacy IAM to run on public cloud IaaS. Retire on premises infrastructure. Low risk but limited benefits. Lift and Shift Move and Improve Start the process of adopting some cloud native identity services. Identify so-called strangler patterns to retire legacy products and/or features. Hybrid SSO Extend IDaaS to on premises apps, migrate users, configurations, and policies from legacy IAM to cloud and associated on premises gateways. Cloud Native Identity Services Begin adopting built in cloud native identity services. Map to native architecture patterns, tools, and modern DevOps practices. Multi Cloud Identity Define and apply basic patterns for identity services across multiple public and private cloud platforms. Establish clear ownership of shared responsibilities.
  • 13. © Strata Identity Inc. 2019. All Rights Reserved. Patents Pending. 13 Hybrid Multiple Directories Multiple Policies OAuth, OIDC, JWT SCIM, Cookie Based, HTTP Headers On-Prem Reverse Proxy Yes Multi Cloud Multiple Directories Multiple Policies OAuth, OIDC, JWT SCIM, SAML Cloud Proxies Yes Cloud Native Cloud Directory CSP / IDaaS OAuth, OIDC, JWT SCIM, SAML Cloud Proxy Yes Move & Improve Simple AD AWS Cognito OAuth, OIDC, JWT SCIM, Cookie Based, HTTP Headers Cloud Proxy Yes Lift & Shift Active Directory SiteMinder Cookies & Header Agents or Proxy No Baseline Active Directory SiteMinder Cookies & Header Agents or Proxy No Identities Policies Sessions Integration & Enforcement DevOps A Cloud Identity Maturity Model
  • 14. © Strata Identity Inc. 2019. All Rights Reserved. Patents Pending. 14 Why Modernize
  • 15. © Strata Identity Inc. 2019. All Rights Reserved. Patents Pending. 15 Legacy Identity Characteristics vs Cloud Requirements Legacy IAM Cloud Deployment Model • Pre-deployed servers for peak capacity • Bare OS, some virtualization • Individually edited config files • Autoscaling • Containers and orchestrators • Declarative, immutable configuration Integration Model • Static agents for web, Java, .Net apps • Proprietary APIs • Proprietary cookies or HTTP Headers • Sidecars and Nginx proxies • Opensource tools and documented APIs • Standards based tokens User Model • Single, consolidated user directory • Distributed directories per cloud Policy Model • Static policy evaluation • Custom deployed MFA • Adaptive authentication and authorization • Strong authentication by default
  • 16. © Strata Identity Inc. 2019. All Rights Reserved. Patents Pending. 16 How Identity Is Delivered To Apps In Legacy Deployments
  • 17. © Strata Identity Inc. 2019. All Rights Reserved. Patents Pending. 17 Benefits of Identity Migration and Modernization Become Cloud Native Save Money Get More Done Faster Break Lock-In Future Proof Investments Leap To The Cloud • Adopt cloud native architectures with an identity capability to match. • Move to the cloud while extending your existing identity and policies. • Focus on digital transformation and don’t worry about infrastructure. • Migrating off old technology will save you operational costs, legacy licensing & maintenance costs, and infrastructure expense. • Automated migration saves you time and money. • Look for ways to turn migrations from complex, multi-quarter initiatives into quick software powered projects. Knock off your migration tasks quickly. • Consider externally sourcing experts so you don’t have to find and hire rare talent. • API abstraction layers give you the freedom to use the identity system of your choice. • Replicate identities, policies, configurations across platforms. • Leverage your existing investments in the cloud through hybrid configurations. • Extend value-producing apps and systems to the cloud. • Sync identities and policies to keep your hybrid environments orchestrated. • Determine whether you can make the jump straight to cloud native. • Use an incremental migration approach or move everything straight to a cloud native design.
  • 18. © Strata Identity Inc. 2019. All Rights Reserved. Patents Pending. 18 Lift & Shift or Move & Improve
  • 19. © Strata Identity Inc. 2019. All Rights Reserved. Patents Pending. 19 Migration and Modernization Use Cases Move on premises legacy IAM to run on public cloud IaaS. Retire on premises infrastructure. Low risk but limited benefits. Lift and Shift Move and Improve Start the process of adopting some cloud native identity services. Identify so-called strangler patterns to retire legacy products and/or features. Hybrid SSO Extend IDaaS to on premises apps, migrate users, configurations, and policies from legacy IAM to cloud and associated on premises gateways. Cloud Native Identity Services Begin adopting built in cloud native identity services. Map to native architecture patterns, tools, and modern DevOps practices. Multi Cloud Identity Define and apply basic patterns for identity services across multiple public and private cloud platforms. Establish clear ownership of shared responsibilities.
  • 20. © Strata Identity Inc. 2019. All Rights Reserved. Patents Pending. 20 Virtualized Infrastructure moves from on-premises deployment to IaaS service like AWS EC2, GCP, Azure VM. Lift and Shift: Identity and Apps to IaaS
  • 21. © Strata Identity Inc. 2019. All Rights Reserved. Patents Pending. 21 Replace some elements of Infrastructure with IaaS-provided services like AWS Cognito, Google Cloud Identity and Azure AD. Move and Improve: Adopting Cloud Native Identity Services
  • 22. © Strata Identity Inc. 2019. All Rights Reserved. Patents Pending. 22 Becoming Cloud Native
  • 23. © Strata Identity Inc. 2019. All Rights Reserved. Patents Pending. 23 Migration and Modernization Use Cases Move on premises legacy IAM to run on public cloud IaaS. Retire on premises infrastructure. Low risk but limited benefits. Lift and Shift Move and Improve Start the process of adopting some cloud native identity services. Identify so-called strangler patterns to retire legacy products and/or features. Hybrid SSO Extend IDaaS to on premises apps, migrate users, configurations, and policies from legacy IAM to cloud and associated on premises gateways. Cloud Native Identity Services Begin adopting built in cloud native identity services. Map to cloud native architecture patterns, tools, and modern DevOps practices. Multi Cloud Identity Define and apply basic patterns for identity services across multiple public and private cloud platforms. Establish clear ownership of shared responsibilities.
  • 24. © Strata Identity Inc. 2019. All Rights Reserved. Patents Pending. 24 Cloud Native Identity and Apps Implement a cloud native containerized microservices platform with native identity microservices provided by cloud service providers.
  • 25. © Strata Identity Inc. 2019. All Rights Reserved. Patents Pending. 25 Identity for Multi Cloud
  • 26. © Strata Identity Inc. 2019. All Rights Reserved. Patents Pending. 26 Migration and Modernization Use Cases Move on premises legacy IAM to run on public cloud IaaS. Retire on premises infrastructure. Low risk but limited benefits. Lift and Shift Move and Improve Start the process of adopting some cloud native identity services. Identify so-called strangler patterns to retire legacy products and/or features. Hybrid SSO Extend IDaaS to on premises apps, migrate users, configurations, and policies from legacy IAM to cloud and associated on premises gateways. Cloud Native Identity Services Begin adopting built in cloud native identity services. Map to native architecture patterns, tools, and modern DevOps practices. Multi Cloud Identity Define and apply basic patterns for identity services across multiple public and private cloud platforms. Establish clear ownership of shared responsibilities.
  • 27. © Strata Identity Inc. 2019. All Rights Reserved. Patents Pending. 27 Multi Cloud Identity Across Public and Private Clouds Seamless identity and application integration across multiple public and private clouds.
  • 28. © Strata Identity Inc. 2019. All Rights Reserved. Patents Pending. 28 Extending Cloud Native to Hybrid
  • 29. © Strata Identity Inc. 2019. All Rights Reserved. Patents Pending. 29 Migration and Modernization Use Cases Move on premises legacy IAM to run on public cloud IaaS. Retire on premises infrastructure. Low risk but limited benefits. Lift and Shift Move and Improve Start the process of adopting some cloud native identity services. Identify so-called strangler patterns to retire legacy products and/or features. Hybrid SSO Extend IDaaS to on premises apps, migrate users, configurations, and policies from legacy IAM to cloud and associated on premises gateways. Cloud Native Identity Services Begin adopting built in cloud native identity services. Map to native architecture patterns, tools, and modern DevOps practices. Multi Cloud Identity Define and apply basic patterns for identity services across multiple public and private cloud platforms. Establish clear ownership of shared responsibilities.
  • 30. © Strata Identity Inc. 2019. All Rights Reserved. Patents Pending. 30 Cloud based IDaaS links back to on-prem network to leverage existing directories and extend SSO to on-prem apps. Extending IDaaS to Hybrid SSO
  • 31. © Strata Identity Inc. 2019. All Rights Reserved. Patents Pending. 31 Putting It All Together
  • 32. © Strata Identity Inc. 2019. All Rights Reserved. Patents Pending. 32 On A Journey to Modern Identity Lift and Shift Move and Improve Hybrid SSOCloud Native Identity Services Multi Cloud Identity
  • 33. © Strata Identity Inc. 2019. All Rights Reserved. Patents Pending. 33 On A Journey to Modern Identity Lift and Shift Move and Improve Hybrid SSOCloud Native Identity Services Multi Cloud Identity
  • 34. © Strata Identity Inc. 2019. All Rights Reserved. Patents Pending. 34 On A Journey to Modern Identity Lift and Shift Move and Improve Hybrid SSOMulti Cloud Identity Cloud Native Identity Services
  • 35. © Strata Identity Inc. 2019. All Rights Reserved. Patents Pending. 35 On A Journey to Modern Identity Lift and Shift Move and Improve Hybrid SSOMulti Cloud Identity Cloud Native Identity Services
  • 36. © Strata Identity Inc. 2019. All Rights Reserved. Patents Pending. 36 On A Journey to Modern Identity Lift and Shift Move and Improve Hybrid SSOCloud Native Identity Services Multi Cloud Identity
  • 37. © Strata Identity Inc. 2019. All Rights Reserved. Patents Pending. 37 On A Journey to Modern Identity Lift and Shift Move and Improve Hybrid SSOCloud Native Identity Services Multi Cloud Identity
  • 38. © Strata Identity Inc. 2019. All Rights Reserved. Patents Pending. 38 Takeaways: A Customer Perspective “We are on this journey, but it has to be incremental. No big bangs!” “We cannot afford lock in. We need unfettered access to innovation on each of our cloud platforms.” “There is a new identity model that is distributed, not centralized.”
  • 39. © Strata Identity Inc. 2019. All Rights Reserved. Patents Pending. Strata helps organizations move off legacy identity systems and onto modern cloud native identity systems across multiple clouds Thank You!