SlideShare ist ein Scribd-Unternehmen logo
1 von 57
Password Fatigation
http://your.intranet.com




                               your.   intranet.com

                                                  john.doe@vasco.com
                                              Y
                                                  ********




© 2013 - VASCO Data Security                            IDENTIKEY Federation Server Workshop   2
http://your.intranet.com
                                                    your
                                                  domain
                               your.   intranet.com

                                              Y


                                                                        …



© 2013 - VASCO Data Security                       IDENTIKEY Federation Server Workshop   3
your
                               domain




                                                             Identity
                                                         Service

© 2013 - VASCO Data Security    IDENTIKEY Federation Server Workshop    4
your
                                          domain



                                                              SAML
                               Identity




                                                           Service




© 2013 - VASCO Data Security               IDENTIKEY Federation Server Workshop   5
your
                               domain


                                                  Reduces
                                                  Identity             $
                                                  Management
                                                  Costs




© 2013 - VASCO Data Security    IDENTIKEY Federation Server Workshop   6
your
                               domain




© 2013 - VASCO Data Security    IDENTIKEY Federation Server Workshop   7
your
                               domain




© 2013 - VASCO Data Security    IDENTIKEY Federation Server Workshop   8
your                        the
                               domain                     cloud




                                                     …




© 2013 - VASCO Data Security    IDENTIKEY Federation Server Workshop   9
your                         the
                                          domain                      cloud


                                          Authentication


                                                                 …
                               Identity




                                                            Service




                                                                 Users DIGIPASS
© 2013 - VASCO Data Security                IDENTIKEY Federation Server Workshop   10
Yes you can
                  8
            Can I access?
                                        1
                           Please Login @ …

     Jack                               6
                                                           A
                                                Service
                                                                       Ticket ?
                                                                   7
                 3                                         Authentication
                                    2

                                                                       OTP ?
                                   4        Identity
                                                Identity                5         Authentication




                                                                                  Service




                                                                                     Jack
© 2013 - VASCO Data Security                                   IDENTIKEY Federation Server Workshop   11
User
                                                        A
                                             Service




                                   2
                                    Ticket   Identity                          Authentication

                                                                    Ticket ?
                                                                4
                                   3

                        Please Login @ …
            Can I access?
                                       1
                                                        B
     Jack                                    Service
                               Yes you can
                  5
© 2013 - VASCO Data Security                                IDENTIKEY Federation Server Workshop   12
…
                                                           Identity




                               Identity                   Authentication




© 2013 - VASCO Data Security              IDENTIKEY Federation Server Workshop   13
Identity
                               One Family

                                      Identity                      Authentication



                                  Identity Server
                                   Federation




            SAML


© 2013 - VASCO Data Security                        IDENTIKEY Federation Server Workshop   14
IFS: The selling story



      Raf Van Ermengem
                 Trainer
Existing        New               New
customer       Customer          Customer




                              helpdesk costs
Security    User Management
                              B2B associates
Catherine Falcke
       CEO




                   17
Remote access
        OWA
25


                     18
Protect all company      Brent Kehl
 applications with    Account Manager




                                        19
Which applications?




 How many users?
5




80




             25           40               15



     Sales        Admin        Technical        21
I don’t talk
                                      RADIUS
         25


 Sales




            40



 Admin




                    Upgrade license to Enterprise
            15



Technical        Selling 55 user licenses Enterprise



                 Selling 55 DIGIPASS Authenticators
                                                       22
Username & OTP   Check OTP




Sandra




                                      23
SAML?    SOAP?
         Username C
  ?
          Username A



            Username C
Sandra                   OpenID?

                                   OAuth?




                                            24
Single Sign On   Future-ready




                    No upgrade
  Secure          existing licenses
Username
         OTP
Sandra




                    27
Easy
                   Future
 management of
 Secure
    licenses        ready




                    Easy
   SSO              user          1 login
                     No
                 management
                 administration
                   overload




Convenient            …



                                            28
New
 Existing
customer       Customer




            User Management
Security
John Forbes
  Manager




              Customer




                         30
31
Protection web
   applications         Alice Malley
                      Account Manager




Consultants leaving
    company




                                    32
Which applications?




 How many users?




                      33
7




70




                40                30



     Employee        Consultant        34
Username
         OTP
Dennis




                    36
1 central
        point




       Secure     Future
SSO
                  proof




         …



                           37
Existing         New              New
customer        Customer         Customer




Security    User Management   helpdesk costs
Marc Celis
IT Manager




              39
David Gomez
Password issues
                  Account manager




 Helpdesk cost




                                40
Which applications?




 How many users?




                      41
7
             Soft       HR portal      My
             skills                 employees




             Training    Training    Training
             Credits      Tracks       offer




5120




                  120                     5000




       Employee              Associates          42
Complaints?

Login = annoying




  What’s my
                   SSO = solution?
  password?




                                     43
44
44
Soft
                    skills




                  HR portal




                    Training
                    Credits




       Username    Training
                    Tracks
       Password
Lisa
                  Training
                    offer



                     My
                  employees




                               45
                               45
1 central    Decrease
    point        TCO




                 Easy
  1 login        user
              management




Convenient



                           46
47
47
Soft
                    skills




                  HR portal




                    Training
                    Credits




       Username    Training
                    Tracks
       OTP
Lisa
                  Training
                    offer



                     My
                  employees




                               48
                               48
1 central    Decrease
   point        TCO




                Easy
  1 login       user
             management




Convenient    Security



                          49
                          49
120              5000




Employee         B2B associates




 User license?
           120               5000



                                    Security
Employee          B2B associates




                                               50
                                               50
Security ?




               5000




    B2B associates




                      51
                      51
Soft
             5000                skills


                    Username
                    Password   HR portal
B2B associates



                                 Training
                                 Credits

             120

                    Username    Training
                                 Tracks
                    OTP
  Employee

                               Training
                                 offer



                                  My
                               employees




                                            52
                                            52
53
Soft
             5000                skills


                    Username
                    Password
                    OTP        HR portal
B2B associates



                                 Training
                                 Credits

             120

                    Username    Training
                                 Tracks
                    OTP
  Employee

                               Training
                                 offer



                                  My
                               employees




                                            54
                                            54
1 central      Future
    point         ready        decrease
                                 TCO




                 Easy
    SSO          user          Secure
              management




Convenient    Cost effective



                                          55
                                          55
Existing         New              New
customer        Customer         Customer




                              helpdesk costs
Security    User Management
                              B2B associates
Define Title in Insert Header/Footer Slide   57

Weitere ähnliche Inhalte

Ähnlich wie Reduce Password Fatigue and Improve Security with Single Sign-On

Cisco Study: State of Web Security
Cisco Study: State of Web Security Cisco Study: State of Web Security
Cisco Study: State of Web Security Cisco Canada
 
Cisco tec chris young - security intelligence operations
Cisco tec   chris young - security intelligence operationsCisco tec   chris young - security intelligence operations
Cisco tec chris young - security intelligence operationsCisco Public Relations
 
Kappa data fun in the sun lux 21022013
Kappa data fun in the sun lux 21022013Kappa data fun in the sun lux 21022013
Kappa data fun in the sun lux 21022013Kappa Data
 
Kappa data corporate preso v2 luxembourg 2013
Kappa data corporate preso v2 luxembourg 2013Kappa data corporate preso v2 luxembourg 2013
Kappa data corporate preso v2 luxembourg 2013Kappa Data
 
Roger boesch xen desktop mit cisco
Roger boesch xen desktop mit ciscoRoger boesch xen desktop mit cisco
Roger boesch xen desktop mit ciscoDigicomp Academy AG
 
How to Implement Cloud Security: The Nuts and Bolts of Novell Cloud Security ...
How to Implement Cloud Security: The Nuts and Bolts of Novell Cloud Security ...How to Implement Cloud Security: The Nuts and Bolts of Novell Cloud Security ...
How to Implement Cloud Security: The Nuts and Bolts of Novell Cloud Security ...Novell
 
Network Infrastructure Virtualization Case Study
Network Infrastructure Virtualization Case StudyNetwork Infrastructure Virtualization Case Study
Network Infrastructure Virtualization Case StudyCisco Canada
 
Cat6500 Praesentation
Cat6500 PraesentationCat6500 Praesentation
Cat6500 PraesentationSophan_Pheng
 
Geospatial Community Cloud Vision
Geospatial Community Cloud VisionGeospatial Community Cloud Vision
Geospatial Community Cloud VisionDaneyon Hansen
 
The Zero Trust Model of Information Security
The Zero Trust Model of Information Security The Zero Trust Model of Information Security
The Zero Trust Model of Information Security Tripwire
 
Federal VMUG - March - Reflex VMC Overview
Federal VMUG - March - Reflex VMC OverviewFederal VMUG - March - Reflex VMC Overview
Federal VMUG - March - Reflex VMC Overviewlangonej
 
Over the Air 2011 Security Workshop
Over the Air 2011 Security Workshop Over the Air 2011 Security Workshop
Over the Air 2011 Security Workshop Ericsson Labs
 
ccmigration_09186a008033a3b4
ccmigration_09186a008033a3b4ccmigration_09186a008033a3b4
ccmigration_09186a008033a3b4guest66dc5f
 
DSS ITSEC Conference 2012 - VASCO Authenticates The World
DSS ITSEC Conference 2012 - VASCO Authenticates The WorldDSS ITSEC Conference 2012 - VASCO Authenticates The World
DSS ITSEC Conference 2012 - VASCO Authenticates The WorldAndris Soroka
 
Security & Governance for the Cloud: a Savvis Case Study (Presented at Cloud ...
Security & Governance for the Cloud: a Savvis Case Study (Presented at Cloud ...Security & Governance for the Cloud: a Savvis Case Study (Presented at Cloud ...
Security & Governance for the Cloud: a Savvis Case Study (Presented at Cloud ...CA API Management
 
Sogeti Cloud Seminar Identity In The Clouds
Sogeti Cloud Seminar   Identity In The CloudsSogeti Cloud Seminar   Identity In The Clouds
Sogeti Cloud Seminar Identity In The CloudsRon Moerman
 
Virtual Data Centers with OpenStack Quantum
Virtual Data Centers with OpenStack QuantumVirtual Data Centers with OpenStack Quantum
Virtual Data Centers with OpenStack Quantumlaurabeckcahoon
 
Virtual data centers with OpenStack Quantum
Virtual data centers with OpenStack QuantumVirtual data centers with OpenStack Quantum
Virtual data centers with OpenStack QuantumLew Tucker
 
Cisco Cloud Briefing and Experiences for Cloud Slam 2011
Cisco Cloud Briefing and Experiences for Cloud Slam 2011Cisco Cloud Briefing and Experiences for Cloud Slam 2011
Cisco Cloud Briefing and Experiences for Cloud Slam 2011Cisco Collaboration
 

Ähnlich wie Reduce Password Fatigue and Improve Security with Single Sign-On (20)

Cisco Study: State of Web Security
Cisco Study: State of Web Security Cisco Study: State of Web Security
Cisco Study: State of Web Security
 
Cisco tec chris young - security intelligence operations
Cisco tec   chris young - security intelligence operationsCisco tec   chris young - security intelligence operations
Cisco tec chris young - security intelligence operations
 
Kappa data fun in the sun lux 21022013
Kappa data fun in the sun lux 21022013Kappa data fun in the sun lux 21022013
Kappa data fun in the sun lux 21022013
 
Kappa data corporate preso v2 luxembourg 2013
Kappa data corporate preso v2 luxembourg 2013Kappa data corporate preso v2 luxembourg 2013
Kappa data corporate preso v2 luxembourg 2013
 
Roger boesch xen desktop mit cisco
Roger boesch xen desktop mit ciscoRoger boesch xen desktop mit cisco
Roger boesch xen desktop mit cisco
 
How to Implement Cloud Security: The Nuts and Bolts of Novell Cloud Security ...
How to Implement Cloud Security: The Nuts and Bolts of Novell Cloud Security ...How to Implement Cloud Security: The Nuts and Bolts of Novell Cloud Security ...
How to Implement Cloud Security: The Nuts and Bolts of Novell Cloud Security ...
 
Network Infrastructure Virtualization Case Study
Network Infrastructure Virtualization Case StudyNetwork Infrastructure Virtualization Case Study
Network Infrastructure Virtualization Case Study
 
Cat6500 Praesentation
Cat6500 PraesentationCat6500 Praesentation
Cat6500 Praesentation
 
Geospatial Community Cloud Vision
Geospatial Community Cloud VisionGeospatial Community Cloud Vision
Geospatial Community Cloud Vision
 
Monetizing the Enterprise: Borderless Networks
Monetizing the Enterprise: Borderless NetworksMonetizing the Enterprise: Borderless Networks
Monetizing the Enterprise: Borderless Networks
 
The Zero Trust Model of Information Security
The Zero Trust Model of Information Security The Zero Trust Model of Information Security
The Zero Trust Model of Information Security
 
Federal VMUG - March - Reflex VMC Overview
Federal VMUG - March - Reflex VMC OverviewFederal VMUG - March - Reflex VMC Overview
Federal VMUG - March - Reflex VMC Overview
 
Over the Air 2011 Security Workshop
Over the Air 2011 Security Workshop Over the Air 2011 Security Workshop
Over the Air 2011 Security Workshop
 
ccmigration_09186a008033a3b4
ccmigration_09186a008033a3b4ccmigration_09186a008033a3b4
ccmigration_09186a008033a3b4
 
DSS ITSEC Conference 2012 - VASCO Authenticates The World
DSS ITSEC Conference 2012 - VASCO Authenticates The WorldDSS ITSEC Conference 2012 - VASCO Authenticates The World
DSS ITSEC Conference 2012 - VASCO Authenticates The World
 
Security & Governance for the Cloud: a Savvis Case Study (Presented at Cloud ...
Security & Governance for the Cloud: a Savvis Case Study (Presented at Cloud ...Security & Governance for the Cloud: a Savvis Case Study (Presented at Cloud ...
Security & Governance for the Cloud: a Savvis Case Study (Presented at Cloud ...
 
Sogeti Cloud Seminar Identity In The Clouds
Sogeti Cloud Seminar   Identity In The CloudsSogeti Cloud Seminar   Identity In The Clouds
Sogeti Cloud Seminar Identity In The Clouds
 
Virtual Data Centers with OpenStack Quantum
Virtual Data Centers with OpenStack QuantumVirtual Data Centers with OpenStack Quantum
Virtual Data Centers with OpenStack Quantum
 
Virtual data centers with OpenStack Quantum
Virtual data centers with OpenStack QuantumVirtual data centers with OpenStack Quantum
Virtual data centers with OpenStack Quantum
 
Cisco Cloud Briefing and Experiences for Cloud Slam 2011
Cisco Cloud Briefing and Experiences for Cloud Slam 2011Cisco Cloud Briefing and Experiences for Cloud Slam 2011
Cisco Cloud Briefing and Experiences for Cloud Slam 2011
 

Mehr von VASCO Data Security (11)

Increasing your mobile banking business
Increasing your mobile banking businessIncreasing your mobile banking business
Increasing your mobile banking business
 
MYDIGIPASS.COM leaflet
MYDIGIPASS.COM leafletMYDIGIPASS.COM leaflet
MYDIGIPASS.COM leaflet
 
We Authenticate the World
We Authenticate the WorldWe Authenticate the World
We Authenticate the World
 
Secure Online Banking
Secure Online BankingSecure Online Banking
Secure Online Banking
 
Secure your Business
Secure your BusinessSecure your Business
Secure your Business
 
Identikey
IdentikeyIdentikey
Identikey
 
How to successfully implement a secure mobile strategy
How to successfully implement a secure mobile strategyHow to successfully implement a secure mobile strategy
How to successfully implement a secure mobile strategy
 
aXsGuard Gatekeeper
aXsGuard GatekeeperaXsGuard Gatekeeper
aXsGuard Gatekeeper
 
DIGIPASS for Apps
DIGIPASS for AppsDIGIPASS for Apps
DIGIPASS for Apps
 
Infosec1november
Infosec1novemberInfosec1november
Infosec1november
 
Infosec31october
Infosec31octoberInfosec31october
Infosec31october
 

Kürzlich hochgeladen

DSPy a system for AI to Write Prompts and Do Fine Tuning
DSPy a system for AI to Write Prompts and Do Fine TuningDSPy a system for AI to Write Prompts and Do Fine Tuning
DSPy a system for AI to Write Prompts and Do Fine TuningLars Bell
 
The Role of FIDO in a Cyber Secure Netherlands: FIDO Paris Seminar.pptx
The Role of FIDO in a Cyber Secure Netherlands: FIDO Paris Seminar.pptxThe Role of FIDO in a Cyber Secure Netherlands: FIDO Paris Seminar.pptx
The Role of FIDO in a Cyber Secure Netherlands: FIDO Paris Seminar.pptxLoriGlavin3
 
Streamlining Python Development: A Guide to a Modern Project Setup
Streamlining Python Development: A Guide to a Modern Project SetupStreamlining Python Development: A Guide to a Modern Project Setup
Streamlining Python Development: A Guide to a Modern Project SetupFlorian Wilhelm
 
New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024BookNet Canada
 
SIP trunking in Janus @ Kamailio World 2024
SIP trunking in Janus @ Kamailio World 2024SIP trunking in Janus @ Kamailio World 2024
SIP trunking in Janus @ Kamailio World 2024Lorenzo Miniero
 
SAP Build Work Zone - Overview L2-L3.pptx
SAP Build Work Zone - Overview L2-L3.pptxSAP Build Work Zone - Overview L2-L3.pptx
SAP Build Work Zone - Overview L2-L3.pptxNavinnSomaal
 
Hyperautomation and AI/ML: A Strategy for Digital Transformation Success.pdf
Hyperautomation and AI/ML: A Strategy for Digital Transformation Success.pdfHyperautomation and AI/ML: A Strategy for Digital Transformation Success.pdf
Hyperautomation and AI/ML: A Strategy for Digital Transformation Success.pdfPrecisely
 
"ML in Production",Oleksandr Bagan
"ML in Production",Oleksandr Bagan"ML in Production",Oleksandr Bagan
"ML in Production",Oleksandr BaganFwdays
 
DevEX - reference for building teams, processes, and platforms
DevEX - reference for building teams, processes, and platformsDevEX - reference for building teams, processes, and platforms
DevEX - reference for building teams, processes, and platformsSergiu Bodiu
 
Connect Wave/ connectwave Pitch Deck Presentation
Connect Wave/ connectwave Pitch Deck PresentationConnect Wave/ connectwave Pitch Deck Presentation
Connect Wave/ connectwave Pitch Deck PresentationSlibray Presentation
 
TeamStation AI System Report LATAM IT Salaries 2024
TeamStation AI System Report LATAM IT Salaries 2024TeamStation AI System Report LATAM IT Salaries 2024
TeamStation AI System Report LATAM IT Salaries 2024Lonnie McRorey
 
Are Multi-Cloud and Serverless Good or Bad?
Are Multi-Cloud and Serverless Good or Bad?Are Multi-Cloud and Serverless Good or Bad?
Are Multi-Cloud and Serverless Good or Bad?Mattias Andersson
 
Nell’iperspazio con Rocket: il Framework Web di Rust!
Nell’iperspazio con Rocket: il Framework Web di Rust!Nell’iperspazio con Rocket: il Framework Web di Rust!
Nell’iperspazio con Rocket: il Framework Web di Rust!Commit University
 
DevoxxFR 2024 Reproducible Builds with Apache Maven
DevoxxFR 2024 Reproducible Builds with Apache MavenDevoxxFR 2024 Reproducible Builds with Apache Maven
DevoxxFR 2024 Reproducible Builds with Apache MavenHervé Boutemy
 
Take control of your SAP testing with UiPath Test Suite
Take control of your SAP testing with UiPath Test SuiteTake control of your SAP testing with UiPath Test Suite
Take control of your SAP testing with UiPath Test SuiteDianaGray10
 
Passkey Providers and Enabling Portability: FIDO Paris Seminar.pptx
Passkey Providers and Enabling Portability: FIDO Paris Seminar.pptxPasskey Providers and Enabling Portability: FIDO Paris Seminar.pptx
Passkey Providers and Enabling Portability: FIDO Paris Seminar.pptxLoriGlavin3
 
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024BookNet Canada
 
Commit 2024 - Secret Management made easy
Commit 2024 - Secret Management made easyCommit 2024 - Secret Management made easy
Commit 2024 - Secret Management made easyAlfredo García Lavilla
 
Ensuring Technical Readiness For Copilot in Microsoft 365
Ensuring Technical Readiness For Copilot in Microsoft 365Ensuring Technical Readiness For Copilot in Microsoft 365
Ensuring Technical Readiness For Copilot in Microsoft 3652toLead Limited
 

Kürzlich hochgeladen (20)

DSPy a system for AI to Write Prompts and Do Fine Tuning
DSPy a system for AI to Write Prompts and Do Fine TuningDSPy a system for AI to Write Prompts and Do Fine Tuning
DSPy a system for AI to Write Prompts and Do Fine Tuning
 
DMCC Future of Trade Web3 - Special Edition
DMCC Future of Trade Web3 - Special EditionDMCC Future of Trade Web3 - Special Edition
DMCC Future of Trade Web3 - Special Edition
 
The Role of FIDO in a Cyber Secure Netherlands: FIDO Paris Seminar.pptx
The Role of FIDO in a Cyber Secure Netherlands: FIDO Paris Seminar.pptxThe Role of FIDO in a Cyber Secure Netherlands: FIDO Paris Seminar.pptx
The Role of FIDO in a Cyber Secure Netherlands: FIDO Paris Seminar.pptx
 
Streamlining Python Development: A Guide to a Modern Project Setup
Streamlining Python Development: A Guide to a Modern Project SetupStreamlining Python Development: A Guide to a Modern Project Setup
Streamlining Python Development: A Guide to a Modern Project Setup
 
New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
 
SIP trunking in Janus @ Kamailio World 2024
SIP trunking in Janus @ Kamailio World 2024SIP trunking in Janus @ Kamailio World 2024
SIP trunking in Janus @ Kamailio World 2024
 
SAP Build Work Zone - Overview L2-L3.pptx
SAP Build Work Zone - Overview L2-L3.pptxSAP Build Work Zone - Overview L2-L3.pptx
SAP Build Work Zone - Overview L2-L3.pptx
 
Hyperautomation and AI/ML: A Strategy for Digital Transformation Success.pdf
Hyperautomation and AI/ML: A Strategy for Digital Transformation Success.pdfHyperautomation and AI/ML: A Strategy for Digital Transformation Success.pdf
Hyperautomation and AI/ML: A Strategy for Digital Transformation Success.pdf
 
"ML in Production",Oleksandr Bagan
"ML in Production",Oleksandr Bagan"ML in Production",Oleksandr Bagan
"ML in Production",Oleksandr Bagan
 
DevEX - reference for building teams, processes, and platforms
DevEX - reference for building teams, processes, and platformsDevEX - reference for building teams, processes, and platforms
DevEX - reference for building teams, processes, and platforms
 
Connect Wave/ connectwave Pitch Deck Presentation
Connect Wave/ connectwave Pitch Deck PresentationConnect Wave/ connectwave Pitch Deck Presentation
Connect Wave/ connectwave Pitch Deck Presentation
 
TeamStation AI System Report LATAM IT Salaries 2024
TeamStation AI System Report LATAM IT Salaries 2024TeamStation AI System Report LATAM IT Salaries 2024
TeamStation AI System Report LATAM IT Salaries 2024
 
Are Multi-Cloud and Serverless Good or Bad?
Are Multi-Cloud and Serverless Good or Bad?Are Multi-Cloud and Serverless Good or Bad?
Are Multi-Cloud and Serverless Good or Bad?
 
Nell’iperspazio con Rocket: il Framework Web di Rust!
Nell’iperspazio con Rocket: il Framework Web di Rust!Nell’iperspazio con Rocket: il Framework Web di Rust!
Nell’iperspazio con Rocket: il Framework Web di Rust!
 
DevoxxFR 2024 Reproducible Builds with Apache Maven
DevoxxFR 2024 Reproducible Builds with Apache MavenDevoxxFR 2024 Reproducible Builds with Apache Maven
DevoxxFR 2024 Reproducible Builds with Apache Maven
 
Take control of your SAP testing with UiPath Test Suite
Take control of your SAP testing with UiPath Test SuiteTake control of your SAP testing with UiPath Test Suite
Take control of your SAP testing with UiPath Test Suite
 
Passkey Providers and Enabling Portability: FIDO Paris Seminar.pptx
Passkey Providers and Enabling Portability: FIDO Paris Seminar.pptxPasskey Providers and Enabling Portability: FIDO Paris Seminar.pptx
Passkey Providers and Enabling Portability: FIDO Paris Seminar.pptx
 
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
 
Commit 2024 - Secret Management made easy
Commit 2024 - Secret Management made easyCommit 2024 - Secret Management made easy
Commit 2024 - Secret Management made easy
 
Ensuring Technical Readiness For Copilot in Microsoft 365
Ensuring Technical Readiness For Copilot in Microsoft 365Ensuring Technical Readiness For Copilot in Microsoft 365
Ensuring Technical Readiness For Copilot in Microsoft 365
 

Reduce Password Fatigue and Improve Security with Single Sign-On

  • 2. http://your.intranet.com your. intranet.com john.doe@vasco.com Y ******** © 2013 - VASCO Data Security IDENTIKEY Federation Server Workshop 2
  • 3. http://your.intranet.com your domain your. intranet.com Y … © 2013 - VASCO Data Security IDENTIKEY Federation Server Workshop 3
  • 4. your domain Identity Service © 2013 - VASCO Data Security IDENTIKEY Federation Server Workshop 4
  • 5. your domain SAML Identity Service © 2013 - VASCO Data Security IDENTIKEY Federation Server Workshop 5
  • 6. your domain Reduces Identity $ Management Costs © 2013 - VASCO Data Security IDENTIKEY Federation Server Workshop 6
  • 7. your domain © 2013 - VASCO Data Security IDENTIKEY Federation Server Workshop 7
  • 8. your domain © 2013 - VASCO Data Security IDENTIKEY Federation Server Workshop 8
  • 9. your the domain cloud … © 2013 - VASCO Data Security IDENTIKEY Federation Server Workshop 9
  • 10. your the domain cloud Authentication … Identity Service Users DIGIPASS © 2013 - VASCO Data Security IDENTIKEY Federation Server Workshop 10
  • 11. Yes you can 8 Can I access? 1 Please Login @ … Jack 6 A Service Ticket ? 7 3 Authentication 2 OTP ? 4 Identity Identity 5 Authentication Service Jack © 2013 - VASCO Data Security IDENTIKEY Federation Server Workshop 11
  • 12. User A Service 2 Ticket Identity Authentication Ticket ? 4 3 Please Login @ … Can I access? 1 B Jack Service Yes you can 5 © 2013 - VASCO Data Security IDENTIKEY Federation Server Workshop 12
  • 13. Identity Identity Authentication © 2013 - VASCO Data Security IDENTIKEY Federation Server Workshop 13
  • 14. Identity One Family Identity Authentication Identity Server Federation SAML © 2013 - VASCO Data Security IDENTIKEY Federation Server Workshop 14
  • 15. IFS: The selling story Raf Van Ermengem Trainer
  • 16. Existing New New customer Customer Customer helpdesk costs Security User Management B2B associates
  • 18. Remote access OWA 25 18
  • 19. Protect all company Brent Kehl applications with Account Manager 19
  • 20. Which applications? How many users?
  • 21. 5 80 25 40 15 Sales Admin Technical 21
  • 22. I don’t talk RADIUS 25 Sales 40 Admin Upgrade license to Enterprise 15 Technical Selling 55 user licenses Enterprise Selling 55 DIGIPASS Authenticators 22
  • 23. Username & OTP Check OTP Sandra 23
  • 24. SAML? SOAP? Username C ? Username A Username C Sandra OpenID? OAuth? 24
  • 25. Single Sign On Future-ready No upgrade Secure existing licenses
  • 26.
  • 27. Username OTP Sandra 27
  • 28. Easy Future management of Secure licenses ready Easy SSO user 1 login No management administration overload Convenient … 28
  • 29. New Existing customer Customer User Management Security
  • 30. John Forbes Manager Customer 30
  • 31. 31
  • 32. Protection web applications Alice Malley Account Manager Consultants leaving company 32
  • 33. Which applications? How many users? 33
  • 34. 7 70 40 30 Employee Consultant 34
  • 35.
  • 36. Username OTP Dennis 36
  • 37. 1 central point Secure Future SSO proof … 37
  • 38. Existing New New customer Customer Customer Security User Management helpdesk costs
  • 40. David Gomez Password issues Account manager Helpdesk cost 40
  • 41. Which applications? How many users? 41
  • 42. 7 Soft HR portal My skills employees Training Training Training Credits Tracks offer 5120 120 5000 Employee Associates 42
  • 43. Complaints? Login = annoying What’s my SSO = solution? password? 43
  • 44. 44 44
  • 45. Soft skills HR portal Training Credits Username Training Tracks Password Lisa Training offer My employees 45 45
  • 46. 1 central Decrease point TCO Easy 1 login user management Convenient 46
  • 47. 47 47
  • 48. Soft skills HR portal Training Credits Username Training Tracks OTP Lisa Training offer My employees 48 48
  • 49. 1 central Decrease point TCO Easy 1 login user management Convenient Security 49 49
  • 50. 120 5000 Employee B2B associates User license? 120 5000 Security Employee B2B associates 50 50
  • 51. Security ? 5000 B2B associates 51 51
  • 52. Soft 5000 skills Username Password HR portal B2B associates Training Credits 120 Username Training Tracks OTP Employee Training offer My employees 52 52
  • 53. 53
  • 54. Soft 5000 skills Username Password OTP HR portal B2B associates Training Credits 120 Username Training Tracks OTP Employee Training offer My employees 54 54
  • 55. 1 central Future point ready decrease TCO Easy SSO user Secure management Convenient Cost effective 55 55
  • 56. Existing New New customer Customer Customer helpdesk costs Security User Management B2B associates
  • 57. Define Title in Insert Header/Footer Slide 57

Hinweis der Redaktion

  1. The IT security problem of today:Password Fatigation
  2. This is a classic login screen on your intranet, a way of getting access using a username and password.
  3. Besides the intranet your company is also offering other internalapplications that require an additional login.
  4. Applications with the main purpose of offering a service to a select user group and therefor storing identities, in the form of a username and password.
  5. “Provider” is a generic way of referring to both IdP’s (Identity Providers) and SP’s (Service Providers). There are overlaps when it comes to defining Identity providers vs. Service Providers. According to the OASIS (organization) that created SAML an Identity provider is defined as “A kind of provider that creates, maintains, and manages identity information for principals and provides principal authentication to other service providers within a federation, such as with web browser profiles.” A Service provider is “A role donned by a system entity where the system entity provides services to principals or other system entities” and a Federation is “An association comprising any number of service providers and identity providers.”
  6. In simple terms and as they relate to identity management an Identity provider can be described as a Service Provider for storing identity profiles and offering incentives to other SP’s with the aim of federating user identities. It should be noted however that Identity Providers can also provide services beyond those related to the storage of identity profiles. This way reducing the cost for identity management.
  7. Single sign-on (SSO) is a property of access control of multiple related, but independent software systems. With this property a user logs in once and gains access to all systems without being prompted to log in again at each of them. Conversely, Single sign-off is the property whereby a single action of signing out terminates access to multiple software systems. As different applications and resources support different authentication mechanisms, single sign-on has to internally translate to and store different credentials compared to what is used for initial authentication. Single sign-on requires that users literally sign in once to establish their credentials. Systems which require the user to log in multiple times to the same identity are inherently not single sign-on. For example, an environment where users are prompted to log in to their desktop, then log in to their email using the same credentials, is not single sign-on.
  8. As single sign-on provides access to many resources once the user is initially authenticated ("keys to the castle") it increases the negative impact in case the credentials are available to other persons and misused. Therefore, single sign-on requires an increased focus on the protection of the user credentials, and should ideally be combined with strong authentication methods like smart cards and one-time password tokens.
  9. FIdM, or the "federation" of identity, describes the technologies, standards and use-cases which serve to enable the portability of identity information across otherwise autonomous security domains. The ultimate goal of identity federation is to enable users of one domain to securely access data or systems of another domain seamlessly, and without the need for completely redundant user administration. Identity federation comes in many flavors, including "user-controlled" or "user-centric" scenarios, as well as enterprise controlled or B2B scenarios.
  10. Digital identity platforms that allow users to log onto third-party websites, applications, mobile devices and gaming systems with their existing identity, i.e. enable social login.Social login, allows public access for your application, without the need of managing their Identity.
  11. Hello everybody. Let’s give you some help to sell the IDENTIKEY Federation Server.
  12. We will go through 3 case studies.First one:An existing customer who has a security concernSecond one:A new customer who has some issues with User ManagementAnd the last one:A customer who likes to decrease the helpdesk costs.Fasten your seatbelts, let’s start with the first case.
  13. Let’s say hi to Catherine Falcke. She is the CEO of “Beyond the door”.This company is situated in selling and placing doors, garage doors, skylights, window security,…More than 100 employees are working for this company.
  14. Good to know is that the company already uses the VASCO IDENTIKEY Authentication Server to protect the remote access for the Sales PeopleAlready customer of VASCO?Yes. 3 years ago a VASCO reseller sold and installedan IDENTIKEY Authentication Server.Reason: Protection of the remote access for the complete Sales team (25 persons)Protection of the OWA for the complete Sales teamQ: Which edition of IDENTIKEY Authentication Server did the reseller sold?IK Gold, for the web filters
  15. She remembers, during a previous contact, that it’s no problem to protect also all the web based applications with a OTP.So she setup a meeting with Brent Kehl from Easysis, her dedicated reseller.
  16. Now we need to get more information from MssFalcke.How many applications are you using?Who has access to these applications?
  17. Well, we have in total 5 different web based applications:Sharepoint, OWA, hardware inventory (Baramundi), Salesforce and SecurexThe last 2 are cloud based solutions. I hope this is not a problem?All these applications are protected with static passwordsWho has access to these applications?Besides all the 25 sales people, also my complete administrative staff (40 persons) and some technical guys (15 persons)So, in total 80 employees have access to all the internal applications.
  18. Brent listened very carefully, thought about it, and came up with a solution!Dear Mss. Falcke, Thanks to the fact that you are already working with a VASCO solution, it is actually simple.Let me explain how:We will upgrade the 25 user licenses of the sales people from a Gold to an Enterprise editionYou need to buy 55 extra user licenses, Enterprise EditionAnd 55 DIGIPASS Authenticators, for the administrative staff and technical guys.
  19. And how does this work in real life.Say hi to Sandra. Sandra is an administrative person. As from today, she has a secured access to the web based applications, thanks to IK Authentication Server.So each day, time she needs to login on each site with a OTP. Not really convenient!?Can we offer an even more convenient solution?
  20. We can do better than this. Just keep the next concerns in mind:Each day Sandra, and the others, need to log in in different applications = annoyingIs she using, on each application the same username?Are all the web based applications talking SOAP? Or SAML? Oauth, …More and more applications are cloud based. So there is a big chance that this company will work in the future with extra applications.Upgrade of user licenses, can be hard to sell. And even than, you are not sure that it can work (SAML, Oauth, ….)
  21. So, let’s give them a solution:Whereby we offer the end user a SSOWhereby security Which is future-ready:Extra applications  No problemApplications talking SAML, REST, Oauth, SOAP  can be easily integrated.Which on not need an upgrade of existing licenses.
  22. Well, we can offer a solution which take care of all these topics: IDENTIKEY Authentication Server, in combination with IDENTIKEY Federation Server.And the good news is that they belong to the same familyOK, but how will it look like?
  23. So, thanks to the combination of IK authentication server and Federation Server, we offer the end user a secure and convenient solution.
  24. So,The IDENTIKEY Authentication Server, in combination with the IDENTIKEY Federation Server, offers the customer a lot of advantagesFor the end user:1 login to access all the applicationsLogin is secured by a One Time PasswordFor the company, and more specific, the IT-people:1 central point to manage all the usersNo administration overloadEasy management of licenses
  25. Brief recapitulation:Case 1 :An existing IK Authentication customer.Request for securing web based applicationsSolution IK authentication and Federation ServerCase 2:New customerWeb based applications – scared of hackingSolution: IK authentication and Federation ServerCase 3:New customerWeb based applications – Likes to be a differentiatorSolution: IK authentication, Federation Server and MYDIGIGIPASS.COM
  26. The company QuickMedia is situated in the marketing vertical.They offer their customers:Social Media Marketing CampaignsSEO solutions (Search Engine Optimization)Content marketingHelp to convert website visits into customers…
  27. John is concerned about confidentiality. All the company applications are accessible via an username and password.So, he is scared that someone could have access to the internal databases of the company (without knowing it)
  28. QuickMedia invited Alice Malley, a reseller of VASCO.John will explain that he likes to have a secure solution for his web based applications.Another concern he has, is about the consultants. He is not always sure that, when they leave the company, the access on each website is blocked.@Peter Vervloedt: Gartner report regarding the time it takes before an ex-employee is bloc
  29. Well, and again, we must ask these 2 questions:Which applications would you like to protect?And how many persons are using these applications?
  30. Well, we have in total 7 different web based application running.The customer has in total 7 different applications running:3 managed internallySharepointWordPress (for blogs)SAP (Management of data)3 managed externallyOffice 365HRnetSource (online HR portal)EPAY (Cloud based time tracking tool)Salesforce50 people or working in our company. 40 of them are on the Payroll of QuickMedia, the other 10 are consultants.
  31. Alice can offer John a great solution: IFS together with the IAS.Q&AWhich solution can we offer? And Why?IAS in combination with IFSSecure (OTP) and simple user management (for blocking leaving people)What was the request again?Security and blocking consultants
  32. So, thanks to the combination of IK authentication server and Federation Server, we offer the end user a secure and convenient solution.
  33. So,The IDENTIKEY Authentication Server, in combination with the IDENTIKEY Federation Server, offers the customer a lot of advantagesFor the end user:Login is secured by a One Time PasswordFor the company, and more specific, the IT-people:1 central point to manage all the usersNo administration overloadEasy blocking consultants who are leaving the company
  34. Brief recapitulation:Case 1 :An existing IK Authentication customer.Request for securing web based applicationsSolution IK authentication and Federation ServerCase 2:New customerWeb based applications – scared of hackingSolution: IK authentication and Federation ServerCase 3:New customerWeb based applications – Likes to be a differentiatorSolution: IK authentication, Federation Server and MYDIGIGIPASS.COM
  35. Marc Celis is the IT manager of EduSocra. This company is offering HR-managers, of several companies in France, online tools to create/follow up, … training tracks of their employees.Good to know is that they are linked (financially) with the national government.
  36. As an IT manager, Marc sees that 40% of the IT tickets are created because of password issues.Since they changed the password policy (stronger).This implicates also that the workload of the IT-department increases. EduSocra even took the recruitment of 2 new IT administrators in consideration.
  37. Can you give me more information about the applications and the people who are using these?
  38. We have in total 7 different applications. All internally managed, except Google apps.All the internal applications are “house made” and accessible by the B2B associates as well as the employees.In total 5120 persons are using the online applications.From the 5120 people, 120 are employees of EduSocra.
  39. Justin: As far I can see, your company has setup a great solution for their employees and B2B-associates.Nevertheless, are people having complaints about this way of working?Marc: We hear more and more people complaining about the login on each website.They very often forget their username, password. This increases the workload of the IT staff.And keep also in mind that people are very impatient these days. The like to have a solution asap.
  40. Mr. Celis, we can offer you the IDENTIKEY Federation Server. With this solution you will create a SSO-solution for your employees as well for your B2B-associates.
  41. So, if it’s one of your employees or a business associate, they need to fill in only one their username and password.It’s a very convenient solution.But sorry, this is also a very dangerous solution!
  42. Well, this is a really great solution and very convenient for the end user and IT administrators.But there is a major security risk!! All the web based applications are accessible with a username and same static password.
  43. Get rid of these static passwords!! Combine the IDENTIKEY Federation Server together with the IDENTIKEY Authentication Server.Which IDENTIKEY Authentication Server?Is already possible with a standard edition. Is tricky, no backup license!!
  44. Get rid of these static passwords!! Combine the IDENTIKEY Federation Server together with the IDENTIKEY Authentication Server.Which IDENTIKEY Authentication Server?Is already possible with a standard edition. Is tricky, no backup license!!
  45. Get rid of these static passwords!! Combine the IDENTIKEY Federation Server together with the IDENTIKEY Authentication Server.Which IDENTIKEY Authentication Server?Is already possible with a standard edition. Is tricky, no backup license!!
  46. Marc Celis is convienced of the proposed solution.He has however, some issues with the total cost of this solution.Paying for user licenses on the IFS, for employees and B2B associates no issue.This will decrease the helpdesk costs so acceptablePaying for security? Buying user licenses on IAS for employees:No issueOwn staff  extra cost is acceptable.For the 5000 B2B associates  to expensiveAre they still an associate after 1 year?
  47. Marc Celis is convienced of the proposed solution.He has however, some issues with the total cost of this solution.Paying for user licenses on the IFS, for employees and B2B associates no issue.This will decrease the helpdesk costs so acceptablePaying for security? Buying user licenses on IAS for employees:No issueOwn staff  extra cost is acceptable.For the 5000 B2B associates  to expensiveAre they still an associate after 1 year?
  48. And how would the solution look like?So, the B2B associates will secure login, with a free DIGIPASS authenticator on the MDP-platform.And MYDIGIPASS.COM can easily be linked to the IDENTIKEY Federation Server.
  49. And the name of this solution? MYDIGIPASS.COM
  50. And how would the solution look like?So, the B2B associates will secure login, with a free DIGIPASS authenticator on the MDP-platform.And MYDIGIPASS.COM can easily be linked to the IDENTIKEY Federation Server.
  51. The IDENTIKEY Federation Server offers you a bunch of advantages:1 login to all the applications1 central place to manage the users1 central point to manage leaving employeesSSO increases productivity
  52. Brief recapitulation:Combine the IAS and IFS gives customers a solution for different issues:Focus on SecurityFocus on User ManagementOr Focus on Help desk costs.Case 1 :An existing IK Authentication customer.Request for securing web based applicationsSolution IK authentication and Federation ServerCase 2:New customerWeb based applications – scared of hackingSolution: IK authentication and Federation ServerCase 3:New customerWeb based applications – Likes to be a differentiatorSolution: IK authentication, Federation Server and MYDIGIGIPASS.COM