<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Roger Halbheer on Security &#187; Identity</title>
	<atom:link href="http://www.halbheer.ch/security/tag/identity/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.halbheer.ch/security</link>
	<description>Information Security Discussion by Microsoft&#039;s Worldwide Chief Security Advisor.</description>
	<lastBuildDate>Wed, 16 May 2012 18:03:39 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Office 365 Single Sign-On with AD FS 2.0 whitepaper</title>
		<link>http://www.halbheer.ch/security/2012/03/05/office-365-single-sign-on-with-ad-fs-2-0-whitepaper/</link>
		<comments>http://www.halbheer.ch/security/2012/03/05/office-365-single-sign-on-with-ad-fs-2-0-whitepaper/#comments</comments>
		<pubDate>Mon, 05 Mar 2012 10:39:28 +0000</pubDate>
		<dc:creator>Roger Halbheer</dc:creator>
				<category><![CDATA[Cloud Computing]]></category>
		<category><![CDATA[Industry]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Cloud]]></category>
		<category><![CDATA[Federation]]></category>
		<category><![CDATA[Identity]]></category>

		<guid isPermaLink="false">http://www.halbheer.ch/security/?p=2612</guid>
		<description><![CDATA[<p>Sorry, I did not blog for quite a while. </p> <p>When looking at the Cloud, one of the key challenges to address &#8211; in my opinion &#8211; is how to manage the identity of the different users. If you have to add an additional identity to all the logons you already have, the Cloud will <span style="color:#777"> . . . &#8594; Read More: <a href="http://www.halbheer.ch/security/2012/03/05/office-365-single-sign-on-with-ad-fs-2-0-whitepaper/">Office 365 Single Sign-On with AD FS 2.0 whitepaper</a></span>]]></description>
			<content:encoded><![CDATA[<p>Sorry, I did not blog for quite a while. </p>
<p>When looking at the Cloud, one of the key challenges to address &#8211; in my opinion &#8211; is how to manage the identity of the different users. If you have to add an additional identity to all the logons you already have, the Cloud will just add to the burden. Therefore, I am a firm believer that you need to have federation between your on-premise identity and your cloud identities.</p>
<p>We just released a paper <a href="http://www.microsoft.com/download/en/details.aspx?id=28971" target="_blank">Office 365 Single Sign-On with AD FS 2.0 whitepaper</a> on how to address this with Office 365 and ADFS 2.0:</p>
<blockquote><p>Through its support for the WS-Federation (WS-Fed) and WS-Trust protocols, Microsoft Active Directory Federation Services (AD FS) 2.0 provides claims-based (Web) single sign-on (also known as identity federation) with the Microsoft Office 365 offering and its Web application and rich client applications. </p>
<p>Building on existing documentation, this document is intended to provide a better understanding of the different single sign-on deployment options for the services in services in Office 365, how to enable single sign-on using corporate Active Directory credentials and AD FS 2.0 to the service in Office, and the different configuration elements to be aware of for such deployment.</p>
<p>This document is intended for system architects and IT professionals who are interested in understanding the basics of the single sign-on feature of Office 365 with AD FS 2.0 along with planning and deploying such a deployment in their environment.</p>
</blockquote>
<p>You should have an in-depth look at this</p>
<p>Roger</p>
]]></content:encoded>
			<wfw:commentRss>http://www.halbheer.ch/security/2012/03/05/office-365-single-sign-on-with-ad-fs-2-0-whitepaper/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Is the online world more dangerous?</title>
		<link>http://www.halbheer.ch/security/2010/10/05/is-the-online-world-more-dangerous/</link>
		<comments>http://www.halbheer.ch/security/2010/10/05/is-the-online-world-more-dangerous/#comments</comments>
		<pubDate>Tue, 05 Oct 2010 06:34:27 +0000</pubDate>
		<dc:creator>Roger Halbheer</dc:creator>
				<category><![CDATA[Consumer]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[People]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Children]]></category>
		<category><![CDATA[Identity]]></category>
		<category><![CDATA[Online Safety]]></category>

		<guid isPermaLink="false">http://www.halbheer.info/security/2010/10/05/is-the-online-world-more-dangerous</guid>
		<description><![CDATA[<p>I often hear statements that the risk of losing your identity or being a victim of fraud is much higher online than offline. From my point of view it is more about the feelings of the consumer: In the real world, we know the risks – at least we learned them over the ages from <span style="color:#777"> . . . &#8594; Read More: <a href="http://www.halbheer.ch/security/2010/10/05/is-the-online-world-more-dangerous/">Is the online world more dangerous?</a></span>]]></description>
			<content:encoded><![CDATA[<p>I often hear statements that the risk of losing your identity or being a victim of fraud is much higher online than offline. From my point of view it is more about the feelings of the consumer: In the real world, we know the risks – at least we learned them over the ages from our parents and we learned to live with them. For the average consumer, the Internet is probably 10-15 years all and there is no common sense yet. There is no “we learned to live with the risks” – yet.</p>
<p>We published a paper called <a href="http://go.microsoft.com/?linkid=9746266" target="_blank">Myth vs. Fact: Online and the Real World</a> (this link point to the more secure version in XPS but if you want pdf, <a href="http://go.microsoft.com/?linkid=9746267" target="_blank">here you go</a> <img style="border-bottom-style: none; border-right-style: none; border-top-style: none; border-left-style: none" class="wlEmoticon wlEmoticon-winkingsmile" alt="Winking smile" src="http://www.halbheer.ch/security/wp-content/uploads/2010/10/wlEmoticon-winkingsmile.png">), which I think is worth looking at. If you want to leverage it, feel free.</p>
<p>Roger</p>
]]></content:encoded>
			<wfw:commentRss>http://www.halbheer.ch/security/2010/10/05/is-the-online-world-more-dangerous/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Interpol&#8217;s Chief&#8217;s Facebook Identity Stolen</title>
		<link>http://www.halbheer.ch/security/2010/09/20/interpols-chiefs-facebook-identity-stolen/</link>
		<comments>http://www.halbheer.ch/security/2010/09/20/interpols-chiefs-facebook-identity-stolen/#comments</comments>
		<pubDate>Mon, 20 Sep 2010 12:52:37 +0000</pubDate>
		<dc:creator>Roger Halbheer</dc:creator>
				<category><![CDATA[Crime]]></category>
		<category><![CDATA[Cybercrime]]></category>
		<category><![CDATA[Incidents]]></category>
		<category><![CDATA[Industry]]></category>
		<category><![CDATA[Identity]]></category>

		<guid isPermaLink="false">http://www.halbheer.info/security/2010/09/20/interpols-chiefs-facebook-identity-stolen</guid>
		<description><![CDATA[<p>This is one of the risks, not a lot of people look into: It is fairly easy for me to setup a Facebook account in another person’s name. This is what happened to Ronald K. Noble, head of Interpol: Interpol Chief Ronald K. Noble Has Facebook Identity Stolen.</p> <p>Roger</p> ]]></description>
			<content:encoded><![CDATA[<p>This is one of the risks, not a lot of people look into: It is fairly easy for me to setup a Facebook account in another person’s name. This is what happened to Ronald K. Noble, head of Interpol: <a href="http://www.darknet.org.uk/2010/09/interpol-chief-ronald-k-noble-has-facebook-identity-stolen/">Interpol Chief Ronald K. Noble Has Facebook Identity Stolen</a>.</p>
<p>Roger</p>
]]></content:encoded>
			<wfw:commentRss>http://www.halbheer.ch/security/2010/09/20/interpols-chiefs-facebook-identity-stolen/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Doing the right thing on ID management isn&#039;t enough&#8230;</title>
		<link>http://www.halbheer.ch/security/2010/07/16/doing-the-right-thing-on-id-management-isnt-enough/</link>
		<comments>http://www.halbheer.ch/security/2010/07/16/doing-the-right-thing-on-id-management-isnt-enough/#comments</comments>
		<pubDate>Fri, 16 Jul 2010 19:55:17 +0000</pubDate>
		<dc:creator>Roger Halbheer</dc:creator>
				<category><![CDATA[Cloud Computing]]></category>
		<category><![CDATA[Industry]]></category>
		<category><![CDATA[Trends]]></category>
		<category><![CDATA[Cloud]]></category>
		<category><![CDATA[Identity]]></category>

		<guid isPermaLink="false">http://www.halbheer.info/security/2010/07/16/doing-the-right-thing-on-id-management-isnt-enough</guid>
		<description><![CDATA[<p>Even though it might be obvious, compliance is not only about protecting data but identities as well – and more. Jon Collins, Freeform Dynamics, whom I value high, wrote a good article: Doing the right thing on ID management isn&#8217;t enough&#8230; – you should read it!</p> <p>Roger</p> ]]></description>
			<content:encoded><![CDATA[<p>Even though it might be obvious, compliance is not only about protecting data but identities as well – and more. Jon Collins, Freeform Dynamics, whom I value high, wrote a good article: <a href="http://www.theregister.co.uk/2010/07/16/id_management_compliance/" target="_blank">Doing the right thing on ID management isn&#8217;t enough&#8230;</a> – you should read it!</p>
<p>Roger</p>
]]></content:encoded>
			<wfw:commentRss>http://www.halbheer.ch/security/2010/07/16/doing-the-right-thing-on-id-management-isnt-enough/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Identity in the Cloud</title>
		<link>http://www.halbheer.ch/security/2010/05/25/identity-in-the-cloud/</link>
		<comments>http://www.halbheer.ch/security/2010/05/25/identity-in-the-cloud/#comments</comments>
		<pubDate>Tue, 25 May 2010 19:38:10 +0000</pubDate>
		<dc:creator>Roger Halbheer</dc:creator>
				<category><![CDATA[Cloud Computing]]></category>
		<category><![CDATA[Industry]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Process]]></category>
		<category><![CDATA[Architecture]]></category>
		<category><![CDATA[Cloud]]></category>
		<category><![CDATA[Identity]]></category>
		<category><![CDATA[Processes]]></category>

		<guid isPermaLink="false">http://www.halbheer.info/security/?p=1535</guid>
		<description><![CDATA[<p>Kim Cameron, one of our key identity architects had an interesting presentation on identity in the cloud and a corresponding interview. Both are worth looking at if you are planning to move into the direction of the cloud. Especially as it is definitely one of the key challenges:</p> <p>This is Kim&#8217;s presentation:</p> <p> <p> <p>If <span style="color:#777"> . . . &#8594; Read More: <a href="http://www.halbheer.ch/security/2010/05/25/identity-in-the-cloud/">Identity in the Cloud</a></span>]]></description>
			<content:encoded><![CDATA[<p>Kim Cameron, one of our key identity architects had an interesting presentation on identity in the cloud and a corresponding interview. Both are worth looking at if you are planning to move into the direction of the cloud. Especially as it is definitely one of the key challenges:</p>
<p>This is Kim&#8217;s presentation:</p>
<p> <object data="data:application/x-silverlight-2," type="application/x-silverlight-2" width="560" height="340"><param name="source" value="http://www.microsoft.com/showcase/silverlight/player/1/player-en.xap" /><param name="enableHtmlAccess" value="true" /><param name="background" value="black" /><param name="minRuntimeVersion" value="3.0.40624.0" /><param name="autoUpgrade" value="true" /><param name="initParams" value="Culture=en-GB,Uuid=2c503d1c-9b52-41a7-ab63-dc7d5842c77d,Autoplay=false,MarketingOverlayText=Visit this video's web site,ShowMarketingOverlay=true,ShowMenu=True,Tabs=Embed;Email;Share;Info" /><a href="http://go.microsoft.com/fwlink/?LinkID=149156&amp;v=3.0.40624.0" onmousedown="javascript:new Image().src = 'http://m.webtrends.com/dcsygm2gb10000kf9xm7kfvub_9p1t/dcs.gif?dcsdat=' + new Date().getTime() + '&#038;dcssip=www.microsoft.com&#038;dcsuri=' + window.location.href + '&#038;WT.tz=-8&#038;WT.bh=16&#038;WT.ul=en-GB&#038;WT.cd=32&#038;WT.jo=Yes&#038;WT.ti=&#038;WT.js=Yes&#038;WT.jv=1.5&#038;WT.fi=Yes&#038;WT.fv=10.0&#038;WT.sli=Not%20Installed&#038;WT.slv=Version%20Unavailable&#038;WT.dl=1&#038;WT.seg_1=Not%20Logged%20In&#038;WT.vt_f_a=2&#038;WT.vt_f=2&#038;WT.vt_nvr1=2&#038;WT.vt_nvr2=2&#038;WT.vt_nvr3=2&#038;WT.vt_nvr4=2&#038;vp_site=Embedded&#038;wtEvtSrc=' + window.location.href + '&#038;vp_sli=Embedded'" border="0">     <img src="http://img.microsoft.com/showcase/Content/img/resx/en-GB/installSL.gif" alt="Get Microsoft Silverlight" style="border-style: none" /> </a> <noscript>
<div><img alt="DCSIMG" id="DCSIMG" width="1" height="1" src="http://m.webtrends.com/dcsygm2gb10000kf9xm7kfvub_9p1t/njs.gif?dcsuri=/nojavascript&amp;WT.js=No" /></div>
<p></noscript> </object>
<p>If you want his slides, <a href="http://download.microsoft.com/documents/uk/msdn/architecture/architectinsight/2010/KEY25_Beyond_The_Laws_London.ppt" target="_blank">here they are</a>.</p>
<p>And finally he was interviewed after the presentation. It gives you more insights into our thoughts around identity and identity federation:</p>
<p> <object data="data:application/x-silverlight-2," type="application/x-silverlight-2" width="512" height="384"><param name="source" value="http://channel9.msdn.com/App_Themes/default/VideoPlayer10_01_18.xap" /><param name="initParams" value="deferredLoad=true,duration=0,m=http://ecn.channel9.msdn.com/o9/ch9/6/5/8/5/4/5/TAKIMCAMERON_ch9.wmv,autostart=false,autohide=true,showembed=true, thumbnail=http://ecn.channel9.msdn.com/o9/ch9/6/5/8/5/4/5/TAKIMCAMERON_512_ch9.png, postid=545856" /><param name="background" value="#00FFFFFF" /><a href="http://go.microsoft.com/fwlink/?LinkID=124807" style="text-decoration: none;"> <img src="http://go.microsoft.com/fwlink/?LinkId=108181" alt="Get Microsoft Silverlight" style="border-style: none" /> </a> </object>
<p>Remember, from my point of view, identity processes, management and federation are key ingredients for a successful cloud strategy</p>
<p>Roger</p>
]]></content:encoded>
			<wfw:commentRss>http://www.halbheer.ch/security/2010/05/25/identity-in-the-cloud/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
<enclosure url="http://ecn.channel9.msdn.com/o9/ch9/6/5/8/5/4/5/TAKIMCAMERON_ch9.wmv" length="213446461" type="video/x-ms-wmv" />
		</item>
	</channel>
</rss>

