Sign in
TechNet Blogs
Technet Blog Images
More ...
Common Tasks
Blog Home
Email Blog Author
About
RSS for posts
RSS for comments
Search
Tags
AD FS
ADFS
Certificate Enrollment
Claims
Claims Based Authentication
Cloud Security
Federation
FIM 2010
General
HSPD12
ICAM
Identity
Identity Management
OMB
PIV
PKI
SAML
Security
SharePoint
Smart Card
SSO
UAG
Video
Windows Server 2008
Windows Server 2008 R2
Archives
Archives
September 2012
(1)
August 2012
(1)
June 2012
(1)
March 2012
(1)
January 2012
(2)
November 2011
(1)
October 2011
(4)
September 2011
(3)
August 2011
(3)
May 2011
(1)
February 2011
(10)
January 2011
(11)
December 2010
(1)
October 2010
(1)
September 2010
(1)
June 2010
(5)
December 2009
(1)
October 2009
(4)
March 2009
(1)
February 2009
(1)
January 2009
(2)
September 2007
(1)
August 2007
(1)
July 2007
(2)
June 2007
(3)
August 2006
(1)
June 2006
(1)
May 2006
(1)
Browse by Tags
TechNet Blogs
>
Security and Identity in the Cloud
>
All Tags
>
security
Tagged Content List
Blog Post:
Custom HomeRealmDiscovery Page with AD FS 2.0
DmitriiL
Recently I decided to dissect the structure of the default pages in AD FS 2.0 and see what can be done with creating slightly different look from its default look. I wanted to see what files control what areas in the UI and what can be done with minimum code changes. I started working with one of the...
on
18 Sep 2012
Blog Post:
Chaining Multiple STS
DmitriiL
A few month ago I learned something about claims based authentication that I thought was not possible. Ever since starting working on federation solutions, and learning about it via training courses, reading white papers, specifications and presentations the following two topologies were always shown...
on
18 Aug 2012
Blog Post:
Authentication Assurance and Claims Based Authentication
DmitriiL
Authentication Mechanism Assurance is described in the following Microsoft publication: http://technet.microsoft.com/en-us/library/dd378897(v=WS.10).aspx . In this post I want to dig a bit more into different configuration options, show how it works and provide example of how it can be configured with...
on
27 Jun 2012
Blog Post:
UAG 2010 and AD FS v2 White Paper is Published
DmitriiL
Over the last three month I published many articles on UAG and AD FS. While it each of the posts provides its own information, many of them refer or build on the knowledge provided in the prior posts. So if you had to read it altogether you’d have to start from the end and read forward. One continuous...
on
5 Nov 2011
Blog Post:
AD FS and UAG are Better Together–Example of a real Solution
DmitriiL
In the last nine posts we reviewed different topologies and discussed some of the techniques on how to integrate these topologies together. In this post we’ll take a look at real example of a production implementation. The solution very similar to the following design has been implemented by one of the...
on
29 Oct 2011
Blog Post:
Designing UAG and AD FS Solution
DmitriiL
In the last many posts we looked at all kind of different topologies for UAG and AD FS configuration. Now, since we are armed with knowledge of different configuration options, we can put all of them to use and see how we can apply them to real life situations. Before we do this, we need to revisit some...
on
18 Oct 2011
Blog Post:
UAG and ADFS Better Together–Authentication via Azure ACS
DmitriiL
This post discussing how it is possible to publish applications to Internet based users who authenticate to the UAG via one of the Internet Cloud Identity Providers, such as LiveID, Google, Yahoo or Facebook. The Windows Azure ACS acts as IdP-STS in this configuration topology. This is essentially the...
on
17 Oct 2011
Blog Post:
UAG and ADFS Better Together–Publishing Applications to Partner Organizations
DmitriiL
In this scenario, our partner organization users access claims based applications published by our organization UAG servers. The partner users provide security tokens issued by the partner controlled Identity Provider to our AD FS v2 published by the UAG server. This configuration is the most common...
on
2 Oct 2011
Blog Post:
UAG and AD FS are Better Together – Strong Auth to Cloud Based Applications
DmitriiL
Today we will discuss a solution that provides the following functionality: You what to require your company external users to use strong AuthN when they access 3 rd party trusted claims based applications. These applications can be hosted in the Cloud or by Partner organization. The description of this...
on
22 Sep 2011
Blog Post:
UAG and AD FS are Better Together - UAG as AD FS Proxy
DmitriiL
In previous topologies ( 1 and 2 ) we did not expose AD FS server to the outside users as primary form of authentication. This topology will do this. One of the benefits of using UAG server in combination with AD FS is that it can now act as gateway or proxy server to the internal AD FS server, in fact...
on
1 Sep 2011
Blog Post:
UAG SP1 and AD FS v2 are Better Together–Introduction
DmitriiL
A few weeks ago I started working on a white paper about UAG SP1 and AD FS v2 configuration topologies and sample complex design based on those topologies. I’m still working on it, but I decided to publish different parts of it for folks to see and potentially get some feedback about it as well. Today...
on
21 Aug 2011
Blog Post:
Secure Application Access by using AD FS and UAG – Strong Authentication
DmitriiL
In the last two posts on this subject I showed to you how to use UAG with Forms Based Authentication and as ADFS Proxy. Todays demonstration shows how to use it with Strong Authentication – Certificate Authentication. The topology in this configuration is very similar to the FBA topology, but it requires...
on
21 Feb 2011
Blog Post:
Microsoft Business Ready Security–Secure Collaboration for Roaming Users with Unified Access Gateway
DmitriiL
Did you know that you can download virtual labs to your own host system and test Microsoft Business Ready Security (BRS) solutions? It is available to anyone on the Internet. Go check it out for yourself: http://go.microsoft.com/fwlink/?LinkId=190269 If for some reason you can not download those labs...
on
8 Feb 2011
Blog Post:
Implementing FIM 2010 Certificate Management (Part 4)
DmitriiL
This is the fourth and final installment in a four part series showing how to implement FIM 2010 Certificate Management solution. You can watch the previous three parts by going to each presentation: “ Implementing FIM 2010 Certificate Management (Part 1) ” “ Implementing FIM 2010 Certificate Management...
on
3 Feb 2011
Blog Post:
Implementing FIM 2010 Certificate Management (Part 3)
DmitriiL
This is the third installment in a four part series showing how to implement FIM 2010 Certificate Management solution. You can watch the first part of this series by going to the “ Implementing FIM 2010 Certificate Management (Part 1) ” and the second part at “ Implementing FIM 2010 Certificate Management...
on
3 Feb 2011
Blog Post:
Implementing FIM 2010 Certificate Management (Part 2)
DmitriiL
This is the second installment in a four part series showing how to implement FIM 2010 Certificate Management solution. You can watch the first part of this series by going to the “ Implementing FIM 2010 Certificate Management (Part 1 )”. If you wonder what is the final result of this specific implementation...
on
2 Feb 2011
Blog Post:
PKI Installation Made Easy in HD
DmitriiL
Who said that implementing PKI is hard? The following one hour video demonstration shows how to implement the most common PKI solution – two tier PKI with Root CA and Subordinate Issuing CA. I’ll discuss the design and why it is done this way, discuss best settings for PKI implementation and show how...
on
27 Jan 2011
Blog Post:
FIM 2010 - Joining Data From Another MA
DmitriiL
This video demonstration is another installment in the “Implementing FIM 2010”. It shows how to configure a Management Agent (MA) for joining and then do some breadcrumb of the dirty data. You can watch all video demonstration in the “Implementing FIM 2010” by going to my “Implementing FIM 2010” video...
on
26 Jan 2011
Blog Post:
FIM 2010–Importing and Synchronizing Data–Video Demonstration
DmitriiL
This is a the second lab from the Implementing Forefront Identity Manager 2010 training. Before watching this demonstration it might be helpful to watch prior demonstrations, but not required. In this demonstration we are going to perform the following tasks: Connect to an HR data source and import...
on
19 Jan 2011
Blog Post:
The FIM Experience–Exercise 4–Video Demonstration
DmitriiL
This is a continuation of the first lab from the Implementing Forefront Identity Manager 2010 training. Before watching this demonstration it might be helpful to watch the prior two demonstrations, but not required. In this demonstration we are going to perform the following tasks: Log on to Windows...
on
18 Jan 2011
Blog Post:
The FIM Experience–Exercise 2 and 3–Video Demonstration
DmitriiL
This is a continuation of the first lab from the Implementing Forefront Identity Manager 2010 training. You can watch the first part of the lab here . In this demonstration we are going to perform the following tasks: Add new users and examine group memberships Add full-time employee Add a contractor...
on
18 Jan 2011
Blog Post:
The FIM Experience–Exercise 1
DmitriiL
Here is the recording of the first lab exercise from the Implementing Forefront Identity Manager 2010 training. In this exercise we are going to edit user identity data and observe the effect on other connected systems. Please watch this video in Full screen and in HD for higher quality and better user...
on
18 Jan 2011
Blog Post:
PKI Installation Made Easy–Video
DmitriiL
Ever wonder how difficult it is to install a two tier PKI system? It is actually not that difficult. Watch this video with live step-by-step demonstration showing how to do just that. Entire system can be up and running in under one hour time frame. This is about 70 minutes video presentation showing...
on
15 Dec 2010
Blog Post:
Open Standard Authentication in the Enterprise, Part 3
DmitriiL
In previous post we started to talk about different SSO solutions. This post will cover another common SSO approach. Current Solutions Federal Agencies employ two primary strategies to provide Single Sign On across multiple Domains, Applications and across Agency boundaries: Application...
on
15 Jun 2010
Blog Post:
Open Standard Authentication in the Enterprise, Part 2
DmitriiL
In previous post we started to talk about different complexities of SSO implementations. Lets review what type of solutions are common in current implementations. Current Solutions Federal Agencies employ two primary strategies to provide Single Sign On across multiple Domains, Applications and...
on
14 Jun 2010
Page 1 of 2 (38 items)
1
2