<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.technet.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Enterprise IT Identity &amp; Access Management</title><link>http://blogs.technet.com/yaleli/default.aspx</link><description>A Buyer's &amp; Integrator's Guide - WebLog Version 1.0</description><dc:language>en-US</dc:language><generator>CommunityServer 2.1 SP1 (Build: 61025.2)</generator><item><title>Introduction to IAM Buyer's Guide</title><link>http://blogs.technet.com/yaleli/archive/2008/04/01/Introduction-to-IAM-Buyer_2700_s-Guide.aspx</link><pubDate>Tue, 01 Apr 2008 14:00:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:422037</guid><dc:creator>Yale Li</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/yaleli/comments/422037.aspx</comments><wfw:commentRss>http://blogs.technet.com/yaleli/commentrss.aspx?PostID=422037</wfw:commentRss><wfw:comment>http://blogs.technet.com/yaleli/rsscomments.aspx?PostID=422037</wfw:comment><description>&lt;BLOCKQUOTE dir=ltr style="MARGIN-RIGHT: 0px"&gt;
&lt;BLOCKQUOTE dir=ltr style="MARGIN-RIGHT: 0px"&gt;
&lt;BLOCKQUOTE dir=ltr style="MARGIN-RIGHT: 0px"&gt;
&lt;BLOCKQUOTE dir=ltr style="MARGIN-RIGHT: 0px"&gt;&lt;FONT size=1&gt;
&lt;P dir=ltr style="MARGIN-RIGHT: 0px"&gt;&lt;FONT size=1&gt;“Our vision for security is to create a world where there is greater trust — where people and organizations can use a range of devices to be more reliably and securely connected to the information, services and people that matter most to them.” - &lt;STRONG&gt;Bill Gates&lt;/STRONG&gt;, Chairman, Microsoft&lt;/FONT&gt;&lt;/P&gt;
&lt;P dir=ltr style="MARGIN-RIGHT: 0px"&gt;&lt;FONT size=1&gt;“As a CIO, I strive to ensure productive, secure, cost effective solutions that help our users realize their potential.&amp;nbsp; Identity and Access Management is the foundation for any solution that I provide to our users.” - &lt;STRONG&gt;Ron Markezich&lt;/STRONG&gt;, VP, Microsoft&lt;/FONT&gt;&lt;/P&gt;&lt;/FONT&gt;&lt;/BLOCKQUOTE&gt;&lt;/BLOCKQUOTE&gt;&lt;/BLOCKQUOTE&gt;&lt;/BLOCKQUOTE&gt;
&lt;P class=content&gt;&lt;FONT size=2&gt;Thank you for visiting&amp;nbsp;my weblog.&amp;nbsp;Please&amp;nbsp;scroll down&amp;nbsp;because I'll keep the Introduction page at top.&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=content&gt;&lt;FONT size=2&gt;&lt;STRONG&gt;Audiences:&lt;/STRONG&gt; CIOs, CSOs, IT Directors/Managers, Enterprise/IT Architects, IT Pros, PMs, Consultants, IAM Product Vendors, Developers&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=content&gt;&lt;FONT size=2&gt;&lt;STRONG&gt;Purpose:&lt;/STRONG&gt; To share my personal view and experience on how Identity &amp;amp; Access Management (IAM, also referred as IdM or IdA)&amp;nbsp;should be done in enterprise IT B2E (Business to Employees) environment (up to&amp;nbsp;half million&amp;nbsp;seats and&amp;nbsp;one million&amp;nbsp;nodes globally). Unlike most other IAM&amp;nbsp;Internet sites, I do&amp;nbsp;not sell&amp;nbsp;products or services. I&amp;nbsp;see IAM from a buyer's angle rather than from a seller's angle. My goal is to purely&amp;nbsp;share&amp;nbsp;information&amp;nbsp;and&amp;nbsp;benefit other enterprise IT divisions&amp;nbsp;/ departments to&amp;nbsp;improve security, increase productivity,&amp;nbsp;minimize cost, and&amp;nbsp;satisfy regulatory compliance&amp;nbsp;in long term. Hopefully, this will also set an IT requirements bar for IAM product vendors.&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=content&gt;&lt;FONT size=1&gt;&lt;STRONG&gt;Yale Li&lt;/STRONG&gt;, PMP, CISSP, ITIL, CCNA, MCSE+I, MCSD, MCDBA, MCNE, CLP, CWSE, CLSE, CNP, CCP, ASE&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=content&gt;&lt;A href="http://blogs.technet.com/photos/yaleli/picture422299.aspx" target=_blank mce_href="http://blogs.technet.com/photos/yaleli/picture422299.aspx"&gt;&lt;IMG style="WIDTH: 144px; HEIGHT: 30px" height=24 src="http://blogs.technet.com/photos/yaleli/images/422299/thumb.aspx" width=107 border=0 mce_src="http://blogs.technet.com/photos/yaleli/images/422299/thumb.aspx"&gt;&lt;/A&gt;&lt;A href="http://blogs.technet.com/photos/yaleli/picture422300.aspx" target=_blank mce_href="http://blogs.technet.com/photos/yaleli/picture422300.aspx"&gt;&lt;IMG style="WIDTH: 144px; HEIGHT: 30px" height=28 src="http://blogs.technet.com/photos/yaleli/images/422300/thumb.aspx" width=105 border=0 mce_src="http://blogs.technet.com/photos/yaleli/images/422300/thumb.aspx"&gt;&lt;/A&gt;&lt;A href="http://blogs.technet.com/photos/yaleli/picture422411.aspx" target=_blank mce_href="http://blogs.technet.com/photos/yaleli/picture422411.aspx"&gt;&lt;IMG src="http://blogs.technet.com/photos/yaleli/images/422411/thumb.aspx" border=0 mce_src="http://blogs.technet.com/photos/yaleli/images/422411/thumb.aspx"&gt;&lt;/A&gt;&lt;A href="http://blogs.technet.com/photos/yaleli/picture422300.aspx" target=_blank mce_href="http://blogs.technet.com/photos/yaleli/picture422300.aspx"&gt;&lt;IMG style="WIDTH: 144px; HEIGHT: 31px" height=30 src="http://blogs.technet.com/photos/yaleli/images/422300/thumb.aspx" width=107 border=0 mce_src="http://blogs.technet.com/photos/yaleli/images/422300/thumb.aspx"&gt;&lt;/A&gt;&lt;A href="http://blogs.technet.com/photos/yaleli/picture422299.aspx" target=_blank mce_href="http://blogs.technet.com/photos/yaleli/picture422299.aspx"&gt;&lt;IMG style="WIDTH: 144px; HEIGHT: 30px" height=30 src="http://blogs.technet.com/photos/yaleli/images/422299/thumb.aspx" width=131 border=0 mce_src="http://blogs.technet.com/photos/yaleli/images/422299/thumb.aspx"&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P class=content&gt;&lt;FONT size=1&gt;Disclaimer: &lt;/FONT&gt;&lt;FONT size=1&gt;All opinions posted here are those of the author and are in no way intended to represent the opinions of&amp;nbsp;author's employer. &lt;!--webbot bot="Navigation" i-checksum="27395" endspan --&gt;This posting is provided "AS IS" with no warranties, and confers no rights. Use of included&amp;nbsp;code samples are subject to the terms specified at &lt;/FONT&gt;&lt;A href="http://www.microsoft.com/info/cpyright.htm" target=_blank mce_href="http://www.microsoft.com/info/cpyright.htm"&gt;&lt;FONT size=1&gt;http://www.microsoft.com/info/cpyright.htm&lt;/FONT&gt;&lt;/A&gt;&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=422037" width="1" height="1"&gt;</description></item><item><title>Major IAM Vendors</title><link>http://blogs.technet.com/yaleli/archive/2008/04/01/Major-IAM-Vendors.aspx</link><pubDate>Tue, 01 Apr 2008 14:00:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:422182</guid><dc:creator>Yale Li</dc:creator><slash:comments>2</slash:comments><comments>http://blogs.technet.com/yaleli/comments/422182.aspx</comments><wfw:commentRss>http://blogs.technet.com/yaleli/commentrss.aspx?PostID=422182</wfw:commentRss><wfw:comment>http://blogs.technet.com/yaleli/rsscomments.aspx?PostID=422182</wfw:comment><description>&lt;P style="LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Times New Roman','serif'; COLOR: black; FONT-SIZE: 10pt; mso-fareast-font-family: 'Times New Roman'"&gt;Vendor selection is critical in IT business. I still remember&amp;nbsp;an old&amp;nbsp;story when I joint&amp;nbsp;big blue&amp;nbsp;family last Century:&amp;nbsp;a wise advice was spread among IT decision makers globally: “You will never be fired if you buy from IBM”.&amp;nbsp; &lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY: 'Times New Roman','serif'; FONT-SIZE: 10pt; mso-fareast-font-family: 'Times New Roman'"&gt;&lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Times New Roman','serif'; FONT-SIZE: 10pt; mso-fareast-font-family: 'Times New Roman'"&gt;&amp;nbsp;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Times New Roman','serif'; COLOR: black; FONT-SIZE: 10pt; mso-fareast-font-family: 'Times New Roman'"&gt;It had worked for a long while. Then, people got fired. Finally, you&amp;nbsp;can not buy PCs from IBM because they are sold to Lenovo. Despite of the result, this&amp;nbsp;phenomenon reflects an enterprise&amp;nbsp;strategy: go with the industry and market leader. &lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Times New Roman','serif'; FONT-SIZE: 10pt; mso-fareast-font-family: 'Times New Roman'"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Times New Roman','serif'; COLOR: black; FONT-SIZE: 10pt; mso-fareast-font-family: 'Times New Roman'"&gt;In currently IAM industry and market,&amp;nbsp;a question is “who is the leader?”.&amp;nbsp;My answer is none because no single vendor can provide a complete&amp;nbsp;end to end IAM solution. Near a hundred IAM vendors are fighting a war to become the leader.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Mergers and acquisitions happen frequently.&lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY: 'Times New Roman','serif'; FONT-SIZE: 10pt; mso-fareast-font-family: 'Times New Roman'"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Times New Roman','serif'; FONT-SIZE: 10pt; mso-fareast-font-family: 'Times New Roman'"&gt;&amp;nbsp;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Times New Roman','serif'; FONT-SIZE: 10pt; mso-fareast-font-family: 'Times New Roman'"&gt;Before you&amp;nbsp;invest on IAM projects, you should be aware of major IAM product vendors. Just like&amp;nbsp;buying a car, you will have more choices if&amp;nbsp;you know all major&amp;nbsp;auto makers. I&amp;nbsp;have gathered most major IAM&amp;nbsp;vendors in&amp;nbsp;following&amp;nbsp;list (in alphabetic order):&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Times New Roman','serif'; FONT-SIZE: 10pt; mso-fareast-font-family: 'Times New Roman'"&gt;&amp;nbsp;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Times New Roman','serif'; FONT-SIZE: 10pt; mso-fareast-font-family: 'Times New Roman'"&gt;A10 Networks - &lt;A href="http://www.a10networks.com/" mce_href="http://www.a10networks.com/"&gt;&lt;SPAN style="COLOR: blue"&gt;http://www.a10networks.com&lt;/SPAN&gt;&lt;/A&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Times New Roman','serif'; FONT-SIZE: 10pt; mso-fareast-font-family: 'Times New Roman'"&gt;Abridean (bought by nCiper) - &lt;A href="http://www.abridean.com/" mce_href="http://www.abridean.com/"&gt;&lt;SPAN style="COLOR: blue"&gt;http://www.abridean.com&lt;/SPAN&gt;&lt;/A&gt;&lt;BR&gt;ActivIdentity (renamed from ActivCard) - &lt;A href="http://www.actividentity.com/" mce_href="http://www.actividentity.com/"&gt;&lt;SPAN style="COLOR: blue"&gt;http://www.actividentity.com&lt;/SPAN&gt;&lt;/A&gt;&lt;BR&gt;Alacris (bought by Microsoft) - &lt;A href="http://www.microsoft.com/windowsserversystem/clm" mce_href="http://www.microsoft.com/windowsserversystem/clm"&gt;&lt;SPAN style="COLOR: blue"&gt;http://www.microsoft.com/windowsserversystem/clm&lt;/SPAN&gt;&lt;/A&gt;&lt;BR&gt;Aladdin - &lt;A href="http://www.aladdin.com/" mce_href="http://www.aladdin.com/"&gt;&lt;SPAN style="COLOR: blue"&gt;http://www.aladdin.com&lt;/SPAN&gt;&lt;/A&gt;&lt;BR&gt;ASG - &lt;A href="http://www.asg.com/" mce_href="http://www.asg.com/"&gt;&lt;SPAN style="COLOR: blue"&gt;http://www.asg.com&lt;/SPAN&gt;&lt;/A&gt;&lt;BR&gt;Authentify - &lt;A href="http://www.authentify.com/" mce_href="http://www.authentify.com/"&gt;&lt;SPAN style="COLOR: blue"&gt;http://www.authentify.com&lt;/SPAN&gt;&lt;/A&gt;&lt;BR&gt;Avatier - &lt;A href="http://www.avatier.com/" mce_href="http://www.avatier.com/"&gt;&lt;SPAN style="COLOR: blue"&gt;http://www.avatier.com&lt;/SPAN&gt;&lt;/A&gt;&lt;BR&gt;Axalto (see Gemalto)&amp;nbsp;- &lt;A href="http://www.axalto.com/" mce_href="http://www.axalto.com/"&gt;&lt;SPAN style="COLOR: blue"&gt;http://www.axalto.com&lt;/SPAN&gt;&lt;/A&gt;&lt;BR&gt;Bayshore - &lt;A href="http://www.bayshore.com/" mce_href="http://www.bayshore.com/"&gt;&lt;SPAN style="COLOR: blue"&gt;http://www.bayshore.com&lt;/SPAN&gt;&lt;/A&gt;&lt;BR&gt;BEA - &lt;A href="http://www.bea.com/" mce_href="http://www.bea.com/"&gt;&lt;SPAN style="COLOR: blue"&gt;http://www.bea.com&lt;/SPAN&gt;&lt;/A&gt;&lt;BR&gt;Beta Systems - &lt;A href="http://www2.betasystems.com/en" mce_href="http://www2.betasystems.com/en"&gt;&lt;SPAN style="COLOR: blue"&gt;http://www2.betasystems.com/en&lt;/SPAN&gt;&lt;/A&gt;&lt;BR&gt;BHOLD - &lt;A href="http://www.bholdcompany.com/" mce_href="http://www.bholdcompany.com/"&gt;&lt;SPAN style="COLOR: blue"&gt;http://www.bholdcompany.com&lt;/SPAN&gt;&lt;/A&gt;&lt;BR&gt;BindView (bought by Symantec) - &lt;A href="http://www.bindview.com/" mce_href="http://www.bindview.com/"&gt;&lt;SPAN style="COLOR: blue"&gt;http://www.bindview.com&lt;/SPAN&gt;&lt;/A&gt;&lt;BR&gt;BMC - &lt;A href="http://www.bmc.com/" mce_href="http://www.bmc.com/"&gt;&lt;SPAN style="COLOR: blue"&gt;http://www.bmc.com&lt;/SPAN&gt;&lt;/A&gt;&lt;BR&gt;BNX Systems - &lt;A href="http://www.bnx.com/" mce_href="http://www.bnx.com/"&gt;&lt;SPAN style="COLOR: blue"&gt;http://www.bnx.com&lt;/SPAN&gt;&lt;/A&gt;&lt;BR&gt;Bridgestream - &lt;A href="http://www.bridgestream.com/" mce_href="http://www.bridgestream.com/"&gt;&lt;SPAN style="COLOR: blue"&gt;http://www.bridgestream.com&lt;/SPAN&gt;&lt;/A&gt;&lt;BR&gt;CA - &lt;A href="http://www.ca.com/" mce_href="http://www.ca.com/"&gt;&lt;SPAN style="COLOR: blue"&gt;http://www.ca.com/&lt;/SPAN&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Times New Roman','serif'; FONT-SIZE: 10pt; mso-fareast-font-family: 'Times New Roman'"&gt;Centrify - &lt;A href="http://www.centrify.com/"&gt;http://www.centrify.com/&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Times New Roman','serif'; FONT-SIZE: 10pt; mso-fareast-font-family: 'Times New Roman'"&gt;Citrix - &lt;A href="http://www.citrix.com/" mce_href="http://www.citrix.com/"&gt;&lt;SPAN style="COLOR: blue"&gt;http://www.citrix.com&lt;/SPAN&gt;&lt;/A&gt;&lt;BR&gt;Courion - &lt;A href="http://www.courion.com/" mce_href="http://www.courion.com/"&gt;&lt;SPAN style="COLOR: blue"&gt;http://www.courion.com&lt;/SPAN&gt;&lt;/A&gt;&lt;BR&gt;Credentica - &lt;A href="http://www.credentica.com/" mce_href="http://www.credentica.com/"&gt;&lt;SPAN style="COLOR: blue"&gt;http://www.credentica.com&lt;/SPAN&gt;&lt;/A&gt;&lt;BR&gt;Datapower (bought by IBM) - &lt;A href="http://www.datapower.com/" mce_href="http://www.datapower.com/"&gt;&lt;SPAN style="COLOR: blue"&gt;http://www.datapower.com&lt;/SPAN&gt;&lt;/A&gt;&lt;BR&gt;Digital Persona - &lt;A href="http://www.digitalpersona.com/" mce_href="http://www.digitalpersona.com/"&gt;&lt;SPAN style="COLOR: blue"&gt;http://www.digitalpersona.com&lt;/SPAN&gt;&lt;/A&gt;&lt;BR&gt;Enatel - &lt;A href="http://www.enatel.com/" mce_href="http://www.enatel.com/"&gt;&lt;SPAN style="COLOR: blue"&gt;http://www.enatel.com&lt;/SPAN&gt;&lt;/A&gt;&lt;BR&gt;Entegrity - &lt;A href="http://www.entegrity.com/" mce_href="http://www.entegrity.com/"&gt;&lt;SPAN style="COLOR: blue"&gt;http://www.entegrity.com&lt;/SPAN&gt;&lt;/A&gt;&lt;BR&gt;Entrust - &lt;A href="http://www.entrust.com/" mce_href="http://www.entrust.com/"&gt;&lt;SPAN style="COLOR: blue"&gt;http://www.entrust.com&lt;/SPAN&gt;&lt;/A&gt;&lt;BR&gt;Epok - &lt;A href="http://www.epokinc.com/" mce_href="http://www.epokinc.com/"&gt;&lt;SPAN style="COLOR: blue"&gt;http://www.epokinc.com&lt;/SPAN&gt;&lt;/A&gt;&lt;BR&gt;Eurekify - &lt;A href="http://www.eurekify.com/" mce_href="http://www.eurekify.com/"&gt;&lt;SPAN style="COLOR: blue"&gt;http://www.eurekify.com&lt;/SPAN&gt;&lt;/A&gt;&lt;BR&gt;Evidian - &lt;A href="http://www.evidian.com/" mce_href="http://www.evidian.com/"&gt;&lt;SPAN style="COLOR: blue"&gt;http://www.evidian.com&lt;/SPAN&gt;&lt;/A&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Times New Roman','serif'; FONT-SIZE: 10pt; mso-fareast-font-family: 'Times New Roman'"&gt;Fastpass&amp;nbsp;- &lt;A href="http://www.fastpasscorp.com/" mce_href="http://www.fastpasscorp.com/"&gt;&lt;SPAN style="COLOR: blue"&gt;http://www.fastpasscorp.com&lt;/SPAN&gt;&lt;/A&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Times New Roman','serif'; FONT-SIZE: 10pt; mso-fareast-font-family: 'Times New Roman'"&gt;Fischer Int’l - &lt;A href="http://www.fischerinternational.com/" mce_href="http://www.fischerinternational.com/"&gt;&lt;SPAN style="COLOR: blue"&gt;http://www.fischerinternational.com&lt;/SPAN&gt;&lt;/A&gt;&lt;BR&gt;Gemplus (see Gemalto)&amp;nbsp;- &lt;A href="http://www.gemplus.com/" mce_href="http://www.gemplus.com/"&gt;&lt;SPAN style="COLOR: blue"&gt;http://www.gemplus.com&lt;/SPAN&gt;&lt;/A&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Times New Roman','serif'; FONT-SIZE: 10pt; mso-fareast-font-family: 'Times New Roman'"&gt;Gemalto (merger of Gemplus and Axalto)&amp;nbsp;- &lt;A href="http://www.gemalto.com/" mce_href="http://www.gemalto.com/"&gt;&lt;SPAN style="COLOR: blue"&gt;http://www.gemalto.com&lt;/SPAN&gt;&lt;/A&gt;&lt;BR&gt;GlobalSign - &lt;A href="http://www.globalsign.com/" mce_href="http://www.globalsign.com/"&gt;&lt;SPAN style="COLOR: blue"&gt;http://www.globalsign.com&lt;/SPAN&gt;&lt;/A&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Times New Roman','serif'; FONT-SIZE: 10pt; mso-fareast-font-family: 'Times New Roman'"&gt;HID -&amp;nbsp;&lt;U&gt;&lt;SPAN style="COLOR: purple"&gt;&lt;A href="http://www.hidcorp.com/" mce_href="http://www.hidcorp.com/"&gt;&lt;SPAN style="COLOR: blue"&gt;http://www.hidcorp.com&lt;/SPAN&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;/U&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Times New Roman','serif'; COLOR: black; FONT-SIZE: 10pt; mso-fareast-font-family: 'Times New Roman'"&gt;HP -&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY: 'Times New Roman','serif'; COLOR: purple; FONT-SIZE: 10pt; mso-fareast-font-family: 'Times New Roman'"&gt;&lt;A href="http://www.hp.com/" mce_href="http://www.hp.com/"&gt;&lt;SPAN style="COLOR: blue"&gt;http://www.hp.com&lt;/SPAN&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY: 'Times New Roman','serif'; FONT-SIZE: 10pt; mso-fareast-font-family: 'Times New Roman'"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Times New Roman','serif'; COLOR: black; FONT-SIZE: 10pt; mso-fareast-font-family: 'Times New Roman'"&gt;IBM -&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY: 'Times New Roman','serif'; COLOR: purple; FONT-SIZE: 10pt; mso-fareast-font-family: 'Times New Roman'"&gt;&lt;A href="http://www.ibm.com/" mce_href="http://www.ibm.com/"&gt;&lt;SPAN style="COLOR: blue"&gt;http://www.ibm.com&lt;/SPAN&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY: 'Times New Roman','serif'; FONT-SIZE: 10pt; mso-fareast-font-family: 'Times New Roman'"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Times New Roman','serif'; FONT-SIZE: 10pt; mso-fareast-font-family: 'Times New Roman'"&gt;Identity Engines -&amp;nbsp;&lt;A href="http://www.idengines.com/" mce_href="http://www.idengines.com/"&gt;&lt;SPAN style="COLOR: blue"&gt;http://www.idengines.com&lt;/SPAN&gt;&lt;/A&gt;&lt;BR&gt;Imanami - &lt;A href="http://www.imanami.com/" mce_href="http://www.imanami.com/"&gt;&lt;SPAN style="COLOR: blue"&gt;http://www.imanami.com&lt;/SPAN&gt;&lt;/A&gt;&lt;BR&gt;Imprivata - &lt;A href="http://www.imprivata.com/" mce_href="http://www.imprivata.com/"&gt;&lt;SPAN style="COLOR: blue"&gt;http://www.imprivata.com&lt;/SPAN&gt;&lt;/A&gt;&lt;BR&gt;Indala - &lt;A href="http://www.indala.com/" mce_href="http://www.indala.com/"&gt;&lt;SPAN style="COLOR: blue"&gt;http://www.indala.com&lt;/SPAN&gt;&lt;/A&gt;&lt;BR&gt;Jericho Sys Juniper - &lt;A href="http://www.jerichosystems.com/" mce_href="http://www.jerichosystems.com/"&gt;&lt;SPAN style="COLOR: blue"&gt;http://www.jerichosystems.com&lt;/SPAN&gt;&lt;/A&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Times New Roman','serif'; FONT-SIZE: 10pt; mso-fareast-font-family: 'Times New Roman'"&gt;LogicTrends&amp;nbsp;- &lt;A href="http://www.logictrends.com/" mce_href="http://www.logictrends.com/"&gt;&lt;SPAN style="COLOR: blue"&gt;http://www.logictrends.com&lt;/SPAN&gt;&lt;/A&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Times New Roman','serif'; FONT-SIZE: 10pt; mso-fareast-font-family: 'Times New Roman'"&gt;Maxware - &lt;A href="http://www.maxware.com/" mce_href="http://www.maxware.com/"&gt;&lt;SPAN style="COLOR: blue"&gt;http://www.maxware.com&lt;/SPAN&gt;&lt;/A&gt;&lt;BR&gt;Microsoft - &lt;A href="http://www.microsoft.com/" mce_href="http://www.microsoft.com/"&gt;&lt;SPAN style="COLOR: blue"&gt;http://www.microsoft.com&lt;/SPAN&gt;&lt;/A&gt;&amp;nbsp;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Times New Roman','serif'; FONT-SIZE: 10pt; mso-fareast-font-family: 'Times New Roman'"&gt;Mirapoint - &lt;A href="http://www.mirapoint.com/" mce_href="http://www.mirapoint.com/"&gt;&lt;SPAN style="COLOR: blue"&gt;www.mirapoint.com&lt;/SPAN&gt;&lt;/A&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Times New Roman','serif'; FONT-SIZE: 10pt; mso-fareast-font-family: 'Times New Roman'"&gt;M-Tech - &lt;A href="http://www.mtechit.com/" mce_href="http://www.mtechit.com/"&gt;&lt;SPAN style="COLOR: blue"&gt;www.mtechit.com&lt;/SPAN&gt;&lt;/A&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Times New Roman','serif'; FONT-SIZE: 10pt; mso-fareast-font-family: 'Times New Roman'"&gt;nCipher - &lt;A href="http://www.ncipher.com/" mce_href="http://www.ncipher.com/"&gt;&lt;SPAN style="COLOR: blue"&gt;http://www.ncipher.com&lt;/SPAN&gt;&lt;/A&gt;&lt;BR&gt;NetIQ - &lt;A href="http://www.netiq.com/" mce_href="http://www.netiq.com/"&gt;&lt;SPAN style="COLOR: blue"&gt;http://www.netiq.com&lt;/SPAN&gt;&lt;/A&gt;&lt;BR&gt;NetPro - &lt;A href="http://www.netpro.com/" mce_href="http://www.netpro.com/"&gt;&lt;SPAN style="COLOR: blue"&gt;http://www.netpro.com&lt;/SPAN&gt;&lt;/A&gt;&lt;BR&gt;NeuStar - &lt;A href="http://www.neustar.biz/" mce_href="http://www.neustar.biz/"&gt;&lt;SPAN style="COLOR: blue"&gt;http://www.neustar.biz&lt;/SPAN&gt;&lt;/A&gt;&lt;BR&gt;Novell - &lt;A href="http://www.novell.com/" mce_href="http://www.novell.com/"&gt;&lt;SPAN style="COLOR: blue"&gt;http://www.novell.com&lt;/SPAN&gt;&lt;/A&gt;&lt;BR&gt;Oblix (bought by Oracle) - &lt;A href="http://www.oracle.com/oblix" mce_href="http://www.oracle.com/oblix"&gt;&lt;SPAN style="COLOR: blue"&gt;http://www.oracle.com/oblix&lt;/SPAN&gt;&lt;/A&gt;&lt;BR&gt;OctetString (bought by Oracle) - &lt;A href="http://www.oracle.com/octetstring" mce_href="http://www.oracle.com/octetstring"&gt;&lt;SPAN style="COLOR: blue"&gt;http://www.oracle.com/octetstring&lt;/SPAN&gt;&lt;/A&gt;&lt;BR&gt;Omnikey - &lt;A href="http://www.omnikey.com/" mce_href="http://www.omnikey.com/"&gt;&lt;SPAN style="COLOR: blue"&gt;http://www.omnikey.com&lt;/SPAN&gt;&lt;/A&gt;&lt;BR&gt;Oracle - &lt;A href="http://www.oracle.com/" mce_href="http://www.oracle.com/"&gt;&lt;SPAN style="COLOR: blue"&gt;http://www.oracle.com&lt;/SPAN&gt;&lt;/A&gt;&lt;BR&gt;OSM - &lt;A href="http://www.cosuser.com/" mce_href="http://www.cosuser.com/"&gt;&lt;SPAN style="COLOR: blue"&gt;http://www.cosuser.com&lt;/SPAN&gt;&lt;/A&gt;&lt;BR&gt;Paramount Defenses&amp;nbsp;- &lt;A href="http://www.paramountdefenses.com/" mce_href="http://www.paramountdefenses.com/"&gt;&lt;SPAN style="COLOR: blue"&gt;http://www.paramountdefenses.com&lt;/SPAN&gt;&lt;/A&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Times New Roman','serif'; FONT-SIZE: 10pt; mso-fareast-font-family: 'Times New Roman'"&gt;Passlogix - &lt;A href="http://www.passlogix.com/" mce_href="http://www.passlogix.com/"&gt;&lt;SPAN style="COLOR: blue"&gt;http://www.passlogix.com&lt;/SPAN&gt;&lt;/A&gt;&lt;BR&gt;Persistent Sys. - &lt;A href="http://www.persistent.com/" mce_href="http://www.persistent.com/"&gt;&lt;SPAN style="COLOR: blue"&gt;http://www.Persistent.com&lt;/SPAN&gt;&lt;/A&gt;&lt;BR&gt;&lt;SPAN style="COLOR: black"&gt;Philips&lt;/SPAN&gt;&lt;SPAN style="COLOR: purple"&gt; - &lt;A href="http://www.philips.com/" mce_href="http://www.philips.com/"&gt;&lt;SPAN style="COLOR: blue"&gt;http://www.philips.com&lt;/SPAN&gt;&lt;/A&gt;&lt;BR&gt;&lt;/SPAN&gt;&lt;SPAN style="COLOR: black"&gt;Ping Identity -&lt;/SPAN&gt;&lt;SPAN style="COLOR: purple"&gt; &lt;A href="http://www.persistentsys.com/" mce_href="http://www.persistentsys.com/"&gt;&lt;SPAN style="COLOR: blue"&gt;http://www.persistentsys.com&lt;/SPAN&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;BR&gt;Proginet - &lt;A href="http://www.proginet.com/" mce_href="http://www.proginet.com/"&gt;&lt;SPAN style="COLOR: blue"&gt;http://www.proginet.com&lt;/SPAN&gt;&lt;/A&gt;&lt;BR&gt;Protocom (bought by ActivIdentity) - &lt;A href="http://www.protocom.com/" mce_href="http://www.protocom.com/"&gt;&lt;SPAN style="COLOR: blue"&gt;http://www.protocom.com&lt;/SPAN&gt;&lt;/A&gt;&lt;BR&gt;Quest - &lt;A href="http://www.quest.com/" mce_href="http://www.quest.com/"&gt;&lt;SPAN style="COLOR: blue"&gt;http://www.quest.com&lt;/SPAN&gt;&lt;/A&gt;&lt;BR&gt;Radiant Logic - &lt;A href="http://www.radiantlogic.com/" mce_href="http://www.radiantlogic.com/"&gt;&lt;SPAN style="COLOR: blue"&gt;http://www.radiantlogic.com&lt;/SPAN&gt;&lt;/A&gt;&lt;BR&gt;Red Hat - &lt;A href="http://www.redhat.com/" mce_href="http://www.redhat.com/"&gt;&lt;SPAN style="COLOR: blue"&gt;http://www.redhat.com&lt;/SPAN&gt;&lt;/A&gt;&lt;BR&gt;RSA Security (bought by EMC)&amp;nbsp;- &lt;A href="http://www.rsasecurity.com/" mce_href="http://www.rsasecurity.com/"&gt;&lt;SPAN style="COLOR: blue"&gt;http://www.rsasecurity.com&lt;/SPAN&gt;&lt;/A&gt;&lt;BR&gt;SafeStone - &lt;A href="http://www.safestone.com/" mce_href="http://www.safestone.com/"&gt;&lt;SPAN style="COLOR: blue"&gt;http://www.safestone.com&lt;/SPAN&gt;&lt;/A&gt;&lt;BR&gt;Secured Services - &lt;A href="http://www.secured-services.com/" mce_href="http://www.secured-services.com/"&gt;&lt;SPAN style="COLOR: blue"&gt;http://www.secured-services.com&lt;/SPAN&gt;&lt;/A&gt;&lt;BR&gt;Securent - &lt;A href="http://www.securent.net/" mce_href="http://www.securent.net/"&gt;&lt;SPAN style="COLOR: blue"&gt;http://www.securent.net&lt;/SPAN&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY: 'Times New Roman','serif'; FONT-SIZE: 10pt"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY: 'Times New Roman','serif'; FONT-SIZE: 10pt; mso-fareast-font-family: 'Times New Roman'"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Times New Roman','serif'; FONT-SIZE: 10pt"&gt;SecurIT - &lt;A href="http://www.securit.biz/" mce_href="http://www.securit.biz/"&gt;&lt;SPAN style="COLOR: blue"&gt;http://www.securIT.biz&lt;/SPAN&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY: 'Times New Roman','serif'; FONT-SIZE: 10pt; mso-fareast-font-family: 'Times New Roman'"&gt;&lt;BR&gt;Sentillion - &lt;A href="http://www.sentillion.com/" mce_href="http://www.sentillion.com/"&gt;&lt;SPAN style="COLOR: blue"&gt;http://www.Sentillion.com&lt;/SPAN&gt;&lt;/A&gt;&lt;BR&gt;Siemens - &lt;A href="http://www.siemens.com/" mce_href="http://www.siemens.com/"&gt;&lt;SPAN style="COLOR: blue"&gt;http://www.siemens.com&lt;/SPAN&gt;&lt;/A&gt;&lt;BR&gt;Sun - &lt;A href="http://www.sun.com/" mce_href="http://www.sun.com/"&gt;&lt;SPAN style="COLOR: blue"&gt;http://www.sun.com&lt;/SPAN&gt;&lt;/A&gt;&lt;BR&gt;Sxip - &lt;A href="http://www.sxip.com/" mce_href="http://www.sxip.com/"&gt;&lt;SPAN style="COLOR: blue"&gt;http://www.sxip.com&lt;/SPAN&gt;&lt;/A&gt;&lt;BR&gt;Symantec - &lt;A href="http://www.symantec.com/" mce_href="http://www.symantec.com/"&gt;&lt;SPAN style="COLOR: blue"&gt;http://www.symantec.com&lt;/SPAN&gt;&lt;/A&gt;&lt;BR&gt;SymLabs - &lt;A href="http://www.symlabs.com/" mce_href="http://www.symlabs.com/"&gt;&lt;SPAN style="COLOR: blue"&gt;http://www.symlabs.com&lt;/SPAN&gt;&lt;/A&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Times New Roman','serif'; FONT-SIZE: 10pt; mso-fareast-font-family: 'Times New Roman'"&gt;Thor (bought by Oracle) - &lt;A href="http://www.thortechnologies.com/" mce_href="http://www.thortechnologies.com/"&gt;&lt;SPAN style="COLOR: blue"&gt;http://www.thortechnologies.com&lt;/SPAN&gt;&lt;/A&gt;&lt;BR&gt;Trustgenix (bought by HP) - &lt;A href="http://www.trustgenix.com/" mce_href="http://www.trustgenix.com/"&gt;&lt;SPAN style="COLOR: blue"&gt;http://www.trustgenix.com&lt;/SPAN&gt;&lt;/A&gt;&lt;BR&gt;Valicert - &lt;A href="http://www.valicert.com/" mce_href="http://www.valicert.com/"&gt;&lt;SPAN style="COLOR: blue"&gt;http://www.valicert.com&lt;/SPAN&gt;&lt;/A&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Times New Roman','serif'; FONT-SIZE: 10pt; mso-fareast-font-family: 'Times New Roman'"&gt;VASCO - &lt;A href="http://www.vasco.com/" mce_href="http://www.vasco.com/"&gt;&lt;SPAN style="COLOR: blue"&gt;http://www.vasco.com&lt;/SPAN&gt;&lt;/A&gt;&lt;BR&gt;Veridicom - &lt;A href="http://www.veridicom.com/" mce_href="http://www.veridicom.com/"&gt;&lt;SPAN style="COLOR: blue"&gt;http://www.veridicom.com&lt;/SPAN&gt;&lt;/A&gt;&lt;BR&gt;Voelcker - &lt;A href="http://www.voelcker.com/" mce_href="http://www.voelcker.com/"&gt;&lt;SPAN style="COLOR: blue"&gt;http://www.voelcker.com&lt;/SPAN&gt;&lt;/A&gt;&lt;BR&gt;ZeroKnowledge - &lt;A href="http://www.zeroknowledge.com/" mce_href="http://www.zeroknowledge.com/"&gt;&lt;SPAN style="COLOR: blue"&gt;http://www.zeroknowledge.com&lt;/SPAN&gt;&lt;/A&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Times New Roman','serif'; FONT-SIZE: 10pt; mso-fareast-font-family: 'Times New Roman'"&gt;&amp;nbsp;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Times New Roman','serif'; COLOR: black; FONT-SIZE: 10pt; mso-fareast-font-family: 'Times New Roman'"&gt;I understand it is not practical to review every product of every vendor through an individual effort. In order to rate vendors fairly, I encourage you to join the community and post your comment if you have experience with any vendors and their products. &lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY: 'Times New Roman','serif'; FONT-SIZE: 10pt; mso-fareast-font-family: 'Times New Roman'"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Times New Roman','serif'; FONT-SIZE: 10pt"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=422182" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/yaleli/archive/tags/4.+Solution/default.aspx">4. Solution</category></item><item><title>RSA 2007 Conference Take Aways</title><link>http://blogs.technet.com/yaleli/archive/2007/02/10/rsa-2007-conference-take-aways.aspx</link><pubDate>Sat, 10 Feb 2007 04:00:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:633534</guid><dc:creator>Yale Li</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/yaleli/comments/633534.aspx</comments><wfw:commentRss>http://blogs.technet.com/yaleli/commentrss.aspx?PostID=633534</wfw:commentRss><wfw:comment>http://blogs.technet.com/yaleli/rsscomments.aspx?PostID=633534</wfw:comment><description>&lt;P&gt;There was no much exciting news at RSA2007.&amp;nbsp;I think I need to write a&amp;nbsp;few things&amp;nbsp;down here or otherwise I will no longer remember them:&lt;/P&gt;
&lt;P&gt;- Information Centric Security: The information is the king. However,&amp;nbsp;the king&amp;nbsp;can not live in a castle all the time. You, as a security professional, should be a knight to protect the king no matter where the king goes. How:&amp;nbsp;add security controls to data in addition to&amp;nbsp;network (for example, use&amp;nbsp;Rights Management Server to protect data in addition to IPSec).&amp;nbsp;&lt;/P&gt;
&lt;P&gt;- User Centric Identity: Identity and Access Management is all about enabling people to do business more efficiently and securely. It will be supported by solutions such as Strong Authentication, Identity Lifecycle Management, Federation Services etc. You will see that more and more dedicated security companies&amp;nbsp;merged into&amp;nbsp;bigger business companies as a trend.&lt;/P&gt;
&lt;P&gt;Following is&amp;nbsp;a link&amp;nbsp;to photo&amp;nbsp;taken for&amp;nbsp;Bill Gates' last RSA conference keynote speech&amp;nbsp;with his successor Craig Mundie. Identity is one of three major&amp;nbsp;area&amp;nbsp;in their security strategy&amp;nbsp;(the content in this blog&amp;nbsp;is&amp;nbsp;a kind of&amp;nbsp;input to that vision). The other two are Network and Protection.&lt;/P&gt;
&lt;P&gt;&lt;SPAN minmax_bound="true"&gt;&lt;SPAN minmax_bound="true"&gt;&lt;A href="http://null/photos/yaleli/images/633509/original.aspx" mce_href="http://null/photos/yaleli/images/633509/original.aspx" minmax_bound="true"&gt;&lt;/A&gt;&lt;U&gt;&lt;FONT color=#0066cc&gt;&lt;A href="http://blogs.technet.com/photos/yaleli/picture633509.aspx" mce_href="http://blogs.technet.com/photos/yaleli/picture633509.aspx"&gt;http://blogs.technet.com/photos/yaleli/picture633509.aspx&lt;/A&gt;&lt;/FONT&gt;&lt;/U&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=633534" width="1" height="1"&gt;</description></item><item><title>Review - Microsoft CLM Certificate Lifecycle Manager Beta 2</title><link>http://blogs.technet.com/yaleli/archive/2006/10/25/review-microsoft-clm-certificate-lifecycle-manager-beta-2.aspx</link><pubDate>Wed, 25 Oct 2006 13:00:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:479369</guid><dc:creator>Yale Li</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/yaleli/comments/479369.aspx</comments><wfw:commentRss>http://blogs.technet.com/yaleli/commentrss.aspx?PostID=479369</wfw:commentRss><wfw:comment>http://blogs.technet.com/yaleli/rsscomments.aspx?PostID=479369</wfw:comment><description>&lt;P&gt;I reviewed CLM Beta 1 half year ago and rated it low. Now,&amp;nbsp;CLM Beta&amp;nbsp;2 is ready for prime time and I'm going to&amp;nbsp;deploy it in production environment. I've seen a lot of improvements in Beta 2&amp;nbsp;so many cons in Beta 1 are removed. Base CSP Smart Card support is a huge for me.&amp;nbsp;For smart card PIN distribution to users, CLM provide 3 - 4 ways:&lt;/P&gt;
&lt;P&gt;- User Provided: The admin or user will provide&amp;nbsp;the initial&amp;nbsp;PIN at the time of enrollment&lt;/P&gt;
&lt;P&gt;- Random: Nobody knows the initial PIN; Users will need to&amp;nbsp;do self service PIN unblock to get the initial PIN.&lt;/P&gt;
&lt;P&gt;- Server Distributed: CLM will print the initial PIN on a hard copy of user letter; This simulates bank ATM PIN distribution; A template is provided with many configurable variables for letter customization.&lt;/P&gt;
&lt;P&gt;- Custom Distributed: This allows you to program custom API if above ways don't work for you.&lt;/P&gt;
&lt;P mce_keep="true"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Pros:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;- Microsoft Base CSP Smart Card support&amp;nbsp;&lt;/P&gt;
&lt;P&gt;- Custome API to enhance CLM functionalities&lt;/P&gt;
&lt;P&gt;- Format (Initialize) smart card&lt;/P&gt;
&lt;P&gt;- HSM support for agent key protection&lt;/P&gt;
&lt;P&gt;- SQL 2005 support&lt;/P&gt;
&lt;P&gt;- Turn key system and no coding is required&lt;/P&gt;
&lt;P&gt;- Can manage both smart cards (including USB tokens) and certificates&lt;/P&gt;
&lt;P&gt;- Feature rich self service Web UI&lt;/P&gt;
&lt;P&gt;- Built-in work flow engine&amp;nbsp;to handle&amp;nbsp;approval and notification &lt;/P&gt;
&lt;P&gt;- Flexable policies&lt;/P&gt;
&lt;P&gt;- Temp smart card&lt;/P&gt;
&lt;P&gt;- Easy installation&lt;/P&gt;
&lt;P mce_keep="true"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Cons:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;- In multiple forest environment, each forest needs its own CLM and SQL database.&lt;/P&gt;
&lt;P&gt;- Granting permission is tedious work&lt;/P&gt;
&lt;P&gt;- CLM Client and .NET Framework 2.0 are required on client PC for self service.&lt;/P&gt;
&lt;P mce_keep="true"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Overall Rating:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;8&amp;nbsp;out of 10&lt;/P&gt;
&lt;P&gt;(0-2: fail to work, 3-5:&amp;nbsp;work in&amp;nbsp;demo/test environment, 6-8: work in production environment, 9-10: excellent quality,&amp;nbsp;great value, highly recommended)&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=479369" width="1" height="1"&gt;</description></item><item><title>Review - ADFS v1 &amp; Preview - ADFS v2</title><link>http://blogs.technet.com/yaleli/archive/2006/10/25/review-adfs-v1-preview-adfs-v2.aspx</link><pubDate>Wed, 25 Oct 2006 13:00:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:479385</guid><dc:creator>Yale Li</dc:creator><slash:comments>2</slash:comments><comments>http://blogs.technet.com/yaleli/comments/479385.aspx</comments><wfw:commentRss>http://blogs.technet.com/yaleli/commentrss.aspx?PostID=479385</wfw:commentRss><wfw:comment>http://blogs.technet.com/yaleli/rsscomments.aspx?PostID=479385</wfw:comment><description>&lt;P mce_keep="true"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Century Gothic'; mso-fareast-font-family: 'Times New Roman'; mso-fareast-language: EN-US; mso-bidi-language: AR-SA; mso-ansi-language: EN-US; mso-bidi-font-family: Tahoma"&gt;Active Directory Federation Service (ADFS) is a component of Active Directory released as part of Windows Server 2003 R2.&lt;/SPAN&gt;&lt;SPAN style="FONT-SIZE: 12pt; FONT-FAMILY: 'Times New Roman'; mso-fareast-font-family: SimSun; mso-fareast-language: ZH-CN; mso-bidi-language: AR-SA; mso-ansi-language: EN-US"&gt; &lt;/SPAN&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Century Gothic'; mso-fareast-font-family: 'Times New Roman'; mso-fareast-language: EN-US; mso-bidi-language: AR-SA; mso-ansi-language: EN-US; mso-bidi-font-family: Tahoma"&gt;ADFS v1 can be used in various B2B/B2E/B2C Web Single Sign On and Identity Federation scenarios. &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Pros:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;- Enable Federated SSO&amp;nbsp;between organizations&lt;/P&gt;
&lt;P&gt;- Enable&amp;nbsp;Extranet SSO&amp;nbsp;within the same corporate environment&lt;/P&gt;
&lt;P&gt;- Support either password and client cert/smart card&amp;nbsp;logon&lt;/P&gt;
&lt;P&gt;- AD and ADAM intergration&lt;/P&gt;
&lt;P&gt;- Easy installation (ADFS-A, ADFS-R, ADFS-Proxy, ADSF-Web Agent)&lt;/P&gt;
&lt;P mce_keep="true"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Cons:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;- NT Token based and Claims based web app support only&lt;/P&gt;
&lt;P&gt;- Requires Windows Server R2 and ADFS web agent installation on IIS web server&lt;/P&gt;
&lt;P&gt;- Everyone with machine join rights can setup ADFS Account server and Resource server (corporate may lose controll without security policy)&lt;/P&gt;
&lt;P&gt;- No CardSpace support&lt;/P&gt;
&lt;P mce_keep="true"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Overall Rating:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;8&amp;nbsp;out of 10&lt;/P&gt;
&lt;P&gt;(0-2: fail to work, 3-5:&amp;nbsp;work in&amp;nbsp;demo/test environment, 6-8: work in production environment, 9-10: excellent quality,&amp;nbsp;great value, highly recommended)&lt;/P&gt;
&lt;P mce_keep="true"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;ADFS v2, to be released in Longhorn Server&amp;nbsp;timeframe, will add support for:&lt;/P&gt;
&lt;P&gt;-&amp;nbsp;Rich client web service apps&lt;/P&gt;
&lt;P&gt;- Windows CardSpace&lt;/P&gt;
&lt;P&gt;- Others (undecided yet, such as manageability, SAML 2.0 support, brokered authentication ...)&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=479385" width="1" height="1"&gt;</description></item><item><title>IAM in TwC</title><link>http://blogs.technet.com/yaleli/archive/2006/06/10/434672.aspx</link><pubDate>Sat, 10 Jun 2006 03:00:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:434672</guid><dc:creator>Yale Li</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/yaleli/comments/434672.aspx</comments><wfw:commentRss>http://blogs.technet.com/yaleli/commentrss.aspx?PostID=434672</wfw:commentRss><wfw:comment>http://blogs.technet.com/yaleli/rsscomments.aspx?PostID=434672</wfw:comment><description>&lt;P&gt;I attended 2006 Microsoft EE &amp;amp; TwC Forum recently and tried to find out if there is&amp;nbsp;any relationship between&amp;nbsp;IAM and TwC. It is interesting that TwC (Trustworthy Computing) has Identity and Access Control as a grand child. &lt;/P&gt;
&lt;P&gt;At top level, TwC&amp;nbsp;has four children, referred as&amp;nbsp;4 pillars:&lt;/P&gt;
&lt;BLOCKQUOTE dir=ltr style="MARGIN-RIGHT: 0px"&gt;
&lt;P&gt;1. Security&lt;/P&gt;
&lt;P&gt;2. Privacy&lt;/P&gt;
&lt;P&gt;3. Reliability&lt;/P&gt;
&lt;P&gt;4. Business Practices&lt;/P&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;At next level, the Security pillar in TwC has three children, known as 3 elements:&lt;/P&gt;
&lt;BLOCKQUOTE dir=ltr style="MARGIN-RIGHT: 0px"&gt;
&lt;P&gt;1. Fundamentals&lt;/P&gt;
&lt;P&gt;2. Threat and Vulnerability Mitigation&lt;/P&gt;
&lt;P&gt;3. Identity and Access Control &lt;/P&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;Finally, IAC (Identity and Access Control) itself has 3 parts:&lt;/P&gt;
&lt;BLOCKQUOTE dir=ltr style="MARGIN-RIGHT: 0px"&gt;
&lt;P&gt;1. Trustworthy Identity: Strong Authentication and Credential Management (&lt;A href="http://download.microsoft.com/download/9/e/2/9e206d8a-37a2-4c17-a6df-ef1e82ce37f4/TrustworthyID.doc"&gt;http://download.microsoft.com/download/9/e/2/9e206d8a-37a2-4c17-a6df-ef1e82ce37f4/TrustworthyID.doc&lt;/A&gt;)&lt;/P&gt;
&lt;P&gt;2. Access Policy Management: Authorizing for Access (&lt;A href="http://download.microsoft.com/download/e/e/4/ee4eb053-31bf-4180-96a5-91866e43ee6c/AccessPolicyMgt.doc"&gt;http://download.microsoft.com/download/e/e/4/ee4eb053-31bf-4180-96a5-91866e43ee6c/AccessPolicyMgt.doc&lt;/A&gt;)&lt;/P&gt;
&lt;P&gt;3. Information Protection (&lt;A href="http://download.microsoft.com/download/2/b/d/2bdcaef5-865f-46f0-a555-cb6ce5c6bd0e/information_protection.doc"&gt;http://download.microsoft.com/download/2/b/d/2bdcaef5-865f-46f0-a555-cb6ce5c6bd0e/information_protection.doc&lt;/A&gt;)&lt;/P&gt;&lt;/BLOCKQUOTE&gt;
&lt;P dir=ltr&gt;The forum content&amp;nbsp;(such as Microsoft's 10 year authentication and authorization strategies) may be confidential and not available for public yet. But above docs should provide you enough readings about IAM in TwC.&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=434672" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/yaleli/archive/tags/2.+Strategy/default.aspx">2. Strategy</category></item><item><title>IAM Strategy</title><link>http://blogs.technet.com/yaleli/archive/2006/06/08/422395.aspx</link><pubDate>Thu, 08 Jun 2006 10:00:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:422395</guid><dc:creator>Yale Li</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/yaleli/comments/422395.aspx</comments><wfw:commentRss>http://blogs.technet.com/yaleli/commentrss.aspx?PostID=422395</wfw:commentRss><wfw:comment>http://blogs.technet.com/yaleli/rsscomments.aspx?PostID=422395</wfw:comment><description>&lt;P&gt;IAM is a combination of processes, technologies, and policies enabled by software&amp;nbsp;to manage digital identities in their lifecycle and specify how they are used to access resources. IAM is a superset of AAA (Authentication, Authorization, Auditing)*. Here are some general strategies for enterprise to consider:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Obtain executive sponsorship because IAM is an important part of information security 
&lt;LI&gt;Understand your business and define processes first 
&lt;LI&gt;Automate provisioning process 
&lt;LI&gt;Offer self services to employees 
&lt;LI&gt;Buy: Directory Servers, Meta Directories, Virtual directory servers, Administration products (directory and PKI management tools, and provisioning products) 
&lt;LI&gt;Build: Access Layer, Workflow Processes 
&lt;LI&gt;Architect:&amp;nbsp;Integrates&amp;nbsp;above compoments and processes&amp;nbsp;together, takes forethought and skill (may not need all components at first) 
&lt;LI&gt;Lay out&amp;nbsp;requirements and business logics as much as possible before starting integration 
&lt;LI&gt;Before signing a contract with any vendor, check out references and foster a good partner relationship&lt;/LI&gt;&lt;/UL&gt;
&lt;P&gt;*Note: Gartner and Forrester have 4 A's with additional Administration. Auditing is also referred as Audit&amp;nbsp;or Accounting or Accountability.&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=422395" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/yaleli/archive/tags/2.+Strategy/default.aspx">2. Strategy</category></item><item><title>How to Reduce TCO of Identity &amp; Access Management</title><link>http://blogs.technet.com/yaleli/archive/2006/06/07/422893.aspx</link><pubDate>Wed, 07 Jun 2006 10:00:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:422893</guid><dc:creator>Yale Li</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/yaleli/comments/422893.aspx</comments><wfw:commentRss>http://blogs.technet.com/yaleli/commentrss.aspx?PostID=422893</wfw:commentRss><wfw:comment>http://blogs.technet.com/yaleli/rsscomments.aspx?PostID=422893</wfw:comment><description>&lt;P&gt;Identity &amp;amp; Access Management&amp;nbsp;is an&amp;nbsp;expensive investment in IT.&amp;nbsp;Here are some tips to&amp;nbsp;reduce Total Cost of Ownership:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Follow the rule&amp;nbsp;of economy of scale -&amp;nbsp;If more people use the same solution, the unit cost of the solution will decrease. Therefore, you should&amp;nbsp;always search and&amp;nbsp;use the most popular out of shelf IAM solution in the market place first.&amp;nbsp; Your own custom built solution should be the last resource only when no other commercial solutions are available or they can not meet your needs.&lt;/LI&gt;
&lt;LI&gt;Automate repeating manual tasks - Labor time is always expensive than machine time. You should identify the repeating manual IAM tasks and automate them as much as possible.&amp;nbsp;Most of those tasks can be done by scripting. Technet Script Center is a good resource for Microsoft solutions such as Active Directory: &lt;A href="http://www.microsoft.com/technet/scriptcenter/default.mspx"&gt;http://www.microsoft.com/technet/scriptcenter/default.mspx&lt;/A&gt;. I'll provide more IAM script in Sample Code category in the future.&lt;/LI&gt;
&lt;LI&gt;Outsource your IAM operations - If your company's IT team is based in North America or Europe, you should definitely consider outsourcing IAM Tier 1 or Tier 2 support to offshore, such as India or China. The cost could&amp;nbsp;be reduced to 1/8th for US companies. It will also help to outsource IAM Tier 3 and Architecture/Integration work to larger&amp;nbsp;IT service companies such as Microsoft*, IBM and HP.&lt;/LI&gt;&lt;/UL&gt;
&lt;P&gt;In TCO, hardware is the smallest portion,&amp;nbsp;support is the largest portion, and software is in the middle. Currently, Microsoft MIIS is the lowest cost solution for&amp;nbsp;identity lifecycle management service&amp;nbsp;and Microsoft CA is the lowest cost solution for certificate service.&lt;/P&gt;
&lt;P&gt;*Note:&amp;nbsp;Microsoft has a new IT service offering called Microsoft Managed Solutions. This is different from Microsoft Consulting Service.&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=422893" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/yaleli/archive/tags/7.+How+To_2700_s/default.aspx">7. How To's</category></item><item><title>Authentication Strategy</title><link>http://blogs.technet.com/yaleli/archive/2006/06/06/422404.aspx</link><pubDate>Tue, 06 Jun 2006 10:00:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:422404</guid><dc:creator>Yale Li</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/yaleli/comments/422404.aspx</comments><wfw:commentRss>http://blogs.technet.com/yaleli/commentrss.aspx?PostID=422404</wfw:commentRss><wfw:comment>http://blogs.technet.com/yaleli/rsscomments.aspx?PostID=422404</wfw:comment><description>&lt;P style="MARGIN-LEFT: 27pt"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Arial"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Arial; mso-fareast-font-family: SimSun; mso-fareast-language: EN-US; mso-bidi-language: HE; mso-ansi-language: EN-US"&gt;Authentication&lt;/SPAN&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Arial; mso-fareast-font-family: SimSun; mso-fareast-language: EN-US; mso-bidi-language: HE; mso-ansi-language: EN-US"&gt; &lt;/SPAN&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Arial; mso-fareast-font-family: SimSun; mso-fareast-language: ZH-CN; mso-bidi-language: HE; mso-ansi-language: EN-US"&gt;is &lt;/SPAN&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Arial; mso-fareast-font-family: SimSun; mso-fareast-language: EN-US; mso-bidi-language: HE; mso-ansi-language: EN-US"&gt;the procedure through which a user or a device or a service (or application) provides sufficient credentials to satisfy access requirements to another service, application, or system. &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN-LEFT: 27pt"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Arial"&gt;User Authentication Strategy:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN-LEFT: 27pt"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Arial"&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Arial"&gt;&lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&lt;SPAN style="mso-bidi-font-family: Arial"&gt;&lt;FONT size=2&gt;&lt;FONT face=Arial&gt;&lt;SPAN style="FONT-SIZE: 10pt; COLOR: windowtext; FONT-FAMILY: Symbol; mso-bidi-font-family: Symbol; mso-fareast-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;·&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;Prepare and plan for&amp;nbsp;Strong User Authentication&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN-LEFT: 27pt"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Arial"&gt;&lt;o:p&gt;&lt;SPAN style="mso-bidi-font-family: Arial"&gt;&lt;/SPAN&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;FONT face=Arial&gt;&lt;SPAN style="FONT-SIZE: 10pt; COLOR: windowtext; FONT-FAMILY: Symbol; mso-bidi-font-family: Symbol; mso-fareast-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;·&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&lt;FONT size=2&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Arial"&gt;Educate&amp;nbsp;line of business&amp;nbsp;application owners to use standard OS and directory protocol authentication and avoid application custom authentication.&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN-LEFT: 45pt; TEXT-INDENT: -0.25in; mso-list: l1 level1 lfo1; tab-stops: list 45.0pt"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Arial"&gt;&lt;/SPAN&gt;&lt;FONT face=Arial&gt;&lt;FONT size=2&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-bidi-font-family: Symbol; mso-fareast-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;·&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="mso-bidi-font-family: Arial"&gt;Use PKI product&amp;nbsp;for digital certificate service and RMS product for license servic&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 4pt 0in 6pt 45pt; TEXT-INDENT: -0.25in; mso-list: l1 level1 lfo1; tab-stops: list 45.0pt"&gt;&lt;FONT face=Arial&gt;&lt;FONT size=2&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-bidi-font-family: Symbol; mso-fareast-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;·&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="mso-bidi-font-family: Arial"&gt;Keep Password logon as temporary authentication method for problematic road warriors&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 4pt 0in 6pt 45pt; TEXT-INDENT: -0.25in; mso-list: l1 level1 lfo1; tab-stops: list 45.0pt"&gt;&lt;FONT face=Arial&gt;&lt;FONT size=2&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-bidi-font-family: Symbol; mso-fareast-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;·&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="mso-bidi-font-family: Arial"&gt;Use Kerberos V5 as authentication protocol&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 4pt 0in 6pt 45pt; TEXT-INDENT: -0.25in; mso-list: l1 level1 lfo1; tab-stops: list 45.0pt"&gt;&lt;SPAN style="mso-bidi-font-family: Arial"&gt;&lt;/SPAN&gt;&lt;FONT face=Arial&gt;&lt;FONT size=2&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-bidi-font-family: Symbol; mso-fareast-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;·&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;SPAN style="mso-bidi-font-family: Arial"&gt;&lt;FONT size=2&gt;&lt;FONT face=Arial&gt;Use Smartcard/PIN two factor authentication, and&lt;/FONT&gt; &lt;/FONT&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="mso-bidi-font-family: Arial; mso-fareast-language: ZH-CN"&gt;evaluate USB Tokens, Wireless Smart Card, Biometrics, TPM&amp;nbsp;authentication&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 4pt 0in 6pt 45pt; TEXT-INDENT: -0.25in; mso-list: l1 level1 lfo1; tab-stops: list 45.0pt"&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-bidi-font-family: Symbol; mso-fareast-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=2&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 4pt 0in 6pt 0.35in"&gt;&lt;SPAN style="mso-bidi-font-family: Arial"&gt;&lt;o:p&gt;&lt;FONT face=Arial size=2&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 4pt 0in 6pt 0.35in"&gt;&lt;SPAN style="mso-bidi-font-family: Arial"&gt;&lt;FONT size=2&gt;&lt;FONT face=Arial&gt;Application/Service Authentication Strategy:&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 4pt 0in 6pt 27pt; TEXT-INDENT: 0in; mso-list: l0 level1 lfo2; tab-stops: list 45.0pt"&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-bidi-font-family: Symbol; mso-fareast-font-family: Symbol; mso-fareast-language: ZH-CN"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=2&gt;·&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="mso-bidi-font-family: Arial; mso-fareast-language: ZH-CN"&gt;&lt;FONT size=2&gt;&lt;FONT face=Arial&gt;Use Managed Password (strong password and changed by application itself), Hash, or Software Token for system account&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 4pt 0in 6pt 27pt; TEXT-INDENT: 0in; mso-list: l0 level1 lfo2; tab-stops: list 45.0pt"&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-bidi-font-family: Symbol; mso-fareast-font-family: Symbol; mso-fareast-language: ZH-CN"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=2&gt;·&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="mso-bidi-font-family: Arial; mso-fareast-language: ZH-CN"&gt;&lt;FONT size=2&gt;&lt;FONT face=Arial&gt;Evaluate TPM as long term solution for application/service authentication&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 4pt 0in 6pt 0.35in"&gt;&lt;SPAN style="mso-bidi-font-family: Arial; mso-fareast-language: ZH-CN"&gt;&lt;o:p&gt;&lt;FONT face=Arial size=2&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 4pt 0in 6pt 0.35in"&gt;&lt;SPAN style="mso-bidi-font-family: Arial"&gt;&lt;FONT size=2&gt;&lt;FONT face=Arial&gt;Device Authentication Strategy:&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 4pt 0in 6pt 45pt; TEXT-INDENT: -0.25in; mso-list: l1 level1 lfo1; tab-stops: list 45.0pt"&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-bidi-font-family: Symbol; mso-fareast-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=2&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 4pt 0in 6pt 45pt; TEXT-INDENT: -0.25in; mso-list: l1 level1 lfo1; tab-stops: list 45.0pt"&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-bidi-font-family: Symbol; mso-fareast-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=2&gt;·&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="mso-bidi-font-family: Arial"&gt;&lt;FONT size=2&gt;&lt;FONT face=Arial&gt;Use EAP-TLS machine cert&amp;nbsp;in conjunction with&amp;nbsp;user smart card cert for wireless LAN access&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 4pt 0in 6pt 45pt; TEXT-INDENT: -0.25in; mso-list: l1 level1 lfo1; tab-stops: list 45.0pt"&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-bidi-font-family: Symbol; mso-fareast-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=2&gt;·&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT size=2&gt;&lt;FONT face=Arial&gt;&lt;SPAN style="mso-bidi-font-family: Arial"&gt;Use&amp;nbsp;Windows Vista (with Network Access Protection feature at server side) for&lt;/SPAN&gt;&lt;SPAN style="mso-bidi-font-family: Arial; mso-fareast-language: ZH-CN"&gt; &lt;/SPAN&gt;&lt;SPAN style="mso-bidi-font-family: Arial"&gt;wireless Corpnet LAN connec&lt;/SPAN&gt;&lt;SPAN style="mso-bidi-font-family: Arial; mso-fareast-language: ZH-CN"&gt;tion&lt;/SPAN&gt;&lt;SPAN style="mso-bidi-font-family: Arial"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 4pt 0in 6pt 45pt; TEXT-INDENT: -0.25in; mso-list: l1 level1 lfo1; tab-stops: list 45.0pt"&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-bidi-font-family: Symbol; mso-fareast-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=2&gt;·&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="mso-bidi-font-family: Arial"&gt;&lt;FONT size=2&gt;&lt;FONT face=Arial&gt;Use Windows Mobile 2005 (with software cert authentication)&amp;nbsp;for wireless phone device email synchronization&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 4pt 0in 6pt 45pt; TEXT-INDENT: -0.25in; mso-list: l1 level1 lfo1; tab-stops: list 45.0pt"&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-bidi-font-family: Symbol; mso-fareast-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=2&gt;·&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="mso-bidi-font-family: Arial; mso-fareast-language: ZH-CN"&gt;&lt;FONT face=Arial size=2&gt;Evaluate TPM as long term solution for device authentication&lt;/FONT&gt;&lt;/SPAN&gt;&lt;SPAN style="mso-bidi-font-family: Arial"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=422404" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/yaleli/archive/tags/2.+Strategy/default.aspx">2. Strategy</category></item><item><title>Authorization Strategy</title><link>http://blogs.technet.com/yaleli/archive/2006/06/05/422539.aspx</link><pubDate>Mon, 05 Jun 2006 10:00:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:422539</guid><dc:creator>Yale Li</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/yaleli/comments/422539.aspx</comments><wfw:commentRss>http://blogs.technet.com/yaleli/commentrss.aspx?PostID=422539</wfw:commentRss><wfw:comment>http://blogs.technet.com/yaleli/rsscomments.aspx?PostID=422539</wfw:comment><description>&lt;P&gt;Authorization (or establishment or entitlement) defines a user's (or process') rights and permissions&amp;nbsp;to a resource. After a user (or process) is authenticated, authorization determines what that user can do&amp;nbsp;to the resource.&lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P&gt;Here are some&amp;nbsp;authorization strategies to improve security:&lt;o:p&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;By default, grant users&amp;nbsp;no rights and permissions&lt;o:p&gt;&lt;/o:p&gt; 
&lt;LI&gt;Grant users least privileged rights and permissions on "need to know" basis&lt;o:p&gt;&lt;/o:p&gt; 
&lt;LI&gt;Push authorization processes from upper/applications layers to lower/OS layers as much as possible&lt;o:p&gt;&lt;/o:p&gt; 
&lt;LI&gt;Prepare&amp;nbsp;or plan Role-Based authorization&lt;o:p&gt;&lt;/o:p&gt; 
&lt;LI&gt;Move from manual authorization&amp;nbsp;management processes to automated authorization management processes with next generation IAM role/group management products&lt;/LI&gt;&lt;/UL&gt;
&lt;P&gt;Please be aware of that Role-Base authorization will be a subset of Claim-Based authorization in long term.&lt;o:p&gt;&lt;/o:p&gt;&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=422539" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/yaleli/archive/tags/2.+Strategy/default.aspx">2. Strategy</category></item><item><title>Auditing Strategy</title><link>http://blogs.technet.com/yaleli/archive/2006/06/04/422541.aspx</link><pubDate>Sun, 04 Jun 2006 10:00:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:422541</guid><dc:creator>Yale Li</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/yaleli/comments/422541.aspx</comments><wfw:commentRss>http://blogs.technet.com/yaleli/commentrss.aspx?PostID=422541</wfw:commentRss><wfw:comment>http://blogs.technet.com/yaleli/rsscomments.aspx?PostID=422541</wfw:comment><description>&lt;P&gt;Auditing (also referred as Audit&amp;nbsp;or Accounting or Accountability) ensures that the activities associated with user access are logged for monitoring, regulatory and investigative purposes. &lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P&gt;Auditing Strategies for IAM to&amp;nbsp;be compliance:&lt;o:p&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;UL type=disc&gt;
&lt;LI class=MsoNormal style="MARGIN: 0in 0in 0pt; mso-list: l0 level1 lfo1; tab-stops: list .5in; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto"&gt;Identify regulations you company must&amp;nbsp;be compliance: such as SOX (Sarbanes-Oxley), HIPAA (Health Insurance Portability and Accountability Act), GLBA (Gramm-Leach-Bliley Act), Basel II.&lt;o:p&gt;&lt;/o:p&gt; 
&lt;LI class=MsoNormal style="MARGIN: 0in 0in 0pt; mso-list: l0 level1 lfo1; tab-stops: list .5in; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto"&gt;Assess current compliance baseline and perform gap analysis&lt;o:p&gt;&lt;/o:p&gt; 
&lt;LI class=MsoNormal style="MARGIN: 0in 0in 0pt; mso-list: l0 level1 lfo1; tab-stops: list .5in; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto"&gt;Implement IAM controls and compare with industry standards and best practices, such as ISO 17799&lt;o:p&gt;&lt;/o:p&gt; 
&lt;LI class=MsoNormal style="MARGIN: 0in 0in 0pt; mso-list: l0 level1 lfo1; tab-stops: list .5in; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto"&gt;Measure, test, remediate, and demonstrate your IAM controls&lt;o:p&gt;&lt;/o:p&gt; 
&lt;LI class=MsoNormal style="MARGIN: 0in 0in 0pt; mso-list: l0 level1 lfo1; tab-stops: list .5in; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto"&gt;Ensure IAM audit logs are secure and scalable&lt;o:p&gt;&lt;/o:p&gt; 
&lt;LI class=MsoNormal style="MARGIN: 0in 0in 0pt; mso-list: l0 level1 lfo1; tab-stops: list .5in; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto"&gt;Get&amp;nbsp;IAM reporting&amp;nbsp;tools&amp;nbsp;that meet auditor's needs&lt;o:p&gt;&lt;/o:p&gt;&lt;/LI&gt;&lt;/UL&gt;
&lt;P&gt;Usually, enterprise IT should have a dedicated governance/audit team (or professionals) to provide compliance guidelines. If not,&amp;nbsp;you should&amp;nbsp;consult with external audit professional service.&lt;o:p&gt;&lt;/o:p&gt;&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=422541" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/yaleli/archive/tags/2.+Strategy/default.aspx">2. Strategy</category></item><item><title>How to Improve Security with Identity &amp; Access Management</title><link>http://blogs.technet.com/yaleli/archive/2006/06/03/422895.aspx</link><pubDate>Sat, 03 Jun 2006 06:00:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:422895</guid><dc:creator>Yale Li</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/yaleli/comments/422895.aspx</comments><wfw:commentRss>http://blogs.technet.com/yaleli/commentrss.aspx?PostID=422895</wfw:commentRss><wfw:comment>http://blogs.technet.com/yaleli/rsscomments.aspx?PostID=422895</wfw:comment><description>&lt;P&gt;Every time I told&amp;nbsp;a friend&amp;nbsp;I&amp;nbsp;got&amp;nbsp;an IT security job,&amp;nbsp;I&amp;nbsp;was always&amp;nbsp;asked a similar question "Do you&amp;nbsp;catch hackers or virus?".&amp;nbsp;Of course, the popularity of&amp;nbsp;the Internet definitely puts&amp;nbsp;external threats and attacks on enterprise IT security's radar.&amp;nbsp;However, I still personally believe internal threats and attacks cost more damage.&lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P&gt;According to a 2003 study by the Computer Security Institute (CSI) and the United States Federal Bureau of Investigations (FBI), nearly half of all security breaches—an astounding 45 percent—come from within the enterprise by disgruntled or malicious employees. Industry analyst firm The Gartner Group estimates that more than 70 percent of unauthorized access to information systems is committed by employees and believes that more than 95 percent of intrusions result in significant financial losses.&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Arial"&gt; &lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;SUA,&amp;nbsp;LPA and SAT are good&amp;nbsp;IAM defense weapons&amp;nbsp;against internal identity theft:&lt;o:p&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;UL type=disc&gt;
&lt;LI class=MsoNormal style="MARGIN: 0in 0in 0pt; mso-list: l0 level1 lfo1; tab-stops: list .5in; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto"&gt;SUA (Strong User Authentication): Password is always weak. You should plan for 2 factor authentication (see Technology Category for definition) such as&amp;nbsp;Smart Card, USB Token, or RSA SecurID. When you&amp;nbsp;evaluate/buy a technology, an important thing is&amp;nbsp;to give equal weight to associated&amp;nbsp;lifecycle management system.&lt;o:p&gt;&lt;/o:p&gt; 
&lt;LI class=MsoNormal style="MARGIN: 0in 0in 0pt; mso-list: l0 level1 lfo1; tab-stops: list .5in; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto"&gt;LPA (Least Privileged Authorization or Access): A strategy to minimize internal security risk is to reduce attack surface area. LPA is an&amp;nbsp;execution of this strategy. First, you need to classify your data. Then, the access will be granted for different class of data on a "need to know" basis. A suite of software products could be used to&amp;nbsp;help LPA&amp;nbsp;(such as group management, role management, rule management, authorization management, access management, self service, workflow&amp;nbsp;etc.). &lt;o:p&gt;&lt;/o:p&gt;
&lt;LI class=MsoNormal style="MARGIN: 0in 0in 0pt; mso-list: l0 level1 lfo1; tab-stops: list .5in; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto"&gt;SAT (Security Awareness Training): IAM is about process and software is just an enabler. One import process is user security awareness training.&amp;nbsp;For&amp;nbsp;example, it is easier to prevent social engineering&amp;nbsp;through this training process and it is hard (or even&amp;nbsp;not possible)&amp;nbsp;through technology.&amp;nbsp;You need to develop training courses and deliver it to all users. &lt;o:p&gt;&lt;/o:p&gt;&lt;/LI&gt;&lt;/UL&gt;
&lt;P&gt;An IAM project to improve security will cost money. Here is a rough estimate formula to calculate cost justification:&lt;o:p&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P&gt;value of all data&amp;nbsp;($) × &lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&lt;/SPAN&gt;probability of breach (%) &amp;gt; cost of project ($)&lt;o:p&gt;&lt;/o:p&gt;&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=422895" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/yaleli/archive/tags/7.+How+To_2700_s/default.aspx">7. How To's</category></item><item><title>How to Increase Productivity with Identity &amp; Access Management</title><link>http://blogs.technet.com/yaleli/archive/2006/06/02/422894.aspx</link><pubDate>Fri, 02 Jun 2006 06:00:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:422894</guid><dc:creator>Yale Li</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/yaleli/comments/422894.aspx</comments><wfw:commentRss>http://blogs.technet.com/yaleli/commentrss.aspx?PostID=422894</wfw:commentRss><wfw:comment>http://blogs.technet.com/yaleli/rsscomments.aspx?PostID=422894</wfw:comment><description>&lt;P&gt;With right IAM solutions, your business can increase employee's productivity (or avoid the loss) significantly. Before you look into IAM solutions, you should identify&amp;nbsp;major factors impacting employee's productivity&amp;nbsp;in your business. Some common factors are:&lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;UL type=disc&gt;
&lt;LI class=MsoNormal style="MARGIN: 0in 0in 0pt; mso-list: l0 level1 lfo1; tab-stops: list .5in; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto"&gt;New employee setup time - the waste time to get a new network/system account and proper permissions to access resources. An employee could loss up to&amp;nbsp;two day's productivity.&lt;o:p&gt;&lt;/o:p&gt; 
&lt;LI class=MsoNormal style="MARGIN: 0in 0in 0pt; mso-list: l0 level1 lfo1; tab-stops: list .5in; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto"&gt;Existing employee transition time - the waste time to get proper permissions to access new resources. An employee could loss up to&amp;nbsp;one day's productivity.&lt;o:p&gt;&lt;/o:p&gt; 
&lt;LI class=MsoNormal style="MARGIN: 0in 0in 0pt; mso-list: l0 level1 lfo1; tab-stops: list .5in; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto"&gt;Employee password (or PIN) reset time - the waste time to get a new password or PIN after it's forgotten. An employee could loss up to&amp;nbsp;half day's productivity.&lt;o:p&gt;&lt;/o:p&gt; 
&lt;LI class=MsoNormal style="MARGIN: 0in 0in 0pt; mso-list: l0 level1 lfo1; tab-stops: list .5in; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto"&gt;Business merger/acquisition transition time - the waste time to consolidate identity and access for two or more organizations. This is also referred as business agility problem.&lt;o:p&gt;&lt;/o:p&gt; 
&lt;LI class=MsoNormal style="MARGIN: 0in 0in 0pt; mso-list: l0 level1 lfo1; tab-stops: list .5in; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto"&gt;IAM service/support overhead - the waste time to get a new IAM related service or support.&lt;o:p&gt;&lt;/o:p&gt;&lt;/LI&gt;&lt;/UL&gt;
&lt;P&gt;The productivity loss can be calculated by average lost hours multiplied by average wage.&amp;nbsp;In the case of&amp;nbsp;the password reset, industry data shows the productivity loss is from near $100 to over $200 per employee per year. &lt;o:p&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P&gt;After you analyze&amp;nbsp;business productivity loss, you&amp;nbsp;can&amp;nbsp;look for&amp;nbsp;effective IAM&amp;nbsp;solutions (which of course should cost less than the lost dollars). In this area, the IAM solutions are:&lt;o:p&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P style="MARGIN-LEFT: 0.5in; TEXT-INDENT: -0.25in; mso-list: l1 level1 lfo2; tab-stops: list .5in"&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;·&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;Automated real-time provisioning management - the system will create/update accounts and groups instantly in Directory after data in authoritative HR system is updated. For example, you run SAP&amp;nbsp;as HR system and MIIS as Meta Directory/Lifecycle Manager, your&amp;nbsp;will need&amp;nbsp;MIIS SAP connector (such as Microsoft MIIS SAP MA&amp;nbsp;Beta or M-Tech ID-Sync MIIS SAP MA). &lt;o:p&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P style="MARGIN-LEFT: 0.5in; TEXT-INDENT: -0.25in; mso-list: l1 level1 lfo2; tab-stops: list .5in"&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;·&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;Self Services - the intranet web applications (some with a workflow engine at back) enabling employees to help themselves. For example, a Q/A based Password Reset web app will allow employees to reset password instantly&amp;nbsp;(such as Microsoft MIIS 2003 SP2 or M-Tech P-Sync). &lt;/P&gt;
&lt;P style="MARGIN-LEFT: 0.5in; TEXT-INDENT: -0.25in; mso-list: l1 level1 lfo2; tab-stops: list .5in"&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;·&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;Automated group/entitlement management &lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&lt;/SPAN&gt;- similar to automated provisioning, the system will take care employee’s group membership and entitlement automatically without manual intervention. Currently, this type of IAM solution is new and not mature in the market (such as Quest ActivRoles Server, upcoming Microsoft MIIS code name Gemini, and Microsoft Mission Ridge).&lt;/P&gt;
&lt;P&gt;You don't have to spend extra dollars for a dedicated IAM product&amp;nbsp;to resolve the&amp;nbsp;agility problem. This solution should be just a bulk provisioning feature in&amp;nbsp;a good&amp;nbsp;provisioning management product.&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=422894" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/yaleli/archive/tags/7.+How+To_2700_s/default.aspx">7. How To's</category></item><item><title>How to Help Regulatory Compliance with Identity &amp; Access Management</title><link>http://blogs.technet.com/yaleli/archive/2006/06/01/422896.aspx</link><pubDate>Fri, 02 Jun 2006 01:00:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:422896</guid><dc:creator>Yale Li</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/yaleli/comments/422896.aspx</comments><wfw:commentRss>http://blogs.technet.com/yaleli/commentrss.aspx?PostID=422896</wfw:commentRss><wfw:comment>http://blogs.technet.com/yaleli/rsscomments.aspx?PostID=422896</wfw:comment><description>&lt;P&gt;You can use&amp;nbsp;IAM solutions to help demonstrating regulatory compliance such as SOX Section 404 and 302, HIPPA, GLB, Basel II Capital Accord, FDA 21-CFR-11, HSPD-12, EU Privacy Directive, PIPEDA, and LSF.&lt;/P&gt;
&lt;P&gt;SOX: There are many SOX compliance tools and you may wonder why IAM is needed. SOX compliance tools are very good at roles and SoD (separation of duties) analysis, but are weak at workflow management, reverse synchronization, and integration with multiple target systems, etc. IAM solutions are strong in those area and can&amp;nbsp;meet following SOX requirements:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Controlling the accessibility of financial information 
&lt;LI&gt;Monitoring and auditing financial information accessibility in real time as well as periodically&amp;nbsp; 
&lt;LI&gt;Making sure that users access permissions to financial data are added and removed in a timely manner 
&lt;LI&gt;Making sure that these controls are applied to all systems associated with financial or business transactions and not only to the traditional financial systems&lt;/LI&gt;&lt;/UL&gt;
&lt;P&gt;HIPPA: Similarly, IAM&amp;nbsp;provides very specific solutions to help healthcare organizations meet&amp;nbsp;following HIPAA requirements and reduce overall organizational risk:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Each user must be uniquely identified before being granted access to confidential information. 
&lt;LI&gt;Access to PHI must be restricted to only those persons who need access as part of their role, and the conditions of this access must be clear. 
&lt;LI&gt;PHI must be reasonably safeguarded against intentional or inadvertent disclosure. 
&lt;LI&gt;Access to protected resources must be tracked, so that complete access reports can be generated. 
&lt;LI&gt;Login attempts must be tracked so that suspicious login attempts can be analyzed and corrective action taken. 
&lt;LI&gt;Access to protected resources must be terminated quickly when an employee leaves the company. 
&lt;LI&gt;A user's session can be terminated after a specific period of inactivity. 
&lt;LI&gt;For large corporations, procedures must be implemented to protect private information of a healthcare entity from access by someone in the&lt;BR&gt;larger organization. 
&lt;LI&gt;Procedures for creating and managing passwords must be implemented.&lt;/LI&gt;&lt;/UL&gt;
&lt;P&gt;GLB: IAM solutions will help addressing following&amp;nbsp; GLB requirements:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Evaluate IT environments and understand the security risks 
&lt;LI&gt;Establish information security policies 
&lt;LI&gt;Conduct independent assessments 
&lt;LI&gt;Provide training and security awareness programs fro employees 
&lt;LI&gt;Scrutinize business relationships to ensure adequate security 
&lt;LI&gt;Upgrade security programs that are in place&lt;/LI&gt;&lt;/UL&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=422896" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/yaleli/archive/tags/7.+How+To_2700_s/default.aspx">7. How To's</category></item><item><title>Authentication Protocols and Standards</title><link>http://blogs.technet.com/yaleli/archive/2006/06/01/422399.aspx</link><pubDate>Fri, 02 Jun 2006 00:00:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:422399</guid><dc:creator>Yale Li</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/yaleli/comments/422399.aspx</comments><wfw:commentRss>http://blogs.technet.com/yaleli/commentrss.aspx?PostID=422399</wfw:commentRss><wfw:comment>http://blogs.technet.com/yaleli/rsscomments.aspx?PostID=422399</wfw:comment><description>&lt;P class=MsoNormal style="MARGIN: 4pt 0in 6pt"&gt;&lt;FONT face=Arial size=2&gt;Some of most popular authentication protocols and standards are:&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN-LEFT: 0.5in; TEXT-INDENT: -0.25in; mso-list: l0 level1 lfo1; tab-stops: list .5in"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;·&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;B&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Arial"&gt;KERBEROS v5:&lt;/SPAN&gt;&lt;/B&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Arial"&gt; &lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN-LEFT: 0.25in"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Arial"&gt;Kerberos is an open standard for distributed systems authentication (&lt;A href="http://www.ietf.org/rfc/rfc1510.txt?number=1510"&gt;RFC 1510&lt;/A&gt;). It relies on shared secret (or password) authentication by users to an authentication server called a Key Distribution Center (KDC). The KDC grants users access to applications, optional delegation of access from an application service to another service, and optional inter-domain trusts between groups of KDCs. In Windows servers and clients running Microsoft Windows 2000 Server or later, the Kerberos version 5 authentication protocol is the basis of authentication to Active Directory. It has an extension (PKINIT) to support smart card logon. It is also integrated into SMB, HTTP, and RPC, as well as the client and server applications that use these protocols.&lt;/SPAN&gt; &lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Arial"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN-LEFT: 0.5in; TEXT-INDENT: -0.25in; mso-list: l0 level1 lfo1; tab-stops: list .5in"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;·&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;B&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Arial"&gt;NTLM:&lt;/SPAN&gt;&lt;/B&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Arial"&gt; &lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN-LEFT: 0.25in"&gt;&lt;SPAN style="FONT-SIZE: 10pt; COLOR: #333333; FONT-FAMILY: Arial"&gt;Windows NT Challenge/Response (NTLM) is the authentication protocol used on networks that include systems running the Windows NT operating system and on stand-alone systems. NTLM stands for Windows NT LAN Manager, a name chosen to distinguish this more advanced challenge/response-based protocol from its weaker predecessor LAN Manager (LM). NTLM credentials are based on data obtained during the interactive logon process and consist of a domain name, a user name, and a one-way hash of the user's password. NTLM uses an encrypted challenge/response protocol to authenticate a user without sending the user's password over the wire. Instead, the system requesting authentication must perform a calculation that proves it has access to the secured NTLM credentials.&lt;/SPAN&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Arial"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN-LEFT: 0.5in; TEXT-INDENT: -0.25in; mso-list: l0 level1 lfo1; tab-stops: list .5in"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;·&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;B&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Arial"&gt;X.509:&lt;/SPAN&gt;&lt;/B&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Arial"&gt; &lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN-LEFT: 0.25in"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Arial"&gt;The X.500 directory standards published by the ITU contain a subsection, X.509, which sets out recommendations for an authentication services framework. X.509, in its third revision, defines both a detailed syntax for certificates and an operational protocol specifying how a certificate is used for authentication. X.509 based authentication (such as Smart Card Logon and SSL/TLS Client Certificate) requires either an internal PKI Infrastructure or an external certificate service.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN-LEFT: 0.5in; TEXT-INDENT: -0.25in; mso-list: l0 level1 lfo1; tab-stops: list .5in"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;·&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;B&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Arial"&gt;Transport Layer Security 1.0/Secure Sockets Layer 3.0:&lt;/SPAN&gt;&lt;/B&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Arial"&gt; &lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN-LEFT: 0.25in"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Arial"&gt;SSL 3.0 and TLS 1.0 are closely related protocols. SSL 3.0 is a proprietary Netscape Communications protocol, while TLS 1.0 is the Internet Engineering Task Force (IETF) standard. TLS, or &lt;A href="http://www.ietf.org/rfc/rfc2246.txt?number=2246"&gt;RFC 2246&lt;/A&gt;, operates at the transport layer of the protocol stack. It’s invoked automatically whenever a user’s workstation connects to a server that requires secure communications. TLS/SSL uses a handshaking procedure to authenticate the server and (optionally) the client through X.509 certificates, to negotiate the algorithms for the session, and to exchange session keys for encryption and message digests.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN-LEFT: 0.5in; TEXT-INDENT: -0.25in; mso-list: l0 level1 lfo1; tab-stops: list .5in"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;·&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;B style="mso-bidi-font-weight: normal"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Arial"&gt;EAP-TLS&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;
&lt;P style="MARGIN-LEFT: 0.25in"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Arial"&gt;EAP-TLS uses a TLS handshake as the basis for authentication. TLS authenticates peers by exchanging digital certificates. In EAP-TLS, certificates are used to provide authentication in both directions. The server presents a certificate to the client, and, after validating the server's certificate, the client presents a client certificate. Naturally, the certificate may be protected on the client by a passphrase, PIN, or stored on a smart card, depending on the implementation. One flaw in EAP-TLS protocol noted by many observers is that the identity exchange proceeds in the clear before exchange of certificates, so a passive attack could easily observe user names. &lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN-LEFT: 0.5in; TEXT-INDENT: -0.25in; mso-list: l0 level1 lfo1; tab-stops: list .5in"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;·&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;B style="mso-bidi-font-weight: normal"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Arial"&gt;TTLS and PEAP&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;
&lt;P style="MARGIN-LEFT: 0.25in"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Arial"&gt;The structure of TTLS and PEAP are quite similar. Both are two-stage protocols that establish security in stage one and then exchange authentication in stage two. Stage one of both protocols establishes a TLS tunnel and authenticates the authentication server to the client with a certificate. (TTLS and PEAP still use certificates to authenticate the wireless network to the user, but only a few certificates will be required, so it is much more manageable.) Once that secure channel has been established, client authentication credentials are exchanged in the second stage. &lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN-LEFT: 0.25in"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Arial"&gt;TTLS uses the TLS channel/tunnel to exchange "attribute-value pairs" (AVPs), much like RADIUS. (In fact, the AVP encoding format is very similar to RADIUS.) The general encoding of information allows a TTLS server to validate AVPs against any type of authentication mechanism. TTLS implementations today support all methods defined by EAP, as well as several older methods (CHAP, PAP, MS-CHAP and MS-CHAPv2). TTLS can easily be extended to work with new protocols by defining new attributes to support new protocols. &lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN-LEFT: 0.25in"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Arial"&gt;PEAP uses the TLS channel to protect a second EAP exchange. Authentication must be performed using a protocol that is defined for use with EAP. In practice, the restriction to EAP methods is not a severe drawback because any "important" authentication protocol would be defined for use with EAP in short order so that PEAP could use it. A far greater concern is client software support. PEAP is backed by Microsoft, and clients are beginning to become available for recent professional versions of Windows (XP now, with Windows 2000 support coming shortly). Suppliers of PEAP clients for other operating systems have yet to materialize, which may restrict PEAP to being used only in pure Microsoft networks. &lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN-LEFT: 0.5in; TEXT-INDENT: -0.25in; mso-list: l0 level1 lfo1; tab-stops: list .5in"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;·&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;B&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Arial"&gt;Remote Access Dial-in User Services:&lt;/SPAN&gt;&lt;/B&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Arial"&gt; &lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN-LEFT: 0.25in"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Arial"&gt;RADIUS, or &lt;A href="http://www.ietf.org/rfc/rfc2138.txt?number=2138"&gt;RFC 2138&lt;/A&gt;, encrypts user ID/password information or challenge/response token information over the network. While initially created to support remote or network access servers, RADIUS has evolved to provide a standard mechanism by which Internet service providers (ISPs) relay authentication requests back to corporate customers.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN-LEFT: 0.5in; TEXT-INDENT: -0.25in; mso-list: l0 level1 lfo1; tab-stops: list .5in"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;·&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;B&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Arial"&gt;Security Assertion Markup Language (SAML): &lt;/SPAN&gt;&lt;/B&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Arial"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN-LEFT: 0.25in"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Arial"&gt;When combined with XML-based remote procedure calls (RPCs) such as the Simple Object Access Protocol (SOAP), SAML serves as a distributed authentication protocol between authentication and other security services. As such, SAML allows loosely coupled security domains with heterogeneous systems and authentication methods to federate authentication. Liberty Alliance specifications leverage SAML as the underlying protocol while providing extensions such as account linking and global logout.&lt;/SPAN&gt;&lt;SPAN style="FONT-SIZE: 9pt; FONT-FAMILY: Verdana"&gt; &lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN-LEFT: 0.5in; TEXT-INDENT: -0.25in; mso-list: l0 level1 lfo1; tab-stops: list .5in"&gt;&lt;SPAN style="FONT-SIZE: 9pt; FONT-FAMILY: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;·&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;B&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Arial"&gt;Web Service Security (WSS):&lt;/SPAN&gt;&lt;/B&gt;&lt;SPAN style="FONT-SIZE: 9pt; FONT-FAMILY: Verdana"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN-LEFT: 0.25in"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Arial"&gt;Web Services Security (WSS) specifies ways to encode authentication and other security tokens in Simple Object Access Protocol (SOAP) message headers. Web Services Security Language (WS-Security) outlines encoding mechanisms for user IDs/passwords, X.509 certificates, Kerberos tickets, and SAML assertions.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN-LEFT: 0.5in; TEXT-INDENT: -0.25in; mso-list: l0 level1 lfo1; tab-stops: list .5in"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;·&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;B&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Arial"&gt;eXtensible rights Markup Language (XrML): &lt;/SPAN&gt;&lt;/B&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Arial"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt 0.25in; mso-layout-grid-align: none"&gt;&lt;SPAN style="mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Arial; mso-bidi-language: AR-SA"&gt;&lt;FONT size=2&gt;&lt;FONT face=Arial&gt;XrML is an XML-based usage grammar for specifying rights and conditions to control the access to digital content and services. Using XrML, anyone owning or distributing digital resources (such as content, services, or software applications) can identify the parties allowed to use those resources, the rights available to those parties, and the terms and conditions under which those rights may be exercised. These four elements are the Core of the language and determine the full context of the rights that are specified. In other words, it is not sufficient to just specify that the right to view certain content has been granted, but also &lt;I&gt;who &lt;/I&gt;can view it and under &lt;I&gt;what &lt;/I&gt;conditions.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN-LEFT: 0.5in; TEXT-INDENT: -0.25in; mso-list: l0 level1 lfo1; tab-stops: list .5in"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;·&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;B&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Arial"&gt;Simple Authentication and Security Layer:&lt;/SPAN&gt;&lt;/B&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Arial"&gt; &lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN-LEFT: 0.25in"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Arial"&gt;SASL, or Request for Comment (&lt;A href="http://www.ietf.org/rfc/rfc2222.txt?number=2222"&gt;RFC 2222&lt;/A&gt;), is a generalized negotiation mechanism and authentication abstraction layer for any connection-based protocol, including Simple Mail Transfer Protocol (SMTP), Internet Message Access Protocol 4 (IMAP4), and Lightweight Directory Access Protocol version 3 (LDAPv3).&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN-LEFT: 0.5in; TEXT-INDENT: -0.25in; mso-list: l0 level1 lfo1; tab-stops: list .5in"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;·&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;B&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Arial"&gt;Secure Shell:&lt;/SPAN&gt;&lt;/B&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Arial"&gt; &lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN-LEFT: 0.25in"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Arial"&gt;SSH, now at version 2.0, is a secure protocol and set of tools for secure, remote user authentication and access to servers. SSH can be used to secure any network-based traffic by setting it up as a ”pipe” (i.e., binding it to a certain port at both ends). This makes it useful for functions such as running X-Windows across the Internet. SSH runs on most UNIX systems, Windows servers, and client platforms, and there are open source SSH solutions for these environments. The SSH protocol consists of three major components: the Transport Layer Protocol provides server authentication, confidentiality, and integrity with perfect forward secrecy; the User Authentication Protocol authenticates the client to the server; and the Connection Protocol multiplexes the encrypted tunnel into several logical channels.&lt;/SPAN&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Arial; mso-fareast-font-family: SimSun; mso-fareast-language: ZH-CN"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN-LEFT: 0.5in; TEXT-INDENT: -0.25in; mso-list: l0 level1 lfo1; tab-stops: list .5in"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;·&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;B&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Arial; mso-fareast-font-family: SimSun; mso-fareast-language: ZH-CN"&gt;BAPI&lt;/SPAN&gt;&lt;/B&gt;&lt;B&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Arial"&gt;:&lt;/SPAN&gt;&lt;/B&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Arial"&gt; &lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN-LEFT: 0.25in"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Arial; mso-fareast-font-family: SimSun; mso-fareast-language: ZH-CN"&gt;The&lt;/SPAN&gt;&lt;SPAN style="FONT-SIZE: 9pt; FONT-FAMILY: Arial"&gt; &lt;/SPAN&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Arial"&gt;Biometric Application Programming Interface (BAPI) defines a standard software protocol and application programming interface (API) for communication between software applications and biometric devices. BAPI is designed to bring&lt;/SPAN&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Arial; mso-fareast-font-family: SimSun; mso-fareast-language: ZH-CN"&gt; standards a&lt;/SPAN&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Arial"&gt;nd compatibility to the biometric hardware and software markets&lt;/SPAN&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Arial; mso-fareast-font-family: SimSun; mso-fareast-language: ZH-CN"&gt;. &lt;/SPAN&gt;&lt;SPAN style="FONT-SIZE: 10pt; COLOR: windowtext; FONT-FAMILY: Arial"&gt;In 2000, Microsoft acquired BAPI technology from I/O Software with the intention to integrate the technology into the upcoming versions of Windows. As a direct result of Microsoft's integration, BAPI will be positioned to provide a seamless and consistent plug-and-play experience to Windows, and the vast majority of PC users. Triggered by Microsoft's commitment to the integration of biometrics, a quickly growing number of biometric vendors have adopted the BAPI standard. Microsoft my extend Kerberos in Blackcomb to support domain Biometrics logon (Longhorn local Biometrics logon has been but).&lt;/SPAN&gt;&lt;SPAN style="FONT-SIZE: 9pt; FONT-FAMILY: Verdana; mso-fareast-font-family: SimSun; mso-fareast-language: ZH-CN"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Arial"&gt;Many other authentication methods are B2C focused and will not be explained here (such as IIS Basic, Digest, Form Based, Passport and InfoCard&amp;nbsp;etc.)&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=422399" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/yaleli/archive/tags/1.+Technology/default.aspx">1. Technology</category></item></channel></rss>