<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.technet.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Enterprise IT Identity &amp; Access Management : 2. Strategy</title><link>http://blogs.technet.com/yaleli/archive/tags/2.+Strategy/default.aspx</link><description>Tags: 2. Strategy</description><dc:language>en-US</dc:language><generator>CommunityServer 2.1 SP1 (Build: 61025.2)</generator><item><title>IAM in TwC</title><link>http://blogs.technet.com/yaleli/archive/2006/06/10/434672.aspx</link><pubDate>Sat, 10 Jun 2006 03:00:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:434672</guid><dc:creator>Yale Li</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/yaleli/comments/434672.aspx</comments><wfw:commentRss>http://blogs.technet.com/yaleli/commentrss.aspx?PostID=434672</wfw:commentRss><wfw:comment>http://blogs.technet.com/yaleli/rsscomments.aspx?PostID=434672</wfw:comment><description>&lt;P&gt;I attended 2006 Microsoft EE &amp;amp; TwC Forum recently and tried to find out if there is&amp;nbsp;any relationship between&amp;nbsp;IAM and TwC. It is interesting that TwC (Trustworthy Computing) has Identity and Access Control as a grand child. &lt;/P&gt;
&lt;P&gt;At top level, TwC&amp;nbsp;has four children, referred as&amp;nbsp;4 pillars:&lt;/P&gt;
&lt;BLOCKQUOTE dir=ltr style="MARGIN-RIGHT: 0px"&gt;
&lt;P&gt;1. Security&lt;/P&gt;
&lt;P&gt;2. Privacy&lt;/P&gt;
&lt;P&gt;3. Reliability&lt;/P&gt;
&lt;P&gt;4. Business Practices&lt;/P&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;At next level, the Security pillar in TwC has three children, known as 3 elements:&lt;/P&gt;
&lt;BLOCKQUOTE dir=ltr style="MARGIN-RIGHT: 0px"&gt;
&lt;P&gt;1. Fundamentals&lt;/P&gt;
&lt;P&gt;2. Threat and Vulnerability Mitigation&lt;/P&gt;
&lt;P&gt;3. Identity and Access Control &lt;/P&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;Finally, IAC (Identity and Access Control) itself has 3 parts:&lt;/P&gt;
&lt;BLOCKQUOTE dir=ltr style="MARGIN-RIGHT: 0px"&gt;
&lt;P&gt;1. Trustworthy Identity: Strong Authentication and Credential Management (&lt;A href="http://download.microsoft.com/download/9/e/2/9e206d8a-37a2-4c17-a6df-ef1e82ce37f4/TrustworthyID.doc"&gt;http://download.microsoft.com/download/9/e/2/9e206d8a-37a2-4c17-a6df-ef1e82ce37f4/TrustworthyID.doc&lt;/A&gt;)&lt;/P&gt;
&lt;P&gt;2. Access Policy Management: Authorizing for Access (&lt;A href="http://download.microsoft.com/download/e/e/4/ee4eb053-31bf-4180-96a5-91866e43ee6c/AccessPolicyMgt.doc"&gt;http://download.microsoft.com/download/e/e/4/ee4eb053-31bf-4180-96a5-91866e43ee6c/AccessPolicyMgt.doc&lt;/A&gt;)&lt;/P&gt;
&lt;P&gt;3. Information Protection (&lt;A href="http://download.microsoft.com/download/2/b/d/2bdcaef5-865f-46f0-a555-cb6ce5c6bd0e/information_protection.doc"&gt;http://download.microsoft.com/download/2/b/d/2bdcaef5-865f-46f0-a555-cb6ce5c6bd0e/information_protection.doc&lt;/A&gt;)&lt;/P&gt;&lt;/BLOCKQUOTE&gt;
&lt;P dir=ltr&gt;The forum content&amp;nbsp;(such as Microsoft's 10 year authentication and authorization strategies) may be confidential and not available for public yet. But above docs should provide you enough readings about IAM in TwC.&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=434672" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/yaleli/archive/tags/2.+Strategy/default.aspx">2. Strategy</category></item><item><title>IAM Strategy</title><link>http://blogs.technet.com/yaleli/archive/2006/06/08/422395.aspx</link><pubDate>Thu, 08 Jun 2006 10:00:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:422395</guid><dc:creator>Yale Li</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/yaleli/comments/422395.aspx</comments><wfw:commentRss>http://blogs.technet.com/yaleli/commentrss.aspx?PostID=422395</wfw:commentRss><wfw:comment>http://blogs.technet.com/yaleli/rsscomments.aspx?PostID=422395</wfw:comment><description>&lt;P&gt;IAM is a combination of processes, technologies, and policies enabled by software&amp;nbsp;to manage digital identities in their lifecycle and specify how they are used to access resources. IAM is a superset of AAA (Authentication, Authorization, Auditing)*. Here are some general strategies for enterprise to consider:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Obtain executive sponsorship because IAM is an important part of information security 
&lt;LI&gt;Understand your business and define processes first 
&lt;LI&gt;Automate provisioning process 
&lt;LI&gt;Offer self services to employees 
&lt;LI&gt;Buy: Directory Servers, Meta Directories, Virtual directory servers, Administration products (directory and PKI management tools, and provisioning products) 
&lt;LI&gt;Build: Access Layer, Workflow Processes 
&lt;LI&gt;Architect:&amp;nbsp;Integrates&amp;nbsp;above compoments and processes&amp;nbsp;together, takes forethought and skill (may not need all components at first) 
&lt;LI&gt;Lay out&amp;nbsp;requirements and business logics as much as possible before starting integration 
&lt;LI&gt;Before signing a contract with any vendor, check out references and foster a good partner relationship&lt;/LI&gt;&lt;/UL&gt;
&lt;P&gt;*Note: Gartner and Forrester have 4 A's with additional Administration. Auditing is also referred as Audit&amp;nbsp;or Accounting or Accountability.&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=422395" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/yaleli/archive/tags/2.+Strategy/default.aspx">2. Strategy</category></item><item><title>Authentication Strategy</title><link>http://blogs.technet.com/yaleli/archive/2006/06/06/422404.aspx</link><pubDate>Tue, 06 Jun 2006 10:00:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:422404</guid><dc:creator>Yale Li</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/yaleli/comments/422404.aspx</comments><wfw:commentRss>http://blogs.technet.com/yaleli/commentrss.aspx?PostID=422404</wfw:commentRss><wfw:comment>http://blogs.technet.com/yaleli/rsscomments.aspx?PostID=422404</wfw:comment><description>&lt;P style="MARGIN-LEFT: 27pt"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Arial"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Arial; mso-fareast-font-family: SimSun; mso-fareast-language: EN-US; mso-bidi-language: HE; mso-ansi-language: EN-US"&gt;Authentication&lt;/SPAN&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Arial; mso-fareast-font-family: SimSun; mso-fareast-language: EN-US; mso-bidi-language: HE; mso-ansi-language: EN-US"&gt; &lt;/SPAN&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Arial; mso-fareast-font-family: SimSun; mso-fareast-language: ZH-CN; mso-bidi-language: HE; mso-ansi-language: EN-US"&gt;is &lt;/SPAN&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Arial; mso-fareast-font-family: SimSun; mso-fareast-language: EN-US; mso-bidi-language: HE; mso-ansi-language: EN-US"&gt;the procedure through which a user or a device or a service (or application) provides sufficient credentials to satisfy access requirements to another service, application, or system. &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN-LEFT: 27pt"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Arial"&gt;User Authentication Strategy:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN-LEFT: 27pt"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Arial"&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Arial"&gt;&lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&lt;SPAN style="mso-bidi-font-family: Arial"&gt;&lt;FONT size=2&gt;&lt;FONT face=Arial&gt;&lt;SPAN style="FONT-SIZE: 10pt; COLOR: windowtext; FONT-FAMILY: Symbol; mso-bidi-font-family: Symbol; mso-fareast-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;·&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;Prepare and plan for&amp;nbsp;Strong User Authentication&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN-LEFT: 27pt"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Arial"&gt;&lt;o:p&gt;&lt;SPAN style="mso-bidi-font-family: Arial"&gt;&lt;/SPAN&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;FONT face=Arial&gt;&lt;SPAN style="FONT-SIZE: 10pt; COLOR: windowtext; FONT-FAMILY: Symbol; mso-bidi-font-family: Symbol; mso-fareast-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;·&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&lt;FONT size=2&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Arial"&gt;Educate&amp;nbsp;line of business&amp;nbsp;application owners to use standard OS and directory protocol authentication and avoid application custom authentication.&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN-LEFT: 45pt; TEXT-INDENT: -0.25in; mso-list: l1 level1 lfo1; tab-stops: list 45.0pt"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Arial"&gt;&lt;/SPAN&gt;&lt;FONT face=Arial&gt;&lt;FONT size=2&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-bidi-font-family: Symbol; mso-fareast-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;·&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="mso-bidi-font-family: Arial"&gt;Use PKI product&amp;nbsp;for digital certificate service and RMS product for license servic&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 4pt 0in 6pt 45pt; TEXT-INDENT: -0.25in; mso-list: l1 level1 lfo1; tab-stops: list 45.0pt"&gt;&lt;FONT face=Arial&gt;&lt;FONT size=2&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-bidi-font-family: Symbol; mso-fareast-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;·&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="mso-bidi-font-family: Arial"&gt;Keep Password logon as temporary authentication method for problematic road warriors&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 4pt 0in 6pt 45pt; TEXT-INDENT: -0.25in; mso-list: l1 level1 lfo1; tab-stops: list 45.0pt"&gt;&lt;FONT face=Arial&gt;&lt;FONT size=2&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-bidi-font-family: Symbol; mso-fareast-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;·&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="mso-bidi-font-family: Arial"&gt;Use Kerberos V5 as authentication protocol&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 4pt 0in 6pt 45pt; TEXT-INDENT: -0.25in; mso-list: l1 level1 lfo1; tab-stops: list 45.0pt"&gt;&lt;SPAN style="mso-bidi-font-family: Arial"&gt;&lt;/SPAN&gt;&lt;FONT face=Arial&gt;&lt;FONT size=2&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-bidi-font-family: Symbol; mso-fareast-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;·&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;SPAN style="mso-bidi-font-family: Arial"&gt;&lt;FONT size=2&gt;&lt;FONT face=Arial&gt;Use Smartcard/PIN two factor authentication, and&lt;/FONT&gt; &lt;/FONT&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="mso-bidi-font-family: Arial; mso-fareast-language: ZH-CN"&gt;evaluate USB Tokens, Wireless Smart Card, Biometrics, TPM&amp;nbsp;authentication&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 4pt 0in 6pt 45pt; TEXT-INDENT: -0.25in; mso-list: l1 level1 lfo1; tab-stops: list 45.0pt"&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-bidi-font-family: Symbol; mso-fareast-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=2&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 4pt 0in 6pt 0.35in"&gt;&lt;SPAN style="mso-bidi-font-family: Arial"&gt;&lt;o:p&gt;&lt;FONT face=Arial size=2&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 4pt 0in 6pt 0.35in"&gt;&lt;SPAN style="mso-bidi-font-family: Arial"&gt;&lt;FONT size=2&gt;&lt;FONT face=Arial&gt;Application/Service Authentication Strategy:&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 4pt 0in 6pt 27pt; TEXT-INDENT: 0in; mso-list: l0 level1 lfo2; tab-stops: list 45.0pt"&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-bidi-font-family: Symbol; mso-fareast-font-family: Symbol; mso-fareast-language: ZH-CN"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=2&gt;·&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="mso-bidi-font-family: Arial; mso-fareast-language: ZH-CN"&gt;&lt;FONT size=2&gt;&lt;FONT face=Arial&gt;Use Managed Password (strong password and changed by application itself), Hash, or Software Token for system account&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 4pt 0in 6pt 27pt; TEXT-INDENT: 0in; mso-list: l0 level1 lfo2; tab-stops: list 45.0pt"&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-bidi-font-family: Symbol; mso-fareast-font-family: Symbol; mso-fareast-language: ZH-CN"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=2&gt;·&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="mso-bidi-font-family: Arial; mso-fareast-language: ZH-CN"&gt;&lt;FONT size=2&gt;&lt;FONT face=Arial&gt;Evaluate TPM as long term solution for application/service authentication&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 4pt 0in 6pt 0.35in"&gt;&lt;SPAN style="mso-bidi-font-family: Arial; mso-fareast-language: ZH-CN"&gt;&lt;o:p&gt;&lt;FONT face=Arial size=2&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 4pt 0in 6pt 0.35in"&gt;&lt;SPAN style="mso-bidi-font-family: Arial"&gt;&lt;FONT size=2&gt;&lt;FONT face=Arial&gt;Device Authentication Strategy:&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 4pt 0in 6pt 45pt; TEXT-INDENT: -0.25in; mso-list: l1 level1 lfo1; tab-stops: list 45.0pt"&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-bidi-font-family: Symbol; mso-fareast-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=2&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 4pt 0in 6pt 45pt; TEXT-INDENT: -0.25in; mso-list: l1 level1 lfo1; tab-stops: list 45.0pt"&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-bidi-font-family: Symbol; mso-fareast-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=2&gt;·&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="mso-bidi-font-family: Arial"&gt;&lt;FONT size=2&gt;&lt;FONT face=Arial&gt;Use EAP-TLS machine cert&amp;nbsp;in conjunction with&amp;nbsp;user smart card cert for wireless LAN access&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 4pt 0in 6pt 45pt; TEXT-INDENT: -0.25in; mso-list: l1 level1 lfo1; tab-stops: list 45.0pt"&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-bidi-font-family: Symbol; mso-fareast-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=2&gt;·&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT size=2&gt;&lt;FONT face=Arial&gt;&lt;SPAN style="mso-bidi-font-family: Arial"&gt;Use&amp;nbsp;Windows Vista (with Network Access Protection feature at server side) for&lt;/SPAN&gt;&lt;SPAN style="mso-bidi-font-family: Arial; mso-fareast-language: ZH-CN"&gt; &lt;/SPAN&gt;&lt;SPAN style="mso-bidi-font-family: Arial"&gt;wireless Corpnet LAN connec&lt;/SPAN&gt;&lt;SPAN style="mso-bidi-font-family: Arial; mso-fareast-language: ZH-CN"&gt;tion&lt;/SPAN&gt;&lt;SPAN style="mso-bidi-font-family: Arial"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 4pt 0in 6pt 45pt; TEXT-INDENT: -0.25in; mso-list: l1 level1 lfo1; tab-stops: list 45.0pt"&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-bidi-font-family: Symbol; mso-fareast-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=2&gt;·&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="mso-bidi-font-family: Arial"&gt;&lt;FONT size=2&gt;&lt;FONT face=Arial&gt;Use Windows Mobile 2005 (with software cert authentication)&amp;nbsp;for wireless phone device email synchronization&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 4pt 0in 6pt 45pt; TEXT-INDENT: -0.25in; mso-list: l1 level1 lfo1; tab-stops: list 45.0pt"&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-bidi-font-family: Symbol; mso-fareast-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=2&gt;·&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="mso-bidi-font-family: Arial; mso-fareast-language: ZH-CN"&gt;&lt;FONT face=Arial size=2&gt;Evaluate TPM as long term solution for device authentication&lt;/FONT&gt;&lt;/SPAN&gt;&lt;SPAN style="mso-bidi-font-family: Arial"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=422404" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/yaleli/archive/tags/2.+Strategy/default.aspx">2. Strategy</category></item><item><title>Authorization Strategy</title><link>http://blogs.technet.com/yaleli/archive/2006/06/05/422539.aspx</link><pubDate>Mon, 05 Jun 2006 10:00:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:422539</guid><dc:creator>Yale Li</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/yaleli/comments/422539.aspx</comments><wfw:commentRss>http://blogs.technet.com/yaleli/commentrss.aspx?PostID=422539</wfw:commentRss><wfw:comment>http://blogs.technet.com/yaleli/rsscomments.aspx?PostID=422539</wfw:comment><description>&lt;P&gt;Authorization (or establishment or entitlement) defines a user's (or process') rights and permissions&amp;nbsp;to a resource. After a user (or process) is authenticated, authorization determines what that user can do&amp;nbsp;to the resource.&lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P&gt;Here are some&amp;nbsp;authorization strategies to improve security:&lt;o:p&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;By default, grant users&amp;nbsp;no rights and permissions&lt;o:p&gt;&lt;/o:p&gt; 
&lt;LI&gt;Grant users least privileged rights and permissions on "need to know" basis&lt;o:p&gt;&lt;/o:p&gt; 
&lt;LI&gt;Push authorization processes from upper/applications layers to lower/OS layers as much as possible&lt;o:p&gt;&lt;/o:p&gt; 
&lt;LI&gt;Prepare&amp;nbsp;or plan Role-Based authorization&lt;o:p&gt;&lt;/o:p&gt; 
&lt;LI&gt;Move from manual authorization&amp;nbsp;management processes to automated authorization management processes with next generation IAM role/group management products&lt;/LI&gt;&lt;/UL&gt;
&lt;P&gt;Please be aware of that Role-Base authorization will be a subset of Claim-Based authorization in long term.&lt;o:p&gt;&lt;/o:p&gt;&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=422539" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/yaleli/archive/tags/2.+Strategy/default.aspx">2. Strategy</category></item><item><title>Auditing Strategy</title><link>http://blogs.technet.com/yaleli/archive/2006/06/04/422541.aspx</link><pubDate>Sun, 04 Jun 2006 10:00:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:422541</guid><dc:creator>Yale Li</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/yaleli/comments/422541.aspx</comments><wfw:commentRss>http://blogs.technet.com/yaleli/commentrss.aspx?PostID=422541</wfw:commentRss><wfw:comment>http://blogs.technet.com/yaleli/rsscomments.aspx?PostID=422541</wfw:comment><description>&lt;P&gt;Auditing (also referred as Audit&amp;nbsp;or Accounting or Accountability) ensures that the activities associated with user access are logged for monitoring, regulatory and investigative purposes. &lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P&gt;Auditing Strategies for IAM to&amp;nbsp;be compliance:&lt;o:p&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;UL type=disc&gt;
&lt;LI class=MsoNormal style="MARGIN: 0in 0in 0pt; mso-list: l0 level1 lfo1; tab-stops: list .5in; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto"&gt;Identify regulations you company must&amp;nbsp;be compliance: such as SOX (Sarbanes-Oxley), HIPAA (Health Insurance Portability and Accountability Act), GLBA (Gramm-Leach-Bliley Act), Basel II.&lt;o:p&gt;&lt;/o:p&gt; 
&lt;LI class=MsoNormal style="MARGIN: 0in 0in 0pt; mso-list: l0 level1 lfo1; tab-stops: list .5in; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto"&gt;Assess current compliance baseline and perform gap analysis&lt;o:p&gt;&lt;/o:p&gt; 
&lt;LI class=MsoNormal style="MARGIN: 0in 0in 0pt; mso-list: l0 level1 lfo1; tab-stops: list .5in; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto"&gt;Implement IAM controls and compare with industry standards and best practices, such as ISO 17799&lt;o:p&gt;&lt;/o:p&gt; 
&lt;LI class=MsoNormal style="MARGIN: 0in 0in 0pt; mso-list: l0 level1 lfo1; tab-stops: list .5in; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto"&gt;Measure, test, remediate, and demonstrate your IAM controls&lt;o:p&gt;&lt;/o:p&gt; 
&lt;LI class=MsoNormal style="MARGIN: 0in 0in 0pt; mso-list: l0 level1 lfo1; tab-stops: list .5in; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto"&gt;Ensure IAM audit logs are secure and scalable&lt;o:p&gt;&lt;/o:p&gt; 
&lt;LI class=MsoNormal style="MARGIN: 0in 0in 0pt; mso-list: l0 level1 lfo1; tab-stops: list .5in; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto"&gt;Get&amp;nbsp;IAM reporting&amp;nbsp;tools&amp;nbsp;that meet auditor's needs&lt;o:p&gt;&lt;/o:p&gt;&lt;/LI&gt;&lt;/UL&gt;
&lt;P&gt;Usually, enterprise IT should have a dedicated governance/audit team (or professionals) to provide compliance guidelines. If not,&amp;nbsp;you should&amp;nbsp;consult with external audit professional service.&lt;o:p&gt;&lt;/o:p&gt;&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=422541" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/yaleli/archive/tags/2.+Strategy/default.aspx">2. Strategy</category></item><item><title>Systems Management Stategy</title><link>http://blogs.technet.com/yaleli/archive/2006/03/17/422415.aspx</link><pubDate>Fri, 17 Mar 2006 15:00:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:422415</guid><dc:creator>Yale Li</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/yaleli/comments/422415.aspx</comments><wfw:commentRss>http://blogs.technet.com/yaleli/commentrss.aspx?PostID=422415</wfw:commentRss><wfw:comment>http://blogs.technet.com/yaleli/rsscomments.aspx?PostID=422415</wfw:comment><description>&lt;P&gt;Digital identities includes not only people but also devices, such as machine account and machine certificate, and applications (or software services). Therefore, there is a small&amp;nbsp;overlapped area between systems management and IAM. Although systems management is another big area in IT, you should have&amp;nbsp;a good&amp;nbsp;understanding of systems management&amp;nbsp;in order to figure out&amp;nbsp;where the common area should be organized into.&lt;/P&gt;
&lt;P&gt;Major Systems Management Goals:&lt;/P&gt;
&lt;P&gt;- Asset and Inventory Management&lt;/P&gt;
&lt;P&gt;- Configuration Management&lt;/P&gt;
&lt;P&gt;- Remote Control&lt;/P&gt;
&lt;P&gt;- Health Monitoring&lt;/P&gt;
&lt;P&gt;- Software Provision and Distribution&lt;/P&gt;
&lt;P&gt;- Software License Metering&lt;/P&gt;
&lt;P&gt;Software Provision and Distribution is most like the area which an IAM system can also take care by using AD GPO or provisioning tool. The strategy is to treat systems management as an exteranl dependancy, just like how HR system is treated as an external dependancy.&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=422415" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/yaleli/archive/tags/2.+Strategy/default.aspx">2. Strategy</category></item></channel></rss>