10.30.2015 - Bridging the OAuth2/SAML2 Divide, Part1

It’s no secret that OAuth2 and OpenID Connect are gaining in popularity. It seems that all of our customers are in the process of rolling out OAuth2 and OpenID Connect, or are thinking about it. But how can these newer protocols play nicely in your enterprise if you already have a SAML2 or WS-Federation infrastructure? The answer is an identity broker (also known as a federation proxy). ...

10.15.2015 - Benefits of a Cloud Federation Broker

Before diving into the benefits of a cloud federation (SAML or WS-Federation) broker, let me first cover what it is.  You can think of a cloud federation broker as a gateway or proxy server that all federation request go through.  Optimal IdM’s federation broker (The OptimalCloud) is a cloud service that contains one or more trusts to an on premise Identity Provider (IdP) or trust to a customer/business partner, which users authenticate with their local credentials, and a trust for each federated application (both on premise and cloud hosted applications), see picture below. ...

10.8.2015 - A Virtual Directory Server (VDS) Is a Swiss Army Knife That Enterprise Architects Cannot Be Without

Even at the smallest companies, the infrastructure needed to support the business is complex.  From data centers to data stores, the technical footprint of a company can span the globe.  There are internal applications, intranet applications, external federated applications (SAML, OAuth) and there are internal-corporate users and external-partner users that access these company resources on a daily basis.  It is easy to see how securely combining all the pieces required to allow a business to run can be difficult task. ...

Tags

  • The database in which all of your organization’s sensitive identity data is stored.
  • A digital ledger in which digital transactions are recorded chronologically and publicly.
  • Securely managing customer identity and profile data, and controlling customer access to applications and services.
  • The means of linking a person's electronic identity and attributes, stored across multiple distinct identity management systems.
  • A legal framework that sets guidelines for the collection and processing of personal information of individuals within the EU.
  • The policy-based centralized orchestration of user identity management and access control.
  • An authentication infrastructure that is built, hosted and managed by a third-party service provider.
  • A security system that requires more than one method of authentication from independent categories of credentials to verify the user's identity for a login or other transaction.
  • A global provider of innovative and affordable identity access management solutions. 
  • Managing and auditing account and data access by privileged users.
  • Tools and technologies for controlling user access to critical information within an organization.
  • An authentication process that allows a user to access multiple applications with one set of login credentials.