Showing posts with label Centrify User Suite. Show all posts
Showing posts with label Centrify User Suite. Show all posts

Sunday, December 28, 2014

Business Cases - Web-Mobile SSO Planning Session II: Apps

Planning for Applications

When we plan for Applications (Web or Mobile), we need to think about different strategies.  These types of questions arise:
  • How will the application be published?  
    Centrify provides the user portal, however, depending on your environment, you may have an intranet or content management platform that is used as a hub for applications.
  • What is the policy to access these applications?
    Apps can have different assurance requirements.  Maybe certain portions of the HR app are for intranet-only access with step-up (or two-factor) authentication.  Maybe your Netsuite-based ERP should only be available from inside of the United States.
  • Who should be entitled to access each app?
    Your security team may want to grant access based role or job function.  Centrify User Suite uses AD or Cloud Directory principals for app visibility.
  • What are the authentication capabilities of the app?
    Modern (especially cloud-based apps) provide federation technologies (like SAML, etc) but legacy apps don't have those capabilities or aren't available in the current version.  Also (and unfortunately) not all apps may be looking at the corporate directory (e.g. AD) as the identity repository (which can enable Kerberos or NTLM).  CUS offers the flexibility of password-vaulting and replaying.
  • How is the application provisioning model?
    This topic impacts the bottom-line of the business because the timely deprovisioning of cloud apps can impact the billing depending on how the application provider is metering the usage of the application.  In addition, some apps need to have entitlements provisioned as well for the purposes of role-based access.
  • What is the strategy for on-premise apps?
    Are these apps accessible via an existing VPN infrastructure (e.g. CheckPoint, Cisco, Microsoft's DirectAccess or others) or will you make use of the Centrify App Gateway (VPN-less access)?
These are high-level categories, there are advanced topics like timeouts, attribute-mapping, provisioning of certificates for federation trust, etc; but we will cover each scenario individually.

We will start by publishing these Web applications:
  • On-premises SharePoint (as a shortcut)
  • On-premises Apache or Java-based apps (leveraging NTLM, Kerberos & ADFS-less WS-Fed apps)
  • Google Apps
  • Salesforce
  • Office365.
Later we'll move on to Mobile apps on the Google Play and Apple App Store.

Monday, December 15, 2014

Cloud Lab # 0 - Signing-up for a Centrify Cloud Tenant

In a previous post, I discussed the capabilities of the Centrify Cloud Service.  Unfortunately this post will become obsolete because Centrify adds capabilities and tweaks the service every month, but as of December 2014 (v 14.10), here are the high-level capabilities:

To register for a Centrify cloud tenant you'll need an email address.  Follow these instructions:

  1. Go to http://www.centrify.com/lp/trial/centrify-solutions.asp and request a trial.  Alternatively, you can register for an Express account via www.centrify.com > Free Products > Centrify Express for SaaS > Request a Trial.  After 30 days, the premium features will be disabled.  Fill out the form:
  2. You will receive an email from Centrify on the email address specified. Click on the validation link:
  3. Upon validation you will be assigned a tenant ID.  Press the button to log in to Cloud Manager

    You will also receive an email with your initial credentials.
  4. When you attempt to log in to the cloud manager with your password, you'll be asked to provide an additional authentication method - since e-mail is the only option, you'll receive an email to your account, click on the link and you'll be signed in.
  5. Upon login, you'll be welcome by the configuration wizard.

What happens when a tenant is created?
The Centrify Cloud service runs in Microsoft Azure platform;  note that when the tenant was created, you had the chance to create your tenant in different places based on your region.  In the background, these tasks are created:

  • Multiple copies of the service and basic data are created inside the cloud (for redundancy)
  • Sets of different encryption keys are created (for encryption services)
  • An internal dedicated Certificate Authority is created.
  • The initial login suffix is created based on the user's email address.
  • The tenant is branded with Centrify's logo and colors.
This is obviously a simplified list, but it's important that they are understood for future posts.  This lab contains no videos.


Next-up:  Initial setup and customization.