Contextual Access and Multi-Factor Authentication Lessons learned on - - PowerPoint PPT Presentation

contextual access and multi factor authentication
SMART_READER_LITE
LIVE PREVIEW

Contextual Access and Multi-Factor Authentication Lessons learned on - - PowerPoint PPT Presentation

Conference 2018 Contextual Access and Multi-Factor Authentication Lessons learned on getting past single-factor authentication! Panelists Corey Scholefield - Team Lead, Identity Services Wendy Blake Director, Network and Technical Services


slide-1
SLIDE 1

Conference 2018

Lessons learned on getting past single-factor authentication!

Contextual Access and Multi-Factor Authentication

slide-2
SLIDE 2

Conference 2018

Panelists

2

Corey Scholefield - Team Lead, Identity Services

Wendy Blake – Director, Network and Technical Services Sean Feil – Specialist, Identity, Information Technologies

Sebastian Gonzales, Sr. Mgr – Identity & Access Mgmt.

slide-3
SLIDE 3

Conference 2018 ¡

Contextual Access Control

¡

Multi-factor Authentication

What are we talking about?

3

slide-4
SLIDE 4

Conference 2018 ¡

Meet your neighbour and discuss multi- factor authentication capability at your

  • rganization…!

¡

Deployed or not ?

¡

Support for or not ?

Meet your neighbour!

4

slide-5
SLIDE 5

Conference 2018 ¡

Business Drivers

¡

Restricting privileged access

¡

Reduce risk of ransomware/phishing

¡

PCI Compliance

Use Case - TRU

5

slide-6
SLIDE 6

Conference 2018

¡ Systems in scope for

deployment

¡

Primary

¡

Password vault (thycotic)

¡

Firewall UI (Panorama)

¡

RDP to desktops (users who use VPN to access network)

¡

Secondary

¡

VPN

¡

Servers (Linux and Windows)

¡

Banner privileged accounts

¡

Root/administrator accounts

¡

BANSECURE named accounts

¡

INB accounts

Use Case - TRU

6

slide-7
SLIDE 7

Conference 2018 ¡

Lessons Learned

¡

Have a well defined plan

¡

If we knew now…..?

¡

Overall we have had a good experience

Use Case - TRU

7

slide-8
SLIDE 8

Conference 2018

Use Case - UCalgary

8

slide-9
SLIDE 9

Conference 2018

UCalgary – Business Drivers

9

Prevent account compromise Reduce support burden Reduce costs associated with risk Reduce lost productivity Audit requirements

slide-10
SLIDE 10

Conference 2018

UCalgary – Deployment

10

Deployed

Testing Pilot Technical Pilot Business Pilot All Staff All Students

slide-11
SLIDE 11

Conference 2018

UCalgary – Deployment

11

Legacy Interfaces (technical) New Interfaces (technical)

SAML 2 WS-FED OpenID Connect OAuth RADIUS LDAP SecurID native RADIUS CAS (custom)

slide-12
SLIDE 12

Conference 2018

UCalgary – Deployment

12

slide-13
SLIDE 13

Conference 2018

UCalgary – Lessons Learned

13

slide-14
SLIDE 14

Conference 2018

UCalgary – Lessons Learned

14

slide-15
SLIDE 15

Conference 2018

UCalgary – Lessons Learned

15

slide-16
SLIDE 16

Conference 2018

UCalgary – Lessons Learned

16

slide-17
SLIDE 17

Conference 2018

UCalgary – Lessons Learned

17

slide-18
SLIDE 18

Conference 2018

UCalgary – Next Steps

18

  • Hardware token support and deployment strategy
  • Deploy to remaining staff and students
  • Expand systems protected by MFA
  • Strengthen contextual access to reduce need for token authentication
slide-19
SLIDE 19

Conference 2018

UVic – Business Drivers

19

AUDIT + PCI

Manage Risk

Compromised Accounts

slide-20
SLIDE 20

Conference 2018

2012 • Cisco VPN – for NETS Staff 2014 • Unix Shell - for Privileged Admins 2017

  • Banner 8 Forms – Finance
  • On-premise Yubikey OTP Server + Key Management in IdentityIQ

2018

  • VPN MFA access expanded to IT staff
  • CAS 5.2 SSO + Banner 9 / AppNavigator

UVic – YubiKey MFA applications

20

slide-21
SLIDE 21

Conference 2018

UVic – Lessons Learned

21

  • Gartner

research

  • Unicon

support

  • Audit
  • Info Sec
  • Reputational

risk

  • People
  • Process
  • Technology
  • Leadership
  • IT
  • Clients

Buy-in Business Process Best- practices Driving Forces

slide-22
SLIDE 22
slide-23
SLIDE 23

Conference 2018

UVic – Next Steps

23

Staff desktops Web apps More factors

slide-24
SLIDE 24

Conference 2018 ¡

Business Drivers

¡

Deployment

¡

Lessons Learned

¡

If we knew now…..

¡

Next Steps

Use Case

24

slide-25
SLIDE 25

Conference 2018 25

slide-26
SLIDE 26

Conference 2018 26

slide-27
SLIDE 27

Conference 2018 27

slide-28
SLIDE 28

Conference 2018 28

slide-29
SLIDE 29

Conference 2018 29

slide-30
SLIDE 30

Conference 2018 30

slide-31
SLIDE 31

Conference 2018 31

slide-32
SLIDE 32

Conference 2018 ¡

Lessons Learned.

¡

Don’t be afraid to ask for ….

¡

Some of the best support is in the communities…

¡

Set a 25 min floor to present…

¡

Test your communications not just your tech…

¡

If we knew now…..

¡

Portion Control….

Use Case

32

slide-33
SLIDE 33