Federated Identity, SSO and Multifactor Authentication June 23 rd , - - PowerPoint PPT Presentation

federated identity sso and multifactor authentication
SMART_READER_LITE
LIVE PREVIEW

Federated Identity, SSO and Multifactor Authentication June 23 rd , - - PowerPoint PPT Presentation

Computing Services and Systems Development Federated Identity, SSO and Multifactor Authentication June 23 rd , 2017 Computing Services and Systems Development F EDERATED I DENTITY , SSO AND MFA @ THE U NIVERSITY OF P ITTSBURGH Tony Carra


slide-1
SLIDE 1

Computing Services and Systems Development

Federated Identity, SSO and Multifactor Authentication

June 23rd, 2017

slide-2
SLIDE 2

Computing Services and Systems Development

FEDERATED IDENTITY, SSO AND MFA @

THE UNIVERSITY OF PITTSBURGH

Tony Carra

slide-3
SLIDE 3

Computing Services and Systems Development

Pitt Passport

  • Single Sign-on service
  • Grants access to Web Based Services such as;

– My.Pitt.edu – CourseWeb (Blackboard) – Student Information System – Box – Office 365 – Many Others

slide-4
SLIDE 4

Computing Services and Systems Development

Features of Pitt Passport

  • Consistent

– Consistent, trusted login experience; passport.pitt.edu

  • Multifactor Authentication

– Enhanced security with added layer

  • Login History
slide-5
SLIDE 5

Computing Services and Systems Development

Technology behind Pitt Passport

  • Shibboleth
  • Pitt Passport is more than just Shibboleth…

– Central Database / Registry – Active Directory – Provisioning System

slide-6
SLIDE 6

Computing Services and Systems Development

Pitt Passport and IAM system

Student System Human Resources System ID Center System UPMC Systems

Identity Provisioning System Central Directory System Account Management Web Site Act Mgt Web Service

Office 365 Active Directory in Azure

Other Cloud Applications Box Panopto

Other University Systems Active Directory Pitt Passport

slide-7
SLIDE 7

Computing Services and Systems Development

Groups

  • Managed via Web Based Application
  • Allows flexibility…for Users and

Departments

– Create Groups – Maintain membership – Can be used through-out many different applications

slide-8
SLIDE 8

Computing Services and Systems Development

Why Shibboleth?

  • Reduced number of IDs and passwords for

end users

  • Works with SAML 2.0
  • Easy to customize for different

configurations

  • Built for High Ed and Research organizations
slide-9
SLIDE 9

Computing Services and Systems Development

Multifactor Authentication in Pitt Passport

  • Provided by Duo Security
  • Adds a layer of security
  • Requires 2 “Factors” to verify identity

– Something you Know – Something you Have

slide-10
SLIDE 10

Computing Services and Systems Development

Multifactor Authentication (cont.)

  • Benefits:

– Secure – Efficient – Convenient

slide-11
SLIDE 11

Computing Services and Systems Development

Joining InCommon Federation

  • Implementation of Service Providers
  • Trusted Partners

– Level of Trust – Others Universities working with partners

  • Certificates
slide-12
SLIDE 12

Computing Services and Systems Development

Thank You Questions?