Home > Ask the Security Experts > Identity Management and Access Control Questions & Answers > Can ADFS technology manage multiple-user authentication?
Ask The Security Expert: Questions & Answers
EMAIL THIS

Can ADFS technology manage multiple-user authentication?

Joel Dubin, past SearchSecurity.com expert EXPERT RESPONSE FROM: Joel Dubin, past SearchSecurity.com expert

Pose a Question
Other Security Categories
Meet all Security Experts
Become an Expert for this site


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


>
QUESTION POSED ON: 19 February 2007
Is Active Directory Federation Services (ADFS) technology mature enough for managing the authentication of remote customers to a Web application?

>
Active Directory Federation Services (ADFS) became a standard feature in Windows Server 2003 R2. The problem with ADFS is not so much the maturity of the technology itself, but rather the shifting landscape of standards for federated identity management and whether those standards are in line with your environment. Those standards underpin all federated identity management systems, including ADFS. Despite the name, ADFS isn't an extension of Active Directory; it's a Windows component that uses Active Directory.

There have been a few issues with ADFS, but let's first take a look at federated identity management, a technology still in a state of evolution.

Federated identity management is closely related to single sign-on, another technology for allowing authentication across diverse systems. Single sign-on allows a user with a single user ID and password -- or other login credentials -- access to multiple systems. The single user ID and password replaces multiple IDs and passwords a user might need to log on to different applications and systems.

The difference between single sign-on and federated identity is that single sign-on is for logging on within a single enterprise. Federated identity is used for logging in across several enterprises. Such a system could allow, for example, a company to directly access the systems of its suppliers -- different companies with different IT systems in different domains.

Communication among various enterprises with unrelated IT systems across corporate boundaries is the key to federated identity management systems, like ADFS. These systems can only play each other if they all abide by an independent set of standards -- agreed on by all members of the system -- for communicating authentication information to each other.

Microsoft and IBM compiled a set of standards using the WS-Federation protocol for message-based applications. Another standard is Security Assertion Markup Language (SAML), which is based on XML. Microsoft backed early versions of SAML, but broke with the standard in 2005 when SAML 2.0 was released. SAML 2.0 is backed by a consortium of companies and organizations, including the Liberty Alliance and the Organization for the Advancement of Structured Information Systems (OASIS). Both are heavily involved in setting federated identity management standards.

It's important to keep track of the different standards and platforms they work with, and the ever-shifting alliances backing each standard. Match these with your environment before making a decision on a federated identity management implementation.

Finally, Joe Kaplan, a Microsoft MVP in directory services, has reported a problem with the way ADFS handles cookies for maintaining authentication session state. Cookies are frequently used for managing such sessions, but can pose problems when used across domain and enterprise boundaries, as with ADFS. Kaplan has described workarounds and how to avoid common pitfalls with cookies and ADFS. The technology is sound, but it may need tweaking to handle cookies properly.

For more information:

  • Learn more about one of the most exciting features in Microsoft Windows Server 2003, ADFS.
  • In this Q&A, Joel Dubin explores the differences between local identity, SSO and federated identity management models.


  • BROWSE BY TAG
    Identity Management and Access Control,   Web Authentication and Access Control,   Enterprise Identity and Access Management,   Enterprise Single Sign-On (SSO),   User Authentication Services,   Expert Archive: Identity Management and Access Control,   VIEW ALL TAGS

    Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



    RELATED CONTENT
    Identity Management and Access Control
    Is Identity Management as a Service (IDaaS) a good idea?
    How to log in to multiple servers with federated single sign-on (SSO)
    How to confirm the receipt of an email with security protocols
    Learn about enterprise strategy for server virtualization single sign-on
    Employee information security awareness training for new IAM systems
    Can you combine RFID tag technology with GPS to track stolen goods?
    Is there a free enterprise-caliber password-management tool?
    Cryptosystem attacks that do not involve obtaining the decryption key
    Can any firm or organization get a digital signature certificate?
    Should the CTO have domain administrator access?

    Web Authentication and Access Control
    Group to shed light on secure identity management threats
    How to confirm the receipt of an email with security protocols
    Schneier-Ranum Face-Off: Is Perfect Access Control Possible?
    Kaminsky reveals key flaws in X.509 SSL certificates at Black Hat
    Changing times for identity management
    How to use single sign-on for Web access control to prevent malware
    IBM USB banking device stops keyloggers, malware
    Can mutual authentication beat phishing or man-in-the-middle attacks?
    Could someone place a rootkit on an internal network through a router?
    Sun launches open source OpenSSO for identity management

    Enterprise Single Sign-On (SSO)
    How to log in to multiple servers with federated single sign-on (SSO)
    Security on a budget: How to make the most of authentication tools
    Best Identity and Access Management Products
    Changing times for identity management
    Kerberos configuration as an authentication system for single sign-on
    How to use single sign-on for Web access control to prevent malware
    Learn about enterprise strategy for server virtualization single sign-on
    Enterprise single sign-on: Easing the authentication process
    Exploring authentication methods: How to develop secure systems
    User provisioning and SSO for PeopleSoft- and Unix-based products
    Enterprise Single Sign-On (SSO) Research

    RELATED GLOSSARY TERMS
    Terms from Whatis.com − the technology online dictionary
    access log  (SearchSecurity.com)
    anonymous Web surfing  (SearchSecurity.com)
    authentication, authorization, and accounting  (SearchSecurity.com)
    identity chaos  (SearchSecurity.com)
    knowledge-based authentication  (SearchSecurity.com)
    multifactor authentication (MFA)  (SearchSecurity.com)
    walled garden  (SearchSecurity.com)

    RELATED RESOURCES
    2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
    Search Bitpipe.com for the latest white papers and business webcasts
    Whatis.com, the online computer dictionary



    Search and Browse the Expert Answer Center
    Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
    Browse our Expert Advice



    Find Security Solutions for Your Business
    TechTarget Security Media
    Information Security View this month\\'s issue and subscribe today.
    Information Security Decisions Apply online for free conference admission.
    SearchSecurity.com
    HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Site Map




    All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts