Thursday, November 01, 2007

Is federation stillborn?

I was party to a short, but interesting internal e-mail debate yesterday about federation. One view was that it was never going to amount to much due to politics and complexity. The other view was that it is starting to take off in certain scenarios and could potentially grow much bigger albeit the socio-political and complexity ramifications still loom.

I figured the debate was more or less over after a few e-mails but then I happened to read John Fontana's Network World article titled Microsoft switching SharePoint to claims-based authentication. So I'll switch the debate from internal e-mail to my blog and state that it will be scenarios that applications like SharePoint enable that will propel federation forward. Second, to see that Microsoft is opening up such a critical piece of their collaboration platform to federation and non-Active Directory authentication is both amazing and awesome.

I learned a lot about making products and technologies "viral" while I was at Microsoft. Bundling SharePoint services with the server operating system did just that - it introduced SharePoint to tens of thousands of companies and, at the same time, enabled those pesky administrators to build SharePoint sites with no IT oversight. Result? Hundreds of SharePoint sites at most companies before IT even knew how to spell SharePoint. Now Microsoft is going to enable SharePoint to be downloaded without having to purchase a server. The result will be that nearly everyone will become infected. (Need some free software to determine how many SharePoint sites you have? Click here.)

Add federation to the mix and the result is a federated, collaboration solution that nearly anyone will be able to "stand up". Yes, it may be complicated to set up but the admins can figure that out and while the various IT committees and internal standards groups are meeting in conference rooms with poor air circulation and no windows a whole new class of federated SharePoint sites will be springing up from the earth...

Technorati Tags:
, , , , , , ,

Wednesday, October 31, 2007

Matt Flynn's Identity Management Blog: Surviving an Identity Audit

Check out Matt Flynn's Identity Management Blog: Surviving an Identity Audit and Matt's associated white paper on this topic. Good reading. There's not enough info on how identity and identity audits in particular map to compliance - despite the fact that compliance is a big driver/stick for getting your identity house in order. (You need to overlook the commercial reference at the end of Matt's whitepaper. Unfortunately, we sometimes have to support our employer in our writings.)

Identity audit solutions reduce organizational risk by providing reports and monitoring of the identity systems which grant or deny system access and the user accounts empowered to act within the environment. Having effective audit and monitoring in place also has the additional benefit of acting as a deterrent for system users who might otherwise attempt to subvert policy.

While flipping through the channels tonight I happened across an old favorite - "The Exorcist". I was reminded of that famous line "The Power of Christ" while I read Matt's whitepaper where he talks about the "Power of Identity". Unfortunately, it was the Catholic priests at my school that forbade us to see The Exorcist that made us run out to see it immediately (of course).

Matt, maybe you should forbid people from reading your whitepaper? Nice work.

See you at the Gartner conference?


Technorati Tags:
,

Archive the box!

If you liked the Quest Idol video that I posted about in February then you'll like our "Archive the box" video that the same group of guys here at Quest put together...It's all about our Exchange archive manager product.





Technorati Tags:
, ,

Tuesday, October 30, 2007

Identity and the "50 greatest arguments"

Network World recently published this interesting story:

Perhaps the only thing more fun than working on and playing with network technologies is arguing about them. Macs vs. PCs. Ethernet vs. Token Ring. Outsourcing vs. keeping it in-house. Here's our take on the nastiest, most colorful and in some cases, still unresolved network industry arguments. Read up and weigh in.

Yes, a few of their top 50 "arguments" are identity related! Here they are:

X.500 vs. LDAP - Directory services battle took turn with advent of Internet

This architectural argument would pack networking conference sessions, divide the room and ignite heated shouting matches in the early-to-mid-1990s. It was a case of the student overtaking the mentor as the Lightweight Directory Access Protocol was at first a simple alternative to X.500’s Directory Access Protocol (DAP). LDAP was used for accessing X.500 directories via the TCP/IP protocol. With the advent of the Internet and its reliance on TCP/IP, X.500 faded into the background even though it was later modified for use over TCP/IP.

Flashback: I'm at the DISA conference on the Defense Message System (DMS) in Resto, VA circa 1995. I'm talking to the DMS Project Manager - a distant relation of my wife - and tell him that DMS is doomed to failure if it continues to ignore TCP/IP and LDAP over OSI and X.500. He tells me that I'm crazy. Who's crazy now, Wayne?! See the associated argument about SNA and OSI versus TCP/IP in the same list!

Industry standards vs. proprietary technologies

It’s hard to imagine now, but there used to be a rigorous debate about which strategy was best for corporate IT buyers: industry standards or proprietary technology. Standards have won this debate, but that doesn’t mean there weren’t advantages to buying proprietary technology.

Oh, really? Standards have won the debate? Do we have to go back to that argument I recently had about MIT Kerberos and Windows Kerberos? Will the real standard please stand up - you know, the one that is used by more people. After all, isn't it usage that defines success and standards versus "Should", "Must" and "Optional" statements in a piece of paper emitted from the IETF or United Nations?

Let's not even go back to the discussion of X.400 (an ISO standard) versus SMTP (an IETF standard). Why didn't they both win? They are both standards?

P.S. to Network World (John, you missed this one): How come you didn't mention X.400 vs. SMTP? That was a good argument while it lasted buddy!

Technorati Tags:
, , , ,