So you want to SSO …
Scott Tomilson
John DaSilva
You’ve waited long enough …
Copyright © 2015 Cloud Identity Summit. All rights reserved. 2
Mobile AppsWeb Apps SaaS Apps
username
password
username
password
username
password
username
password
username
password
username
password
username
password
username
password
username
password
Copyright © 2015 Cloud Identity Summit .All rights reserved. 3
Copyright © 2015 Cloud Identity Summit .All rights reserved. 4
Integration
Kits
It’s time for SSO …
… what do you mean by SSO?
App Enablement?Session Management? Access Control?
Auditing?Authentication Policy?
“One Username & Password
(or some other form of authentication)
just One Time”
It’s time for SSO …
… and how will we get SSO?
Open Standards?On-Premise ? IdaaS?
Agents vs Gateway?App Changes?
“Eliminate Unnecessary Passwords”
(yes, some work will be needed –
but you want to do this the right way)
Copyright © 2015 Cloud Identity Summit .All rights reserved. 7
Access Management
ENTERPRISE
Federated Identity Management
SSOfor
Web Applications
Copyright © 2015 Cloud Identity Summit. All rights reserved. 8
“First Mile” / “Last Mile” Integration
Federation
Server
Identity
Store
Federation
Server
Target
App
Identity Provider (IdP) Service Provider (SP)
“First Mile” “Last Mile”
“First Mile” Integration
•  If you’re using a Federation Server – hopefully this is
just a configuration exercise:
•  ADconnect (Active Directory)
•  PingFederate (Complex AD, LDAP, WAM, etc.)
•  PingOne Cloud Directory (IdaaS user/group dir.)
•  Worst case – there are Libraries & APIs to help you
integrate a custom portal or user store
Copyright © 2015 Cloud Identity Summit. All rights reserved. 10
“Last Mile” Integration
Here’s where things get interesting …
Copyright © 2015 Cloud Identity Summit. All rights reserved. 11
“Last Mile” Integration
Question #1:
Does your application support Web
(federated) SSO standards?
(i.e.: SAML, WS-Federation, OpenID Connect)
Copyright © 2015 Cloud Identity Summit. All rights reserved. 12
“Last Mile” Integration – with Standards
Copyright © 2015 Cloud Identity Summit. All rights reserved. 13
Federation
Server
Identity
Store
Target
App
Identity Provider (IdP) Service Provider (SP)
SAML
Copyright © 2015 Cloud Identity Summit. All rights reserved. 14
“Last Mile” Integration – with Standards
Your Apps
Your Identity Stores /
Partners
Acme
Beta
Com
SAML
SAML
SAML
Federation
Hub
“Last Mile” Integration – with Standards
Copyright © 2015 Cloud Identity Summit. All rights reserved. 15
Does your app
Web SSO standards?
(SAML/WS-Fed/OIDC)
Do you prefer
IdaaS?
No
Yes
Yes
No
“Last Mile” Integration
Question #2:
Does your application support HTTP
header-based SSO?
Copyright © 2015 Cloud Identity Summit. All rights reserved. 16
“Last Mile” Integration – with HTTP Headers
Federation
Server
Identity
Store
Federation
Server
Target
App
Identity Provider (IdP) Service Provider (SP)
SAML
Agent /
Gateway
HTTP Headers
User: joe
Email: joe@co.co
Group: Sales
“Last Mile” Integration – with HTTP Headers
•  Federated SSO
•  PingFederate Integration Kits:
•  Apache & IIS
•  WAM Features (Session Management, URL Authorization & Auditing)
•  Gateway (Reverse Proxy)
•  Agents: Apache & IIS
Copyright © 2015 Cloud Identity Summit. All rights reserved. 18
“Last Mile” Integration – with Standards
Copyright © 2015 Cloud Identity Summit. All rights reserved. 19
Does your app
support HTTP header
based SSO?
Do you want
WAM features?
No
Yes
Yes
No
“Last Mile” Integration
Question #3:
Can you modify the application?
Copyright © 2015 Cloud Identity Summit. All rights reserved. 20
“Last Mile” Integration – with App Changes
Copyright © 2015 Cloud Identity Summit. All rights reserved. 21
Features Approach Effort Level Product(s)
Federated SSO Implement SAML
L n/a
Implement OpenID Connect
S n/a
HTTP Headers
XS PingFederate
REST API
S PingFederate
PingOne
SSO Integration Kit SDK Library
(Java, .NET) S PingFederate
WAM Features
(Session Management,
URL Authorization &
Auditing)
HTTP Headers
XS PingAccess
“Last Mile” Integration
Question #4:
Did you reach here with 3 NO’s?
Copyright © 2015 Cloud Identity Summit. All rights reserved. 22
“Last Mile” Integration – “I’m out of options…”
•  PingFederate Integration Kits
•  Basic SSO (Password Vaulting)
Copyright © 2015 Cloud Identity Summit. All rights reserved. 23
… still lost?
Talk to us!
SSOfor
Mobile Applications
Copyright © 2015 Cloud Identity Summit. All rights reserved. 24
Copyright © 2015 Cloud Identity Summit .All rights reserved. 25
Get Your Time Machines Ready …
SSO for Mobile Applications
•  Are multiple logins (with the same creds) OK?
•  User experience could be mitigated with long lived
refresh tokens
•  Shared refresh tokens? (Multiple apps – same dev. signer)
•  Shared browser session?
•  Centralized broker of OAuth Access Tokens
•  Napps – http://openid.net/wg/napps/
•  PingOne Mobile – Early Napps draft support
compatible with both PingFederate and PingOneCopyright © 2015 Cloud Identity Summit. All rights reserved. 26
In Closing …
Copyright © 2015 Cloud Identity Summit. All rights reserved. 27
Copyright © 2015 Cloud Identity Summit .All rights reserved. 28

More Related Content

PDF
CIS 2015 SAML-IN / SAML-OUT - Scott Tomilson & John Dasilva
PDF
CIS 2015 SSO for Mobile and Web Apps Ashish Jain
PDF
CIS 2015 Session Management at Scale - Scott Tomilson & Jamshid Khosravian
PDF
The Case For Next Generation IAM
PPTX
DevOps & Apps - Building and Operating Successful Mobile Apps
PPTX
Financial services rely on APIs
PPTX
apidays LIVE Singapore 2021 - Protecting the API ecosystem by Omaru Maruatona...
PPTX
Balancing Mobile UX & Security: An API Management Perspective Presentation fr...
CIS 2015 SAML-IN / SAML-OUT - Scott Tomilson & John Dasilva
CIS 2015 SSO for Mobile and Web Apps Ashish Jain
CIS 2015 Session Management at Scale - Scott Tomilson & Jamshid Khosravian
The Case For Next Generation IAM
DevOps & Apps - Building and Operating Successful Mobile Apps
Financial services rely on APIs
apidays LIVE Singapore 2021 - Protecting the API ecosystem by Omaru Maruatona...
Balancing Mobile UX & Security: An API Management Perspective Presentation fr...

What's hot (20)

PPTX
Gartner IAM London 2017 Session - Security, Standards & User Experience: The ...
PPTX
Trust No One: The New Security Model for Web APIs - SecTor talk by Greg Kliew...
PDF
CIS 2015 What I Learned From Pitching IAM To My CIO - Steve Tout
PDF
CIS 2015 The IDaaS Dating Game - Sean Deuby
PPTX
Criteria for Effective Modern IAM Strategies (Gartner IAM 2018)
PDF
CIS14: PingAccess in Action
PDF
Webinar: Deep Diving Into the KuppingerCole IDaaS Leadership Compass
PPTX
ForgeRock CTO TECHNOLOGY PREVIEW
PDF
NEW INNOVATIONS IN CONSENT, PRIVACY, AND USER-MANAGED ACCESS
PDF
API Security and OAuth for the Enterprise
PPTX
Identity Beyond Employees: How Customer Experience Impacts Your IAM Practices
PDF
Leveraging New Features in CA Single-Sign on to Enable Web Services, Social S...
PPTX
apidays LIVE India - 10 steps to secure your API by Pabitra Kumar Sahoo, Qual...
PDF
Who’s Knocking? Identity for APIs, Web and Mobile
PPTX
Do we have a round wheel? Thoughts on Identity standards
PDF
API Security Webinar : Security Guidelines for Providing and Consuming APIs
PDF
Red Hat Summit - OpenShift Identity Management and Compliance
PDF
[Kong summit 2019] Egress Gateway Pattern - Zhuojie Zhou
PPTX
Inbound Federation and Zero Sign On (ZSO) by Ranjan Jain at Ping Identity Wor...
PPTX
Identity Live London 2017 | Daniel Raskin
Gartner IAM London 2017 Session - Security, Standards & User Experience: The ...
Trust No One: The New Security Model for Web APIs - SecTor talk by Greg Kliew...
CIS 2015 What I Learned From Pitching IAM To My CIO - Steve Tout
CIS 2015 The IDaaS Dating Game - Sean Deuby
Criteria for Effective Modern IAM Strategies (Gartner IAM 2018)
CIS14: PingAccess in Action
Webinar: Deep Diving Into the KuppingerCole IDaaS Leadership Compass
ForgeRock CTO TECHNOLOGY PREVIEW
NEW INNOVATIONS IN CONSENT, PRIVACY, AND USER-MANAGED ACCESS
API Security and OAuth for the Enterprise
Identity Beyond Employees: How Customer Experience Impacts Your IAM Practices
Leveraging New Features in CA Single-Sign on to Enable Web Services, Social S...
apidays LIVE India - 10 steps to secure your API by Pabitra Kumar Sahoo, Qual...
Who’s Knocking? Identity for APIs, Web and Mobile
Do we have a round wheel? Thoughts on Identity standards
API Security Webinar : Security Guidelines for Providing and Consuming APIs
Red Hat Summit - OpenShift Identity Management and Compliance
[Kong summit 2019] Egress Gateway Pattern - Zhuojie Zhou
Inbound Federation and Zero Sign On (ZSO) by Ranjan Jain at Ping Identity Wor...
Identity Live London 2017 | Daniel Raskin
Ad

Viewers also liked (20)

PDF
CIS 2015 SCIM in the Real World - Kelly Grizzle
PDF
CIS 2015- Assessing the Risk of Identity and Access- Venkat Rajaji
PDF
CIS 2015 Modernize IAM with UnboundID and Ping Identity - Terry Sigle & B. Al...
PDF
Mobile Persuasion
PPTX
Identity assurance & the market for verified attributes
PPTX
Project Management is the Catalyst to transform India into a Global Leader in...
PPTX
Digital Rights Management
PPTX
Taste of Failure is Key for Sustainable Success
PPTX
Responsible Global Spend - Sample Program and Timeline
PDF
AGLEA SAP Security Analyzer SoD Remediation SoX authorization
PPTX
Cloud & Mobility Goldmines
PDF
TechNight #12: Cloud Identity Summit 2014 @ Monteray 概要と主要トピック
PDF
CIS13: Next Generation Privileged Identity Management: A Market Overview
PPTX
Advanced Authorization for SAP Global Deployments Part III of III
PDF
OpenID TechNight - Ping Identity 製品紹介
PPTX
OpenID Connect Demo at OpenID Tech Night
PPT
SharePoint Business Track Part 1 of 2
PDF
Digital in store for dummies
PPTX
Colin Glynn, Rolls-Royce plc Presentation
PDF
CIS13: Intelligence-Driven IAM: The Next Generation of Identity and Access Go...
CIS 2015 SCIM in the Real World - Kelly Grizzle
CIS 2015- Assessing the Risk of Identity and Access- Venkat Rajaji
CIS 2015 Modernize IAM with UnboundID and Ping Identity - Terry Sigle & B. Al...
Mobile Persuasion
Identity assurance & the market for verified attributes
Project Management is the Catalyst to transform India into a Global Leader in...
Digital Rights Management
Taste of Failure is Key for Sustainable Success
Responsible Global Spend - Sample Program and Timeline
AGLEA SAP Security Analyzer SoD Remediation SoX authorization
Cloud & Mobility Goldmines
TechNight #12: Cloud Identity Summit 2014 @ Monteray 概要と主要トピック
CIS13: Next Generation Privileged Identity Management: A Market Overview
Advanced Authorization for SAP Global Deployments Part III of III
OpenID TechNight - Ping Identity 製品紹介
OpenID Connect Demo at OpenID Tech Night
SharePoint Business Track Part 1 of 2
Digital in store for dummies
Colin Glynn, Rolls-Royce plc Presentation
CIS13: Intelligence-Driven IAM: The Next Generation of Identity and Access Go...
Ad

Similar to CIS 2015 So you want to SSO … Scott Tomilson & John Dasilva (20)

PDF
CIS 2015 Extreme SAML - Hans Zandbelt
DOCX
School of Computer & Information SciencesITS-532 Cloud C.docx
PDF
Common Challenges of Identity Management and Federated Single Sign-On in a Sa...
PPT
Up 2011-ken huang
PDF
CIS13: Avoiding the Pitfalls of Managing IAM for a Hybrid Environment
PDF
Anil saldhana oasisid_cloud
DOCX
Directions Answer each question individual and respond with full .docx
PDF
CIS14: NSTIC - Identity and Access Management Collaborative Approaches to Nov...
PDF
CIS14: Identity at Scale: Next Gen Federation Architectures
PDF
CIS 2015-API's & Identity: Enabling the Business to Become the Cloud- Carlos ...
PDF
Identity as a Service: a missing gap for moving enterprise applications in In...
PPTX
Identity as a Matter of Public Safety
PPTX
Identity Summit 2015: Connect.gov and Identity Management Systems
PPTX
The Future of Enterprise Identity Management
PDF
CIS13: Identity at Scale
PDF
CIS13: Identity as a Matter of Public Safety: A Case Study in Secure API Acce...
PPTX
Managing Identity from the Cloud: Transformation Advantages at VantisLife Ins...
PDF
CIS 2015 Extreme OAuth - Paul Meyer
PDF
CIS 2015 What’s next? Discovery, Dynamic Registration, Mobile Connect and mor...
PPTX
Intel IT's Identity and Access Management Journey
CIS 2015 Extreme SAML - Hans Zandbelt
School of Computer & Information SciencesITS-532 Cloud C.docx
Common Challenges of Identity Management and Federated Single Sign-On in a Sa...
Up 2011-ken huang
CIS13: Avoiding the Pitfalls of Managing IAM for a Hybrid Environment
Anil saldhana oasisid_cloud
Directions Answer each question individual and respond with full .docx
CIS14: NSTIC - Identity and Access Management Collaborative Approaches to Nov...
CIS14: Identity at Scale: Next Gen Federation Architectures
CIS 2015-API's & Identity: Enabling the Business to Become the Cloud- Carlos ...
Identity as a Service: a missing gap for moving enterprise applications in In...
Identity as a Matter of Public Safety
Identity Summit 2015: Connect.gov and Identity Management Systems
The Future of Enterprise Identity Management
CIS13: Identity at Scale
CIS13: Identity as a Matter of Public Safety: A Case Study in Secure API Acce...
Managing Identity from the Cloud: Transformation Advantages at VantisLife Ins...
CIS 2015 Extreme OAuth - Paul Meyer
CIS 2015 What’s next? Discovery, Dynamic Registration, Mobile Connect and mor...
Intel IT's Identity and Access Management Journey

More from CloudIDSummit (20)

PPTX
CIS 2016 Content Highlights
PPTX
Top 6 Reasons You Should Attend Cloud Identity Summit 2016
PDF
CIS 2015 Security Without Borders: Taming the Cloud and Mobile Frontier - And...
PDF
Mobile security, identity & authentication reasons for optimism 20150607 v2
PDF
CIS 2015 Mobile Security, Identity & Authentication: Reasons for Optimism - R...
PDF
CIS 2015 Virtual Identity: The Vision, Challenges and Experiences in Driving ...
PDF
CIS 2015 Deploying Strong Authentication to a Global Enterprise: A Comedy in ...
PDF
CIS 2015 Without Great Security, Digital Identity is Not Worth the Electrons ...
PDF
CIS 2015 Mergers & Acquisitions in a Cloud Enabled World - Brian Puhl
PDF
CIS 2015 IoT and IDM in your Mobile Enterprise - Brian Katz
PDF
CIS 2015 Practical Deployments Enterprise Cloud Access Management Platform - ...
PDF
CIS 2015 How to secure the Internet of Things? Hannes Tschofenig
PDF
The Industrial Internet, the Identity of Everything and the Industrial Enterp...
PDF
CIS 2015 Identity Relationship Management in the Internet of Things
PDF
CIS 2015 The Ethics of Personal Data - Robin Wilton
PDF
CIS 2015 OpenID Connect and Mobile Applications - David Chase
PDF
CIS 2015 OpenID Connect Workshop Part 1: Challenges for mobile - B. Allyn Fay
PDF
DIRECTORY CIS 2015 - Eric Fazendin
PDF
CIS 2015 Multi-factor for All, the Easy Way - Ran Ne'man
PDF
CIS 2015 Easy Federation in Cloud and on Premises - Ian Jaffe
CIS 2016 Content Highlights
Top 6 Reasons You Should Attend Cloud Identity Summit 2016
CIS 2015 Security Without Borders: Taming the Cloud and Mobile Frontier - And...
Mobile security, identity & authentication reasons for optimism 20150607 v2
CIS 2015 Mobile Security, Identity & Authentication: Reasons for Optimism - R...
CIS 2015 Virtual Identity: The Vision, Challenges and Experiences in Driving ...
CIS 2015 Deploying Strong Authentication to a Global Enterprise: A Comedy in ...
CIS 2015 Without Great Security, Digital Identity is Not Worth the Electrons ...
CIS 2015 Mergers & Acquisitions in a Cloud Enabled World - Brian Puhl
CIS 2015 IoT and IDM in your Mobile Enterprise - Brian Katz
CIS 2015 Practical Deployments Enterprise Cloud Access Management Platform - ...
CIS 2015 How to secure the Internet of Things? Hannes Tschofenig
The Industrial Internet, the Identity of Everything and the Industrial Enterp...
CIS 2015 Identity Relationship Management in the Internet of Things
CIS 2015 The Ethics of Personal Data - Robin Wilton
CIS 2015 OpenID Connect and Mobile Applications - David Chase
CIS 2015 OpenID Connect Workshop Part 1: Challenges for mobile - B. Allyn Fay
DIRECTORY CIS 2015 - Eric Fazendin
CIS 2015 Multi-factor for All, the Easy Way - Ran Ne'man
CIS 2015 Easy Federation in Cloud and on Premises - Ian Jaffe

Recently uploaded (20)

PDF
sustainability-14-14877-v2.pddhzftheheeeee
PPTX
GROUP4NURSINGINFORMATICSREPORT-2 PRESENTATION
PDF
The influence of sentiment analysis in enhancing early warning system model f...
PDF
Improvisation in detection of pomegranate leaf disease using transfer learni...
PDF
Produktkatalog für HOBO Datenlogger, Wetterstationen, Sensoren, Software und ...
PDF
CloudStack 4.21: First Look Webinar slides
PDF
Getting started with AI Agents and Multi-Agent Systems
PDF
STKI Israel Market Study 2025 version august
PPT
What is a Computer? Input Devices /output devices
PPTX
Modernising the Digital Integration Hub
PDF
Statistics on Ai - sourced from AIPRM.pdf
PDF
Developing a website for English-speaking practice to English as a foreign la...
PPTX
The various Industrial Revolutions .pptx
PDF
Zenith AI: Advanced Artificial Intelligence
PPT
Geologic Time for studying geology for geologist
PDF
Taming the Chaos: How to Turn Unstructured Data into Decisions
PDF
UiPath Agentic Automation session 1: RPA to Agents
PDF
How IoT Sensor Integration in 2025 is Transforming Industries Worldwide
PDF
Credit Without Borders: AI and Financial Inclusion in Bangladesh
DOCX
Basics of Cloud Computing - Cloud Ecosystem
sustainability-14-14877-v2.pddhzftheheeeee
GROUP4NURSINGINFORMATICSREPORT-2 PRESENTATION
The influence of sentiment analysis in enhancing early warning system model f...
Improvisation in detection of pomegranate leaf disease using transfer learni...
Produktkatalog für HOBO Datenlogger, Wetterstationen, Sensoren, Software und ...
CloudStack 4.21: First Look Webinar slides
Getting started with AI Agents and Multi-Agent Systems
STKI Israel Market Study 2025 version august
What is a Computer? Input Devices /output devices
Modernising the Digital Integration Hub
Statistics on Ai - sourced from AIPRM.pdf
Developing a website for English-speaking practice to English as a foreign la...
The various Industrial Revolutions .pptx
Zenith AI: Advanced Artificial Intelligence
Geologic Time for studying geology for geologist
Taming the Chaos: How to Turn Unstructured Data into Decisions
UiPath Agentic Automation session 1: RPA to Agents
How IoT Sensor Integration in 2025 is Transforming Industries Worldwide
Credit Without Borders: AI and Financial Inclusion in Bangladesh
Basics of Cloud Computing - Cloud Ecosystem

CIS 2015 So you want to SSO … Scott Tomilson & John Dasilva

  • 1. So you want to SSO … Scott Tomilson John DaSilva
  • 2. You’ve waited long enough … Copyright © 2015 Cloud Identity Summit. All rights reserved. 2 Mobile AppsWeb Apps SaaS Apps username password username password username password username password username password username password username password username password username password
  • 3. Copyright © 2015 Cloud Identity Summit .All rights reserved. 3
  • 4. Copyright © 2015 Cloud Identity Summit .All rights reserved. 4 Integration Kits
  • 5. It’s time for SSO … … what do you mean by SSO? App Enablement?Session Management? Access Control? Auditing?Authentication Policy? “One Username & Password (or some other form of authentication) just One Time”
  • 6. It’s time for SSO … … and how will we get SSO? Open Standards?On-Premise ? IdaaS? Agents vs Gateway?App Changes? “Eliminate Unnecessary Passwords” (yes, some work will be needed – but you want to do this the right way)
  • 7. Copyright © 2015 Cloud Identity Summit .All rights reserved. 7 Access Management ENTERPRISE Federated Identity Management
  • 8. SSOfor Web Applications Copyright © 2015 Cloud Identity Summit. All rights reserved. 8
  • 9. “First Mile” / “Last Mile” Integration Federation Server Identity Store Federation Server Target App Identity Provider (IdP) Service Provider (SP) “First Mile” “Last Mile”
  • 10. “First Mile” Integration •  If you’re using a Federation Server – hopefully this is just a configuration exercise: •  ADconnect (Active Directory) •  PingFederate (Complex AD, LDAP, WAM, etc.) •  PingOne Cloud Directory (IdaaS user/group dir.) •  Worst case – there are Libraries & APIs to help you integrate a custom portal or user store Copyright © 2015 Cloud Identity Summit. All rights reserved. 10
  • 11. “Last Mile” Integration Here’s where things get interesting … Copyright © 2015 Cloud Identity Summit. All rights reserved. 11
  • 12. “Last Mile” Integration Question #1: Does your application support Web (federated) SSO standards? (i.e.: SAML, WS-Federation, OpenID Connect) Copyright © 2015 Cloud Identity Summit. All rights reserved. 12
  • 13. “Last Mile” Integration – with Standards Copyright © 2015 Cloud Identity Summit. All rights reserved. 13 Federation Server Identity Store Target App Identity Provider (IdP) Service Provider (SP) SAML
  • 14. Copyright © 2015 Cloud Identity Summit. All rights reserved. 14 “Last Mile” Integration – with Standards Your Apps Your Identity Stores / Partners Acme Beta Com SAML SAML SAML Federation Hub
  • 15. “Last Mile” Integration – with Standards Copyright © 2015 Cloud Identity Summit. All rights reserved. 15 Does your app Web SSO standards? (SAML/WS-Fed/OIDC) Do you prefer IdaaS? No Yes Yes No
  • 16. “Last Mile” Integration Question #2: Does your application support HTTP header-based SSO? Copyright © 2015 Cloud Identity Summit. All rights reserved. 16
  • 17. “Last Mile” Integration – with HTTP Headers Federation Server Identity Store Federation Server Target App Identity Provider (IdP) Service Provider (SP) SAML Agent / Gateway HTTP Headers User: joe Email: [email protected] Group: Sales
  • 18. “Last Mile” Integration – with HTTP Headers •  Federated SSO •  PingFederate Integration Kits: •  Apache & IIS •  WAM Features (Session Management, URL Authorization & Auditing) •  Gateway (Reverse Proxy) •  Agents: Apache & IIS Copyright © 2015 Cloud Identity Summit. All rights reserved. 18
  • 19. “Last Mile” Integration – with Standards Copyright © 2015 Cloud Identity Summit. All rights reserved. 19 Does your app support HTTP header based SSO? Do you want WAM features? No Yes Yes No
  • 20. “Last Mile” Integration Question #3: Can you modify the application? Copyright © 2015 Cloud Identity Summit. All rights reserved. 20
  • 21. “Last Mile” Integration – with App Changes Copyright © 2015 Cloud Identity Summit. All rights reserved. 21 Features Approach Effort Level Product(s) Federated SSO Implement SAML L n/a Implement OpenID Connect S n/a HTTP Headers XS PingFederate REST API S PingFederate PingOne SSO Integration Kit SDK Library (Java, .NET) S PingFederate WAM Features (Session Management, URL Authorization & Auditing) HTTP Headers XS PingAccess
  • 22. “Last Mile” Integration Question #4: Did you reach here with 3 NO’s? Copyright © 2015 Cloud Identity Summit. All rights reserved. 22
  • 23. “Last Mile” Integration – “I’m out of options…” •  PingFederate Integration Kits •  Basic SSO (Password Vaulting) Copyright © 2015 Cloud Identity Summit. All rights reserved. 23 … still lost? Talk to us!
  • 24. SSOfor Mobile Applications Copyright © 2015 Cloud Identity Summit. All rights reserved. 24
  • 25. Copyright © 2015 Cloud Identity Summit .All rights reserved. 25 Get Your Time Machines Ready …
  • 26. SSO for Mobile Applications •  Are multiple logins (with the same creds) OK? •  User experience could be mitigated with long lived refresh tokens •  Shared refresh tokens? (Multiple apps – same dev. signer) •  Shared browser session? •  Centralized broker of OAuth Access Tokens •  Napps – http://openid.net/wg/napps/ •  PingOne Mobile – Early Napps draft support compatible with both PingFederate and PingOneCopyright © 2015 Cloud Identity Summit. All rights reserved. 26
  • 27. In Closing … Copyright © 2015 Cloud Identity Summit. All rights reserved. 27
  • 28. Copyright © 2015 Cloud Identity Summit .All rights reserved. 28