CLB379 SharePoint 2010 Extranets and Authentication. Peter Carson President Envision IT

Similar documents
Extranet Identity Management and Authentication for SharePoint On Premise, Office 365 and Beyond

Extranets in SharePoint 2010 and 2013

Extranets in SharePoint 2010 and 2013

Extranets in SharePoint and Office 365 May 17, 2017

SharePoint 2019 and Extranet User Manager

Extranets in SharePoint and SSO for Claims Apps. January 18, 2017

Extranet User Manager

Thank You Sponsors! GOLD SILVER BRONZE / PRIZES

External Collaboration with Office 365 Project Sites. September 16, 2015

Copyright

Coveo Platform 7.0. Microsoft SharePoint Legacy Connector Guide

Running Effective Projects In Office 365. June 1, 2017

Office 365 External Sharing Webinar November 7, 2017

Search in SharePoint 2013

Application Lifecycle Management for SharePoint in the Enterprise. February 23, 2012

Ramnish Singh IT Advisor Microsoft Corporation Session Code:

Define Your Office 365 External Sharing Strategy

Cloud Access Manager How to Configure Microsoft SharePoint

Web Content Management in SharePoint 2013

Coveo Platform 7.0. Microsoft SharePoint Connector Guide

2010 Publishing Site Upgrade to SharePoint 2013

UC for Enterprise (UCE) NEC Centralized Authentication Service (NEC CAS)

Envision IT Office 365 Productivity Series Experience, Branding and Navigation. June 24, 2015

2012 Microsoft Corporation. All rights reserved. Microsoft, Active Directory, Excel, Lync, Outlook, SharePoint, Silverlight, SQL Server, Windows,

ControlPoint. Native Installation Guide. February 05,

Microsoft SharePoint Server 2013 Plan, Configure & Manage

Qualys SAML & Microsoft Active Directory Federation Services Integration

Service Manager. Ops Console On-Premise User Guide

Deployment guide for Duet Enterprise for Microsoft SharePoint and SAP Server 2.0

Microsoft Exam

Mohit Saxena Senior Technical Lead Microsoft Corporation

esignlive SAML Administrator's Guide Product Release: 6.5 Date: July 05, 2018 esignlive 8200 Decarie Blvd, Suite 300 Montreal, Quebec H4P 2P5

Copyright

Planning and Administering SharePoint 2016

Use EMS to protect your mobile data and mobile app

SharePoint 2013 Web Sites

A: PLANNING AND ADMINISTERING SHAREPOINT 2016

Project management - integrated into Outlook

Replicator. Installing and Configuring Replicator With Least Privilege P. March 09,

2011 NetRiders Skills Challenge Post Secondary Frequently Asked Questions (FAQ)

Advanced Solutions of Microsoft SharePoint Server 2013

Welcome to Database Exporter for SharePoint

Single Sign-On Showdown

Module 5. Conferencing in Lync Server MVA Jump Start

Planning and Administering SharePoint 2016

How To Embed EventTracker Widget to an External Site

Installing and Configuring VMware Identity Manager Connector (Windows) OCT 2018 VMware Identity Manager VMware Identity Manager 3.

October J. Polycom Cloud Services Portal

Course : Planning and Administering SharePoint 2016

AvePoint Governance Automation 2. Release Notes

Microsoft Dynamics GP Web Client Installation and Administration Guide For Service Pack 1

Extranet User Manager User Guide

Dell One Identity Cloud Access Manager 8.0. Overview

with Access Manager 51.1 What is Supported in This Release?

Configuring and Administering Microsoft SharePoint 2010

Copyright

Advanced Solutions of Microsoft SharePoint Server 2013 Course Contact Hours

Entrust PartnerLink Login Instructions

Advanced Solutions of Microsoft SharePoint 2013

SharePoint 2016 Administrator's Survival Camp

Course Outline: Course : Core Solutions Microsoft SharePoint Server 2013

Applying The Exchange Server 2010 Schema Update

Cloud Access Manager Overview

Configure Sharepoint 2010 Development

DocAve. Release Notes. Governance Automation Service Pack 5 Cumulative Update 2. For Microsoft SharePoint

Microsoft Advanced Solutions of Microsoft SharePoint Server

Customize. Building a Customer Portal Using Business Portal. Microsoft Dynamics GP. White Paper

SP Configuring and Administering Microsoft SharePoint 2010

SafeNet Authentication Service

Microsoft Exchange Server Active Directory Schema Changes Reference November 2011

ArcGIS Enterprise Administration

The Project Management Software for Outlook, Web and Smartphone

Planning and Administering SharePoint 2016

Microsoft ADFS Configuration

Migration from On-Premise to Cloud

Integration Guide. SafeNet Authentication Service. NetDocuments

External Data Connector for SharePoint

Connect Install Guide

MOC 20417C: Upgrading Your Skills to MCSA Windows Server 2012

Number: Passing Score: 800 Time Limit: 120 min. Microsoft

External Data Connector for SharePoint

CA SiteMinder Web Access Manager. Configuring SiteMinder Single Sign On for Microsoft SharePoint 2007 Using Forms-based Authentication

Q&As. PRO: Microsoft SharePoint 2010, Administrator. Pass Microsoft Exam with 100% Guarantee

Office 365 and Azure Active Directory Identities In-depth

Audience Profile: Course Outline. Introduction & Architecture. SharePoint 2013 Administration Basics. Creating Web Applications and Site Collections

Vendor: Microsoft. Exam Code: Exam Name: Administering Office 365. Version: DEMO

Accelerate GDPR compliance with the Microsoft Cloud

A: Advanced Technologies of SharePoint 2016

Number: Passing Score: 800 Time Limit: 120 min. Microsoft Managing Microsoft SharePoint Server 2016 (Beta) Version 1.

Who s Attacking Your Database? Monitoring Authentication and Logon Failures in SQL Server

Dell One Identity Manager Administration Guide for Connecting to SharePoint

SharePoint 2013 Web Sites

VIEVU Solution AD Sync and ADFS Guide

Core Solutions of Microsoft Skype for Business 2015

A: Planning and Administering SharePoint 2016

AvePoint Cloud Backup. Release Notes

Configuring ADFS for Academic Works

Advanced On-Prem SSRS 2017 for Non-AD Users. Dr. Subramani Paramasivam MVP & Microsoft Certified Trainer DAGEOP, UK

Microsoft Certified Professional Transcript

HPE Content Manager. Software Version: 9.2. HPE Content Manager Governance and Compliance SharePoint App: Installations Guide

Transcription:

CLB379 SharePoint 2010 Extranets and Authentication Peter Carson President Envision IT

Introduction Peter Carson President, Envision IT SharePoint MVP Virtual Technical Specialist, Microsoft Canada Computer Engineering, UW peter@envisionit.com http://blog.petercarson.ca www.envisionit.com Twitter @carsonpeter

Agenda Authentication Background Preparing your site Setting up FBA ADFS Federation Windows Live ID Federation Combining it all together

Four Categories of Users Internal Users Managed AD Users Managed SQL Users Federated Users

Internal Users Accessing from Inside

Internal Users Working Remotely

Managed Users

Federated Users

Preparing Your Site Ensure that the site is using Claims based security If the site is Classic, there is a PowerShell script that will do a one-time conversion from Classic to Claims > $webapp = Get-SPWebApplication( http://urltowebapplication:port ) > $webapp.useclaimsauthentication = True > $webapp.update() > $webapp.provisionglobally() You need to have a default WA zone for the search crawler to work Extend the WA site to a new site for the Extranet zone Generally you want to use SSL If the site is also going to be available anonymously you should extend it a third time for port 80 anonymous for the Internet zone

Tips to be Aware of If you want search to work anonymously, you need to enable anonymous access on your Windows Authentication zone SharePoint won t let you disable all authentication, but you can enable WA for the Internet zone, and then disable it in IIS SharePoint will let you configure a zone for SSL, but you still need to go into IIS to setup the certificate and bindings

Setting up FBA Decide on where your users are going to be stored SQL or AD are the two common choices Setup the store Configure the authentication type for the Extranet zone Update web.configs for SharePoint web app, Central Admin, and Security Token Service

SQL versus AD Authentication AD Requires a separate set of domain controllers These may already be in place to support the SharePoint farm Provides richer policy and audit controls Single URL inside and outside if not using FBA SQL Can use email address as the username Simpler to implement

Setting up the ASPNETDB Database C:\Windows\Microsoft.NET\Framework64\v2.0.50 727\aspnet_regsql.exe -E -S ServerName d DatabaseName A all You need to have the A all option to have Role support setup

Plan your Settings It is critical that web.config updates are correct If they are wrong, SharePoint may not authenticate (without guidance as to why), or it may blow up entirely Use Envision IT s planning worksheet to ensure no steps are missed

Plan your Settings Key information is Membership, role, and profile provider names Connection string name Provider definitions Connection string definition Custom login form URL Excel Planning Spreadsheet helps you plan and calculate these

ADFS Federation Delegates the authentication role to a remote domain On the partner side you need the following Domain controller running Windows Server 2008 or 2008 R2 ADFS 2.0 installed and wizard run STS login page secured and published externally

ADFS Federation Partner Side Setup the relying party trust in ADFS on the partner server You will need the published URL for your site, and create a realm that uniquely identifies your site with this ADFS Setup a claim rule to map LDAP (AD) attributes to the claim At a minimum you ll likely want email address and groups mapped to the claim Export the certificate for use in SharePoint

ADFS Federation SharePoint Side SharePoint configuration is done through PowerShell Import the certificate from the ADFS server Setup the claim s attribute mapping to SharePoint Create the SPTrustedIdentityTokenIssuer to tie it all together Now it shows up as a Trusted Identity Provider in Central Admin

ADFS Permission Assignments ADFS only allows you to perform authentications, it doesn t allow you to do lookups against the remote AD When assigning permissions in SharePoint, SharePoint has no way of validating whether ADFS users or roles are valid People picker will match anything you type in as an ADFS match; you need to know if it is valid before choosing it

Windows Live ID Integration - Test Configure Microsoft Services Manager https://msm.live.com/ Use your Live ID to login Register and manage your site Retrieve the certificate and import into SharePoint Use PowerShell to create the SPTrustedIdentityTokenIssuer (similar to ADFS)

Windows Live ID Integration - Prod Submit for a compliance review In MSM, submit the site for Production Retrieve the production certificate Repeat the import and SPTrustedIdentityTokenIssuer process on the SharePoint server

Combining It All Together Part of Envision IT s Extranet User Manager is our Hydra provider and EZLogin form Hydra is a single provider that can sit on top of multiple providers Internal AD, DMZ AD, SQL, ADFS, and Live ID can all coexist on one site Allows login by email address, which determines which provider to use Internal AD users are automatically logged in

Resources http://blog.petercarson.ca Steve Peshka s Configuring SharePoint 2010 and ADFS v2 End to End http://blogs.technet.com/b/speschka/archive/2010/07/30/con figuring-sharepoint-2010-and-adfs-v2-end-to-end.aspx Hiran Salvi's Configuring Windows Live ID as Trusted Identity Provider for SharePoint 2010 http://blogs.msdn.com/b/hsalvi/archive/2010/09/01/configuri ng-windows-live-id-authentication-provider-as-federatedidentity-provider-for-sharepoint-2010.aspx

related sessions CLB271 Practical Tips for SharePoint Governance: Oct 25, 10:30am CLB376 Upgrading and Migrating to SharePoint 2010 On-Premise and in the Cloud: Oct 25, 1:00pm CLB277 Why SharePoint Data Protection is Not as Easy as it Looks: Oct 26, 10:30am

Remember To Complete Your Evaluations! You could WIN a Samsung Focus Windows Phone 7! Let us know what you liked & disliked! Remember, 1=Bad, 5=Good Please provide comments! No purchase necessary. The contest is open to residents of Canada (excluding government employees). The Toronto Tech Days evaluation form contest begins on October 25 th, 2011 and ends on October 26 th, 2011. The Vancouver Tech Days evaluation form contest begins on November 15 th, 2011 and ends on November 16 th, 2011. The Montreal Tech Days evaluation form contest begins on November 29 th, 2011 and ends on November 30 th, 2011. Participants can enter the contest in one of two ways: (1) complete and submit an evaluation form by the contest close date; or (2) provide contact information by the contest close date. The draw for Toronto will take place on October 31 st, 2011. The draw for Vancouver will take place on November 21 st, 2011. The draw for Montreal will take place on December 5 th, 2011. The chances of being selected depend upon the number of eligible entries. Selected participants will be contacted by phone and/or e-mail and will be required to answer correctly a time-limited skill-testing question. There are three (3) prizes available to be won. One (1) prize will be given away for each Tech Days event in Toronto (October 25-26 2011), Vancouver (November 15-16 2011) and Montreal (November 29-30 2011). The prize consists of a Samsung Focus Windows Phone 7 (handset only; voice and/or data plan not included) (approximate retail value of $499 CAD). The prize will be delivered to the shipping address designated by the winner within 6-8 weeks. The winner may be required to sign a declaration and release form. For full contest rules, please see a Microsoft Tech Days representative. You can email any additional comments directly to td_can@microsoft.com at any time.

Q & A

2011 Microsoft Corporation. All rights reserved. Microsoft, Windows, Windows Vista and other product names are or may be registered trademarks and/or trademarks in the U.S. and/or other countries. The information herein is for informational purposes only and represents the current view of Microsoft Corporation as of the date of this presentation. Because Microsoft must respond to changing market conditions, it should not be interpreted to be a commitment on the part of Microsoft, and Microsoft cannot guarantee the accuracy of any information provided after the date of this presentation. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.