What is Claims-Based Identity, and Why Should You Care?

There are many features in a typical secure application, three of the most common being:
  • Authentication: “Who are you?”
  • Authorization: “Are you allowed to do this?”
  • Personalization: “How can I personalize your experience?”

This guide will introduce you to “claims-based” identity, a set of ideas and tools that may make it easier for you to build features like these into your apps in a more flexible way. In this guide, we’ll introduce some concepts that may sound new: claims, federated identity, and much more. But many of the ideas presented here have been floating around for a long time.

The protocols we’ll show in this guide have a similar flavor to Kerberos, one of the most broadly accepted authentication protocols in use today (used in Active Directory for example). WS-Federation, SAML, and other federated identity protocols have been incubating for this entire decade. This is really not so new after all, but it does require a new way of thinking as we move toward a better architecture for identity in applications.

Claims based identity is specially compelling for applications that are deployed to the cloud. This Guide will cover such scenarios.


Claims-based identity isn’t new. It’s been being designed and implemented for almost a decade.


Why do we need a guide now?

Only within the last year have tools been released to make claims-based identity generally available to applications on the Windows platform. With the Windows Identity Framework (WIF), Active Directory Federation Services v2 (ADFS), the identity landscape has opened up quite a bit, and our goal in this guide is to show how you can benefit by understanding these concepts and using these tools.

How is the Guide Organized?

The Guide will contain a few introductory chapters that will cover the basics of Claims based Identity, common terminology, protocols and technologies. This is the "theory" part of the book and we hope it will be useful for those new to the subject. Claims based identity is surprisingly simple and yet very powerful. Then, there will be a number of chapters with "case studies". These are very specific, commonly occurring scenarios where we surface goals, challenges and solutions in concrete contexts. As examples of the kind of scenarios we are considering, take a look at these three blog posts:

WebSSO
Federation
Software as a Service - Part I
Software as a Service - Part II

Check the downloads section for early chapters and samples!

Downloads

Blogs

Dominick Baier:

 www.leastprivilege.com News Feed 
Wednesday, November 18, 2009  |  From www.leastprivilege.com
Wednesday, November 11, 2009  |  From www.leastprivilege.com
Tuesday, November 10, 2009  |  From www.leastprivilege.com
Sunday, November 08, 2009  |  From www.leastprivilege.com
Wednesday, October 28, 2009  |  From www.leastprivilege.com
 www.leastprivilege.com News Feed 

Vittorio Bertocci

 Vibro.NET News Feed 
Thursday, November 19, 2009  |  From Vibro.NET
Wednesday, November 18, 2009  |  From Vibro.NET
Wednesday, November 18, 2009  |  From Vibro.NET
Tuesday, November 17, 2009  |  From Vibro.NET
Tuesday, November 17, 2009  |  From Vibro.NET
 Vibro.NET News Feed 

Keith Brown:

 Security Briefs News Feed 
Saturday, October 10, 2009  |  From Security Briefs
Saturday, October 10, 2009  |  From Security Briefs
Wednesday, October 07, 2009  |  From Security Briefs
Wednesday, October 07, 2009  |  From Security Briefs
Tuesday, October 06, 2009  |  From Security Briefs
 Security Briefs News Feed 

Eugenio Pace:


Erwin van der Valk



Matias Woloski

 Matias Woloski's Blog News Feed 
Saturday, August 15, 2009  |  From Matias Woloski's Blog
Tuesday, August 11, 2009  |  From Matias Woloski's Blog
Saturday, July 18, 2009  |  From Matias Woloski's Blog
Thursday, July 16, 2009  |  From Matias Woloski's Blog
Tuesday, July 14, 2009  |  From Matias Woloski's Blog
 Matias Woloski's Blog News Feed 
Last edited Oct 22 at 3:50 PM by eugeniop, version 18

 

Want to leave feedback?
Please use Discussions or Reviews instead.

Updating...
© 2006-2009 Microsoft | About CodePlex | Privacy Statement | Terms of Use | Code of Conduct | Advertise With Us | Version 2009.10.27.15987