Identity Authentication Service SAP Cloud Platform
Total Page:16
File Type:pdf, Size:1020Kb
Identity Authentication Service SAP Cloud Platform Marko Sommer, SAP July 26th, 2017 PUBLIC Legal disclaimer The information in this presentation is confidential and proprietary to SAP and may not be disclosed without the permission of SAP. This presentation is not subject to your license agreement or any other service or subscription agreement with SAP. SAP has no obligation to pursue any course of business outlined in this document or any related presentation, or to develop or release any functionality mentioned therein. This document, or any related presentation and SAP's strategy and possible future developments, products and or platforms directions and functionality are all subject to change and may be changed by SAP at any time for any reason without notice. The information in this document is not a commitment, promise or legal obligation to deliver any material, code or functionality. This document is provided without a warranty of any kind, either express or implied, including but not limited to, the implied warranties of merchantability, fitness for a particular purpose, or non-infringement. This document is for informational purposes and may not be incorporated into a contract. SAP assumes no responsibility for errors or omissions in this document, except if such damages were caused by SAP´s willful misconduct or gross negligence. All forward-looking statements are subject to various risks and uncertainties that could cause actual results to differ materially from expectations. Readers are cautioned not to place undue reliance on these forward-looking statements, which speak only as of their dates, and they should not be relied upon in making purchasing decisions. © 2017 SAP SE or an SAP affiliate company. All rights reserved. ǀ PUBLIC 2 Agenda Introduction . SAP Security Portfolio Product Overview . Access Control . User Management & User Self-Services . Delegated Authentication . Roadmap . Demo Further Information © 2017 SAP SE or an SAP affiliate company. All rights reserved. ǀ PUBLIC 3 Identity and Access Management as a Service In the SAP security portfolio SAP Cloud SAP Cloud Identity Applications Manage access, SAP Cloud SAP Cloud Platform Access users and compliance in the Platform Identity Identity Governance, cloud Authentication Provisioning access analysis service SAP S/4HANA Add-On for Code SAP Single SAP Identity SAP Access SAP Enterprise Vulnerability SAP Sign-On Management Control Threat Detection Business Analysis Suite Ensure corporate Find and correct Make it simple for users to do Know your users and what Counter possible threats and compliance to vulnerabilities in customer what they are allowed to do they can do identify attacks regulatory requirements code 3rd Party SAP NetWeaver Systems Platform Make sure that SAP SAP Cloud Platform SAP HANA solutions run securely Application Server Security © 2017 SAP SE or an SAP affiliate company. All rights reserved. ǀ PUBLIC 4 Identity and Access Management as a Service from SAP Solution overview SAP Cloud Platform offers an end-to-end Identity and Access Management (IAM) solution as a service that helps companies improve the security of their cloud business processes SAP Cloud Platform Identity Provisioning . Automatically sets up and manages user accounts and authorizations in an end-to-end identity lifecycle . Re-uses existing on-premise and cloud user stores . Integrates with SAP Identity Management SAP Cloud Platform Identity Authentication . Simple and secure access to web-based applications . Enterprise features such as password policies and multi- factor and risk-based authentication . On-premise user store integration . Easy consumer and partner on-boarding via self-services © 2017 SAP SE or an SAP affiliate company. All rights reserved. ǀ PUBLIC 5 Aspects for Identity Access Management in Hybrid Scenarios Protect Manage Integrate Control application access Centrally manage Seamlessly integrate into and apply various user profiles and existing single sign-on authentication methods allow self services infrastructure © 2017 SAP SE or an SAP affiliate company. All rights reserved. ǀ PUBLIC 6 Agenda Introduction . SAP Security Portfolio Product Overview . Access Control . User Management & User Self-Services . Delegated Authentication . Roadmap . Demo Further Information © 2017 SAP SE or an SAP affiliate company. All rights reserved. ǀ PUBLIC 7 SAP Cloud Platform Identity Authentication Product Overview SAP Cloud Platform Identity Authentication provides secure access to web applications. It is a software as a service (SaaS) offering by SAP Access protection Identity federation based on SAML 2.0 Web single sign-on and desktop SSO Secure on-premise integration with existing authentication system Social and strong authentication Risk-based authentication Manage users and access to applications User administration and integration with on-premise user stores User groups and application access management User self-services Password and privacy policies Enterprise features for integration Branding of end user UIs Identity Authentication Programmatic integration via SCIM standard © 2017 SAP SE or an SAP affiliate company. All rights reserved. ǀ PUBLIC 8 Configurable Access Levels Access Control Access protection on user level and on application level Public access Self registration is allowed Social authentication [optional] Internal access User status Only users already registered new, active, are entitled to access inactive, locked Private access Only users registered for the application can access © 2017 SAP SE or an SAP affiliate company. All rights reserved. ǀ PUBLIC 9 Custom Password Policy Configuration Access Control Custom password policies serve the need to comply with corporate security guidelines Custom password policies Min/max password length Password expiration period Max period for unused password Min password age Number of passwords in history Number of failed logon attempts until user gets locked Time period a user gets locked due to failed logon attempts © 2017 SAP SE or an SAP affiliate company. All rights reserved. ǀ PUBLIC 10 Risk-based Authentication Access Control Define authentication rules to control application access Allow User Group Membership and/or ****** ****** Logon Logon Two-factor-authentication Network IP Ranges Deny © 2017 SAP SE or an SAP affiliate company. All rights reserved. ǀ PUBLIC 11 Two-factor Authentication with SAP Authenticator Access Control Authentication with one-time passwords Provide two means of identification OTP required for login in addition to password or security token Second factor for high security scenarios Based on SAP Authenticator mobile app OTP (6-digit) created on mobile device Available for iOS and Android RFC 6238 compatible © 2017 SAP SE or an SAP affiliate company. All rights reserved. ǀ PUBLIC 12 Agenda Introduction . SAP Security Portfolio Product Overview . Access Control . User Management & User Self-Services . Delegated Authentication . Roadmap . Demo Further Information © 2017 SAP SE or an SAP affiliate company. All rights reserved. ǀ PUBLIC 13 User management User management & User self-services Web-based and programmatic user management capabilities User administration . Web based user management . User search . Mass user import/export . Monitor user access User groups administration . Define user groups . Assign users to groups Integration . Programmatic integration via SCIM REST APIs © 2017 SAP SE or an SAP affiliate company. All rights reserved. ǀ PUBLIC 14 User self-services User management & User self-services User self services reduce TCO especially for B2C- and B2B-scenarios Convenient user self-services . Configurable self-registration . Account confirmation via email . Forgot password User profile . Edit details & change password . Mobile device activation (for TFA) . (Un-)Link social accounts Product features . Responsive UIs . Multilanguage support © 2017 SAP SE or an SAP affiliate company. All rights reserved. ǀ PUBLIC 15 Branding and customization User management & User self-services User interface, email templates and registration policies can be adjusted to corporate needs Customization features . Company Logo . Application name and logo . Color style . Terms of use & privacy policy . Adjust UI texts via API . Mail templates (account confirmation, forgot pwd., et al.) Product features . Responsive UIs . Multilanguage support © 2017 SAP SE or an SAP affiliate company. All rights reserved. ǀ PUBLIC 16 Agenda Introduction . SAP Security Portfolio Product Overview . Access Control . User Management & User Self-Services . Delegated Authentication . Roadmap . Demo Further Information © 2017 SAP SE or an SAP affiliate company. All rights reserved. ǀ PUBLIC 17 Identity Authentication Service as a proxy to a corporate IdP Delegated authentication IdP proxy via the SAML standard – easy to establish Identity provider proxy SAML Authentication is delegated to Identity Authentication Service corporate identity provider login Reuse of existing single sign-on Applications SAML infrastructure Easy and secure authentication for ****** business-to-employee (B2E) scenarios Logon Federation based on the SAML 2.0 standard 3rd party Cloud Corporate Identity Provider Corporate Network © 2017 SAP SE or an SAP affiliate company. All rights reserved. ǀ PUBLIC 18 Authentication with on-premise User Store Delegated authentication Integrate with an on-premise user store via a secure tunnel On-premise user store ****** Logon Users credentials from: Identity