{"id":1211,"date":"2012-06-05T15:01:10","date_gmt":"2012-06-05T23:01:10","guid":{"rendered":"\/?p=1211"},"modified":"2012-11-08T09:38:38","modified_gmt":"2012-11-08T09:38:38","slug":"craig-burton-on-microsofts-identity-management-as-a-service","status":"publish","type":"post","link":"https:\/\/www.identityblog.com\/?p=1211","title":{"rendered":"Craig Burton on Microsoft&#39;s Identity Management as a Service"},"content":{"rendered":"<p><a href=\"http:\/\/www.craigburton.com\/\">Craig Burton<\/a>\u00a0first\u00a0achieved prominence\u00a0as the Senior Vice President of Corporate Marketing and Development who drove Novell&#39;s innovation and market strategies in the days when it was aggressively turning computing upside down.\u00a0Some years later he founded the Burton Group with Jamie Lewis.\u00a0 Today he is a Distinguished Analyst for Kuppinger Cole, where he just published an intriguing\u00a0response to the blogs\u00a0<a href=\"http:\/\/blogs.msdn.com\/b\/windowsazure\/archive\/2012\/05\/23\/reimagining-active-directory-for-the-social-enterprise-part-1.aspx\" class=\"broken_link\">John <\/a>and I have been doing: \u00a0<a href=\"http:\/\/blogs.kuppingercole.com\/burton\/2012\/06\/05\/microsoft-is-finally-being-relevant\/\" class=\"broken_link\">Microsoft is Finally Being Relevant<\/a>.<\/p>\n<p>For now I&#39;ll refrain from comment and just offer up the goods:<\/p>\n<blockquote><p><span style=\"font-size:14pt;line-height:200%\">Microsoft is Finally Being Relevant<\/span><br \/>\nSurprise surprise. For the last few years it looked as if the battling business units and power struggles within Microsoft had all but rendered the company <a href=\"http:\/\/www.craigburton.com\/?p=3128\">incapable of doing anything innovative or relevant<\/a>. But clearly something has happened to change this lack of leadership and apparent stumbling in the dark. Microsoft is not only doing something innovative \u2014 but profoundly innovative.<\/p>\n<p>In a dual post by Microsoft\u2019s <a href=\"http:\/\/blogs.msdn.com\/b\/windowsazure\/archive\/2012\/05\/23\/reimagining-active-directory-for-the-social-enterprise-part-1.aspx\" class=\"broken_link\">John Shewchuk<\/a> and <a href=\"\/?p=1205\">Kim Cameron<\/a>, the announcement was made about what Kim Cameron alluded to at the <a href=\"http:\/\/youtu.be\/6qbwTFyJa7k\">KuppingerCole EIC in April \u2014 Identity Management as a Service (IDMaaS).<\/a> This is not trivial, and does not suck. It ROCKS.<br \/>\n<span style=\"font-size:12pt;line-height:200%;font-style:italic  \">Why is Identity Management as a Service a Big Deal<\/span><br \/>\nFrom a technical perspective, the place where innovation really makes a difference is the place where the rubber meets the road \u2014 infrastructure. Infrastructure is not only fundamental\u2014as it provides the technical framework and underpinning to support big change \u2014 but infrastructure is hard.<\/p>\n<p>It\u2019s also hard to get funded and hard to sell both outside and inside of companies that make infrastructure.<\/p>\n<p>This is because there is little possibility of showing a direct ROI in core infrastructure investment. It takes vision and guts to invest in infrastructure.<\/p>\n<p>Nobody wants to buy identity infrastructure. In fact no one should have to pay for identity infrastructure. It should be ubiquitous, work, and be free to everyone and controlled by no one. Infrastructure at this level is as fundamental as air. You don\u2019t think about it, you don\u2019t buy it; you just breathe it in and out and get on with the details.<\/p>\n<p>Metaphorically, when it comes to the maturity of identity infrastructure today\u2014we are all sucking on thin air from teeny tubes of infrastructure veneer connected to identity silos (Facebook Connect, Twitter, Federated Identity and so on.)<\/p>\n<p>It\u2019s much like the other core suite of protocols of the Internet \u2014 like TCP\/IP. TCP\/IP is free as far as a piece of software goes. No one ever pays for the transport anymore.<\/p>\n<p>So should be the protocols and infrastructure for doing Identity Management.\u00a0 With this announcement Microsoft is showing that it understands Identity Infrastructure is fundamental to everything in the hybrid world of social-mobile-cloud networking that we are stumbling towards.<\/p>\n<p>Further, Microsoft is making it clear it understands that the current identity provider-centric world we live in now is broken and simply will not work for the future. Significant movement forward from this wretched state requires massive change \u2014 which is what Microsoft is proposing.<\/p>\n<p>From a political and business perspective, Kim Cameron\u2019s vision of a ubiquitous Identity Metasystem has somehow prevailed inside Microsoft and is starting to emerge. This is a big deal. Finally a company with lots of talent that has been wallowing from lack of leadership has stepped up and put a stake in the ground about Identity. Bravo!<\/p>\n<p>Everybody else of significance that could be doing something significant with identity infrastructure \u2014 Google, Facebook, and Amazon for starters \u2014 are trapped in their current business models of trafficking your identity for short term profit. For each of them, the little piece they hold captive of your identity is the product by which they are making money. This is both short sighted and unsustainable.<\/p>\n<p>Microsoft\u2019s plan is much grander. Invest in the hard stuff, solve the really tough identity infrastructure problems across the board\u2014simple, private, and scalable. By taking this high road, Microsoft is betting it can take the leadership role by increasing the size of the pie for other SaaS services and apps that organizations and individuals want and are willing to pay for. Much more visionary that continuing to fight over whatever crumb you can get based on the current broken model.<\/p>\n<p>If Microsoft is allowed to pull this off, it is a good thing.<br \/>\n<span style=\"font-size:12pt;line-height:200%;font-style:italic  \">Stop Gushing and Lay it Out for Me<\/span><br \/>\nTo understand the significance of IDMaaS, it\u2019s useful to take a quick look at how identity management systems have evolved.<\/p>\n<p>Figure 1 shows how identities started out being managed within the boundaries of a domain. Domain-based identity managed need hardly be mentioned here as it can\u2019t possibly meet any of the requirements for identity management in today\u2019s organizational environments. For its day, it worked and it was a good place to start.<\/p>\n<p style=\"text-align: center;\"><a href=\"http:\/\/blogs.kuppingercole.com\/burton\/wp-content\/uploads\/2012\/06\/idmaas1.png\" class=\"broken_link\"><img loading=\"lazy\" class=\"size-large wp-image-107 aligncenter\" title=\"Domain Contained Identity\" src=\"\/wp-content\/images\/2012\/06\/domain_contained_identities.jpg\" alt=\"\" width=\"400\" height=\"292\" \/><\/a><\/p>\n<p><em>Figure 1: Domain Contained Identity<\/em><\/p>\n<p>Figure 2 illustrates the first generation of federated identity management systems. This is a powerful model and was a big step forward from the domain model. In this model there is a service provider that accepts claims from an identity provider. A person can then prove who they are to the identity provider and present claims to the service provider to assure proper access to services and resources. This model works when these a relatively small number of parties involved. But as soon as there a diverse number of parties, it quickly breaks down.<\/p>\n<p style=\"text-align: center;\"><a href=\"http:\/\/blogs.kuppingercole.com\/burton\/wp-content\/uploads\/2012\/06\/idmaas2.png\" class=\"broken_link\"><img loading=\"lazy\" class=\"size-large wp-image-108 aligncenter\" title=\"Identity Federation Model\" src=\"\/wp-content\/images\/2012\/06\/identity_fed_model.jpg\" alt=\"\" width=\"400\" height=\"332\" \/><\/a><\/p>\n<p><em>Figure 2: Identity Federation Model<\/em><\/p>\n<p>Figure 3 shows the scenario with diverse people with diverse relationships with different IPs. When you add diverse and numerous types of devices \u2014 cell phones, tablets, laptops and so on \u2014 it even makes the case stronger as to why the current federated identity model is reaching its limits.<\/p>\n<p style=\"text-align: center;\">\u00a0<a href=\"http:\/\/blogs.kuppingercole.com\/burton\/wp-content\/uploads\/2012\/06\/idmaas3.png\" class=\"broken_link\"><img loading=\"lazy\" class=\"size-large wp-image-109 aligncenter\" title=\"Diverse People and Devices\" src=\"\/wp-content\/images\/2012\/06\/rp_meets_diversity.jpg\" alt=\"\" width=\"400\" height=\"292\" \/><\/a><\/p>\n<p><em>Figure 3: Diverse People and Devices<\/em><\/p>\n<p>So if the Federated Identity model doesn\u2019t work, what will? Figure 4 shows one school of thought were a single IP can somehow grow big enough and inclusive enough, it can manage all of the identity claims of all entities. This architecture is both frightening and poorly thought out. People and organizations need to have the freedom of choice of how their identities are managed and not be locked into an identity management silo of a single provider.<\/p>\n<p style=\"text-align: center;\"><a href=\"http:\/\/blogs.kuppingercole.com\/burton\/wp-content\/uploads\/2012\/06\/idmaas4.png\" class=\"broken_link\"><img loading=\"lazy\" class=\"size-large wp-image-110 aligncenter\" title=\"Omni Identity Provider\" src=\"\/wp-content\/images\/2012\/06\/omni_identity_provider.jpg\" alt=\"\" width=\"400\" height=\"290\" \/><\/a><\/p>\n<p><em>Figure 4: Omni Identity Provider<\/em><\/p>\n<p>Figure 5 is another \u2014 simpler \u2014 graphic showing how a single organization could have federated relationships with multiple constituents. Again, this approach works to a point, but as soon as you consider the impact of the identity explosion brought on by \u2014 cloud computing, social computing, mobile computing, and the API economy \u2014 this approach simply won\u2019t do the job.<\/p>\n<p style=\"text-align: center;\"><a href=\"http:\/\/blogs.kuppingercole.com\/burton\/wp-content\/uploads\/2012\/06\/idmaas5.png\" class=\"broken_link\"><img loading=\"lazy\" class=\"size-large wp-image-111 aligncenter\" title=\"Organization Federated to Many Constituents\" src=\"\/wp-content\/images\/2012\/06\/org_fed_constituents.jpg\" alt=\"\" width=\"400\" height=\"352\" \/><\/a><\/p>\n<p><em>Figure 5: Organization Federated to Many Constituents<\/em><\/p>\n<p>Figure 6 then, shows the simplified notion of the IDMaaS architecture. Any number of organizations, constituents or entities can generate and consume claims through the service in the cloud.<\/p>\n<p style=\"text-align: center;\"><a href=\"http:\/\/blogs.kuppingercole.com\/burton\/wp-content\/uploads\/2012\/06\/idmaas6.png\" class=\"broken_link\"><img loading=\"lazy\" class=\"size-large wp-image-112 aligncenter\" title=\"Any Entity and Any Number of Entities\" src=\"\/wp-content\/images\/2012\/06\/any_entity_any_constituent.jpg\" alt=\"\" width=\"400\" height=\"310\" \/><\/a><\/p>\n<p><em>Figure 6: Any Entity and Any Number of Entities<\/em><\/p>\n<p>Of course Figure 6 doesn\u2019t very effectively illustrate what the three black dots really mean. With the identity explosion we are talking about, the number of entities that are inevitable are several orders of magnitude bigger than anything we have even thought about up to this point.<\/p>\n<p>We are in new territory, it is very unclear what is going to happen as a result all of this.<\/p>\n<p>The fact that Microsoft seems to be acknowledging this fact and is working with vision to address the matter is highly encouraging.<\/p>\n<p>We are not seeing this kind of vision \u2014 or anything close to it \u2014 from any other major vendor to date.<br \/>\n<span style=\"font-size:12pt;line-height:200%;font-style:italic  \">Caveats<\/span><br \/>\nThe biggest problem I see here is Microsoft itself. It isn\u2019t like Microsoft has the reputation of always taking the high road to enhance technology to the benefit of all. To the contrary, Microsoft has the reputation of pretending to take the high road with an \u201cembrace and extend-like\u201d position while executing an exacting and calculating \u201cembrace and execute\u201d practice. Microsoft has become the arrogant elephant to dance with that IBM once was. Microsoft\u2019s past is going to be difficult to shed and it will be a significant effort to convince others that the elephant won\u2019t trample on everyone when it gets the chance.<\/p>\n<p style=\"text-align: center;\"><a href=\"http:\/\/blogs.kuppingercole.com\/burton\/wp-content\/uploads\/2012\/06\/idmaas7.png\" class=\"broken_link\"><img loading=\"lazy\" class=\"size-large wp-image-113 aligncenter\" title=\"The New Microsoft?\" src=\"\/wp-content\/images\/2012\/06\/craigs_new_microsoft.jpg\" alt=\"\" width=\"371\" height=\"500\" \/><\/a><\/p>\n<p><em>Figure 7: The New Microsoft?<\/em><\/p>\n<p><em>(Source: Craig Burton, drawn on the iPhone with Autodesk SketchBook Pro)<\/em><\/p>\n<p>So the tough questions are:<\/p>\n<ul>\n<li>Can Microsoft really execute on such a brave direction?<\/li>\n<li>Will Microsoft follow up on allowing true \u201cFreedom of Choice\u201d for the customer? (Think interoperability. i.e. IDMaaS from any vendor, not just MSFT)<\/li>\n<li>Will the RESTful implementation be usable?<\/li>\n<li>Can the technology transcend the limitations of Kerberos and LDAP as it moves Active Directory to the cloud?<\/li>\n<\/ul>\n<p>\u00a0<\/p>\n<p><span style=\"font-size:12pt;line-height:200%;font-style:italic  \">Summary<\/span><br \/>\nMy explanation is a simplified one, but if you study it a bit, you will start to see where Microsoft is going.<\/p>\n<p>In short, the vision of an Identity Metasystem based on Identity Management as a Service is brilliant thinking.<\/p>\n<p>The proof will be found in how Microsoft executes.<\/p>\n<p>There is a lot to work out here to show if this can really work. But I believe it can happen. Microsoft is in a good position to garner the expertise to give us this first implementation so organizations and people can start to vet the idea and see if this can really fly.<\/p>\n<p>I will be anxious to watch carefully at the progress of this direction.<\/p><\/blockquote>\n<p>I don&#39;t mind taking a few knocks from Craig, and don&#39;t think this\u00a0would be\u00a0the place to respond to them, even if I do think\u00a0that the interoperable claims based identity technology we have\u00a0been building and shipping for the last few years\u00a0is\u00a0the rocket fuel needed to &#8220;transcend the limitations of Kerberos and LDAP as\u00a0we\u00a0move Active Directory to the cloud&#8221; &#8211; one of his main concerns.<\/p>\n<p>But why quibble?\u00a0 Craig\u00a0really gets what&#39;s important.\u00a0\u00a0I like the fact that he\u00a0takes the time to explain why Identity Management as a Service really\u00a0is a big deal.\u00a0\u00a0I suspect part of what\u00a0he is saying is that it\u00a0dwarfs the incremental changes we have seen over the last few years\u00a0because it\u00a0will impact every mainstream technology.<\/p>\n<p>Craig&#39;s points about why infrastructure is hard are all golden, as is his wonderfully simple statement that &#8220;the current identity provider-centric world we live in now is broken and simply will not work for the future.&#8221;<\/p>\n<p>As for\u00a0the tough questions,\u00a0execution\u00a0can only be\u00a0judged by looking at what is shipped and how\u00a0it evolves over time.\u00a0\u00a0I&#39;d like to take up the more general, IdMaaS-related questions in upcoming posts.\u00a0 <a href=\"http:\/\/social.msdn.microsoft.com\/profile\/john_shewchuk\/\">John <\/a>will be\u00a0talking in his posts specifically about our RESTful implementation and providing readers with access so they can judge for themselves and give us feedback.\u00a0 At a practical level,\u00a0we will\u00a0be making\u00a0things available incrementally in cloud time, adding breadth and depth as we go on.\u00a0 This whole aspect of cloud innovation makes it hugely exciting.<\/p>\n<p>By the way, I love Craig&#39;s elephant &#8211; I only wish I could dance so well, metaphorically at least.\u00a0 I also love his graphics: he\u00a0improved and extended the amateur ones I used in my <a href=\"http:\/\/www.youtube.com\/watch?v=6qbwTFyJa7k\">European Identity and Cloud Conference keynote<\/a>.\u00a0 So if it&#39;s OK with him, I&#39;m going to pitch my own and go with his in my upcoming posts.\u00a0 Thanks Craig.<\/p>\n<p>\u00a0<\/p>\n","protected":false},"excerpt":{"rendered":"<p>This is not trivial, and does not suck. It ROCKS.<\/p>\n","protected":false},"author":68,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[2,86,8,87],"tags":[],"_links":{"self":[{"href":"https:\/\/www.identityblog.com\/index.php?rest_route=\/wp\/v2\/posts\/1211"}],"collection":[{"href":"https:\/\/www.identityblog.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.identityblog.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.identityblog.com\/index.php?rest_route=\/wp\/v2\/users\/68"}],"replies":[{"embeddable":true,"href":"https:\/\/www.identityblog.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1211"}],"version-history":[{"count":1,"href":"https:\/\/www.identityblog.com\/index.php?rest_route=\/wp\/v2\/posts\/1211\/revisions"}],"predecessor-version":[{"id":1325,"href":"https:\/\/www.identityblog.com\/index.php?rest_route=\/wp\/v2\/posts\/1211\/revisions\/1325"}],"wp:attachment":[{"href":"https:\/\/www.identityblog.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1211"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.identityblog.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1211"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.identityblog.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1211"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}