{"id":765,"date":"2007-04-26T11:37:51","date_gmt":"2007-04-26T19:37:51","guid":{"rendered":"\/?p=765"},"modified":"2007-04-26T11:37:51","modified_gmt":"2007-04-26T19:37:51","slug":"future-of-active-directory","status":"publish","type":"post","link":"https:\/\/www.identityblog.com\/?p=765","title":{"rendered":"Future of Active Directory"},"content":{"rendered":"<p>Here&#39;s a snippet from &nbsp;<a href=\"http:\/\/www.networkworld.com\/news\/2007\/042407-active-directory-future-identity.html?fsrc=netflash-rss\" class=\"broken_link\">another article by John Fontana<\/a> that will be of interest to people wondering how much wood Microsoft is&nbsp;ready to&nbsp;put behind the claims based model.&nbsp; Stuart Kwan has played a&nbsp;central role in the evolution of Active Directory and the emerging identity products:&nbsp;<\/p>\n<blockquote>\n<p class=\"first\"><em xmlns:w=\"urn:www.microsoft.com\/word\" xmlns:st1=\"urn:www.microsoft.com\/smarttags\" xmlns:o=\"urn:www.microsoft.com\/office\">Las Vegas \u00e2\u20ac\u201c<\/em> <a w=\"urn:www.microsoft.com\/word\" st1=\"urn:www.microsoft.com\/smarttags\" o=\"urn:www.microsoft.com\/office\" href=\"http:\/\/www.networkworld.com\/subnets\/microsoft\/\" class=\"broken_link\">Microsoft<\/a> Tuesday laid out a vision for Active Directory in which it will take on a major role in <a w=\"urn:www.microsoft.com\/word\" st1=\"urn:www.microsoft.com\/smarttags\" o=\"urn:www.microsoft.com\/office\" href=\"http:\/\/www.networkworld.com\/news\/2007\/042307-microsoft-identity-systems.html\" class=\"broken_link\">pushing out user identity data<\/a> to applications and securing collaboration between users. <!--silo end--><\/p>\n<p>\u00e2\u20ac\u0153We are moving from being a directory provider to an identity provider,\u00e2\u20ac\u009d said Stuart Kwan, director of program management for identity and access at Microsoft, during the second day keynote at the annual <a w=\"urn:www.microsoft.com\/word\" st1=\"urn:www.microsoft.com\/smarttags\" o=\"urn:www.microsoft.com\/office\" href=\"http:\/\/www.networkworld.com\/news\/2007\/042307-netpro-active-directory.html\" class=\"broken_link\">NetPro<\/a> Directory Experts Conference.<\/p>\n<p>He said the benefit for corporate users would be a standard user access mechanism that would benefit application development, access management and allow companies to more easily spread their <a w=\"urn:www.microsoft.com\/word\" st1=\"urn:www.microsoft.com\/smarttags\" o=\"urn:www.microsoft.com\/office\" href=\"http:\/\/www.networkworld.com\/news\/2006\/040306-microsoft-identity.html\" class=\"broken_link\">identity systems<\/a>.<\/p>\n<p>Kwan concluded that Active Directory was so close to fulfilling its original goals as a trusted directory service for corporate users that it was time to look ahead and envision the next set of challenges.<\/p>\n<p>The new challenges, Kwan said, will put the directory in a key role in <a w=\"urn:www.microsoft.com\/word\" st1=\"urn:www.microsoft.com\/smarttags\" o=\"urn:www.microsoft.com\/office\" href=\"http:\/\/www.networkworld.com\/news\/2005\/051605-microsoft-identity.html\" class=\"broken_link\">Microsoft\u00e2\u20ac\u2122s Identity Metasystem<\/a>, a model for distributed identity architecture. Coupled with an emerging technology called Security Token Service (<a xmlns:w=\"urn:www.microsoft.com\/word\" xmlns:st1=\"urn:www.microsoft.com\/smarttags\" xmlns:o=\"urn:www.microsoft.com\/office\" href=\"http:\/\/msdn2.microsoft.com\/en-us\/library\/aa480563.aspx\">STS<\/a>), which handles the exchange of identity data, Microsoft envisions an architecture that pushes identity data out to applications that know how to interpret and act upon that data.<\/p>\n<p>Today, applications typically pull user access data from the directory to determine a user\u00e2\u20ac\u2122s access rights. The push model not only affords network efficiencies but more easily ties identity and application development, puts less stress on the directory, provides more flexibility in defining a user and their rights and gives the ability to federate identity with those outside the corporate network.<\/p>\n<p>Kwan said the push mechanism would be similar to the way group membership data for a user is automatically included in today\u00e2\u20ac\u2122s Kerberos authentication process.<\/p>\n<p>In the future, identity data coming from the directory would be transformed by the STS gateway into a properly formatted \u00e2\u20ac\u0153claim\u00e2\u20ac\u009d or a set of claims about the user and his access rights. &nbsp;&nbsp;(<a href=\"http:\/\/www.networkworld.com\/news\/2007\/042407-active-directory-future-identity.html?page=2\" class=\"broken_link\">Continued<\/a> here)<\/p><\/blockquote>\n<p>My one clarification is that&nbsp;neither&nbsp;Stuart nor I&nbsp;are talking about&nbsp;&#8220;Microsoft&#39;s&#8221; identity metasystem&#8221;.&nbsp; We are trying to build an identity metasystem that stretches across vendors and platforms and products and countries.&nbsp;&nbsp;We&#39;re trying to do our part within this metasystem.&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Stuart Kwan explains that AD is moving from being a directory provider to an identity provider.<\/p>\n","protected":false},"author":68,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[10,7],"tags":[],"_links":{"self":[{"href":"https:\/\/www.identityblog.com\/index.php?rest_route=\/wp\/v2\/posts\/765"}],"collection":[{"href":"https:\/\/www.identityblog.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.identityblog.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.identityblog.com\/index.php?rest_route=\/wp\/v2\/users\/68"}],"replies":[{"embeddable":true,"href":"https:\/\/www.identityblog.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=765"}],"version-history":[{"count":0,"href":"https:\/\/www.identityblog.com\/index.php?rest_route=\/wp\/v2\/posts\/765\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.identityblog.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=765"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.identityblog.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=765"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.identityblog.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=765"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}