With the large number of disparate benefits in the ITA program, each fulfilled by different suppliers, student and educators (‘users’) have to maintain multiple user accounts and passwords to access each benefit. Single sign-on is an attempt to use a single account and password to get access to multiple sites/ resources.
The ITA eLearning benefit has 3 different website resources:
SSO in IT Academy program allows two authentication methods for eLearning access
a) Windows Live ID:
b) Federated Identity
All the other IT Academy benefits such as Safari E-Reference, MSDNAA/DreamSpark, TechNet, MOC, MCT, etc are not claims/assertions-enabled [i.e. not federation-enabled] and will continue to use existing authentication mechanisms of WLID or custom user-accounts The different federation identity provider STSs that are able to federate with the IT Academy program include: Microsoft Active Directory Federation System [ADFS] 1.0 and 2.0 CA Site Minder IBM Tivoli Federated Identity Manager (6.2.0.2 or higher) PING Federate RSA Federated Identity Manager Oracle Identity Federation Novell Access Manager Shibboleth All these systems allows one party holding user accounts to project those identities to another party that hosts resources.
All the other IT Academy benefits such as Safari E-Reference, MSDNAA/DreamSpark, TechNet, MOC, MCT, etc are not claims/assertions-enabled [i.e. not federation-enabled] and will continue to use existing authentication mechanisms of WLID or custom user-accounts
The different federation identity provider STSs that are able to federate with the IT Academy program include:
All these systems allows one party holding user accounts to project those identities to another party that hosts resources.
One potential issue with Federation is that standards are rarely comprehensive and each implementation tends to have its own approach. The differing implementations of the standards introduce variability in the way various features work and some may break – rarely is a solution ready out-of-the-box. For example the ADFS accepts one identity provider in entity description, in metadata. Also there could be schema mismatch limitations in SAML token format – what attributes and elements should be there. Single Sign-On (SSO) as the ability for customers to use a single set of credentials to access both on-premises and online resources. Federation is a trust relationship between the Identity Providers and Service Providers that allows Identity providers to share previously agreed upon set of user information in a secure manner. A federation provider is an intermediary between a Claims Provider and a Relying party; where in the RP trusts Federation provider. FP converts the CP's claims into a format that the RP can understand. Identity Providers are organizations that provide user authentication services and share user identity information after successfully authenticating the user. Once authentication is completed, the authorization needed to access ITA websites is provided by the Educator or Student ‘ITA Access code’. While this model may require some server investments and deeper architectural decision making, it does allows support for richer single sign on with your corporate credentials, integration with on-premises multi-factor authentication and a configurable password policy. Please direct any questions via e-mail to Acadsupp@microsoft.com, or phone at 1-800-508-8454 Monday through Friday, 6:30 a.m. to 5:30 p.m. (PST).
One potential issue with Federation is that standards are rarely comprehensive and each implementation tends to have its own approach. The differing implementations of the standards introduce variability in the way various features work and some may break – rarely is a solution ready out-of-the-box.
For example the ADFS accepts one identity provider in entity description, in metadata. Also there could be schema mismatch limitations in SAML token format – what attributes and elements should be there.
Once authentication is completed, the authorization needed to access ITA websites is provided by the Educator or Student ‘ITA Access code’.
While this model may require some server investments and deeper architectural decision making, it does allows support for richer single sign on with your corporate credentials, integration with on-premises multi-factor authentication and a configurable password policy.
Please direct any questions via e-mail to Acadsupp@microsoft.com, or phone at 1-800-508-8454 Monday through Friday, 6:30 a.m. to 5:30 p.m. (PST).