50
Deploying Strong Authentication to a Global Enterprise: A Comedy in Three Acts Laura E. Hunter @adfskitteh Cards Against Identity

CIS 2015 Deploying Strong Authentication to a Global Enterprise: A Comedy in Three Acts - Laura Hunter

Embed Size (px)

Citation preview

Deploying Strong Authentication to a Global Enterprise: A Comedy in Three Acts

Laura E. Hunter@adfskitteh

Cards Against Identity

Act One: The Perpetual Pilot

Cards Against Identity

Microsoft IT’s Azure MFA Deployment was in Pilot for ______ months…

Cards Against Identity

Cards Against Identity

Cards Against Identity Cards Against Identity

Cards Against Identity Cards Against Identity

Cards Against Identity

Cards Against Identity Cards Against Identity

1 month Cards Against Identity1 month Cards Against Identity

Cards Against Identity

Cards Against Identity Cards Against Identity

1 month 2 months1 month 2 months

Cards Against Identity

6 months Cards Against Identity

1 month 2 months1 month 2 months

Cards Against Identity

6 months 12 months

1 month 2 months

12 months

Cards Against Identity

Why so long?

Cards Against Identity

“Sharp Edges” in the User Experience

Cards Against Identity

Lack of Top-Down Organizational Messaging

Cards Against Identity

A year-long pilot was still worthwhile, because it allowed IT to ___________ and ___________.

Cards Against Identity

Learn How To Operate a New Service Offering

Cards Against Identity

Plan for Scale

Cards Against Identity

Act Two: The Inciting Event

Cards Against Identity

Cards Against Identity

What did Laura get for Christmas this year?

Cards Against Identity

Cards Against Identity Cards Against Identity

Cards Against Identity Cards Against Identity

Cards Against Identity

Cards Against Identity Cards Against Identity

1 month Cards Against IdentityA pony Cards Against Identity

Cards Against Identity

Cards Against Identity Cards Against Identity

1 month 2 monthsA pony New shoes

Cards Against Identity

Back2back Seahawks Super Bowl victories

Cards Against Identity

1 month 2 monthsA pony New shoes

Cards Against Identity

Back2back Seahawks Super Bowl victories

A 9:30am Christmas-morning conference call with her CISO

A pony New shoes

A 9:30am Christmas-morning conference call with her CISO

Cards Against Identity

“Hey IT…you can roll out strong auth to all Microsoft users by the end of the month, right?”

Cards Against Identity

Cards Against Identity

Cards Against Identity Cards Against Identity

Cards Against Identity Cards Against Identity

Cards Against Identity

Cards Against Identity Cards Against Identity

1 month Cards Against Identity“Is there a hole in the ground that I can disappear into right now?”

Cards Against Identity

Cards Against Identity

Cards Against Identity Cards Against Identity

1 month 2 months“Is there a hole in the ground that I can disappear into right now?”

“Are you directly out of your everloving mind?”

Cards Against Identity

“Absolutely, boss. We can get that done.”

Cards Against Identity

1 month 2 months“Is there a hole in the ground that I can disappear into right now?”

“Are you directly out of your everloving mind?”

Cards Against Identity

“Absolutely, boss. We can get that done.”

“Sorry, can we chat later? I’m watching Winter Soldier.”

“Is there a hole in the ground that I can disappear into right now?”

“Are you directly out of your everloving mind?”

“Absolutely, boss. We can get that done.”

Cards Against Identity

So how did it go, Laura?

Cards Against Identity

Executive sponsorship…

Cards Against Identity

…including acceptance of some rough edges…

Cards Against Identity

…led to a largely successful deployment of strong auth to Microsoft employees.

Cards Against Identity

Act Three: The New Normal

Cards Against Identity

What Constitutes a Legitimate Exception to Strong Auth Policy?

Cards Against Identity

Cards Against Identity

Cards Against Identity Cards Against Identity

Cards Against Identity Cards Against Identity

Cards Against Identity

Cards Against Identity Cards Against Identity

1 month Cards Against Identity“I’m sitting on my sofa with my iPad. My laptop is on my kitchen table and I don’t feel like getting up to go get it.”

Cards Against Identity

Cards Against Identity

Cards Against Identity Cards Against Identity

1 month 2 months“I’m sitting on my sofa with my iPad. My laptop is on my kitchen table and I don’t feel like getting up to go get it.”

Retail employees working the sales floor.

Cards Against Identity

“I do customer demos.” Cards Against Identity

1 month 2 months“I’m sitting on my sofa with my iPad. My laptop is on my kitchen table and I don’t feel like getting up to go get it.”

Retail employees working the sales floor.

Cards Against Identity

“I do customer demos.” “NEIN! NEIN! NEIN!ZERE VIL’ BE NO EXCEPTIONS!”

“I’m sitting on my sofa with my iPad. My laptop is on my kitchen table and I don’t feel like getting up to go get it.”

Retail employees working the sales floor.

After a Strong Auth Rollout, What Will IT Get Blamed For?

Cards Against Identity

Cards Against Identity

Cards Against Identity Cards Against Identity

Cards Against Identity Cards Against Identity

Cards Against Identity

Cards Against Identity Cards Against Identity

1 month Cards Against Identity“I can’t get on wireless, is it because of 2FA?”

Cards Against Identity

Cards Against Identity

Cards Against Identity Cards Against Identity

1 month 2 months“I can’t get on wireless, is it because of 2FA?”

“I can’t renew my smart card, is this because of 2FA?”

Cards Against Identity

“The MDM PIN policy changed, is this because of 2FA?”

Cards Against Identity

1 month 2 months“I can’t get on wireless, is it because of 2FA?”

“I can’t renew my smart card, is this because of 2FA?”

Cards Against Identity

“The MDM PIN policy changed, is this because of 2FA?”

“<%insert name of app%> wouldn’t launch this morning, is it because of 2FA?”

“I can’t get on wireless, is it because of 2FA?”

“I can’t renew my smart card, is this because of 2FA?”

“The MDM PIN policy changed, is this because of 2FA?”

Cards Against Identity

Postlude: The Road Ahead

Cards Against Identity

THANK YOU!

Laura E. Hunter@adfskitteh

Cards Against Identity Template design: [email protected]