Microsoft PR contacted Microsoft Subnet today to clarify some questions we raised in a post earlier this month, “Microsoft “Geneva” could be genius but skeptics abound.” On May 11, Microsoft announced beta 2 of its new federated identity management platform, code-named Geneva. A previous issue with Geneva was Microsoft’s claims that it supported SAML — which had originally fallen far short of full support of the standard’s 2.0 version, available since 2005. Geneva also supports the WS* standards created by Microsoft and that resulted in competition with SAML, industry experts say. A second issue raised by skeptics was just how much coding developers would have to do to make their apps “claims aware” in order to work with Geneva.
Today, Microsoft PR issued this e-mail statement to us in response.
“Regarding support for SAML: In addition to claims-based architecture, Geneva supports industry standards including WS-* and SAML 2.0 protocols for open and interoperable identity. Our support for the SAML 2.0 protocol is in addition to the SAML token format that Microsoft has supported for some time. We’ve recently demonstrated interoperability between Geneva and SAML vendors such as IBM, CA, Sun and others.”
(In the previous post we noted that Microsoft says its additional support is specifically for SAML 2.0 service provider light.)
“Regarding app developers adding claims components to apps: Geneva works with existing infrastructure and applications. The key to this is Geneva Server’s ability to translate between claims and non-claims tokens. For example, Geneva Server can take a claim and transform it into a Keberos token so that a non-claims app can make a user access decision. Developers who choose to build new apps that are claims-enabled gain significant benefits. By writing to one simple user access model based on claims, developers can improve productivity and reduce development effort (vs. trying to build customer user access logic in each application).”
Geneva will likely be an easy way for Microsoft .Net users to add federated identity to their apps, particularly as apps move into the cloud. What are your thoughts on how well it will work with other applications?
Visit the Microsoft Subnet web site for more news, blogs, podcasts. Subscribe to all Microsoft Subnet bloggers. Sign up for the bi-weekly Microsoft newsletter. (Click on News/Microsoft News Alert.)
Microsoft to show off “Kumo” and offer more ad-supported cloud servicesMicrosoft demos SecondLight 3D UI with its next-gen SurfaceMicrosoft Early Releases Prove Useful to Malware Creators TooPowerShell Summer Scripting Games 2009 (Announced)Windows 7 and WS2008 R2 ship date: holiday ’09CIOs seem to love VMware over Hyper-VUsing offshore certified Microsoft partners? Beware of security holes12 killer freebie SharePoint add-ons Follow Microsoft Subnet on Twitter




