^Search our news archive of 8,978,507 headlines
>switch to our U.S. site U.S. versionLast update: New York 17:01
London 22:01
Tokyo 07:01
One News Page » Category » Computer Industry » Wednesday, 18 November 2009 » Microsoft touts groundbreaking clip on for Active Directory

Information / Related NewsOpen Full Story in New WindowMicrosoft touts groundbreaking 'clip-on' for Active Directory

Reported by Industry Standard on Wednesday, 18 November 2009 (on November 18, 2009)
Industry Standard

LOS ANGELES -- Microsoft will pass out beta code Wednesday it hopes will define the next evolution of directories. It's a modular add-on that is built on a database and designed to add querying capabilities and performance never before possible in a directory.
The code is so early-stage it does not have an official name, although internally Microsoft calls it Next Generation Active Directory (NGAD). Microsoft introduced NGAD, which it calls a directory federation technology, on the second day of its annual Professional Developers Conference going on this week.
Microsoft sets Windows Azure production date
NGAD, however, is not a replacement for Active Directory but a "clip-on" that provides developers a single programming API for building access controls into applications that can run either internally, on devices or on Microsoft's Azure cloud operating system. Users will not have to alter their existing directories but will have to option to replicate data to NGAD instances.
NGAD stores directory data in an SQL-based database and utilizes its table structure and query capabilities to express claims about users such as "I am over 21" or "Henry is my manager." To ensure security, each claim is signed by an issuing source, such as a company, and the signatures stay with the claim no matter where it is stored.
"You can answer questions in your directory that are currently impossible to even ask," says Kim Cameron, identity architect at Microsoft. "You can find out who had access to a file last September." He says NGAD is a reshaping of the programming model for Active Directory.
In addition, the directory design means multitudes of new cloud or other applications won't be hammering the central Active Directory architecture with lookup requests and administrators don't have to perform often tricky updates to directory schema to support those new applications.
"I don't want to do anything to let anybody think that I am going to diddle with Active Directory infrastructure, yet I want to leverage the infrastructure," Cameron says.
The intent is to create a "logical directory" that shares architecture elements such as schema and APIs but is not one monolithic identity store. Instead, users have multiple NGADs deployed to support specific cloud, internal or device-based applications.
"From the point of view of AD these would look like domain controllers, but you could do these magic queries," Cameron says. "I could say who are all the people who report up to Microsoft CEO Steve Ballmer; in AD that query would take hours."
The most unique characteristic of NGAD is its SQL database foundation. It includes an SQL-based "Repository", a central management database for application metadata that includes an identity deployment model. NGAD also introduces a schema called System.Identity and a System.Identity API. The API exposes the schema to developers through LINQ.
The directory also incorporates the "M" modeling language. The System.Identity schema has been available in Microsoft's Oslo CTP but the API is new.
As an add-on NGAD is similar in concept to Active Directory Federation Services, a module for sharing authentication, and Active Directory Application Mode (ADAM), which will eventually give way to NGAD.
NGAD lets users create complex relationships among the data it stores such as friends, colleagues, roles, management chains, service assignments and machine sets. Those relationships can be used to create detailed claims that govern access control
Currently, AD's only relationship construct is "group."
"In a directory there isn't the ability to do the kinds of relationships that you can do even in the world's worst database,"Cameron says.
Another evolutionary element is support for the newest Web technologies such as RSS and REST to create a connection between instances of NGAD and an application or service. For example, an application could subscribe to an NGAD instance via RSS and receive updates to the claims data it stores.
"We are taking what we learned with LDAP generation directories and adding a kind of self-knowledge. The system knows how to update the data," Cameron says.
He says NGAD is in the very early stages and "there are still some really hard problems to solve." Microsoft's goal at PDC is to talk directly to developers, get them to look at the API, let them figure out how the new schema works and then listen to their feedback.
"We want to be open with what we are doing and have a relationship with the industry and lay it all out there," says Cameron, who over the past years has championed an industry-wide effort to create a standard framework around identity. He says this new effort won't be Microsoft centric and that his hope is for another standards-based industry push to define the technology.
NGAD is the next step in Microsoft's claims-based Identity MetaSystem strategy, which began in 2005 and defines a distributed identity architecture for multi-vendor platforms.
As Microsoft builds out its story around the cloud-based Azure platform, NGAD is one of the foundational elements developers can take advantage of for access control.
Microsoft did not lay out a timeframe for the NGAD directory add-on, but if it follows previous directory innovations by the company it could be released as a stand-alone product or baked into the next version of Windows.
Follow John Fontana on Twitter: twitter.com/johnfontana


Links: Open full story in new window Full news story 

Post this: FacebookFacebook  EmailE-mail  TwitterTwitter  MixxMixx  StumbleUponStumbleUpon  FriendFeedFriendFeed
Recent related news
guardian.co.uk
6 hours ago - Politics
Information / Related NewsOpen Full Story in New Window

Downing Street media departments to merge into 'super press office'

Communications operations at the Cabinet Office and Downing Street to be rearranged under 'single...
computing.co.uk
1 day ago - Internet
Information / Related NewsOpen Full Story in New Window

Users give their verdict on Azure

Dave Bailey, , Wednesday 10 March 2010 at 17:25:00 / Some of the first wave of UK adopters met in...
SeekingAlpha
1 day ago - Markets
Information / Related NewsOpen Full Story in New Window

Google (GOOG) unveils an app store for business applications as it pushes forward in its fight against Microsoft (MSFT), but the reason Google's +1% premarket is because of reports its CEO is in "active" talks with China.

Industry Standard
2 days ago - Computer Industry
Information / Related NewsOpen Full Story in New Window

Microsoft warns of new IE bug; attacks under way

Microsoft today warned of a critical vulnerability in Internet Explorer that is already being...
Industry Standard
2 days ago - Computer Industry
Information / Related NewsOpen Full Story in New Window

HP Touts Flash as Killer App Against Apple's iPad

What will HP's Slate Tablet have that Apple's iPad won't? It's Adobe Flash, a key Internet technology...
WebProNews
2 days ago - Internet
Information / Related NewsOpen Full Story in New Window

Update: Microsoft to Roll Out Big MSN Redesign

*Update:* After some delay, Microsoft is now rolling out the new MSN home page design over the next...
Industry Standard
2 days ago - Computer Industry
Information / Related NewsOpen Full Story in New Window

Ford gets scrappage boost from modelling software

Ford has improved its understanding of its sales leads process using a business process modelling...
Mashable
3 days ago - Internet
Information / Related NewsOpen Full Story in New Window

Mashable’s Weekly Guide to Social Media Events

It’s a brand new week, which means it’s time for Mashable’s guide to upcoming social media and...
Industry Standard
4 days ago - Computer Industry
Information / Related NewsOpen Full Story in New Window

Microsoft delivers feature-rich SSL-VPN

We tested Whale Communications' in 2003 and the product didn't fare very well. Microsoft bought  in...
Industry Standard
4 days ago - Computer Industry
Information / Related NewsOpen Full Story in New Window

How we tested Microsoft Forefront UAG

We tested Forefront UAG using Microsoft's virtualization technology. Microsoft brought in a set of...
Twitter   Tweet the News!57
Twitter login: password:
Register to store your twitter account details
There don't appear to be any related tweets.
Be the first to tweet the news!

Tip: Sign up as a Member now - FREE access to news alerts, news bookmarking and more.

Environmentally friendly: One News Page is hosted on servers powered solely by renewable energy
© 2010 One News Page Ltd. All Rights Reserved.  |  About us  |  Press Room  |  Terms & Conditions  |  Privacy Policy  |  Content Accreditation
One News Page - Top Headlines RSS Feed Top News RSS Feed  |  News for my Website  |  Archive  |  Advertise  |  Help  |  Enquiries  |  Bookmark this site  |  U.S. version U.S. version
-