<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Dominik&#039;s Cloud Security Blog</title>
	<atom:link href="http://blog.gocloud-security.ch/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.gocloud-security.ch</link>
	<description>A Swiss blog about Microsoft&#039;s Security &#38; Identity and Access Management solutions for Private and Public Clouds</description>
	<lastBuildDate>Fri, 10 Feb 2012 22:53:53 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
		<item>
		<title>[Update2] FIM 2010 and Exchange 2010 Provisioning and which Account must be Member of the Exchange Recipient Administrators Group?</title>
		<link>http://blog.gocloud-security.ch/2012/02/10/update2-fim-2010-and-exchange-2010-provisioning-and-which-account-must-be-member-of-the-exchange-recipient-administrators-group/</link>
		<comments>http://blog.gocloud-security.ch/2012/02/10/update2-fim-2010-and-exchange-2010-provisioning-and-which-account-must-be-member-of-the-exchange-recipient-administrators-group/#comments</comments>
		<pubDate>Fri, 10 Feb 2012 22:53:53 +0000</pubDate>
		<dc:creator>Dominik Zemp</dc:creator>
				<category><![CDATA[Forefront]]></category>
		<category><![CDATA[Forefront|Forefront Identity Manager]]></category>
		<category><![CDATA[FIM]]></category>

		<guid isPermaLink="false">http://blog.gocloud-security.ch/2012/02/10/update2-fim-2010-and-exchange-2010-provisioning-and-which-account-must-be-member-of-the-exchange-recipient-administrators-group/</guid>
		<description><![CDATA[With this short blog, I would like to point you to another confusing statement that you can find in the article on http://technet.microsoft.com/en-us/magazine/ff472471.aspx: If you just add the service account to the Exchange Recipient group, you will see the following &#8230; <a href="http://blog.gocloud-security.ch/2012/02/10/update2-fim-2010-and-exchange-2010-provisioning-and-which-account-must-be-member-of-the-exchange-recipient-administrators-group/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>With this short blog, I would like to point you to another confusing statement that you can find in the article on <a href="http://technet.microsoft.com/en-us/magazine/ff472471.aspx">http://technet.microsoft.com/en-us/magazine/ff472471.aspx</a>:</p>
<p><a href="http://blog.gocloud-security.ch/wp-content/uploads/2012/02/image.png"><img style="background-image: none; border-bottom: 0px; border-left: 0px; padding-left: 0px; padding-right: 0px; display: inline; border-top: 0px; border-right: 0px; padding-top: 0px" title="image" border="0" alt="image" src="http://blog.gocloud-security.ch/wp-content/uploads/2012/02/image_thumb.png" width="645" height="196"></a></p>
<p>If you just add the service account to the Exchange Recipient group, you will see the following error event in EventLog (and of course, the run profile will stop/fail with the error stopped-extension-dll-exception). </p>
<p><em>There is an error in Exch2010Extension BeginExportToCd() function.Type: System.Management.Automation.Remoting.PSRemotingTransportException</em></p>
<p><em>Message: </em></p>
<p><em>&#8220;Microsoft.MetadirectoryServices.ExtensionException: Processing data from remote server failed with the following error message: The user &#8220;&lt;domain&gt;/<font style="background-color: #ffff00">&lt;ADMAAccount&gt;</font>&#8221; isn&#8217;t assigned to any management roles. For more information, see the about_Remote_Troubleshooting Help topic.</em></p>
<p>So based on the error, it’s clear that you have to add the account used for the Active Directory Management Agent to the Exchange Recipient Administrators group, instead of the FIM Sync Service service account.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.gocloud-security.ch/2012/02/10/update2-fim-2010-and-exchange-2010-provisioning-and-which-account-must-be-member-of-the-exchange-recipient-administrators-group/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>[Update] BitLocker and How To Change the User PIN</title>
		<link>http://blog.gocloud-security.ch/2012/02/09/update-bitlocker-and-how-to-change-the-user-pin/</link>
		<comments>http://blog.gocloud-security.ch/2012/02/09/update-bitlocker-and-how-to-change-the-user-pin/#comments</comments>
		<pubDate>Thu, 09 Feb 2012 06:42:45 +0000</pubDate>
		<dc:creator>Dominik Zemp</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Windows BitLocker]]></category>

		<guid isPermaLink="false">http://blog.gocloud-security.ch/?p=401</guid>
		<description><![CDATA[I’ve just seen that this blog post about BitLocker and how a Windows standard user can change the PIN got many hits in the last couple of days. So I’ve just decided to write a short update on that topic… &#8230; <a href="http://blog.gocloud-security.ch/2012/02/09/update-bitlocker-and-how-to-change-the-user-pin/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>I’ve just seen that this blog post about BitLocker and how a Windows standard user can change the PIN got many hits in the last couple of days. So I’ve just decided to write a short update on that topic…</p>
<p>My old blog (<a title="http://blog.gocloud-security.ch/2009/12/09/bitlocker-and-how-to-change-the-user-pin/" href="http://blog.gocloud-security.ch/2009/12/09/bitlocker-and-how-to-change-the-user-pin/" target="_blank">http://blog.gocloud-security.ch/2009/12/09/bitlocker-and-how-to-change-the-user-pin/</a>) describes a possible solution/approach with a custom service or process that calls the manage-bde command. Now, since a couple of month, there is a much smarter way to allow your Windows standard users to change the BitLocker PIN – MBAM (Microsoft BitLocker Administration and Monitoring)!</p>
<p>MBAM has been released in August 2011 as part of MDOP and integrates different capabilities that have been missed with BitLocker. For example a helpdesk key recovery UI, single recovery keys (the MBAM client will create a new key once a BitLocker recovery key has been exposed), and different audit and compliance reports.</p>
<p>You can find a technical slide deck with all required information about MBAM<br />
on <a href="http://media.ch9.ms/teched/na/2011/ppt/WCL317.pptx" target="_blank">http://media.ch9.ms/teched/na/2011/ppt/WCL317.pptx</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.gocloud-security.ch/2012/02/09/update-bitlocker-and-how-to-change-the-user-pin/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>A Solution for Private Cloud Security</title>
		<link>http://blog.gocloud-security.ch/2012/01/22/a-solution-for-private-cloud-security/</link>
		<comments>http://blog.gocloud-security.ch/2012/01/22/a-solution-for-private-cloud-security/#comments</comments>
		<pubDate>Sun, 22 Jan 2012 08:00:02 +0000</pubDate>
		<dc:creator>Dominik Zemp</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Private Cloud]]></category>

		<guid isPermaLink="false">http://blog.gocloud-security.ch/2012/01/22/a-solution-for-private-cloud-security/</guid>
		<description><![CDATA[And a next blog based on the recent announcements of Microsoft. The A Solution for Private Cloud Security is a series of three papers on private cloud security. And is therefore a part of a collection of documents comprise the &#8230; <a href="http://blog.gocloud-security.ch/2012/01/22/a-solution-for-private-cloud-security/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>And a next blog based on the recent announcements of Microsoft. </p>
<p>The <strong>A Solution for Private Cloud Security </strong>is a series of three papers on private cloud security. And is therefore a part of a collection of documents comprise the <strong>Reference Architecture for Private Cloud</strong> documentation set.</p>
<ul>
<li>Private Cloud Solution Hub, <a title="http://technet.microsoft.com/en-us/cloud/private-cloud" href="http://technet.microsoft.com/en-us/cloud/private-cloud">http://technet.microsoft.com/en-us/cloud/private-cloud</a></li>
<li>Reference Architecture for Private Cloud, <a title="http://social.technet.microsoft.com/wiki/contents/articles/3819.reference-architecture-for-private-cloud.aspx" href="http://social.technet.microsoft.com/wiki/contents/articles/3819.reference-architecture-for-private-cloud.aspx">http://social.technet.microsoft.com/wiki/contents/articles/3819.reference-architecture-for-private-cloud.aspx</a></li>
<li>A Solution for Private Cloud Security, <a title="http://social.technet.microsoft.com/wiki/contents/articles/6642.a-solution-for-private-cloud-security.aspx" href="http://social.technet.microsoft.com/wiki/contents/articles/6642.a-solution-for-private-cloud-security.aspx">http://social.technet.microsoft.com/wiki/contents/articles/6642.a-solution-for-private-cloud-security.aspx</a></li>
</ul>
<p>The current version of the <strong>A Solution for Private Cloud Security </strong>considers the security aspects of design and create robust and comprehensive private and hybrid cloud environments and consists of the following three papers:</p>
<ul>
<li>Blueprint for A Solution for Private Cloud Security</li>
<li>Design Guide for A Solution for Private Cloud</li>
<li>Operations Guide for A Solution for Private Cloud</li>
</ul>
<p> You can download all three documents in Word format as well, on <a title="http://gallery.technet.microsoft.com/A-Solution-for-Private-67209ab1" href="http://gallery.technet.microsoft.com/A-Solution-for-Private-67209ab1">http://gallery.technet.microsoft.com/A-Solution-for-Private-67209ab1</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.gocloud-security.ch/2012/01/22/a-solution-for-private-cloud-security/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Free Microsoft Private Cloud Training</title>
		<link>http://blog.gocloud-security.ch/2012/01/21/free-microsoft-private-cloud-training/</link>
		<comments>http://blog.gocloud-security.ch/2012/01/21/free-microsoft-private-cloud-training/#comments</comments>
		<pubDate>Sat, 21 Jan 2012 15:03:44 +0000</pubDate>
		<dc:creator>Dominik Zemp</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Private Cloud]]></category>

		<guid isPermaLink="false">http://blog.gocloud-security.ch/?p=394</guid>
		<description><![CDATA[After Microsoft&#8217;s announcement of the new System Center 2012 wave, a true private cloud builder, Microsoft offers a free 2-day virtual training event to help the world learn about the upcoming enhancements with the Creating &#38; Managing a Private Cloud &#8230; <a href="http://blog.gocloud-security.ch/2012/01/21/free-microsoft-private-cloud-training/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>After Microsoft&#8217;s announcement of the new System Center 2012 wave, a true private cloud builder, Microsoft offers a free 2-day virtual training event to help the world learn about the upcoming enhancements with the Creating &amp; Managing a Private Cloud with System Center 2012 Jump Start.</p>
<p>You can find more information about this free training on <a href="http://blogs.technet.com/b/server-cloud/archive/2012/01/20/free-microsoft-private-cloud-training.aspx">http://blogs.technet.com/b/server-cloud/archive/2012/01/20/free-microsoft-private-cloud-training.aspx</a></p>
<p>And information about System Center 2012 and the new capabilities to build a private cloud can be found on <a href="http://blogs.technet.com/b/server-cloud/archive/2012/01/17/system-center-2012-a-true-private-cloud-builder.aspx">http://blogs.technet.com/b/server-cloud/archive/2012/01/17/system-center-2012-a-true-private-cloud-builder.aspx.</a></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.gocloud-security.ch/2012/01/21/free-microsoft-private-cloud-training/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>FIM 2010 Community Resources</title>
		<link>http://blog.gocloud-security.ch/2012/01/19/fim-2010-community-resources/</link>
		<comments>http://blog.gocloud-security.ch/2012/01/19/fim-2010-community-resources/#comments</comments>
		<pubDate>Thu, 19 Jan 2012 17:33:10 +0000</pubDate>
		<dc:creator>Dominik Zemp</dc:creator>
				<category><![CDATA[Forefront]]></category>
		<category><![CDATA[Forefront|Forefront Identity Manager]]></category>
		<category><![CDATA[FIM]]></category>

		<guid isPermaLink="false">http://blog.gocloud-security.ch/2012/01/19/fim-2010-community-resources/</guid>
		<description><![CDATA[I thought it would be nice to blog about all the awesome community-related FIM activities/resources. So let’s kick off… FIM PowerShell (MA and MV synchronization extension, Workflow activity and modules), http://fim.codeplex.com/ PowerShell MA 2.0, http://blog.goverco.com/2012/01/powershell-management-agent-updated.html MARunScheduler (MASequencer), http://feedproxy.google.com/~r/AdventuresInIdentityManagement/~3/G6rPb2BEEy4/marunscheduler.html FIM related &#8230; <a href="http://blog.gocloud-security.ch/2012/01/19/fim-2010-community-resources/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>I thought it would be nice to blog about all the awesome community-related FIM activities/resources. So let’s kick off…</p>
<ul>
<li>FIM PowerShell (MA and MV synchronization extension, Workflow activity and modules), <a title="http://fim.codeplex.com/" href="http://fim.codeplex.com/">http://fim.codeplex.com/</a></li>
<li>PowerShell MA 2.0, <a title="http://blog.goverco.com/2012/01/powershell-management-agent-updated.html" href="http://blog.goverco.com/2012/01/powershell-management-agent-updated.html">http://blog.goverco.com/2012/01/powershell-management-agent-updated.html</a></li>
<li>MARunScheduler (MASequencer), <a title="http://feedproxy.google.com/~r/AdventuresInIdentityManagement/~3/G6rPb2BEEy4/marunscheduler.html" href="http://feedproxy.google.com/~r/AdventuresInIdentityManagement/~3/G6rPb2BEEy4/marunscheduler.html">http://feedproxy.google.com/~r/AdventuresInIdentityManagement/~3/G6rPb2BEEy4/marunscheduler.html</a></li>
<li>FIM related projects hosted on CodePlex, <a title="http://www.codeplex.com/site/search?query=FIM&amp;ac=3" href="http://www.codeplex.com/site/search?query=FIM&amp;ac=3">http://www.codeplex.com/site/search?query=FIM&amp;ac=3</a></li>
<li>…</li>
<li>…</li>
</ul>
<p>… and more with a next update!</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.gocloud-security.ch/2012/01/19/fim-2010-community-resources/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Rollup 1 for Forefront UAG 2010 Service Pack 1 Update 1</title>
		<link>http://blog.gocloud-security.ch/2012/01/12/rollup-1-for-forefront-uag-2010-service-pack-1-update-1/</link>
		<comments>http://blog.gocloud-security.ch/2012/01/12/rollup-1-for-forefront-uag-2010-service-pack-1-update-1/#comments</comments>
		<pubDate>Thu, 12 Jan 2012 14:36:03 +0000</pubDate>
		<dc:creator>Dominik Zemp</dc:creator>
				<category><![CDATA[Forefront]]></category>
		<category><![CDATA[Forefront|TMG]]></category>
		<category><![CDATA[Forefront|UAG]]></category>
		<category><![CDATA[UAG]]></category>

		<guid isPermaLink="false">http://blog.gocloud-security.ch/2012/01/12/rollup-1-for-forefront-uag-2010-service-pack-1-update-1/</guid>
		<description><![CDATA[Today, Microsoft released a first rollup package for UAG 2010 SP1 Update 1. You can find a list of all fixes that are included in the rollup 1 on http://support.microsoft.com/kb/2647899. Oh and yes, a rollup 1 for TMG 2010 SP2 &#8230; <a href="http://blog.gocloud-security.ch/2012/01/12/rollup-1-for-forefront-uag-2010-service-pack-1-update-1/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>Today, Microsoft released a first rollup package for UAG 2010 SP1 Update 1. You can find a list of all fixes that are included in the rollup 1 on <a title="http://support.microsoft.com/kb/2647899" href="http://support.microsoft.com/kb/2647899">http://support.microsoft.com/kb/2647899</a>.</p>
<p>Oh and yes, a rollup 1 for TMG 2010 SP2 has been published as well: <a title="http://support.microsoft.com/kb/2649961" href="http://support.microsoft.com/kb/2649961">http://support.microsoft.com/kb/2649961</a></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.gocloud-security.ch/2012/01/12/rollup-1-for-forefront-uag-2010-service-pack-1-update-1/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>[Update] FIM 2010 and Exchange 2010 Provisioning</title>
		<link>http://blog.gocloud-security.ch/2011/12/23/update-fim-2010-and-exchange-2010-provisioning/</link>
		<comments>http://blog.gocloud-security.ch/2011/12/23/update-fim-2010-and-exchange-2010-provisioning/#comments</comments>
		<pubDate>Fri, 23 Dec 2011 07:56:26 +0000</pubDate>
		<dc:creator>Dominik Zemp</dc:creator>
				<category><![CDATA[Forefront]]></category>
		<category><![CDATA[Forefront|Forefront Identity Manager]]></category>
		<category><![CDATA[FIM]]></category>
		<category><![CDATA[Private Cloud]]></category>

		<guid isPermaLink="false">http://blog.gocloud-security.ch/2011/12/23/update-fim-2010-and-exchange-2010-provisioning/</guid>
		<description><![CDATA[Last year, I wrote a first blog (http://blog.gocloud-security.ch/2010/05/13/fim-2010-and-exchange-2010-provisioning) about Exchange 2010 provisioning with FIM 2010 (codeless or not). Now, I’m currently working on a project where one requirement is the quick’n’dirty provisioning of mail-enabled users (please do not mistake a &#8230; <a href="http://blog.gocloud-security.ch/2011/12/23/update-fim-2010-and-exchange-2010-provisioning/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>Last year, I wrote a first blog (<a href="http://blog.gocloud-security.ch/2010/05/13/fim-2010-and-exchange-2010-provisioning">http://blog.gocloud-security.ch/2010/05/13/fim-2010-and-exchange-2010-provisioning</a>) about Exchange 2010 provisioning with FIM 2010 (codeless or not). Now, I’m currently working on a project where one requirement is the quick’n’dirty provisioning of mail-enabled users (please do not mistake a mail-enabled user with a mailbox user!).</p>
<p>The link that I used in my past blog was the one pointing to the TechNet magazine (<a title="http://technet.microsoft.com/en-us/magazine/ff472471.aspx" href="http://technet.microsoft.com/en-us/magazine/ff472471.aspx" target="_blank">http://technet.microsoft.com/en-us/magazine/ff472471.aspx</a>). And one point which really confused me was the following:</p>
<p><a href="http://blog.gocloud-security.ch/wp-content/uploads/2011/12/image.png"><img style="background-image: none; padding-left: 0px; padding-right: 0px; display: inline; padding-top: 0px; border: 0px;" title="image" src="http://blog.gocloud-security.ch/wp-content/uploads/2011/12/image_thumb.png" alt="image" width="614" height="95" border="0" /></a></p>
<p>Based on another table, the following attributes are required for a mail-enabled user:<a href="http://blog.gocloud-security.ch/wp-content/uploads/2011/12/image1.png"><img style="background-image: none; padding-left: 0px; padding-right: 0px; display: inline; padding-top: 0px; border: 0px;" title="image" src="http://blog.gocloud-security.ch/wp-content/uploads/2011/12/image_thumb1.png" alt="image" width="544" height="471" border="0" /></a></p>
<p>Another interesting point is the following:<a href="http://blog.gocloud-security.ch/wp-content/uploads/2011/12/image2.png"><img style="background-image: none; padding-left: 0px; padding-right: 0px; display: inline; padding-top: 0px; border: 0px;" title="image" src="http://blog.gocloud-security.ch/wp-content/uploads/2011/12/image_thumb2.png" alt="image" width="644" height="85" border="0" /></a></p>
<p>Now, wait a second… does that mean that I have to set the <em>msExchHomeServerName</em> as well when using Exchange 2010?? And should I use the <em>ExchangeUtils</em> class (of the Microsoft.MetadirectoryServicesEx) and especially the overloaded <em>CreateMailEnabledUser()</em> method? The answer is simple <strong>NO – </strong>for both questions!</p>
<p>First of all, have a look at the source code of the <em>ExchangeUtils.CreateMailEnabledUser()</em> method (btw, I used the free dotPeek from JetBrains as decompiler):<a href="http://blog.gocloud-security.ch/wp-content/uploads/2011/12/image3.png"><img style="background-image: none; padding-left: 0px; padding-right: 0px; display: inline; padding-top: 0px; border: 0px;" title="image" src="http://blog.gocloud-security.ch/wp-content/uploads/2011/12/image_thumb3.png" alt="image" width="829" height="249" border="0" /></a></p>
<p>So no magic! What the <em>CreateMailEnabledUser()</em> method really does is set the two attributes – the <em>mailNickname</em> and <em>targetAddress – </em>that’s all! But there is another important part as well – the <em>objectType = “user</em>”; line. You are fine with that as long as you use the <em>user</em> class (default in Active Directory) when provisioning the user objects. But that’s not the case in the current project (where we use a custom class in the schema) and therefore anyway a no-go for the <em>CreateMailEnabledUser()</em> method!</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.gocloud-security.ch/2011/12/23/update-fim-2010-and-exchange-2010-provisioning/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>A Guide to Claims-Based Identity and Access Control, Second Edition&#8211;Downloadable eBook</title>
		<link>http://blog.gocloud-security.ch/2011/12/18/a-guide-to-claims-based-identity-and-access-control-second-edition/</link>
		<comments>http://blog.gocloud-security.ch/2011/12/18/a-guide-to-claims-based-identity-and-access-control-second-edition/#comments</comments>
		<pubDate>Sun, 18 Dec 2011 08:53:14 +0000</pubDate>
		<dc:creator>Dominik Zemp</dc:creator>
				<category><![CDATA[Active Directory Federation Services (AD FS) 2.0]]></category>
		<category><![CDATA[Windows Azure]]></category>
		<category><![CDATA[Windows Azure|Access Control Service]]></category>
		<category><![CDATA[Windows Azure|Windows Azure Active Directory]]></category>
		<category><![CDATA[AD FS 2.0]]></category>
		<category><![CDATA[Authentication]]></category>
		<category><![CDATA[Azure]]></category>
		<category><![CDATA[SAML]]></category>

		<guid isPermaLink="false">http://blog.gocloud-security.ch/2011/12/18/a-guide-to-claims-based-identity-and-access-control-second-edition/</guid>
		<description><![CDATA[The phenomenal resource (book) ‘A Guide to Claims-Based Identity and Access Control’ has been renewed and published on MSDN a couple of weeks ago. This resource is the best I’ve ever seen for claims-based authentication and in particular AD FS &#8230; <a href="http://blog.gocloud-security.ch/2011/12/18/a-guide-to-claims-based-identity-and-access-control-second-edition/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>The phenomenal resource (book) ‘A Guide to Claims-Based Identity and Access Control’ has been renewed and published on MSDN a couple of weeks ago. This resource is the best I’ve ever seen for claims-based authentication and in particular AD FS 2.0! Every second invested in reading this book is more than worth the time!</p>
<p>You can find the online version of the 2nd edition on:</p>
<ul>
<li><a title="http://msdn.microsoft.com/en-us/library/ff423674.aspx" href="http://msdn.microsoft.com/en-us/library/ff423674.aspx">http://msdn.microsoft.com/en-us/library/ff423674.aspx</a></li>
</ul>
<p>But now the reason of this post – in addition to the online version, there is now downloadable PDF version of the 2nd edition. You can download it from:</p>
<ul>
<li><a title="http://www.microsoft.com/download/en/details.aspx?id=28362" href="http://www.microsoft.com/download/en/details.aspx?id=28362">http://www.microsoft.com/download/en/details.aspx?id=28362</a></li>
</ul>
<p>So the last thing that is missing is a printed version of the book… for those of you who want to read it under the Christmas tree. <img style="border-bottom-style: none; border-left-style: none; border-top-style: none; border-right-style: none" class="wlEmoticon wlEmoticon-smile" alt="Smile" src="http://blog.gocloud-security.ch/wp-content/uploads/2011/12/wlEmoticon-smile.png"></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.gocloud-security.ch/2011/12/18/a-guide-to-claims-based-identity-and-access-control-second-edition/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Azure Active Directory</title>
		<link>http://blog.gocloud-security.ch/2011/12/12/windows-azure-active-directory/</link>
		<comments>http://blog.gocloud-security.ch/2011/12/12/windows-azure-active-directory/#comments</comments>
		<pubDate>Mon, 12 Dec 2011 16:37:07 +0000</pubDate>
		<dc:creator>Dominik Zemp</dc:creator>
				<category><![CDATA[Office 365]]></category>
		<category><![CDATA[Windows Azure]]></category>
		<category><![CDATA[Windows Azure|Access Control Service]]></category>
		<category><![CDATA[Windows Azure|Windows Azure Active Directory]]></category>
		<category><![CDATA[AD DS]]></category>
		<category><![CDATA[AD FS 2.0]]></category>
		<category><![CDATA[Azure]]></category>

		<guid isPermaLink="false">http://blog.gocloud-security.ch/2011/12/12/windows-azure-active-directory/</guid>
		<description><![CDATA[A really interesting “change” in the name of one of the Windows Azure components, not particular from a content point of view. Read the lines below: “Windows Azure Active Directory is a cloud service that provides identity and access capabilities &#8230; <a href="http://blog.gocloud-security.ch/2011/12/12/windows-azure-active-directory/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>A really interesting “change” in the name of one of the Windows Azure components, not particular from a content point of view. Read the lines below:</p>
<p>“<em><font style="background-color: #ffff00">Windows Azure Active Directory</font><font style="background-color: #ffff00"> is a cloud service that provides identity and access capabilities for applications on Windows Azure and Microsoft Office 365</font>. Windows Azure Active Directory is the multi-tenant cloud service on which Microsoft Office 365 relies on for its identity infrastructure. <br />&nbsp;<br />Windows Azure Active Directory utilizes the enterprise-grade quality and proven capabilities of Active Directory, so you can bring your applications to the cloud easily.&nbsp; <font style="background-color: #ffff00">You can enable single sign-on, security enhanced applications, and simple interoperability with existing Active Directory deployments using Access Control Service (ACS), a feature of Windows Azure Active Directory.</font></em>“</p>
<p>Maybe this indicates the direction of the journey… But anyway, at the moment the Windows Azure Active Directory is just the cloud implementation of AD FS 2.0 (with some custom capabilities). </p>
<p>Read the full article on&nbsp; <a title="http://www.windowsazure.com/en-us/home/tour/access-control/" href="http://www.windowsazure.com/en-us/home/tour/access-control/" target="_blank">http://www.windowsazure.com/en-us/home/tour/access-control/</a></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.gocloud-security.ch/2011/12/12/windows-azure-active-directory/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Web-based Self-Service Password Reset with FIM 2010 R2</title>
		<link>http://blog.gocloud-security.ch/2011/12/09/web-based-self-service-password-reset-with-fim-2010-r2/</link>
		<comments>http://blog.gocloud-security.ch/2011/12/09/web-based-self-service-password-reset-with-fim-2010-r2/#comments</comments>
		<pubDate>Fri, 09 Dec 2011 08:40:09 +0000</pubDate>
		<dc:creator>Dominik Zemp</dc:creator>
				<category><![CDATA[Forefront]]></category>
		<category><![CDATA[Forefront|Forefront Identity Manager]]></category>
		<category><![CDATA[FIM]]></category>

		<guid isPermaLink="false">http://blog.gocloud-security.ch/2011/12/09/web-based-self-service-password-reset-with-fim-2010-r2/</guid>
		<description><![CDATA[With this blog, I want to highlight some of the very interesting articles about one of the new features of FIM 2010 R2 – the web-based self-service password reset. Articles from Anthony Ho: FIM 2010 R2 &#8211; Web-Based Password Reset &#8230; <a href="http://blog.gocloud-security.ch/2011/12/09/web-based-self-service-password-reset-with-fim-2010-r2/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>With this blog, I want to highlight some of the very interesting articles about one of the new features of FIM 2010 R2 – the web-based self-service password reset.</p>
<p>Articles from Anthony Ho:</p>
<ul>
<li>FIM 2010 R2 &#8211; Web-Based Password Reset Part 1, <a title="http://blogs.technet.com/b/aho/archive/2011/08/01/fim-2010-r2-web-based-password-reset.aspx" href="http://blogs.technet.com/b/aho/archive/2011/08/01/fim-2010-r2-web-based-password-reset.aspx">http://blogs.technet.com/b/aho/archive/2011/08/01/fim-2010-r2-web-based-password-reset.aspx</a></li>
<li>FIM 2010 R2 – Web-Based Password Reset Part 2, <a title="http://blogs.technet.com/b/aho/archive/2011/11/29/fim-2010-r2-web-based-password-reset-part-2.aspx" href="http://blogs.technet.com/b/aho/archive/2011/11/29/fim-2010-r2-web-based-password-reset-part-2.aspx">http://blogs.technet.com/b/aho/archive/2011/11/29/fim-2010-r2-web-based-password-reset-part-2.aspx</a></li>
<li>FIM 2010 R2 – Web-Based Password Reset Part 3, <a title="http://blogs.technet.com/b/aho/archive/2011/12/06/fim-2010-r2-web-based-password-reset-part-3.aspx" href="http://blogs.technet.com/b/aho/archive/2011/12/06/fim-2010-r2-web-based-password-reset-part-3.aspx">http://blogs.technet.com/b/aho/archive/2011/12/06/fim-2010-r2-web-based-password-reset-part-3.aspx</a></li>
</ul>
<p>Articles from Paul Williams:</p>
<ul>
<li>Self-service password reset (SSPR) question and answer (QA) gate complexity criteria in FIM 2010 R2, <a title="http://blog.msresource.net/2011/11/24/self-service-password-reset-sspr-question-and-answer-qa-gate-complexity-criteria-in-fim-2010-r2/" href="http://blog.msresource.net/2011/11/24/self-service-password-reset-sspr-question-and-answer-qa-gate-complexity-criteria-in-fim-2010-r2/">http://blog.msresource.net/2011/11/24/self-service-password-reset-sspr-question-and-answer-qa-gate-complexity-criteria-in-fim-2010-r2/</a></li>
</ul>
<p>Articles from Patrick Layani:</p>
<ul>
<li>FIM 2010 R2 – Web-Based SSRP using OTP, <a title="http://blogs.microsoft.co.il/blogs/patrick/archive/2011/12/06/fim-2010-r2-web-based-sspr-using-otp.aspx" href="http://blogs.microsoft.co.il/blogs/patrick/archive/2011/12/06/fim-2010-r2-web-based-sspr-using-otp.aspx">http://blogs.microsoft.co.il/blogs/patrick/archive/2011/12/06/fim-2010-r2-web-based-sspr-using-otp.aspx</a></li>
</ul>
<p>&nbsp;</p>
<p>And finally, the Evaluation Guide on TechNet: <a title="http://technet.microsoft.com/en-us/library/hh322874(WS.10).aspx" href="http://technet.microsoft.com/en-us/library/hh322874(WS.10).aspx">http://technet.microsoft.com/en-us/library/hh322874(WS.10).aspx</a></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.gocloud-security.ch/2011/12/09/web-based-self-service-password-reset-with-fim-2010-r2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

