VMWORLD SITE

VMWORLD SITE
VMWORLD SITE
Showing posts with label SAML. Show all posts
Showing posts with label SAML. Show all posts

Wednesday, 13 October 2010

Technology Preview of Project Horizon Weds 15:00

Noah Wasmer, Director, Advanced Development, VMware
Tiffany To, GPM, Advanced Development, VMware

Another very full session - clearly the keynote on this topic has generated considerable interest

Products under development disclaimer

Next Gen end user computing - the top tier of VMware's view of 3 tier model (middle tier is vCloud Apps Platform, base tier is vSphere infrastructure)

- 75% of ISVs deliver their new apps through web presentation layer - SaaS, virtual, on premise
- Diversity of connecting devices (e.g. 1,000 new types of Android devices will hit the market in 2011)

VMware approach
- single sign on for SaaS apps - aligned with internal apps and controls
- single sign on regardless of device
- looking to use industry standard protocols
- thinapp wrap can add a security layer and can be leased out to non-managed platforms and that lease can be withdrawn when required
- embracing App-V, XenApp, Dropbox (allows users to post data so they can get to it from any location / device), Salesforce etc
- Vmware proposing management of directory federation
- for traditional desktops an app icon will appear as standard, smilarly for other devices that same app will look native to the OS / interface
- modernizing Windows clients using apps isolation / portability
- need to mobilise and sync data
- looking to make externally hosted SaaS look like part of the enterprise.
- Secure STS at the enterprise boundary will talk to VMware Horizon which in turn will talk to the SaaS provision
- Horizon STS will be vAppliance or will run on Windows IIS
- Uses SAML for security passes token across the boundaries, only the token is passed, not the credentials

- Agent specific to each device will advise the service of the device type requesting access which allows the app to be presented in the appropriate format
- Admin can control which devices can access each app

Windows Apps
- ThinApp can allow patching but mitigates conflicts
- Horizon will track apps usage, allow self service, consumerization of devices
- Horizon will allow deployment / leasing of ThinApp wrapped apps to any device anywhere
- ThinApp packaged apps can be lodged in the Horizon cloud and automatic updates from ISVs can be automatically applied
- User credential requirements can be included in the ThinApp wrapper

- Horizon manages the policies of apps / user / device / time mix
- Deactive device access, app access or user access to apps
- Provisions the apps on the devices and, where necessary, creates the user with the SaaS supplier

Data
- Sync roaming profiles across devices
- Sync data around platforms and enable sharing of data between users but across multiple devices
-