DEC 2008 Session Abstracts


Directory Services Track
The Legend of Dean and Joe: More of the Same, Only Different

Speakers: Dean Wells and Joe Richards

Need a good laugh and an injection of AD brilliance all at once? Don't miss the Dean and Joe show this year at DEC 2008. This Active Directory brain trust is returning after a year off to share their unique brand of humor mixed with powerful AD insights and instruction (or maybe it's the other way around?) Come learn little known troubleshooting techniques and Windows Server 2008 best practices from these top-rated trainers and consultants. They promise not to disappoint -- and you might even walk away with a new free tool or two from Mr. Joeware himself!

^ Return to top.

 
Supporting Very Large Active Directories

Speaker: John Serban

Very Large Active Directory (VLAD) present unique design and support challenges. This session will discuss and demonstrate in-depth methods for monitoring and tracking VLAD replication based on USN backlog and replication progress. This session will also discuss how high AD update loads can impact replication and how AD Site design can be used to improve replication performance. Finally, this session will discuss how SAN Technology and VSS Hardware snapshots can be used for quick system recovery.

^ Return to top.

 
Managing the Software Lifecycle with Group Policy, WSUS and MBSA

Speaker: Mark Williams

This session covers solutions for managing the software and Operating Systems deployed in your environment. The session starts with an overview of what solutions are available for managing the Software lifecycle. It then covers in depth, through a scenario-based walk through, what can be accomplished with the in-box solutions or with readily available downloadable solutions. If you are responsible for managing software configuration in your environment and want to walk through some of the available options to Deploy, Update and Manage software, then this is the session for you.

^ Return to top.

 
Active Directory Roadmap

Speaker: Microsoft Program Management

The Directory Services landscape is constantly shifting and evolving as customer needs change and grow. In this session, Microsoft's Directory Services team will share some of their thoughts on changes that are envisioned for Active Directory Domain Services in the future.

^ Return to top.

 
Automating Group Policy Management

Speaker: Darren Mar-Elia

This session focuses on how the administrator can automate, through scripts, various aspects of their Group Policy management using GPMC and AD APIs. The session will include a review of how to use the GPMC and AD APIs using “traditional” VBScript as well as introduce the use of PowerShell to automate Group Policy management either directly, or using some free GP cmdlets. You’ll see examples of performing various management tasks that are not part of the canned scripts available within GPMC or AD APIs, such as how to determine which GPOs contain certain types of settings and how to query a workstation to determine if it is getting the most up-to-date GP settings.

^ Return to top.

 
Group Policy Performance Dissected

Speaker: Darren Mar-Elia

This session will follow on from work the speaker has done on understanding those aspects of Group Policy use and design that impact system performance. The session will look at how Group Policy is processed and attempt to answer the “age old” question of whether it is better to have more, smaller GPOs or fewer big ones. We’ll also look at some tools and techniques for measuring policy performance.

^ Return to top.

 
A Directory Service Geek’s View on AD Recovery in Windows Server 2008

Speaker: Ulf B. Simon-Weidner

This session will look at how to prepare your AD for recovery and will cover authoritative and non-authoritative restore, the new “Windows Backup,” tombstone reanimation, AD Snapshots, Object and Attribute Recovery and Lag-Sites vs. Snapshots. You also will learn the issues with linked attributes in the context of Active Directory Recovery. This session will provide many examples and demos to help you create an Active Directory Recovery Strategy for your company.

^ Return to top.

 
Programming the Directory with the .NET Framework

Speaker: Joe Kaplan

Come to this session and explore programming Active Directory and ADLDS using the .NET Framework. The session will cover the basic facilities offered by the .NET Framework today in versions 1.0-3.5. The session will also cover new LDAP features added to Windows Server 2008 AD such as new controls and filter types and features like fine-grained password policy. After attending this session, participants will know why .NET is important for both application developers and administrators and what it has to offer them now and in the future for building all types of directory-enabled applications (web, GUI, command line, services, etc.).

^ Return to top.

 
Windows Server 2008 in Microsoft

Speaker: Brian Puhl

Come to this session and hear Microsoft IT share their experiences deploying and managing Windows Server 2008 Servers in their production environment, as well as deploying Active Directory Federation Services. You’ll also learn how initiatives such as 2-factor authentication, Least Privilege Access, and Borderless networking have impacted the way Microsoft thinks of Directory Services.

^ Return to top.

Frontier Living: Raising Longhorn on the Outskirts of the Corporate Network

Speaker: Wook Lee

Read-only domain controllers and Server Core are key features of what used to be called Windows Longhorn, now Windows Server 2008. The frontiers of the corporate network include both the branch office as well as the so called DMZ where the corporate network meets the uncivilized internet. HP has spent months figuring out what it takes to make “Longhorn” AD and RODCs in particular, thrive as an essential component of its aggressive datacenter consolidation program. Find out what HP has done with Windows Server 2008 domain controllers in those environments.

^ Return to top.

Why It’s Not About the Directory Anymore

Speaker: Kevin Kampman

As identity management has evolved, a fundamental resource in the equation has been the directory. While the role of the directory and related capabilities hasn’t changed, the real challenge facing organizations today is to present and make identity information available in an abstract, unbounded manner. Identity Services are an approach to raise access and interaction with identity information to address these challenges. In this forward looking session, Kevin Kampman, Burton Group Senior Analyst, will discuss the goals and objectives for Identity Services, and current efforts to articulate the requirements for this capability.

^ Return to top.

 
Strong Authentication

Speaker: Microsoft Program Mgt.

Enterprises large and small are now focused more than ever on stronger authentication mechanisms for access to resources both within the enterprise as well as for remote access by an ever-growing mobile work force. This desire is driven in part by an increased focus on regulatory compliance laws as well as an eye toward lowering overall TCO. The Windows platform has been at the forefront of providing a strong, rich and secure authentication story built upon secure, standard protocols and strong cryptographic techniques. In Windows Vista, investments in authentication were made to offer better support for a number of scenarios that customers requested. Branch office support, flexible smartcard support, stronger crypto support and plug-ability options and a more robust and modular architecture for customization of the interactive logon sequence are examples of some of the investments made. This presentation will provide an overview of the authentication architecture in Windows and some specific investments Microsoft made in the Vista and Longhorn 2008 release. This will set the stage for a deeper dive into some of the scenarios that Microsoft is looking to invest in going forward. And, this session will show how this authentication story builds on Vista investments and plugs into the overall identity and management vision.

^ Return to top.

 
Strong Authentication

Speaker: Alain Lissoir

Learn about the capabilities in the Windows Server 2008 operating systems that enable new management scenarios for Active Directory. We explain how system administrators of the Active Directory directory service can use these capabilities to ease their day-to-day life and ensure smoother deployments and monitoring of their infrastructures. In this session, we briefly review the Microsoft WS-Management implementation under Windows and discuss how, as an Active Directory administrator, you can use its new set of features securely. Through practical examples, we demonstrate how the new Windows Remote Management (WinRM), Windows Remote Shell, and event forwarding features can address management needs for Active Directory Server Core deployment and Active Directory management and monitoring. Attend this presentation to discover how you can accomplish these tasks with a set of features directly available from this new operating system.

^ Return to top.

 
Securely Deploying and Managing an RODC. Improving AD Security and Mitigating Risks!

Speaker: Jorge de Almeida Pinto

With Windows Server 2008, Microsoft implements a new type of DC that aids in mitigating the risks of placing a DC in a non-secure location and assigning permissions to non-Domain Admins on DCs. This session will cover a ligh-level overview of the RODC, including requirements and best-practices. The specific focus will be on RODC deployment and managing it explaining the possibilities and what you need to think of. This session will also include some cool demo's!

^ Return to top.

 
Tale from the Trenches: Linux Integration into AD

Speaker: Robert Auch

Abstract: Come to this session to see how a real-life integration of dozens of Linux servers into a well-established Windows 2000 Native mode forest supporting over 300 Windows 2000 and 2003 servers was accomplished by Empire Today. This session will discuss the planning, design, and implementation of true single-sign on for Windows / Linux interoperability. We will explore Group Policy for Linux, the creation of new containers and OUs in AD to support Linux, and how the problem of UID/GID overlaps can be mitigated or even avoided.

^ Return to top.

 
Using Group Policy with Windows Vista and Windows Server 2008

Speaker: Kevin Sullivan

New to Group Policy? Been using GP for years? Just want to get more info on the environment? This session will cover GP focusing on enhancements to the platform introduced in Windows Vista and the enhancements to the administrators experience made available through Windows Server 2008. Starter GPOs, Search, Comments, GP Service, NLA improvements, Multiple Local GPOs. Additionally time will be spent going over some new tools and enhancements that make troubleshooting a more “joyful” experience.

^ Return to top.

 
Selecting the Best Strategy for Integrating AD with Non-Microsoft Platforms and Applications

Speaker: Dustin Puryear

When it comes to integrating non-Microsoft platforms, application servers, and databases into Active Directory (AD), the adage “so many choices, so little time” really hits home. This session will discuss the wide range of AD integration approaches, including thoughts on native, open source, and commercial solutions. Learn how you can plug a wide range of systems—such as a J2EE Tomcat-based application or a UNIX server—into AD and actually still make it home for dinner.

^ Return to top.

 
Directory Services - Security

Speaker: Mark Foust

A look at what real Security Assessments found in enterprise customers’ Directory Services environments and a look at how new features in Windows Server 2008 can help. Have you ever wondered what security obstacles other enterprises are dealing with on a day-to-day basis? Discover true data and lessons learned from real security audits.

^ Return to top.

 
When Worlds Collide: Active Directory vs. Application Developers

Speaker: Gil Kirkpatrick

To Windows professionals, Active Directory is a mission-critical component of the IT infrastructure, providing distributed authentication, authorization, and policy management to the entire enterprise. To an application developer however, AD is just another LDAP store, or worse, just another database. These conflicting views often result in application developers using AD in highly sub-optimal ways. Learn how to uncover such directory abuse, how to understand what your application developers are trying to accomplish, and how to help educate them about the best ways to leverage Active Directory.

^ Return to top.

 
Synchronization, Federation, Virtualization & Directory Consolidation - Which is the Right Solution & When?

Speaker: Michael Brengs

A common problem facing many enterprise organizations is knowing which technology or solution is the right solution to deploy.

This session describes the key architectural components in an overall identity management implementation and when it is appropriate to deploy a given technology or set of technologies. For example, when should you use a directory, directory synchronization, virtualization or federation?

Often, the right answer is a mixture of technologies. Integrating these components and deploying more than one product is the best way for an organization to see the most value of their IdM infrastructure. Each technology solves a unique problem, combining them into a complete solution is the key to a successful identity management initiative.

^ Return to top.

 
Identity Lifecycle Management (ILM) Track
Workflow Enabling the Datacenter

Speaker: Danny Kim

With the advent of Microsoft's .NET 3.0 technologies and PowerShell, enterprises can use standards based infrastructures to workflow enable all aspects of IT administration and datacenter service management. Coined by Gartner as Run Book Automation, this session will go through a large telecom's implementation utilizing Windows Workflow Foundation, Windows Communications Foundation, and Microsoft PowerShell technologies together to provision services for up to 80,000 servers utilizing virtualization technologies. This session will go over both the business impact and justification as well as the indepth technology implementation for
the project.

^ Return to top.

 
How is Microsoft IT Improving Identity Management?

Speaker: Joel Silver

The way the Microsoft identity management team manages the Active directory is evolving. In this session, you’ll learn about all of the new identity management projects that Microsoft has been working on this year. There has been significant progress in the following areas (just to name a few):

  • SAP MA
  • Elevated access modeling and a role based model for SOX compliance.
  • Next generation ILM implementation

^ Return to top.

 
Reference Madness - Here's a Possible Cure!

Speakers: Dmitry Kazantsev

Do you find references in your LDAP systems that don’t actually refer to the DN, or that refer to an object that will be imported from another MA? Then I invite you to attend this session and learn about how to build a Reference MA – an XMA approach to solving complex references without reinventing the wheel, or causing performance to suffer.

^ Return to top.

 
Partitioning MIIS for Performance and Scalability

Speaker: Richard Wakeman

This session will describe some tools and techniques that may be used to split similar metaverse classes into discrete object partitions. The session will focus on the use of this technique to increase parallel processing in large directory management scenarios.

^ Return to top.

 
10 Ways to Improve the Performance of Your ILM System

Speaker: Jeremy Palenchar

Most ILM solutions need to gather, synchronize, and distribute identity information to a large number of distributed systems in a short period of time. This session will provide detailed actions that can be taken to improve the performance of most ILM implementations. These recommendations are based on results gathered during ILM implementations for multiple Fortune 100 companies and several government agencies. Those new to ILM or veterans from the age of MMS are sure to learn something new.

^ Return to top.

 
Mining for Roles with ILM + SQL 2005 Analysis Services

Speaker: David Lundell

You've heard for years that RBAC is the holy grail of identity management, however, after setup you find yourself faced with a list of questions:

  • How do you make sense of what you have?
  • How do you define your roles?
  • Same job titles?
  • By department?

Come to this session and learn how to apply ILM 2007 and SQL 2005 Analysis Services to perform data mining on your groups and application roles. This will help you discover existing enterprise roles and jump start your RBAC project.

^ Return to top.

 
Advanced Password Synchronization with ILM 2007

Speaker: Patrick Rempel

ILM ships with a great Password Management Solution (PCNS), addressing one of the most common identity management challenges: Users who have too many passwords. Side effects from having too many passwords include:

  • Easy to remember, but weak passwordsPasswords that have been written down
  • Numerous and avoidable helpdesk calls, etc.

Unfortunately, if PCNS and ILM are not in the same forest, as well as AD Schema extension, the Password Management Solution has the handicap to require AD forest trust. This session will demonstrate how to overcome these technical limitations which currently prevent several ILM users (especially multinational corporations with complex forest structure) from rolling out password synchronization.

^ Return to top.

 
Testing: Ease Your Production Elevation Woes

Speaker: Brian Picard

Testing and QA certifying connectors are activities most ILM professionals take for granted. This session will provide a deep dive into testing and certifying connectors for elevation from the initial development phase through the production rollout. This session will use Progressive Insurance’s actual process as an example throughout the discussion.

^ Return to top.

 
Designing an Identity & Access Management Portal

Speaker: Brad Turner and Jerry Camel

ILM "2" is set to introduce the IdentityManagement WSS portal for self-service management of identity and access control. Learn what you can do in your existing deployments to integrate your existing MIIS 2003/ILM 2007 solution with Windows SharePoint Services 3.0 or MOSS 2007. Topics will include centralized SRS report integration with SharePoint, adding custom webparts or migrating existing ASP.NET applications into the portal, and leveraging the built-in workflow capability in SharePoint. Code samples and templates to be provided.

^ Return to top.

 
Moving Large Directories to ADAM, Lessons Learned

Speaker: David Jones

Out of the box AD LDS is not a functional directory. This presentation will cover what it took to make AD LDS work as a directory and what was done to make it ready for production services so that it could emulate and replace Cisco’s existing Netscape Directory Service family of LDAP servers. This presentation will dive into what was flexible, what wasn’t flexible, where that flexibility led to deployment gaps and what was done to get around them.

^ Return to top.

 
Extreme MIIS Group Performance

Speakers: Joe Stepongzi

This session will explore using Extensible Connectivity SQL Management to build a better group management process that supports thousands of group members and deltas throughout the lifecycle of the group. Come to this session and learn how to use the ECMA for snapshots to generate your own deltas and also understand how to use this feature to do individual multi-valued attribute deltas.

^ Return to top.

 
ILM Extensibility

Speaker: Craig Martin

Hello my name is Craig, and I have a problem. I get XMA hammered on a regular basis. Every problem is a nail and I pound it with my trusty XMA. In this session the Open Source LDAP XMA will be used as a basis for discussion on XMA development, including when and how to use an XMA, but more importantly, when NOT to use, and how NOT to use, the XMA.

^ Return to top.

ILM Extensibility

Speaker: Craig Martin

Hello my name is Craig, and I have a problem. I get XMA hammered on a regular basis. Every problem is a nail and I pound it with my trusty XMA. In this session the Open Source LDAP XMA will be used as a basis for discussion on XMA development, including when and how to use and XMA, but more importantly, when NOT to use and how NOT to use the XMA.

^ Return to top

 
Identity Architecture in Windows Server 2008

Speaker: Robert DeLuca

This session will give you a new view of the design of your identity infrastructure with an eye for taking advantage of the future technology available in Windows Server 2008. Coverage areas will include the entire Microsoft identity stack, as well as a general discussion of the architecture alternatives available to write applications effectively on the platform.

^ Return to top.

 
Managing Multiple AD Forests and Domains Through Identity Virtualization

Speaker: Donald "Trey" Henderson

The United States Air Force relies on the ability to access information anywhere, anytime. Five years ago, applications across the Air Force stood up their own Active Directory Forests. This process created orphaned and unmanageable accounts propagating “dirty data” throughout the service. The Air Force took initial steps to consolidate user identities using meta-directories but problems with replication, timeliness of data and high administrative costs plagued the program.

Today, through the considerable efforts of Air Force Directory Services, the Air Force has established a single authoritative view of identity data for enterprise applications. Using Virtual Directory, The Air Force has implemented capabilities that consolidate over 800,000 Air Force identities, automate account creation and maintenance processes, and provide timely and relevant data to enterprise applications. Ryan Daly and Donald Henderson III, two members of Booz Allen’s Identity and Access Management team, will discuss the business and technology drivers that led the Air Force to explore virtualization as an alternative to meta-directories. They will also provide insight as to how Booz Allen designed the system to scale to the required level and how the virtual directory construct enables new capabilities to increase the efficiency of Air Force users/programs ultimately saving the service significant time and money.

^ Return to top.

 
Group Management in ILM “2”

Speaker: Jeff Staiman

In this session, you will learn how to setup a group management solution for your organization. The session will Include an ILM “2” group management demo, lessons from our own MSIT self-host, and a discussion and walk-through of extending the group schema.

^ Return to top.

 
Codeless Provisioning in ILM “2”

Speaker: Bobby Gill

Having to write code to provision objects and perform transformations upon attribute flows has long been a bane of an administrator’s existence. ILM “2” allows you to define, with little or no code, the rules that govern how data flows in and out of ILM. We’ll show you how to do this as well as how to integrate this functionality with other concepts in ILM “2” including Sets, Policy Rules and Processes.

^ Return to top.

 
Stop Paying all that Money for Password Resets, Automate with ILM “2” Self-Service Password Reset!

Speaker: Alym Rayani

In this session, you will learn how to setup a self-service password reset solution for your organization. The session will Include an ILM “2” self-service password reset demo, lessons from our own MSIT self-host, and a discussion on authentication including challenges like Question & Answer and Smartcard gates.

^ Return to top.

 
Customizing and Extending ILM “2” for Your Business

Speaker: Andreas Kjellman

In this session we will show you how to customize your ILM “2” deployment to meet your business needs. We will talk about the new extensibility points that are offered in ILM “2” and how to use them. The session will walk-through scenarios and show you how write to the ILM “2” web service.

^ Return to top.

 
Don’t Get Stuck Using Old Technologies — Know your Options!

Speaker: Rhonda Layfield

SYSVOL now has choices for the replication engine used. In the past we all used the File Replication Service (FRS) regardless of how well it worked. FRS had its limitations and problem areas such as: journal wraps and morphed files and folders. The new replication engine — Distributed File System — Replication (DFS-R) offers superior functionality over FRS. DFS-R replicates only the data that has changed in a file, not the entire file, and it self-heals when journal wraps are encountered. Rhonda will walk you through how FRS replicates data compared to DFS-R and the NEW migration tool to migrate from FRS to DFS-R for your SYSVOL replication. When you leave this session you will have step-by-step instructions for migrating to DFS-R and lots of reasons to do so.

^ Return to top.

 
ILM 2007 – an Architect’s View

Speaker: Hugh Simpson-Wells

When we talk of ILM 2007, it is all too easy to dive straight into code. This is a codeless presentation! If you are going to architect a good solution, you must fully understand a few things:

  • What can be done without code
  • Where extensions are needed
  • What state-based and convergent systems are
  • What triggers ‘rules’
  • What you can’t do with rules extensions
  • Where custom MA extensions can - and should - be used

Calling on Oxford Computer Group’s experience of over 300 enterprise wide identity and access solution deployments, this presentation covers these issues, establishes some basic principles, and then goes on to examine useful architectures based upon them.

^ Return to top.

 
Secure Foundations for Services Identity

Speaker: Earl Perkins

This session will explore the today and tomorrow’s foundations for identity and access management infrastructure that will support the shift to the web 2.0 world for both enterprise and consumers with a focus on impacts to the future role of the directory in a service-centric enterprise.

^ Return to top.

 
Federated Identity Track
Customizing ADFS for use in Real World Scenarios

Speaker: Joe Kaplan

Active Directory Federation Services (ADFS) is a power technology in Windows Server that enables authentication and authorization of users across organizational boundaries for web applications. Out of the box, ADFS is useful but may not be optimized for your organization's needs. In this session, you will learn about the types of customization opportunities that ADFS allows. We will then explore a range of customization scenarios from the basics that everyone should consider doing all the way through some advanced scenarios that demonstrate the full power of the product.

^ Return to top.

 
ADFS Inside Microsoft

Speaker: Brian Puhl

Servers are set up, and nobody to federate with! Microsoft IT deployed Active Directory Federation Services in early 2005 and has been rapidly pushing the adoption of ADFSv1 (Windows Server 2003 R2) and ADFSv1.1 (Windows Server 2008) internally ever since. Come hear the technology, legal, process, and general challenges and benefits of Microsoft’s internal deployment. The session will cover where Microsoft has been, where they’re at, where they see the future of federation internally as they enter the CardSpace and federated identity era.

^ Return to top.

 
ADFS – Achieving Cross-Platform Interoperability

Speaker: Chris Calderon

In this session, we’ll focus on overcoming the challenges for achieving cross-platform interoperability with identity federation. Key topics that will be covered are: understanding the anatomy of identity federation; what are the components, technologies, and common challenges faced in these types of projects. Additionally, the session will cover what enables cross-organization and cross-platform interoperability.

^ Return to top.

 
Hanging out in the CardSpace Kitchen

Speaker: Pam Dingle

Want to be ahead of the adoption curve? Hang out with Pamela Dingle and learn a few recipes for baking information cards into your IT infrastructure. No more abstract theories, Pamela will present basic recipes for setting up an Identity Provider that will create and validate corporately branded information cards, and for enabling consuming applications both within and outside your network perimeter to accept your company information card.

Don't forget to bring your appetite for technical detail!

^ Return to top.

 
Building Claims Aware Applications

Speaker: Matt Steele

Claims-based authorization is cool, its hip, its what’s happening. You gotta get yourself some of that hot sauce for your own web-service apps. But where do you start? This session will walk you through the technologies and the code you need to enable fine-grained claims-based authorization decisions in your application. The session will include an introduction to claims-based authorization, handling simple claims such roles and groups, as well as more complex claim structures.

^ Return to top.

 
Secure Cross-organization Collaboration with SharePoint, ADFS, and Rights Management Server

Speaker: Donovan Follette

When you set up a new project team, one of the first things you want to do is create a Sharepoint site to support team collaboration. But what if some of your team members are part of a different company? You can give them VPN access and Active Directory credentials, but do you really want to inherit all the headaches of managing their identities? Of course not. And how can you be sure that once they have access to your project documentation, they don’t accidentally forward it on to someone who shouldn’t see it? Learn how you can integrate SharePoint, ADFS, and Rights Management Server (RMS) to support inter-organizational collaboration that is both secure and easy to manage.

^ Return to top.

 
Active Directory Federation Services Case Studies

Speaker: Donovan Follette

Active Directory Federation Services (ADFS) enables secure, standards-based identity federation between organizations. Learn how various Microsoft customers have successfully implemented ADFS to provide secure collaboration and claims-based authorization between multiple organizations.

^ Return to top.

 
Active Directory Federation Services Architecture Deep Dive

Speaker: Matt Steele

Active Directory Federation Services (ADFS) is Microsoft’s standards-based solution for identity federation. In this session we will discuss the basics of claims-based authorization, how federation process as defined by WS-Federation actually works, the different kinds of authentication that ADFS supports, internal structure of ADFS, etc.

^ Return to top.

 
Managing Active Directory Domain Services in Windows Server 2008

Speaker: A. Lissior

Learn about the Microsoft Management Solutions available in and out of the box that help you to enable new Active Directory Domain Services management scenarios. We will explain how Active Directory system administrators can use these solutions to increase efficiency in common daily tasks and help to ensure smoother deployments and monitoring of infrastructure.

^ Return to top.

 
Information Protection Track
Network Access Protection - Resource Isolation

Speaker: Deji Akomolafe

Network Access Protection, a new security and network hygiene configuration and enforcement platform in Windows Server 2008, provides a set of administrative facilities for protecting a Windows network. NAP provides a network administrator an intuitive methodology for configuring security policies, rules and remediation options that jointly facilitate a more effective protection mechanism for network resources. This discussion will include a demonstration on how, by leveraging the capabilities of NAP components, specifically the IPSec enforcement method, an administrator can ensure that requests for protected domain resources are transparently granted to requestors who meet defined health and compliance requirements, while simultaneously denying similar requests from non-compliant requestors.

^ Return to top.

 
Microsoft Rights Management Sevices

Speaker: Anthony Morgante

The session will present an overview of RMS, including a "drive through of user experience," architecture and integration with ADFS in Windows Server 2008.

^ Return to top.

 
Extending Active Directory RMS

Speaker: Andy Schan

Once you have a solid RMS deployment in place, RMS can be extended to provide additional functionality to the enterprise. This session will look at how AD RMS support for XPS can be leveraged, and how MOSS 2007 provides the ability to protect content in document libraries, while Exchange Server 2007 SP1 introduced server-side license pre-fetching. In addition, AD RMS can be extended outside the enterprise by leveraging ADFS with business partners and suppliers.

^ Return to top.

 
RMS Large Scale Architecture Design and Deployment

Speaker: Andy Schan

This session will cover the factors involved in designing and deploying a large (greater than 200,000) RMS deployment, including considerations for multiple forests and a geographically dispersed environment.

^ Return to top.

 
RMS Deployment Best Practices

Speaker: Peter Waxman

Learn about RMS deployment best practices: Do's and Don'ts, covering real world enterprise scenarios and what to be mindful of in going from evaluation to corporate wide deployment. What’s the best way to integrate additional RMS aware applications and devices? Business requirements demand protection for external collaboration with partners, customers, and suppliers? You’ll come away understanding how you can use federated identities, AD identities, and Live ID to turn on these scenarios.

^ Return to top.

 
It’s 10PM, Do You Know Where Your Sensitive Iinformation Is?

Speaker: Peter Waxman

Information protection and leakage prevention is a top of mind issue from the IT Professional all the way to the boardroom. Come hear about how Microsoft is addressing this problem with Active Directory Rights Management Servics. You’ll learn what it does, how it works, and see demos of some of the wave of innovation of RMS enablement in Windows Server 2008, Sharepoint Server 2007, Exchange, Windows Mobile, and in Microsoft’s ISV products.

^ Return to top.

 
Developer Track
Automating AD Administration: State of the Union

Speaker: Don Jones

ADSI, VBScript, Windows PowerShell, command-line tools...it seems as if the means to automate AD administration are out there, but they're inconsistent and involve a half-dozen different technologies. Come to this session and hear a "state of the union address" about automating AD administration: Learn what works, what doesn't, and what's coming, and
discover the "right tool" to focus on today for key AD management tasks.

^ Return to top.

 
Windows PowerShell v.Next: What's Coming

Speaker: Don Jones

This session will introduces you to what's on deck for the next version of Microsoft's powerful new command-line administrative interface: PowerShell v.Next! Discover what Microsoft has learned from over 1 million v1 downloads, see new features in action, and learn WHY those new features exist and what problems they solve. You'll get a head start on mastering Windows PowerShell's next version!

^ Return to top.

 
Roundtables and Discussions
Directory & Identity Experts Panel Discussion

Join top technology advocates in the directory and identity field for a lively exchange of ideas that will enlighten, educate and entertain you all at once.

^ Return to top.

 
Pre-Conference Workshops
Identity All Up: Architecting an Integrated, Streamlined Microsoft Identity & Access Platform

Come do what's never been done before. Join Oxford Computer Group, NetPro, and Microsoft in one action-packed day that's all about taking your Microsoft Identity and Access (IDA) platform to the next level. This team of experts will share hands-on guidance for designing your identity infrastructure to leverage the new technology available in Windows Server 2008. The full-day workshop will cover how to build out your identity management platform with Rights Management Services (RMS), Certificate Lifecycle Management (CLM) and Federation using the complete array of Microsoft IDA technologies. The day will also highlight architecture alternatives available to write applications effectively on the platform and an exclusive sneak peek look at ILM 2- the next version of Identity Lifecycle Manager - with the latest ILM 2 bits.

Sunday, March 2, 2008
8:00am - 5:00pm
Cost:  $500

Register ››

Come to DEC 2008 a day early and learn how to:

  • Provision Certificates using ILM
  • Provision Certificates to SmartCards
  • When to use Federation vs. Provisioning
  • Provision Certificates for RMS
  • How to use Federation and Provisioning to enable access to SharePoint
  • Leverage RMS to protect the content in SharePoint

 

 
© 2007 NetPro Computing, Inc . All rights reserved.