Module 5
Module 5
Identity Access Management in the cloud, Identity and Access Management functions, Identity and Access
Management (IAM) Model, Identity Federation, Authentication for SaaS and Paas customers, Authentication
for IaaS customers, Enterprise Architecture with IDaaS , IDaaS Security Recommendations. Virtualization:
Hardware Virtualization, Software Virtualization, Memory Virtualization, Storage Virtualization, Data
Virtualization, Network Virtualization, Virtualization Security Recommendations.
Identity and Access Management in the cloud
Identity and Access Management (IAM) in the cloud is a critical security practice that controls who can access
cloud resources and what they can do with them. It involves identifying, authenticating, and authorizing users,
groups, and even systems to access cloud services. IAM policies define permissions, roles, and access levels,
ensuring only authorized entities have access to the necessary resources while adhering to principles like "least
privilege" to minimize risks.
Key Aspects of Cloud IAM:
Identification:
Determining who or what is requesting access (users, applications, etc.).
Authentication:
Verifying the identity of the requesting entity (e.g., through username/password, multi-factor authentication).
Authorization:
Determining what permissions the authenticated entity has to access specific resources.
Access Control:
Enforcing policies to restrict access to cloud resources based on roles, permissions, and other factors.
Identity Governance:
Managing the lifecycle of identities, including provisioning, deprovisioning, and access reviews.
Centralized Management:
Providing a single point of control for managing identities and access across different cloud platforms.
Benefits of Cloud IAM:
Enhanced Security:
Controls access to sensitive data and resources, reducing the risk of unauthorized access and breaches.
Improved Compliance:
Ensures adherence to regulatory requirements and industry standards for data protection and access control.
Simplified Management:
Streamlines the process of managing identities and access across the cloud, reducing administrative overhead.
Increased Agility:
Enables organizations to quickly provision and deprovision access as needed, supporting business needs.
Challenges of Cloud IAM:
Complexity:
Managing identities and access across multiple cloud platforms and services can be complex.
Keeping Up with Technology:
The cloud landscape is constantly evolving, requiring ongoing monitoring and adaptation of IAM practices.
Security Risks:
IAM implementations must be robust and secure to prevent unauthorized access and potential breaches.
User Experience:
Ensuring that users can easily access the resources they need while adhering to security policies is a key
challenge.
IAM Identities Classified As
1. IAM Users
2. IAM Groups
3. IAM Roles
Root User: The root user will automatically be created and granted unrestricted rights. We can create an admin user with
fewer powers to control the entire Amazon account.
IAM Users: We can utilize IAM users to access the AWS Console and their administrative permissions differ from those
of the Root user and if we can keep track of their login information.
Example
With the aid of IAM users, we can accomplish our goal of giving a specific person access to every service available in the
Amazon dashboard with only a limited set of permissions, such as read-only access. Let’s say user-1 is a user that I want
to have read-only access to the EC2 instance and no additional permissions, such as create, delete, or update. By creating
an IAM user and attaching user-1 to that IAM user, we may allow the user access to the EC2 instance with the required
permissions.
IAM Groups: A group is a collection of users, and a single person can be a member of several groups. With the aid of
groups, we can manage permissions for many users quickly and efficiently.
IAM Roles
While policies cannot be directly given to any of the services accessible through the Amazon dashboard, IAM roles are
similar to IAM users in that they may be assumed by anybody who requires them. By using roles, we can provide AWS
Services access rights to other AWS Services.
IAM Policies
IAM Policies can manage access for AWS by attaching them to the IAM Identities or resources IAM policies defines
permissions of AWS identities and AWS resources when a user or any resource makes a request to AWS will validate
these policies and confirms whether the request to be allowed or to be denied. AWS policies are stored in the form of
Jason format the number of policies to be attached to particular IAM identities depends upon [Link] permissions required
for one IAM identity. IAM identity can have multiple policies attached to them.
Access Management For AWS Resources Identity Management
• Access management
• Federation
• RBAC/EM
• Multi-Factor authentication
• Access governance
• Customer IAM
• API Security
• IDaaS – Identity as a service
• Granular permissions
• Privileged Identity management – PIM (PAM or PIM is the same)
Figure – Services under IAM
More About the Services: Looking into the services on brief, Identity management is purely responsible for managing
the identity lifecycle. Access management is responsible for the access to the resources, access governance is responsible
for access request grant and audits. PIM or PAM is responsible for managing all the privileged access to the resources.
The remaining services either help these services or help in increasing the productivity of these services.
Market for IAM: Current situation of the market, there are three market leaders (Okta, SailPoint and Cyberark) who
master one of the three domains (Identity Management, Identity Governance and Privilege access management),
according to Gartner and Forrester reports. These companies have developed solutions and are still developing new
solutions that allow an organization to manage identity and its access securely without any hindrances in the workflow.
There are other IAM tools, Beyond Trust, Ping, One login, Centrify, Azure Active Directory, Oracle Identity Cloud
Services and many more.
Benefits of IAM Systems
• Enhanced Security: IAM prevents unauthorized access to sensitive data and systems, thus minimizing the
access of the unauthorized personnel.
• Improved Compliance: It also guarantees that the organization complies with the legal requirements concerning
the access control as well as the tracking of activities performed by the users.
• Increased Productivity: Automates processes of the management of users and access, thus minimizing the
numbers of manual operations and providing faster access to the required resources.
• Reduced Risk: Portfolios reduce internal risks and data losses due to strict access protocols in place.
• Centralized management is capable of consolidating identity and company access control and enforcing the same
across different systems.
Importance of IAM for Organizations
• Security: IAM makes certain that only the right people are given access to core systems and information and
thus safeguards organizations from threats within and outside.
• Regulatory Compliance: IAM aids organizations in compliance with the legal and industry-compliant
requirements based on the accessibility and the log records of the user activities.
• Operational Efficiency: IAM provides means of minimizing workload to IT teams by automating tasks such as
onboarding, offboarding, and shifts in user roles.
• Risk Mitigation: IAM also helps in combating data breaches and cyber attacks since it has strict measures
towards providing access to users.
• User Experience: It provides easier access to the firm’s partners, employees, and customers in interacting with
the systems with increased security, thus enhancing productivity and customer satisfaction.
IAM and Compliance Regulations
• Access Control: IAM helps in authorizing only the right people access to information; this complies with data
protection laws such as GDPR and HIPAA.
• Audit Trails: Saves a rich history of users activities to assist in audits and other reporting requirements.
• Segregation of Duties: Implements strict access control with respect to the roles that inhabitants are to undertake
to avoid breaching conflict of interest rules as provided by SOX and its equivalents.
• Data Protection: Enhances data protection; the program is useful in supporting compliance with Data Security
policies in line with PCI-DSS and other standards.
• User Authentication: Provides multi-factor authentication, thus satisfies security standards for many compliance
programs.
IAM Technologies and Tools
• Single Sign-On (SSO): A choice that lets a user login and use multiple applications at once, as well as give more
security to the services. Example: Its competitors include Okta and Microsoft Azure AD.
• Multi-Factor Authentication (MFA): A second one is that you must verify your account with two or more ways
to boost its security. Example: Some of the examples of Two Factor Authentication applications are Duo Security
and Google Authenticator.
• Role-Based Access Control (RBAC): Secures the system based on employees’ roles, where the user will have
the least privilege to access the system. Example: IBM Security Identity Manager.
• Privileged Access Management (PAM): Performs functions associated with obtaining and maintaining high
levels of accessible (“privileged”) computing resources. Example: CyberArk, BeyondTrust.
Resource Access Control
Identity and access management (IAM) will allows you to manage the permissions to the resources in the AWS cloud like
users who can access particular serivce to which extent and also instead of mantaing the permissions individually you can
manage the permissions to group of users at a time.
1. Managing permissions: For example you want to assign an permission to the user that he/her can only perform
restart the instance task on AWS EC2 instance then you can do using AWS IAM.
2. Implemneting role-based access control(RBAC): Identity and Access Management (IAM) will helps you to
manage the permissions based on roles Roles will helps to assign the the permissions to the resourcesw in the
AWS like which resources can access the another resource according to the requirement.
3. Enabling single sign-on (SSO): Identity and Access Management will helps you to maintain the same password
and user name which will reduce the effort of remembering the different password.
IAM Features
Shared Access to your Account: A team working on a project can easily share resources with the help of the shared
access feature.
1. Free of cost: IAM feature of the AWS account is free to use & charges are added only when you access other
Amazon web services using IAM users.
2. Have Centralized control over your AWS account: Any new creation of users, groups, or any form of
cancellation that takes place in the AWS account is controlled by you, and you have control over what & how
data can be accessed by the user.
3. Grant permission to the user: As the root account holds administrative rights, the user will be granted
permission to access certain services by IAM.
4. Multifactor Authentication: Additional layer of security is implemented on your account by a third party, a six-
digit number that you have to put along with your password when you log into your accounts.
Accessing IAM
1. AWS Console: Access the AWS IAM through the GUI. It is an web application provided by the AWS (Amazon
Web Application) it is an console where users can access the aws console
2. AWS Command Line Tools: Instead of accessing the console you can access y the command line interface
(CLI) to access the AWS web application. You can automate the process by using the Scripts.
3. IAM Query API: Programmatic access to IAM and AWS by allowing you to send HTTPS requests directly to
the service.
Authorization:
1. Role-Based Access Control (RBAC): Assigning access based on user roles.
2. Attribute-Based Access Control (ABAC): Assigning access based on user attributes.
Self-Service:
1. User Profile Management: Allowing users to update their own profiles.
2. Password Reset: Allowing users to reset their own passwords.
Password Management:
1. Password Policies: Establishing rules for password creation and management.
2. Password Reset: Managing password reset processes.
Complaints and Incident Management:
1. Security Incident Response: Responding to security incidents.
2. User Complaint Management: Handling user complaints and issues.
Deprovisioning:
1. User Offboarding: Revoking access and deleting user accounts.
2. Role-Based Deprovisioning: Revoking access based on user roles.
By implementing effective identity lifecycle management, organizations can enhance security, streamline access, and
improve user experience.
Authentication for SaaS, PaaS, and IaaS Customers
Authentication is a critical component of cloud security that ensures only authorized users can access cloud resources.
SaaS (Software as a Service) Authentication:
1. Single Sign-On (SSO): Enables users to access SaaS applications with a single set of credentials.
2. Multi-Factor Authentication (MFA): Requires additional verification methods for access.
3. Identity Federation: Enables SSO between SaaS applications and identity providers.
PaaS (Platform as a Service) Authentication:
1. API Keys: Used to authenticate API requests.
2. OAuth: Enables delegated access to PaaS resources.
3. Role-Based Access Control (RBAC): Assigns access based on user roles.
IaaS (Infrastructure as a Service) Authentication:
1. SSH Keys: Used to authenticate access to IaaS resources.
2. API Keys: Used to authenticate API requests.
3. Identity and Access Management (IAM): Manages access to IaaS resources.
Identity-as-a-Service (IDaaS) refers identity and access management services provided through the cloud on a
subscription basis. Identity-as-a-Service is typically fully on-premises and provided via set of software and hardware
means. An identity service stores the information linked with a digital entity in a form which can be managed and queried
for further utilization in electronic transactions. Major core functions of Identity Services are:
1. A data stores.
2. Query Engine.
3. Policy Engine.
Some Distributed transaction systems like cloud computing systems and internetworks magnify the problems tackled by
identity management systems by revealing a larger attack surface to an intruder than a private network does. Whether it is
network congestion protection, privileged component access, or any other defined right or privilege, As the central tenet
of secure network schema leads to the base of validation authorization of object on its identity. Hence, establishing
identity is the key to get trust and to anything that an object seems to claim possession of. Services which provide digital
identity management as a service are classification of internetworked systems. IDaaS – Identity-as-a-Service is a of the
month, which is applied to many services that are already exist. Servers that run the numerous internet domains (.COM,
.ORG, .EDU, .MIL, .RU, .TV etc.) are IDaaS servers. DNS configures the identity of a domain as belonging to a group of
assigned networks, linked with an owner and his information, and so forth. If the identity is configured in the form of IP
number, then the metadata is another property.
Definition of an Identity – An identity refers to a set of attributes or characteristics which make something recognizable
or known. It is digital identity of an individual that is mostly concerned in computer network systems. An attribute and
metadata of any object related to another object that enables an object to be identifiable is termed as Digital Identity. An
identity can belong to an individual and may consist of the following:
1. Things you are: Biological characteristics like gender, age etc.
2. Things you know: Personal data like social security PINs etc.
3. Things you have: Your fingerprint, bank account which you can access etc.
4. Things you relate to: Your family and friends, beliefs and values etc.
To establish an identity, an individual might be demanded to provide a name and password, that is termed as single-factor
authentication method. More secure authentication needs the use of minimum two-factor authentication. To get a multi-
factor authentication, an individual might have a system which checks a biometric factor like fingerprint pattern which is
unique. Multi-factor authentication needs the use of a network security or reliable services which is in the deployment of
reliable services that most common IDaaS applications are employed in the cloud computing. A lot of things has digital
identity. Machine accounts and user, devices, and many other objects configure their identity in various methods. In this,
identities are created and stored in the database of security domains that are the basis of any domain of network. Network
interfaces which are recognized uniquely by Media Access Control (MAC) addresses, that are referred to as Ethernet
Hardware Access (EHA). Network identity assign specific MAC address that enables system to be uniquely found on the
network. The manner in which a Windows provider validates installation of windows on the system of the user is known
as Windows Product Activation and it establish an identification index or profile of the system, which is instructive.
During activation, the following unique data components are fetched:
1. PC manufacturer
2. CPU type and its serial number
3. BIOS checksum
4. Display adapter
5. RAM amount
6. A 25-character software product key and product ID
7. The uniquely assigned Global Unique Identifier or GUID
8. Network address and its MAC address
9. SCSCI and IDE adapters
10. Hard drive and volume serial number
11. Optical drive
12. Region and language settings
Each of the above uniquely identified hardware characteristics is assigned a factor such that an overall sum can be
remunerated.
Advantages of IDaaS
• Reduced costs: IDaaS eliminates the need for organizations to invest in on-premises hardware and software to
manage user identities and access. This can result in significant cost savings in terms of hardware, software, and
maintenance expenses.
• Improved security: IDaaS provides a more secure environment for managing user identities and access. It offers
advanced authentication methods, such as multi-factor authentication, which can enhance security and reduce the
risk of data breaches.
• Scalability: IDaaS is designed to scale easily and can accommodate a large number of users and resources. This
makes it easier to manage user identities and access as organizations grow and expand.
• Flexibility: IDaaS offers a flexible solution that can be customized to meet the specific needs of an organization.
This includes options for integrating with other cloud-based services and on-premises applications.
• Simplified management: IDaaS provides a centralized management interface that enables organizations to
manage user identities and access from a single location. This simplifies the management of user identities and
access across different applications and services.
• Improved user experience: IDaaS offers a seamless user experience across different applications and devices.
This makes it easier for users to access resources and applications, which can improve productivity and user
satisfaction.
Disadvantages of IDaaS
• Dependence on internet connectivity: IDaaS relies on internet connectivity, which means that organizations
may experience disruptions in service if there are issues with the internet connection or if the service provider
experiences downtime.
• Limited customization: While IDaaS offers some flexibility, it may not be as customizable as an on-premises
solution. This may limit an organization’s ability to configure the service to meet specific needs or integrate with
certain applications.
• Security concerns: IDaaS involves transferring sensitive user identity and access information to a third-party
service provider. This raises concerns about data security and privacy, as the service provider may be a target for
cyber attacks or may not be as stringent in its security practices as the organization itself.
• Regulatory compliance: Organizations may face regulatory compliance issues when using IDaaS, particularly if
they operate in industries with strict data privacy regulations. The use of third-party service providers may
require additional compliance measures to be put in place to ensure the security and privacy of sensitive
information.
• Integration challenges: Integrating IDaaS with existing systems and applications may be challenging,
particularly if those systems and applications were not designed with cloud-based identity and access
management in mind.
Virtualization is used to create a virtual version of an underlying service With the help of Virtualization,
multiple operating systems and applications can run on the same machine and its same hardware at the same
time, increasing the utilization and flexibility of hardware. It was initially developed during the mainframe era.
• It is one of the main cost-effective, hardware-reducing, and energy-saving techniques used by cloud
providers. Virtualization allows sharing of a single physical instance of a resource or an application
among multiple customers and organizations at one time. It does this by assigning a logical name to
physical storage and providing a pointer to that physical resource on demand.
The term virtualization is often synonymous with hardware virtualization, which plays a fundamental
role in efficiently delivering Infrastructure-as-a-Service (IaaS) solutions for cloud computing.
Moreover, virtualization technologies provide a virtual environment for not only executing
applications but also for storage, memory, and networking
• Host Machine: The machine on which the virtual machine is going to be built is known as Host
Machine.
• Virtualization has a prominent impact on Cloud Computing. In the case of cloud computing, users
store data in the cloud, but with the help of Virtualization, users have the extra benefit of sharing the
infrastructure.
• Cloud Vendors take care of the required physical resources, but these cloud providers charge a huge
amount for these services which impacts every user or organization. Virtualization helps Users or
Organisations in maintaining those services which are required by a company through external (third-
party) people, which helps in reducing costs to the company. This is the way through which
Virtualization works in Cloud Computing.
Benefits of Virtualization
Drawback of Virtualization
• High Initial Investment: Clouds have a very high initial investment, but it is also true that it will
help in reducing the cost of companies.
• Learning New Infrastructure: As the companies shifted from Servers to Cloud, it requires highly
skilled staff who have skills to work with the cloud easily and for this, you have to hire new staff or
provide training to current staff.
• Risk of Data: Hosting data on third-party resources can lead to putting the data at risk, it has the
chance of getting attacked by any hacker or cracker very easily.
Characteristics of Virtualization
• Increased Security: The ability to control the execution of a guest program in a completely
transparent manner opens new possibilities for delivering a secure, controlled execution environment.
All the operations of the guest programs are generally performed against the virtual machine, which
then translates and applies them to the host programs.
• Managed Execution: In particular, sharing, aggregation, emulation, and isolation are the most
relevant features.
• Sharing: Virtualization allows the creation of a separate computing environment within the same
host.
Aggregation: It is possible to share physical resources among several guests, but virtualization also allows
aggregation, which is the opposite process.
LAYERS OF VIRTUALIZATION
The Instruction Set Architecture (ISA) level layer refers to the interface between software and hardware that
defines the set of instructions a processor can execute.
Types of ISAs:
1. CISC (Complex Instruction Set Computing): ISAs with complex instructions that can perform multiple
operations.
2. RISC (Reduced Instruction Set Computing): ISAs with simple instructions that can be combined to
perform complex operations.
How it works:
Hardware abstraction level virtualization involves abstracting the physical hardware resources of a system,
creating a virtualized environment that can run multiple operating systems or applications.
How it Works:
2. Virtual Machine Creation: Virtual machines are created on top of the hypervisor.
4. Virtual Machine Management: Virtual machines are managed using management tools.
Examples:
Operating system-level virtualization involves creating multiple virtual environments (containers) on a single
host operating system, each with its own isolated environment.
How it Works:
1. Container Creation: Containers are created on top of the host operating system.
Examples:
Library-level virtualization involves providing a compatibility layer for applications to run on a different
platform by emulating the required libraries and APIs.
How it Works:
1. Library Emulation: The library-level virtualization layer emulates the required libraries and APIs.
2. API Translation: The virtualization layer translates API calls from the application to the native platform
APIs.
3. Application Execution: The application runs on the non-native platform using the emulated libraries and
APIs.
Examples:
1. Wine: Runs Windows applications on Linux and macOS by emulating Windows APIs.
Application-level virtualization involves encapsulating an application and its dependencies into a single
package, allowing it to run on any platform without modification.
How it Works:
1. Application Packaging: The application and its dependencies are packaged into a single unit.
3. Application Execution: The packaged application is executed on the client device, using the virtualization
layer.
Examples:
2. Microsoft App-V: Virtualizes Windows applications, allowing them to run on any Windows device.
3. Citrix XenApp: Virtualizes Windows applications, allowing them to run on any device with a Citrix client.
Types of Virtualization
1. Application Virtualization
2. Network Virtualization
3. Desktop Virtualization
4. Storage Virtualization
5. Server Virtualization
6. Data virtualization
[Link] Virtualization: This lets you use an application on your local device while it’s actually hosted
on a remote server. Your personal data and the app’s settings are stored on the server, but you can still run it
locally via the internet. It’s useful if you need to work with multiple versions of the same software. Common
examples include hosted or packaged apps.
Components:
1. Physical Hardware: The underlying hardware that runs the virtualization infrastructure.
2. Operating System: The host operating system that manages the hardware resources.
4. Applications: The virtualized applications that run on top of the virtualization layer.
5. Presentation Layer: The layer that manages the user interface and presentation of the virtualized
applications.
6. Desktop: The user's desktop environment that accesses the virtualized applications.
Architecture Model:
1. Hardware Layer: The physical hardware that runs the virtualization infrastructure.
2. OS Layer: The host operating system that manages the hardware resources.
4. Application Layer: The virtualized applications that run on top of the virtualization layer.
5. Presentation Layer: The layer that manages the user interface and presentation of the virtualized
applications.
How it Works:
1. Application Virtualization: The virtualization layer captures the application's dependencies and
configurations.
3. Presentation Virtualization: The presentation layer manages the user interface and presentation of the
virtualized application.
2. Network Virtualization: This allows multiple virtual networks to run on the same physical network, each
operating independently. You can quickly set up virtual switches, routers, firewalls, and VPNs, making
network management more flexible and efficient.
3. Desktop Virtualization: With desktop virtualization, your operating system is stored on a server and can
be accessed from anywhere on any device. It’s great for users who need flexibility, as it simplifies software
updates and provides portability.
4. Storage Virtualization: This combines storage from different servers into a single system, making it
easier to manage. It ensures smooth performance and efficient operations even when the underlying hardware
changes or fails.
5. Server Virtualization: This splits a physical server into multiple virtual servers, each functioning
independently. It helps improve performance, cut costs and makes tasks like server migration and energy
management easier.
6. Data Virtualization: This brings data from different sources together in one place without needing to
know where or how it’s stored. It creates a unified view of the data, which can be accessed remotely via
cloud services. Companies like Oracle and IBM offer solutions for this.
Virtualization vs Containerization
Uses of Virtualization
• Disaster Recovery: Simplifies backup and recovery by easily restoring virtual machines.
• Testing Environments: Provides isolated virtual environments for development and testing.
• Security Isolation: Keeps applications secure by isolating them in separate virtual machines.
1. Understand the Shared Responsibility Model: Recognize the division of security responsibilities
between the provider and the customer for each service model.
2. Implement Strong Access Controls: Use multi-factor authentication (MFA) and the principle of
least privilege to limit access to sensitive data and resources.
3. Encrypt Data: Ensure data is encrypted both at rest and in transit to protect against unauthorized
access.
4. Regularly Update and Patch: Keep all software and systems updated to mitigate vulnerabilities.
5. Monitor and Audit: Continuously monitor for suspicious activities and conduct regular security
audits to identify and address potential risks.