Like

Welcome On Mobius

Mobius was created by professionnal coders and passionate people.

We made all the best only for you, to enjoy great features and design quality. Mobius was build in order to reach a pixel perfect layout.

Mobius includes exclusive features such as the Themeone Slider, Themeone Shorcode Generator and Mobius Grid Generator.

Our Skills

WordPress90%
Design/Graphics75%
HTML/CSS/jQuery100%
Support/Updates80%

A simple evaluation of SharePoint Authentication Options

By Irfan Bashir 5 years ago

SharePoint has always kept authentication an external subject and SharePoint 2013 is no different. By keeping authentication external and allowing a pluggable interface, SharePoint is able to support a variety of different IC423802authentication methods and providers for the following types of authentications:

  • Forms based authentication
  • Claims  (SAML) based authentication
  • Windows authentication

There are quite a lot of very informative articles explaining the technical details like the following technet article is an excellent technical source to start planning authentication methods in SharePoint 2013.

http://technet.microsoft.com/en-us/library/cc262350(v=office.15).aspx

This one explains in sufficient technical detail some of the important concepts behind Claims authentication.

http://www.sharepointsecurity.com/sharepoint/sharepoint-security/supported-authentication-types-methods-in-sharepoint-2013/

But what really prompted me to write this post was a recent interaction with a client who wanted to configure Windows Live authentication on their SharePoint 2013  farm for their external users. He wanted to know the different approaches which SharePoint provides to make this scenario possible. I gave him a simple technical answer that there are two possible approaches they can follow:

  1. Configure Windows Live Id as a federated authentication provider
    1. http://technet.microsoft.com/en-us/library/ff973117%28v=office.14%29.aspx
    2. http://blogs.msdn.com/b/hsalvi/archive/2010/09/01/configuring-windows-live-id-authentication-provider-as-federated-identity-provider-for-sharepoint-2010.aspx
  2. Configure Forms based authentication and authenticate against Windows Live ID using a Membership provider

Interestingly, the discussion turned into a very simple question. What is the end user experience like ? Will the users be redirected to Window Live authentication screen or will they be entering their user credentials on a custom SharePoint form. Configuring Option 1 will redirect end users to Windows Live authentication screen and get them back as authenticated users in SharePoint. Configuring Option 2 will make the users enter their user credentials on a custom SharePoint login form where their credentials are exposed to the partner SharePoint site they are logging in.

So what started off as a fairly technical discussion in which we were evaluating different criteria like

  • the complexity of the solution (Option 1: Understanding Claims authentication and Federation etc)
  • time to implement (Option 2: It can take more time to fine tune your membership provider)

ended up being a fairly simple conclusion based on what kind of user experience the customer will like to have and then evaluate the different authentication options available.

Category:
  Sharepoint
this post was shared 0 times
 000
About

 Irfan Bashir

  (7 articles)

Irfan is a partner at Allied Consultants. He has over a decade of experience in the US and offshore consulting space provide him a rich perspective on Sharepoint, Yammer and related disciplines. He has worked at several organizations in the past including Microsoft Consulting