English   Deutsch

Sebastian Rohr: Virtual (Desktop) Identities

Virtual (Desktop) Identities
by Sebastian Rohr
sr@kuppingercole.com

While most large vendors like VMware, Microsoft and Citrix are eager to round-up their offerings with tools around deployment management, load balancing and session brokerage up to live-streaming of virtualized applications into the also virtualized Desktops, the access to, usage and separation of resources sometimes is not really that well thought through. As an example, it scared the hell out of me, that "security" as kill-all term was highlighted as the differentiator between the "Professional" and "Platinum" varieties of one vendor. Say, what?

How long have we personally, how long has the community preached, that "security" needs to be integrated right from start, should be basic and mandatory and not an additional feature which you have to pay a premium for? Despite the fact that this may in detail refer to features one will only reap benefits from when deploying a massive enterprise-scale solution, the decision of using and deploying the necessary security barriers and segregations should remain with the customer and should not be "suppressed" by licensing schemes.

One thing that really gave me the shivers though, was the idea of an identity management within the virtualization technology: if you strip the OS from the machine, then strip the user-profile from the OS and finally strip the applications from this to mix & mash them all together during run-time, one does not only have to take care of the traditional "who has access to what" question but also make sure that the "on-the-fly" provisioning of the applications to the virtual desks and the access rights within those can be managed properly. While I am totally PRO desktop virtualization regarding software management, efficiency and especially regarding updates ad patches, I yet did not find a virtualization engineer who could explain to me in detail how this whole monster is handled identity-wise...

Created: 14.01.10, modified: 14.01.10

Information
Newsletter
Kuppinger Cole Identity Management Newsletter
Services
KCP provides strategic consulting services for vendor and user companies covering all areas of identity & access management.
Reports
Use KCP as an independent, objective, and neutral authority on the Market for Identity Management products and solutions
Podcasts
Free audio and video presentations on important IAM-topics
Current surveys
IAM-Studie 2010
PARTICIPATE 
Virtualization Security Trends & Insights
PARTICIPATE 
Blogs
Tim Cole
28.08.2010 11:53
Not Just Any Port in a Storm
READ 
European Identity Conference Blog
27.08.2010 04:45
Google authentication support
READ 
Martin Kuppinger
12.08.2010 11:34
Diving down to the details of access controls
READ 
Sachar Paulus
11.08.2010 10:05
The GRC Marketplace is shaking up: SAP and CA partnering on GRC
READ 
Sebastian Rohr
04.08.2010 20:18
Your token to VISA…
READ 
Felix Gaehtgens
19.02.2010 17:40
Gerry Gebel joins Axiomatics
READ 
Joerg Resch
17.02.2010 11:15
Identity Management is key to Smart Grid Security
READ 
Links
 Kuppinger Cole News

 Kuppinger Cole Podcasts

 Kuppinger Cole on Facebook

 Kuppinger Cole on Twitter

 Visit us at Xing

 IAM-Wiki

 GenericIAM
Imprint Terms and conditions Privacy policy
© 2003-2010 Kuppinger Cole