English   Deutsch

Sebastian Rohr: Virtual (Desktop) Identities

Virtual (Desktop) Identities
by Sebastian Rohr
sr@kuppingercole.com

While most large vendors like VMware, Microsoft and Citrix are eager to round-up their offerings with tools around deployment management, load balancing and session brokerage up to live-streaming of virtualized applications into the also virtualized Desktops, the access to, usage and separation of resources sometimes is not really that well thought through. As an example, it scared the hell out of me, that "security" as kill-all term was highlighted as the differentiator between the "Professional" and "Platinum" varieties of one vendor. Say, what?

How long have we personally, how long has the community preached, that "security" needs to be integrated right from start, should be basic and mandatory and not an additional feature which you have to pay a premium for? Despite the fact that this may in detail refer to features one will only reap benefits from when deploying a massive enterprise-scale solution, the decision of using and deploying the necessary security barriers and segregations should remain with the customer and should not be "suppressed" by licensing schemes.

One thing that really gave me the shivers though, was the idea of an identity management within the virtualization technology: if you strip the OS from the machine, then strip the user-profile from the OS and finally strip the applications from this to mix & mash them all together during run-time, one does not only have to take care of the traditional "who has access to what" question but also make sure that the "on-the-fly" provisioning of the applications to the virtual desks and the access rights within those can be managed properly. While I am totally PRO desktop virtualization regarding software management, efficiency and especially regarding updates ad patches, I yet did not find a virtualization engineer who could explain to me in detail how this whole monster is handled identity-wise...

Created: 14.01.10, modified: 14.01.10

Information
Newsletter
Kuppinger Cole Identity Management Newsletter
Services
KCP provides strategic consulting services for vendor and user companies covering all areas of identity & access management.
Reports
Use KCP as an independent, objective, and neutral authority on the Market for Identity Management products and solutions
Podcasts
Free audio and video presentations on important IAM-topics
Current surveys
Marktstudie IT Service Management
PARTICIPATE 
Blogs
Martin Kuppinger
11.03.2010 11:57
Versatile authentication – break-through for mass adoption of strong authentication?
READ 
Tim Cole
09.03.2010 08:25
The business of business is trust
READ 
Sebastian Rohr
24.02.2010 19:23
Ever had trouble securely sharing data with business partners?
READ 
Felix Gaehtgens
19.02.2010 17:40
Gerry Gebel joins Axiomatics
READ 
Joerg Resch
17.02.2010 11:15
Identity Management is key to Smart Grid Security
READ 
European Identity Conference Blog
12.02.2010 13:16
EIC 2010 Agenda Preview
READ 
Links
 Kuppinger Cole News

 Kuppinger Cole Podcasts

 Kuppinger Cole on Facebook

 Kuppinger Cole on Twitter

 Visit us at Xing

 IAM-Wiki

 GenericIAM
Imprint Terms and conditions Privacy policy
© 2003-2010 Kuppinger Cole + Partner