Educause Security Discussion mailing list archives
Re: Quicklaunch SSO
From: "AJ (Westcliff)" <aj () WESTCLIFF EDU>
Date: Thu, 14 May 2020 12:32:57 -0400
John, Security: 4.9/5 stars (I never give anyone 5) QuickLaunch passed our 3rd party security audit & VPAT. Their AMFA+SSPR is strong with FTU (first time user) that is very useful for students to self-onboard. Customer Service: 4.9/5 stars (I never give anyone 5) We have a dedicated project manager for implementation that understands identity, higher ed use cases and higher ed apps Very responsive on support (so far average response times are sub 10min) I had posted this earlier on IDM listserv: * Has anyone had experience with QuickLaunch SSO? Yes. It is actually QuickLaunch.io after they added Integration/ESB/iPaaS to their stack. * Was it Good or bad? Good. The new v7 is very slick. It offers significantly more analytics and self-service capabilities. * If you implemented it, why it and not another solution? It met all of our requirements and then some. Other solutions we looked at (we look at approximately 8) did not meet all of our requirements (i.e. Duo) or were very expensive (i.e. Okta, Microsoft if you add E3 + P1 to compare apples to apples): Our Main Requirements: a. We wanted a solution that could federate our onsite and cloud apps including student information systems (Banner, AMP), collaboration (Gmail), learning management system (Moodle) so that students and faculty/staff could get secure access to the apps that they need. We selected QuickLaunch because it met all of our requirements: b. We wanted a solution that would support multiple protocols such as SAML 2.0, OAuth, WS- Federation, OpenID Connect, WS-Trust simultaneously so that we could federate current apps and handle future apps. We wanted a solution that would support multi-factor authentication to block malicious logins so that we did not have to purchase a standalone solution like CASDuo (that does not have full stack identity and access management functionality such as functionality to automate student/staff onboarding). c. We wanted a solution that would help reduce help desk service requests by enabling students and faculty/staff to reset their own passwords. (alot of our help desk requests are related to password reset). d. We wanted a solution that could help provision accounts from our student information system and hr system to various apps so we could more effectively onboard (and offboard) students and faculty/staff and get them the right apps, timely. e. We wanted a solution that supported passwordless. f. We wanted a solution that was easy to maintain and in the cloud. g. We wanted an affordable solution. (free or as close to free as possible!) * What estimate of man hours was required? Approximately 25hrs over 2 weeks from our network admin and enterprise apps team to configure our enterprise apps to federate against the QuickLaunch IDP. * What types of requirements did you gather prior to implementation and decision to use it? We spent approximately 6 months defining our requirements for identity and access management and doing proof-of-concepts prior to implementation and decision to use QuickLaunch. Happy to jump on a call. AJ Greene CIO Westcliff University From: The EDUCAUSE Security Community Group Listserv <SECURITY () LISTSERV EDUCAUSE EDU> On Behalf Of Rogers, John Sent: Thursday, May 14, 2020 12:02 PM To: SECURITY () LISTSERV EDUCAUSE EDU Subject: Re: [SECURITY] Quicklaunch SSO EXTERNAL: This email was sent to you from an external source. Please review the content carefully and open attachments or click links only if you recognize the sender. If you use DUO, they recently released a cloud SSO solution that comes natively secure with DUO. It is currently in open beta, but I am keeping an eye on it. It comes free with any license set. Thanks, John Rogers Lead IT Security Engineer Information Technology Department Oklahoma State University <mailto:John.Rogers () okstate edu> John.Rogers () okstate edu 405-744-2752 From: The EDUCAUSE Security Community Group Listserv <SECURITY () LISTSERV EDUCAUSE EDU <mailto:SECURITY () LISTSERV EDUCAUSE EDU> > On Behalf Of Blake Brown Sent: Thursday, May 14, 2020 10:57 AM To: SECURITY () LISTSERV EDUCAUSE EDU <mailto:SECURITY () LISTSERV EDUCAUSE EDU> Subject: [SECURITY] Quicklaunch SSO CAUTION: This email originated from outside of the organization. Do not click links or open attachments unless you recognize the sender and know the content is safe Does anyone here currently use cloud-based Quicklaunch for SSO and if so can you provide feedback on their system, security and customer service? We are currently using ADFS but considering this as an alternative option for SSO functionality. quicklaunch[.]io Thanks, Blake Brown Infrastructure Manager ********** Replies to EDUCAUSE Community Group emails are sent to the entire community list. If you want to reply only to the person who sent the message, copy and paste their email address and forward the email reply. Additional participation and subscription information can be found at https://www.educause.edu/community <https://nam04.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.educa use.edu%2Fcommunity&data=02%7C01%7Cjohn.rogers%40okstate.edu%7C11797d954b8c4 95f8fd208d7f81f72d7%7C2a69c91de8494e34a230cdf8b27e1964%7C0%7C1%7C63725068626 8247292&sdata=hGcrmFwl%2FI4K2nO%2Fl3B%2BtT4HPrOpnZj2Uq9yDGiUV7w%3D&reserved= 0> ********** Replies to EDUCAUSE Community Group emails are sent to the entire community list. If you want to reply only to the person who sent the message, copy and paste their email address and forward the email reply. Additional participation and subscription information can be found at https://www.educause.edu/community ********** Replies to EDUCAUSE Community Group emails are sent to the entire community list. If you want to reply only to the person who sent the message, copy and paste their email address and forward the email reply. Additional participation and subscription information can be found at https://www.educause.edu/community
Current thread:
- Quicklaunch SSO Blake Brown (May 14)
- Re: Quicklaunch SSO Rogers, John (May 14)
- Re: Quicklaunch SSO Blake Brown (May 14)
- Re: Quicklaunch SSO AJ (Westcliff) (May 14)
- <Possible follow-ups>
- Re: Quicklaunch SSO Keenan Martinez (May 14)
- Re: Quicklaunch SSO Blake Brown (May 14)
- Re: Quicklaunch SSO Rogers, John (May 14)