Invention Grant
- Patent Title: Secure resource authorization for external identities using remote principal objects
-
Application No.: US17536816Application Date: 2021-11-29
-
Publication No.: US11552956B2Publication Date: 2023-01-10
- Inventor: Charles Prakash Rao Dasari , Maksym Yaryn , Debashis Choudhury , Jeffrey A. Staiman
- Applicant: Microsoft Technology Licensing, LLC
- Applicant Address: US WA Redmond
- Assignee: Microsoft Technology Licensing, LLC
- Current Assignee: Microsoft Technology Licensing, LLC
- Current Assignee Address: US WA Redmond
- Agency: Fiala & Weaver P.L.L.C.
- Main IPC: H04L29/06
- IPC: H04L29/06 ; G06F21/62 ; H04L9/40 ; H04L67/1097 ; H04L41/0686

Abstract:
Methods of secure resource authorization for external identities using remote principal objects are performed by systems and devices. An external entity creates a user group and defines entitlements to an owning entity's secure resource as a set of permissions for the group. An immutable access template with the permissions and an access policy for the secure resource are provided to the owning entity for approval. On approval, a remote principal object is created in the owner directory according to the permissions and access policy. A remote principal that is a group member requests access via an interface to the owner domain using external domain credentials. The identity of the remote principal is verified against the remote principal object by a token service. Verification causes generation and issuance of a token, with the enumerated entitlements, to the remote principal interface affecting a redirect for access to the secure resource.
Public/Granted literature
- US20220086165A1 SECURE RESOURCE AUTHORIZATION FOR EXTERNAL IDENTITIES USING REMOTE PRINCIPAL OBJECTS Public/Granted day:2022-03-17
Information query