<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Bobel&#039;s Active Directory, Identity, Access &#38; SaaS Blog &#187; Bob Bobel</title>
	<atom:link href="http://www.bobbobel.com/author/rbobel/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.bobbobel.com</link>
	<description>&#34;Anyone can hold the helm when the sea is calm.&#34; - Syrus Publilius</description>
	<lastBuildDate>Thu, 02 Sep 2010 12:07:45 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
		<item>
		<title>Automatically Provisoning and Deprovison Postini</title>
		<link>http://www.bobbobel.com/automatically-provisoning-and-deprovison-postini/</link>
		<comments>http://www.bobbobel.com/automatically-provisoning-and-deprovison-postini/#comments</comments>
		<pubDate>Thu, 02 Sep 2010 12:07:45 +0000</pubDate>
		<dc:creator>Bob Bobel</dc:creator>
				<category><![CDATA[Active Directory]]></category>

		<guid isPermaLink="false">http://www.bobbobel.com/?p=948</guid>
		<description><![CDATA[Today our team uploaded an Policy Extension to the ActiveRoles community for Postini!  This policy will both provision and deprovision Postini gateway accounts when the associated Active Directory account is updated. To use this policy you simply download the policy, install it in ActiveRoles Server then configure the policy with your Postini account details. The new policy is free [...]]]></description>
			<content:encoded><![CDATA[<p>Today our team uploaded an <a href="http://wiki.activeroles.inside.quest.com/index.php/Category:Policy_Extension" target="_blank">Policy Extension</a> to the ActiveRoles community for Postini!  This policy will both provision and deprovision Postini gateway accounts when the associated Active Directory account is updated. To use this policy you simply download the policy, install it in ActiveRoles Server then configure the policy with your Postini account details. The new policy is free for ActiveRoles customers and you can download the the new policy here: <a href="http://wiki.activeroles.inside.quest.com/index.php/Postini_Services_provisioning_for_ActiveRoles_Server" target="_blank">DOWNLOAD NOW</a></p>
<div id="attachment_950" class="wp-caption aligncenter" style="width: 310px"><a href="http://www.bobbobel.com/wp-content/uploads/2010/09/PostiniServiceProvisioningForARS1.jpg"><img class="size-medium wp-image-950" title="PostiniServiceProvisioningForARS" src="http://www.bobbobel.com/wp-content/uploads/2010/09/PostiniServiceProvisioningForARS1-300x210.jpg" alt="ARS Postini Policy" width="300" height="210" /></a><p class="wp-caption-text">ActiveRoles Change History showing Postini Provsioning</p></div>
<p align="left"><a class="tt" href="http://twitter.com/home/?status=Automatically+Provisoning+and+Deprovison+Postini+http://gnfkb.th8.us" title="Post to Twitter"><img class="nothumb" src="http://www.bobbobel.com/wp-content/plugins/tweet-this/icons/tt-twitter-big4.png" alt="Post to Twitter" /></a></p>]]></content:encoded>
			<wfw:commentRss>http://www.bobbobel.com/automatically-provisoning-and-deprovison-postini/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Visual Studio Lightswitch</title>
		<link>http://www.bobbobel.com/visual-studio-lightswitch/</link>
		<comments>http://www.bobbobel.com/visual-studio-lightswitch/#comments</comments>
		<pubDate>Thu, 05 Aug 2010 17:50:29 +0000</pubDate>
		<dc:creator>Bob Bobel</dc:creator>
				<category><![CDATA[Active Directory]]></category>

		<guid isPermaLink="false">http://www.bobbobel.com/?p=945</guid>
		<description><![CDATA[This has been needed for the past 20 years and now Microsoft has finally stepped up to the plate and will cover the gap between tech savy business users and developers. I can not tell you how many Access Databases, Monster Excel Spreadsheets and Microsoft Word Macro&#8217;s I&#8217;ve seen/written/replaced over the past 25 years but [...]]]></description>
			<content:encoded><![CDATA[<p>This has been needed for the past 20 years and now Microsoft has finally stepped up to the plate and will cover the gap between tech savy business users and developers. I can not tell you how many Access Databases, Monster Excel Spreadsheets and Microsoft Word Macro&#8217;s I&#8217;ve seen/written/replaced over the past 25 years but it is in the hundreds. Most of these were started for the right reasons, even though Microsoft office probably wasn&#8217;t the best platform. The challenge is simple to articulate &#8211; I&#8217;m a business user, I don&#8217;t have a staff of developers, I know enough to be dangerous and I want to keep my paycheck. Microsoft Access was pretty close &#8211; but it couldn&#8217;t make the leap and required some pretty specific knowledge.</p>
<p>Microsoft announced Visual Studio Lightswitch at the VS Live conference &#8211; a solution designed to bridge that gap. The application is a part of Microsoft Development Platform Visual Studio and promises to allow the savvy business user to build apps for desktops or cloud delivery by pulling data from Databases, SharePoint as well as integrate with Microsoft&#8217;s Cloud solution; Azure. It seems obvious that since this is part of Visual Studio when the app gets too big for the business user, I&#8217;m guessing (and I hope it does this) the app can be put into the hands of a experienced developer. This will probably drive the developer&#8217;s crazy, but it certainly will be fun to watch.</p>
<p align="left"><a class="tt" href="http://twitter.com/home/?status=Visual+Studio+Lightswitch+http://b6w45.th8.us" title="Post to Twitter"><img class="nothumb" src="http://www.bobbobel.com/wp-content/plugins/tweet-this/icons/tt-twitter-big4.png" alt="Post to Twitter" /></a></p>]]></content:encoded>
			<wfw:commentRss>http://www.bobbobel.com/visual-studio-lightswitch/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>PING Identity&#8217;s Cloud Identity Conference</title>
		<link>http://www.bobbobel.com/ping-identity-cloud-idm-conference/</link>
		<comments>http://www.bobbobel.com/ping-identity-cloud-idm-conference/#comments</comments>
		<pubDate>Tue, 20 Jul 2010 20:03:59 +0000</pubDate>
		<dc:creator>Bob Bobel</dc:creator>
				<category><![CDATA[Active Directory]]></category>
		<category><![CDATA[ADFS]]></category>
		<category><![CDATA[Federation]]></category>
		<category><![CDATA[Just-in-time provisioning]]></category>
		<category><![CDATA[SAAS]]></category>
		<category><![CDATA[SAML]]></category>
		<category><![CDATA[SSO]]></category>

		<guid isPermaLink="false">http://www.bobbobel.com/?p=936</guid>
		<description><![CDATA[I&#8217;ve had the good fortune to find myself at the Ping Identity Cloud Identity Conference. The conference, as the name inplies, is dedicated to dealing with Identity in a SaaS world and all the interesting challenges that happen when identity traverses or is moved into the Internet. Today I&#8217;m sitting through one of Ping&#8217;s Experts [...]]]></description>
			<content:encoded><![CDATA[<p>I&#8217;ve had the good fortune to find myself at the <a href="http://www.cloudidentitysummit.com/" target="_blank">Ping Identity Cloud Identity </a>Conference. The conference, as the name inplies, is dedicated to dealing with Identity in a SaaS world and all the interesting challenges that happen when identity traverses or is moved into the Internet.</p>
<p>Today I&#8217;m sitting through one of Ping&#8217;s Experts (Ian Barnett) who is going through how organizations can implement SAML for a host of reasons. One interesting conversation that came up was around the differences between SAML and OpenID and how their origins put them on a similar path but for different reasons.</p>
<p>A similar discusssion arose around Microsof&#8217;t's ADFS 2.0 and SAML 2.0 and there was certainly more than a little confusion about how the two do or do not interoperate effectivly.</p>
<p align="left"><a class="tt" href="http://twitter.com/home/?status=PING+Identity%E2%80%99s+Cloud+Identity+Conference+http://wzks8.th8.us" title="Post to Twitter"><img class="nothumb" src="http://www.bobbobel.com/wp-content/plugins/tweet-this/icons/tt-twitter-big4.png" alt="Post to Twitter" /></a></p>]]></content:encoded>
			<wfw:commentRss>http://www.bobbobel.com/ping-identity-cloud-idm-conference/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Apple Bumper &#8211; they are kidding right?</title>
		<link>http://www.bobbobel.com/apple-bumper-they-are-kidding-right/</link>
		<comments>http://www.bobbobel.com/apple-bumper-they-are-kidding-right/#comments</comments>
		<pubDate>Fri, 16 Jul 2010 22:39:55 +0000</pubDate>
		<dc:creator>Bob Bobel</dc:creator>
				<category><![CDATA[Active Directory]]></category>
		<category><![CDATA[apple bumper]]></category>
		<category><![CDATA[Droid]]></category>
		<category><![CDATA[HTC Incredible]]></category>
		<category><![CDATA[mobile]]></category>

		<guid isPermaLink="false">http://www.bobbobel.com/?p=934</guid>
		<description><![CDATA[I like the apple touch phones, but a bumper is stupid &#8211; just fix the problem.  I&#8217;m glad I&#8217;m now a HTC droid man. http://www.cnn.com/2010/TECH/mobile/07/16/consumer.reports.iphone.case/index.html?eref=igoogle_cnn]]></description>
			<content:encoded><![CDATA[<p>I like the apple touch phones, but a bumper is stupid &#8211; just fix the problem.</p>
<p> I&#8217;m glad I&#8217;m now a HTC droid man.</p>
<p><a href="http://www.cnn.com/2010/TECH/mobile/07/16/consumer.reports.iphone.case/index.html?eref=igoogle_cnn">http://www.cnn.com/2010/TECH/mobile/07/16/consumer.reports.iphone.case/index.html?eref=igoogle_cnn</a></p>
<p align="left"><a class="tt" href="http://twitter.com/home/?status=Apple+Bumper+%E2%80%93+they+are+kidding+right%3F+http://7xhqg.th8.us" title="Post to Twitter"><img class="nothumb" src="http://www.bobbobel.com/wp-content/plugins/tweet-this/icons/tt-twitter-big4.png" alt="Post to Twitter" /></a></p>]]></content:encoded>
			<wfw:commentRss>http://www.bobbobel.com/apple-bumper-they-are-kidding-right/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Use PowerShell to easly find Obsolete Accounts</title>
		<link>http://www.bobbobel.com/use-powershell-to-easly-find-obsolete-accounts/</link>
		<comments>http://www.bobbobel.com/use-powershell-to-easly-find-obsolete-accounts/#comments</comments>
		<pubDate>Thu, 15 Jul 2010 15:14:21 +0000</pubDate>
		<dc:creator>Bob Bobel</dc:creator>
				<category><![CDATA[Active Directory]]></category>
		<category><![CDATA[Compliance Controls]]></category>
		<category><![CDATA[Compliance Review]]></category>
		<category><![CDATA[obsolete accounts]]></category>
		<category><![CDATA[PoSH]]></category>
		<category><![CDATA[PowerShell AD CMDLETS]]></category>
		<category><![CDATA[Remediation of Old Accounts]]></category>

		<guid isPermaLink="false">http://www.bobbobel.com/?p=930</guid>
		<description><![CDATA[One of the great new capabilities new to ActiveRoles AD CMDLETS version 1.4 is the ability to define criteria for how you want to identify obsolete or inactive accounts. You define the criteria as an &#8220;InactiveAccountsPolicy&#8221; that can be called from the Get-QADUser cmdlet to list accounts matching the obsolete policy then delete, disable or if [...]]]></description>
			<content:encoded><![CDATA[<p><span style="color: #333333;">One of the great new capabilities new to ActiveRoles AD CMDLETS version 1.4 is the ability to define criteria for how you want to identify obsolete or inactive accounts. You define the criteria as an &#8220;InactiveAccountsPolicy&#8221; that can be called from the Get-QADUser cmdlet to list accounts matching the obsolete policy then delete, disable or if you own ActiveRoles Server execute the Deprovisoning policy.</span></p>
<p><span style="color: #333333;"> </span></p>
<p><strong><strong><span style="font-size: large;">Set-QADInactiveAccountsPolicy</span></strong></strong></p>
<p><strong><span style="color: #333333;"> </span><span style="font-size: xx-small;"><span style="font-size: xx-small;"><span style="color: #333333;">Set the current user preference on what accounts to consider inactive by default.</span></p>
<p></span></span></strong><strong><span style="color: #800000;">Syntax</span></p>
<p><span style="font-size: xx-small;"><span style="color: #333333;">Set-QADInactiveAccountsPolicy [-AccountExpiredPeriod &lt;Int32&gt;] [-PasswordNotChangedPeriod &lt;Int32&gt;] [-AccountNotLoggedOnPeriod &lt;Int32&gt;]</p>
<p></span></span><strong><span style="color: #800000;">Parameters</span></p>
<p><span style="font-size: x-small;"><span style="color: #333333;">AccountExpiredPeriod</p>
<p></span></span><span style="font-size: xx-small;"><span style="color: #333333;">Use this parameter to specify the number of days after which an expired account is considered inactive by default. Thus, an account is considered inactive if the account remains in the expired state for more days than specified by this parameter.</p>
<p></span></span><strong><span style="font-size: x-small;"><span style="color: #333333;">AccountNotLoggedOnPeriod</p>
<p></span></span><span style="font-size: xx-small;"><span style="color: #333333;">Use this parameter to specify the period, in days, that an account is not used to log on, after which the account is considered inactive by default. Thus, an account is considered inactive if no successful logons to that account occur for more days than specified by this parameter.</p>
<p></span></span><strong><span style="font-size: x-small;"><span style="color: #333333;">PasswordNotChangedPeriod</p>
<p></span></span><span style="font-size: xx-small;"><span style="color: #333333;">Use this parameter to specify the password age, in days, after which an account is considered inactive by default. Thus, an account is considered inactive if the password of the account remains unchanged for more days than specified by this parameter.</p>
<p></span></span><strong><span style="color: #333333;">Detailed Description</span></p>
<p><span style="font-size: xx-small;"><span style="color: #333333;">Use this cmdlet to specify the default conditions that must be met for a user or computer account to be considered inactive. The inactivity conditions are specific to the current user, and have an effect on the cmdlets that support the Inactive parameter (such as Get-QADUser or Get-QADComputer). If no account-inactivity related parameters other than Inactive are supplied, then the Inactive parameter retrieves the accounts that meet the conditions defined by this cmdlet. To view the inactivity conditions that are currently in effect, use the Get-QADInactiveAccountsPolicy cmdlet.</p>
<p></span></span><strong><span style="color: #333333;"> </span></p>
<p><strong><strong><span style="font-size: large;"><span style="color: #333333;">Get-QADInactiveAccountsPolicy</span></span><span style="font-size: xx-small;"><span style="font-size: xx-small;"><span style="color: #333333;">View the current user preference on what accounts to consider inactive by default.</span></p>
<p></span></span></strong></strong><span style="color: #333333;"> </span></p>
<p><strong><span style="color: #800000;">Syntax</span></p>
<p><span style="font-size: xx-small;"><span style="color: #333333;">Get-QADInactiveAccountsPolicy</p>
<p></span></span><strong><span style="color: #333333;">Detailed Description</span></p>
<p><span style="font-size: xx-small;"><span style="font-size: xx-small;"><span style="color: #333333;">Use this cmdlet to examine the settings that were specified by using Set-QADInactiveAccountsPolicy, and are in effect for the current user session. These settings specify the default conditions that must be met for a user or computer account to be considered inactive. The inactivity conditions are specific to the current user, and have an effect on the cmdlets that support the Inactive parameter (such as Get-QADUser or Get-QADComputer). If no account-inactivity related parameters other than Inactive are supplied, then the Inactive parameter retrieves the accounts that meet the conditions defined by the AccountExpiredPeriod, AccountNotLoggedOnPeriod, and PasswordNotChangedPeriod settings that you can examine using this cmdlet. For details regarding each of these settings, see the corresponding parameter description for the Set-QADInactiveAccountsPolicy cmdlet.</span></p>
<p><span style="color: #333333;"> </span></p>
<p><span style="color: #333333;"> </span></p>
<p></span></span></strong></strong></strong></strong></strong></strong></strong></strong><span style="color: #333333;"> </span></p>
<p><span style="color: #333333;"> </span></p>
<p><span style="color: #333333;">Set-QADInactiveAccountsPolicy</span></p>
<p align="left"><a class="tt" href="http://twitter.com/home/?status=Use+PowerShell+to+easly+find+Obsolete+Accounts+http://gp4sf.th8.us" title="Post to Twitter"><img class="nothumb" src="http://www.bobbobel.com/wp-content/plugins/tweet-this/icons/tt-twitter-big4.png" alt="Post to Twitter" /></a></p>]]></content:encoded>
			<wfw:commentRss>http://www.bobbobel.com/use-powershell-to-easly-find-obsolete-accounts/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>AD CMDLETS 1.4 now live!</title>
		<link>http://www.bobbobel.com/ad-cmdlets-1-4-now-live/</link>
		<comments>http://www.bobbobel.com/ad-cmdlets-1-4-now-live/#comments</comments>
		<pubDate>Thu, 15 Jul 2010 14:07:16 +0000</pubDate>
		<dc:creator>Bob Bobel</dc:creator>
				<category><![CDATA[Active Directory]]></category>
		<category><![CDATA[Active Directory Tools]]></category>
		<category><![CDATA[ActiveRoles Server]]></category>
		<category><![CDATA[AD Help]]></category>
		<category><![CDATA[AD Tools]]></category>
		<category><![CDATA[Bobel]]></category>
		<category><![CDATA[Finding Inactive Accounts]]></category>
		<category><![CDATA[Help with Active Directory]]></category>
		<category><![CDATA[PowerShell AD CMDLETS]]></category>
		<category><![CDATA[PowerShell C]]></category>
		<category><![CDATA[PowerShell Obsolete Accounts]]></category>

		<guid isPermaLink="false">http://www.bobbobel.com/?p=928</guid>
		<description><![CDATA[The 1.4 version of the ActiveRoles AD CMDLETS went live a few moments ago and you can download them here http://www.quest.com/powershell/activeroles-server.aspx.]]></description>
			<content:encoded><![CDATA[<p>The 1.4 version of the ActiveRoles AD CMDLETS went live a few moments ago and you can download them here <a href="http://www.quest.com/powershell/activeroles-server.aspx">http://www.quest.com/powershell/activeroles-server.aspx</a>.</p>
<p align="left"><a class="tt" href="http://twitter.com/home/?status=AD+CMDLETS+1.4+now+live%21+http://hmqsg.th8.us" title="Post to Twitter"><img class="nothumb" src="http://www.bobbobel.com/wp-content/plugins/tweet-this/icons/tt-twitter-big4.png" alt="Post to Twitter" /></a></p>]]></content:encoded>
			<wfw:commentRss>http://www.bobbobel.com/ad-cmdlets-1-4-now-live/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Microsoft KIN &#8211; RIP</title>
		<link>http://www.bobbobel.com/microsoft-kin-rip/</link>
		<comments>http://www.bobbobel.com/microsoft-kin-rip/#comments</comments>
		<pubDate>Thu, 01 Jul 2010 19:16:27 +0000</pubDate>
		<dc:creator>Bob Bobel</dc:creator>
				<category><![CDATA[Active Directory]]></category>
		<category><![CDATA[Microsoft KIN Death]]></category>
		<category><![CDATA[Microsoft Mobile]]></category>

		<guid isPermaLink="false">http://www.bobbobel.com/?p=926</guid>
		<description><![CDATA[I was surprised to read on Engadget that Microsoft killed its entire KIN phone line, less than two months after launch. To me this is scary that a company like Microsoft has struggled to figure out the mobile market despite having Apple and Google showing them how it should be done. Well, Kin is now [...]]]></description>
			<content:encoded><![CDATA[<p>I was surprised to read on Engadget that Microsoft killed its entire KIN phone line, less than two months after launch. To me this is scary that a company like Microsoft has struggled to figure out the mobile market despite having Apple and Google showing them how it should be done. Well, Kin is now in a far better place with Microsoft BOB and Microsoft Clipit &#8211; may they all rest in peace.</p>
<p>http://www.engadget.com/2010/06/30/what-killed-the-kin/</p>
<p align="left"><a class="tt" href="http://twitter.com/home/?status=Microsoft+KIN+%E2%80%93+RIP+http://fekza.th8.us" title="Post to Twitter"><img class="nothumb" src="http://www.bobbobel.com/wp-content/plugins/tweet-this/icons/tt-twitter-big4.png" alt="Post to Twitter" /></a></p>]]></content:encoded>
			<wfw:commentRss>http://www.bobbobel.com/microsoft-kin-rip/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>ActiveRoles User&#8217;s Groups Denmark &amp; Sweeden</title>
		<link>http://www.bobbobel.com/activeroles-users-groups-denmark-sweeden/</link>
		<comments>http://www.bobbobel.com/activeroles-users-groups-denmark-sweeden/#comments</comments>
		<pubDate>Thu, 01 Jul 2010 14:23:56 +0000</pubDate>
		<dc:creator>Bob Bobel</dc:creator>
				<category><![CDATA[Active Directory]]></category>
		<category><![CDATA[Active Directory Help]]></category>
		<category><![CDATA[ActiveRoles EMEA]]></category>
		<category><![CDATA[ActiveRoles User Group]]></category>
		<category><![CDATA[IDM]]></category>

		<guid isPermaLink="false">http://www.bobbobel.com/?p=921</guid>
		<description><![CDATA[Following up on our UG in Boston, Berlin, Toronto and Los Angeles, last week I had the tremendous opportunity to help our regional offices in Copenhagen Denmark and Stockholm Sweden hold their first ActiveRoles User&#8217;s Groups. Both events were held in the Quest regional offices and were well attended by both existing customers and those [...]]]></description>
			<content:encoded><![CDATA[<p>Following up on our UG in Boston, Berlin, Toronto and Los Angeles, last week I had the tremendous opportunity to help our regional offices in Copenhagen Denmark and Stockholm Sweden hold their first ActiveRoles User&#8217;s Groups. Both events were held in the Quest regional offices and were well attended by both existing customers and those new to ActiveRoles. I look forward to next year&#8217;s events! I need to make a special thank you to Christian Dinesen for being the moderator of the User&#8217;s groups as well as my official tour guide in the evening. There was a royal wedding taking place the day after I left Stockholm, but I did get to see some of the wedding entertainers practicing their acrobatics. I recorded the following video with my Droid Incredible.</p>
<p align="left"><a class="tt" href="http://twitter.com/home/?status=ActiveRoles+User%E2%80%99s+Groups+Denmark+%26+Sweeden+http://fcx25.th8.us" title="Post to Twitter"><img class="nothumb" src="http://www.bobbobel.com/wp-content/plugins/tweet-this/icons/tt-twitter-big4.png" alt="Post to Twitter" /></a></p>]]></content:encoded>
			<wfw:commentRss>http://www.bobbobel.com/activeroles-users-groups-denmark-sweeden/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Google Apps goes mutli-domain</title>
		<link>http://www.bobbobel.com/google-apps-goes-mutli-domain/</link>
		<comments>http://www.bobbobel.com/google-apps-goes-mutli-domain/#comments</comments>
		<pubDate>Wed, 23 Jun 2010 18:13:12 +0000</pubDate>
		<dc:creator>Bob Bobel</dc:creator>
				<category><![CDATA[Active Directory]]></category>
		<category><![CDATA[Cloud]]></category>
		<category><![CDATA[Google Apps]]></category>
		<category><![CDATA[Mutli-domain]]></category>
		<category><![CDATA[Provison Google Apps]]></category>
		<category><![CDATA[SAAS management]]></category>

		<guid isPermaLink="false">http://www.bobbobel.com/?p=919</guid>
		<description><![CDATA[Google Apps was limited in that it didn&#8217;t support multiple domains so admins had to do all sorts of workarounds to accommodate this scenario. By adding support for users from different domains with different name spaces that share a common instance of Google Apps. (See the picture from the Google Blog below) Google Apps Blog]]></description>
			<content:encoded><![CDATA[<p>Google Apps was limited in that it didn&#8217;t support multiple domains so admins had to do all sorts of workarounds to accommodate this scenario. By adding support for users from different domains with different name spaces that share a common instance of Google Apps. (See the picture from the Google Blog below)</p>
<p><a href="http://2.bp.blogspot.com/_JPTTyK3AMOQ/TCFx1eIJXmI/AAAAAAAAAJQ/SB-QTcN-mDk/s1600/Picture+9.png"><img id="BLOGGER_PHOTO_ID_5485790984548212322" src="http://2.bp.blogspot.com/_JPTTyK3AMOQ/TCFx1eIJXmI/AAAAAAAAAJQ/SB-QTcN-mDk/Picture+9.png" border="0" alt="" width="487" height="475" /></a></p>
<p><a href="http://googleenterprise.blogspot.com/2010/06/introducing-multi-domain-support-in.html" target="_blank">Google Apps Blog</a></p>
<p align="left"><a class="tt" href="http://twitter.com/home/?status=Google+Apps+goes+mutli-domain+http://a3eez.th8.us" title="Post to Twitter"><img class="nothumb" src="http://www.bobbobel.com/wp-content/plugins/tweet-this/icons/tt-twitter-big4.png" alt="Post to Twitter" /></a></p>]]></content:encoded>
			<wfw:commentRss>http://www.bobbobel.com/google-apps-goes-mutli-domain/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Review, Droid HTC Incredible, My First Week</title>
		<link>http://www.bobbobel.com/review-droid-htc-incredible-my-first-week/</link>
		<comments>http://www.bobbobel.com/review-droid-htc-incredible-my-first-week/#comments</comments>
		<pubDate>Fri, 11 Jun 2010 13:51:30 +0000</pubDate>
		<dc:creator>Bob Bobel</dc:creator>
				<category><![CDATA[Bobel]]></category>
		<category><![CDATA[Droid]]></category>
		<category><![CDATA[Google Android]]></category>
		<category><![CDATA[HTC Incredible]]></category>
		<category><![CDATA[Verizon Droid Incredible Backorder]]></category>

		<guid isPermaLink="false">http://www.bobbobel.com/?p=911</guid>
		<description><![CDATA[Friday of last week I brought my wife home from the hospital where she had undergone surgery for errant gall stones. When I got back to the house there was a shipping tag saying I missed my delivery company and that they had a package waiting for me at the local pickup &#8211; I just knew it [...]]]></description>
			<content:encoded><![CDATA[<p>Friday of last week I brought my wife home from the hospital where she had undergone surgery for errant gall stones. When I got back to the house there was a shipping tag saying I missed my delivery company and that they had a package waiting for me at the local pickup &#8211; I just knew it was my Android phone. Fortunately, the delivery offices were open until 10pm so despite it being late in the day (and Friday) I still was able to pickup my package. Based on the dates Verizon had given me I actually ended up getting the package a week earlier than expected and I wouldn&#8217;t have the phone for the weekend to get used to moving off Windows Mobile.</p>
<p>I walked out to my car and climbed in the driver&#8217;s seat. Next to me was a younger couple and the guy had a box that was strangely similar in size to mine, but I quickly forgot about that and decided to concentrate on using my keys to cut though the tape on my box. Inside that dirty brown box was a smaller white box that held my new droid incredible. I quickly opened the smaller box carefully lifted the phone out and and without regard to the instructions I pushed the power button; nothing happened. Realizing my mistake I quickly rummaged through the box to find the battery that they never would have shipped pre-installed in the phone.</p>
<p>After fumbling around figuring out how to open the phone and inserting the bright red battery (very cool btw)  - I closed the phone, held my breath and pushed the ON button. I now know it was at that moment my mobile life changed for good.  I wasn&#8217;t sure about the best way to &#8220;migrate&#8221; from Windows Mobile so I decided to just use the device for a phone until I came up with a plan to switch over my email. That plan lasted less than 2 hours before I made the leap and started having my email directed to my Incredible &#8211; and out of the box it is working extremely well.</p>
<p>I have been using my HTC Incredible relentlessly for the past week and while I am still getting used to some aspects of the phone I would not hesitate to recomend  this phone to anyone considering it &#8211; the phone is more than incredible &#8211; it is awesome.</p>
<p align="left"><a class="tt" href="http://twitter.com/home/?status=Review%2C+Droid+HTC+Incredible%2C+My+First+Week+http://6cgpm.th8.us" title="Post to Twitter"><img class="nothumb" src="http://www.bobbobel.com/wp-content/plugins/tweet-this/icons/tt-twitter-big4.png" alt="Post to Twitter" /></a></p>]]></content:encoded>
			<wfw:commentRss>http://www.bobbobel.com/review-droid-htc-incredible-my-first-week/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Death of the Incandescent bulb</title>
		<link>http://www.bobbobel.com/death-of-the-incandescent-bulb/</link>
		<comments>http://www.bobbobel.com/death-of-the-incandescent-bulb/#comments</comments>
		<pubDate>Thu, 10 Jun 2010 21:11:13 +0000</pubDate>
		<dc:creator>Bob Bobel</dc:creator>
				<category><![CDATA[Bobel]]></category>
		<category><![CDATA[LED Lights]]></category>
		<category><![CDATA[light emitting diodes]]></category>

		<guid isPermaLink="false">http://www.bobbobel.com/?p=908</guid>
		<description><![CDATA[Another sign that LED lighting is revolutionizing the lighting industry as Toshiba halted its 120 year history of producing incandescent bulbs to concentrait on LED technology. It is interesting because just last year several major cities were discussing outlawing incandescent bulbs and Australia aparently is actually begining regulation of them. http://www.computerworld.com/s/article/9171999/Lights_out_on_incandescent_bulb_production_at_Toshiba]]></description>
			<content:encoded><![CDATA[<p>Another sign that LED lighting is revolutionizing the lighting industry as Toshiba halted its 120 year history of producing incandescent bulbs to concentrait on LED technology. It is interesting because just last year several major cities were discussing outlawing incandescent bulbs and Australia aparently is actually begining regulation of them.</p>
<p><a href="http://www.computerworld.com/s/article/9171999/Lights_out_on_incandescent_bulb_production_at_Toshiba">http://www.computerworld.com/s/article/9171999/Lights_out_on_incandescent_bulb_production_at_Toshiba</a></p>
<p align="left"><a class="tt" href="http://twitter.com/home/?status=Death+of+the+Incandescent+bulb+http://brz3k.th8.us" title="Post to Twitter"><img class="nothumb" src="http://www.bobbobel.com/wp-content/plugins/tweet-this/icons/tt-twitter-big4.png" alt="Post to Twitter" /></a></p>]]></content:encoded>
			<wfw:commentRss>http://www.bobbobel.com/death-of-the-incandescent-bulb/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Droid Incredible, Verizon 3 Week Backorder</title>
		<link>http://www.bobbobel.com/droid-incredible-verizon-3-week-backorder/</link>
		<comments>http://www.bobbobel.com/droid-incredible-verizon-3-week-backorder/#comments</comments>
		<pubDate>Tue, 18 May 2010 13:36:04 +0000</pubDate>
		<dc:creator>Bob Bobel</dc:creator>
				<category><![CDATA[Bobel]]></category>
		<category><![CDATA[Droid]]></category>
		<category><![CDATA[Verizon Droid Incredible Backorder]]></category>
		<category><![CDATA[Windows Mobile]]></category>

		<guid isPermaLink="false">http://www.bobbobel.com/?p=898</guid>
		<description><![CDATA[So I went to the Verizon store yesterday and after a twenty minute wait for help &#8211; I ordered my Droid Incredible. About half way through doing the paper work I was told the phones were on three weeks back-order. When I asked if there was a loaner phone available there was not &#8211; the Verizon rep [...]]]></description>
			<content:encoded><![CDATA[<p>So I went to the Verizon store yesterday and after a twenty minute wait for help &#8211; I ordered my Droid Incredible. About half way through doing the paper work I was told the phones were on three weeks back-order. When I asked if there was a loaner phone available there was not &#8211; the Verizon rep simply said the phones are just that popular. While I don&#8217;t like the wait, I am happy that my decision to switch from Windows Mobile after using it for six years was the right decision; a tough decision &#8211; but the right one. My old phone was the VZ 6800 built by HTC &#8211; this has been a good phone so I expect that the HTC built <a href="inactive accounts enumeration" target="_blank">Incredible </a>will also be a good phone.</p>
<p align="left"><a class="tt" href="http://twitter.com/home/?status=Droid+Incredible%2C+Verizon+3+Week+Backorder+http://qwhs2.th8.us" title="Post to Twitter"><img class="nothumb" src="http://www.bobbobel.com/wp-content/plugins/tweet-this/icons/tt-twitter-big4.png" alt="Post to Twitter" /></a></p>]]></content:encoded>
			<wfw:commentRss>http://www.bobbobel.com/droid-incredible-verizon-3-week-backorder/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>AD CMDLETS Version 1.4 (Early look)</title>
		<link>http://www.bobbobel.com/ad-cmdlets-version-1-4-early-look/</link>
		<comments>http://www.bobbobel.com/ad-cmdlets-version-1-4-early-look/#comments</comments>
		<pubDate>Tue, 18 May 2010 13:23:30 +0000</pubDate>
		<dc:creator>Bob Bobel</dc:creator>
				<category><![CDATA[Active Directory]]></category>
		<category><![CDATA[Active Directory Help]]></category>
		<category><![CDATA[ActiveRoles Server]]></category>
		<category><![CDATA[AD CMDLETS]]></category>
		<category><![CDATA[Bobel]]></category>
		<category><![CDATA[Deprovisioning]]></category>
		<category><![CDATA[inactive accounts enumeration]]></category>
		<category><![CDATA[obsolete accounts]]></category>
		<category><![CDATA[PowerShell]]></category>
		<category><![CDATA[PowerShell Certificate]]></category>
		<category><![CDATA[PowerShell PKI management]]></category>
		<category><![CDATA[Quest CMDLETS]]></category>

		<guid isPermaLink="false">http://www.bobbobel.com/?p=895</guid>
		<description><![CDATA[In late June or early July, a new version of the Active Directory PowerShell CMDLETS will be released. I wanted to give everyone a teaser about the new features to be added. Here you go! -        Certificate management -        Support for cross-domain group membership -        inactive accounts enumeration -        single command to search in multiple [...]]]></description>
			<content:encoded><![CDATA[<p>In late June or early July, a new version of the Active Directory PowerShell CMDLETS will be released. I wanted to give everyone a teaser about the new features to be added.</p>
<p>Here you go!</p>
<p>-        Certificate management<br />
-        Support for cross-domain group membership<br />
-        inactive accounts enumeration<br />
-        single command to search in multiple containers<br />
-        progress indication<br />
-        proxy addresses management</p>
<p>Stay tuned and I will blog with more details around each feature over the next several weeks.</p>
<p align="left"><a class="tt" href="http://twitter.com/home/?status=AD+CMDLETS+Version+1.4+%28Early+look%29+http://48542.th8.us" title="Post to Twitter"><img class="nothumb" src="http://www.bobbobel.com/wp-content/plugins/tweet-this/icons/tt-twitter-big4.png" alt="Post to Twitter" /></a></p>]]></content:encoded>
			<wfw:commentRss>http://www.bobbobel.com/ad-cmdlets-version-1-4-early-look/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Federation Service 2.0, now Shipping</title>
		<link>http://www.bobbobel.com/federation-service-2-0-is-now-shipping/</link>
		<comments>http://www.bobbobel.com/federation-service-2-0-is-now-shipping/#comments</comments>
		<pubDate>Thu, 06 May 2010 07:07:31 +0000</pubDate>
		<dc:creator>Bob Bobel</dc:creator>
				<category><![CDATA[Active Directory]]></category>
		<category><![CDATA[Active Directory Help]]></category>
		<category><![CDATA[ADFS]]></category>
		<category><![CDATA[Identity Access]]></category>

		<guid isPermaLink="false">http://www.bobbobel.com/?p=889</guid>
		<description><![CDATA[ADFS 2.0 (Active Directory Federation Services) was released to the public May 5th, 2010 and announced on the &#8220;Geneva team blog.&#8221;  You can download the package from the Microsoft download site and install for free on Windows Server.  Stuart Kwan gives a brief overview of ADFS 2.0 capabilities in a new channel 9 video produced [...]]]></description>
			<content:encoded><![CDATA[<p>ADFS 2.0 (Active Directory Federation Services) was released to the public May 5th, 2010 and announced on the &#8220;<a href="http://blogs.msdn.com/card/archive/2010/05/05/ad-fs-2-0-is-here.aspx " target="_blank">Geneva team blog</a>.&#8221;  You can download the package from the Microsoft <a href="http://www.microsoft.com/downloads/details.aspx?FamilyID=118c3588-9070-426a-b655-6cec0a92c10b&amp;displaylang=en" target="_blank">download </a>site and install for free on Windows Server.  Stuart Kwan gives a brief overview of ADFS 2.0 capabilities in a new <a href="http://channel9.msdn.com/shows/Identity/Active-Directory-Federation-Services-v2-Ships/" target="_blank">channel 9 video </a>produced by Microsoft. Why is this important? ADFS 2.0 is a big step forward for Microsoft in their delivery of a new paradigm Identity and Access capabilities within software products based on &#8220;claims&#8221; rather than traditional Kerberos authentication.</p>
<p>Lacking in the previous version, SAML 2.0 is now officially supported by ADFS 2.0. SAML is the authentication protocol we used to create our Just-in-Time provisioning example I blogged about earlier this week (see <a href="http://www.bobbobel.com/just-in-time-access-provisioning/" target="_self">JIT Provisioning</a>). With ADFS 2.0 providers can be built for any application that uses either SAML or Claims. SAML is used by Salesforce.com, Google Apps, Service Now, Postini and many other SaaS/cloud services while Claims are now supported in SharePoint 2010 and will be introduced into many additional Microsoft applications.</p>
<p align="left"><a class="tt" href="http://twitter.com/home/?status=Federation+Service+2.0%2C+now+Shipping+http://3qry9.th8.us" title="Post to Twitter"><img class="nothumb" src="http://www.bobbobel.com/wp-content/plugins/tweet-this/icons/tt-twitter-big4.png" alt="Post to Twitter" /></a></p>]]></content:encoded>
			<wfw:commentRss>http://www.bobbobel.com/federation-service-2-0-is-now-shipping/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Just-in-Time Access Provisioning</title>
		<link>http://www.bobbobel.com/just-in-time-access-provisioning/</link>
		<comments>http://www.bobbobel.com/just-in-time-access-provisioning/#comments</comments>
		<pubDate>Fri, 30 Apr 2010 04:56:04 +0000</pubDate>
		<dc:creator>Bob Bobel</dc:creator>
				<category><![CDATA[Access]]></category>
		<category><![CDATA[Active Directory]]></category>
		<category><![CDATA[Entitlement]]></category>
		<category><![CDATA[Access Management]]></category>
		<category><![CDATA[Active Directory Help]]></category>
		<category><![CDATA[Athentication and Authorization]]></category>
		<category><![CDATA[Google Apps provsioning]]></category>
		<category><![CDATA[Just in time provisoning]]></category>
		<category><![CDATA[SAML]]></category>

		<guid isPermaLink="false">http://www.bobbobel.com/?p=863</guid>
		<description><![CDATA[While I was in college I worked summers for a glass company. My job was in the engineering drafting department where I drafted furnace parts, conveyor belts and paint bands that hides the goo they use to stick your windshield to your car. During this time American automakers struggling cope with the explosion of Japanese [...]]]></description>
			<content:encoded><![CDATA[<p>While I was in college I worked summers for a glass company. My job was in the engineering drafting department where I drafted furnace parts, conveyor belts and paint bands that hides the goo they use to stick your windshield to your car. During this time American automakers struggling cope with the explosion of Japanese imported cars. Japanese cars had a reputation of low cost and good quality, but the Japanese automakers also had a secret weapon that made them more efficient &#8211; Just-in-Time manufacturing.</p>
<p>Just-in-Time manufacturing is a simple concept &#8211; rather than keep all the unassembled car parts in expensive warehouses, have them delivered to the factory at the time they are needed to assemble a car.  This idea stuck with me and has been rattling around in the back of my mind for the past twenty years. Dell later used a similar concept steal market share away from IBM and Gateway who were building huge numbers of PCs and storing them until they were sold &#8211; while Dell built PCs that were already sold.</p>
<p>A project I have been working on for the past year or so was applying Just-in-Time concept to the process of granting users access to applications or data. The idea is that when a user attempts to access a resource for which they have not been granted access &#8211; the access attempt kicks of a self-service process or an automatic grant of access.</p>
<p>While I have seen other applications perform similar activities, many people have seen Microsoft SharePoint&#8217;s basic request access feature. The challenge I see with SharePoint is that it only allows generic requests that don&#8217;t allow the user to select the level of access they wish nor does it tell the user the state of their access request. Both are needed and both must be components of any more complete solution. A more complete solution must also provide access to more than just SharePoint; files, folders and applications access are also desperately needed.</p>
<p>Today, we posted a technical preview of Just-in-Time Access Provisioning called the ActiveRoles AuthX Provider The provider not only integrates authentication using SAML between AD users and Google Apps, it also can trigger a self-service access request through ActiveRoles if the user does not yet have an account. Once the request is approved a Google account is created. The next time the user points his/her browser to Google Apps URL the Provider seamlessly authenticates the user by doing an account mapping of AD user to the Google account and creates a SAML token that automatically signs the user into their Google Apps account. We created a 2 minute video showing the process so you can see how this works. The video was a little long and choppy at some points so I cut it down to about 2 minutes.</p>
<p><code><object classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" width="425" height="344" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0"><param name="allowFullScreen" value="true" /><param name="allowscriptaccess" value="always" /><param name="src" value="http://www.youtube.com/v/RN6pYgnQaa8&amp;hl=en&amp;fs=1" /><param name="allowfullscreen" value="true" /><embed type="application/x-shockwave-flash" width="425" height="344" src="http://www.youtube.com/v/RN6pYgnQaa8&amp;hl=en&amp;fs=1" allowfullscreen="true" allowscriptaccess="always"></embed></object></code></p>
<p> <code><a href="http://www.bobbobel.com/wp-content/uploads/2010/04/ActiveRolesAccessProvider.wmv">Video:ActiveRoles Access Provider</a></code></p>
<p align="left"><a class="tt" href="http://twitter.com/home/?status=Just-in-Time+Access+Provisioning+http://irebk.th8.us" title="Post to Twitter"><img class="nothumb" src="http://www.bobbobel.com/wp-content/plugins/tweet-this/icons/tt-twitter-big4.png" alt="Post to Twitter" /></a></p>]]></content:encoded>
			<wfw:commentRss>http://www.bobbobel.com/just-in-time-access-provisioning/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
<enclosure url="http://www.bobbobel.com/wp-content/uploads/2010/04/ActiveRolesAuthXProviderBLOG.wmv" length="1988577" type="video/x-ms-wmv" />
<enclosure url="http://www.bobbobel.com/wp-content/uploads/2010/04/ActiveRolesAccessProvider.wmv" length="2003011" type="video/x-ms-wmv" />
		</item>
	</channel>
</rss>
