methodologies and tools to make user self service a reality

14
Paul Conroy Identity & Access Technology Specialist Methodologies & Tools to make user self service a reality AusCERT 2010 Speaker Presentation

Upload: paul-conroy

Post on 03-Jul-2015

292 views

Category:

Technology


3 download

DESCRIPTION

Presentation given to AusCERT 2010. Goals for improving service delivery and security by enabling self-service.

TRANSCRIPT

Page 1: Methodologies And Tools To Make User Self Service A Reality

Paul Conroy – Identity & Access Technology Specialist

Methodologies & Tools to make user self service a reality

AusCERT2010

Speaker Presentation

Page 2: Methodologies And Tools To Make User Self Service A Reality

Agenda

Business Challenges

Meta-directory concepts

User Self Service Scenarios

Automated provisioning

Attribute change

User self service password reset

Deprovisioning

Summary

Resources

Page 3: Methodologies And Tools To Make User Self Service A Reality

Increased volume

Greater sophistication

Profit motivated

Increased regulatory and compliance pressure

More connectivity and collaboration

Greater need for identity-based protection and

access

Greater IT choice; lower budgets

Business Landscape Product proliferation

Lack of integration

High cost of ownership

Business Challenges

Threats Current Solutions

Security not aligned to business needs and new opportunities

Page 4: Methodologies And Tools To Make User Self Service A Reality

• Deliver results in achievable increments

• Centralised source for auditors

• Credential Management

• Enhanced User Experience – Includes self-service password reset

• Account Provisioning and Access Request

Empower

People

Deliver

Agility and

Efficiency

Increase

Security and

Compliance

Goals of an Identity Management project

Page 5: Methodologies And Tools To Make User Self Service A Reality

Methodologies for Identity Management

Directory Synchronisation

Automated Provisioning

Self Service Management of :-

Groups/Distribution Lists

Attributes

Passwords

Delegated Administration (e.g. for approvals)

Page 6: Methodologies And Tools To Make User Self Service A Reality

Meta Directory Concept

Meta-directory

MAINFRAME

FINANCE

APPLICATION

FINANCE

PORTAL

iPLANET

SMART

CARD

EXCHANGE

ACTIVE

DIRECTORY

Page 7: Methodologies And Tools To Make User Self Service A Reality

Methodologies for Identity Management

Directory Synchronisation

Automated Provisioning

Self Service Management of :-

Groups/Distribution Lists

Attributes

Passwords

Delegated Administration (e.g. for approvals)

Page 8: Methodologies And Tools To Make User Self Service A Reality

New Employee Scenario

Meta-directory

MAINFRAME

FINANCE

APPLICATION

FINANCE

PORTAL

iPLANET

SMART

CARD

EXCHANGE

ACTIVE

DIRECTORY

HR SYSTEM

Given Name Melissa

Surname Meyers

Title Analyst

Department Finance

EmployeeID 122145

Employee ty Full Time

email

PROVISIONING

POLICY APPLIED

MANAGER

APPROVAL

MANAGER

APPROVAL

Given Name Melissa

Surname Meyers

Title Analyst

Department Finance

EmployeeID 122145

Employee ty Full Time

email

Given Name Melissa

Surname Meyers

Title Analyst

Department Finance

EmployeeID 122145

Employee ty Full Time

emailmmeyers@

contoso.com

Page 9: Methodologies And Tools To Make User Self Service A Reality

Methodologies for Identity Management

Directory Synchronisation

Automated Provisioning

Self Service Management of :-

Groups/Distribution Lists

Attributes

Passwords

Delegated Administration (e.g. for approvals)

Page 10: Methodologies And Tools To Make User Self Service A Reality

iPLANET

Password Reset And Synchronisation

Meta-directory

FINANCE

APPLICATION

FINANCE

PORTAL

ACTIVE

DIRECTORY

WINDOWS

MACHINE

PASSWORD

SYCHRONISATION

MELISSA

Page 11: Methodologies And Tools To Make User Self Service A Reality

Given Name Melissa

Surname Meyers

Title

Group

Marketing

Manager

Department Marketing

EmployeeID 122145

Employee ty Full Time

emailmmeyers@

contoso.com

Attribute Management

Meta-directory

MAINFRAME

FINANCE

APPLICATION

FINANCE

PORTAL

iPLANET

SMART

CARD

HR SYSTEM

Given Name Melissa

Surname Meyers

Title

Group

Marketing

Manager

Department Marketing

EmployeeID 122145

Employee ty Full Time

emailmmeyers@

contoso.comPROVISIONING

POLICY APPLIED

MARKETING

APPLICATION

MARKETING

PORTAL

Given Name Melissa

Surname Meyers

Title Analyst

Department Finance

EmployeeID 122145

Employee ty Full Time

emailmmeyers@

contoso.com

EXCHANGE

ACTIVE

DIRECTORY

Page 12: Methodologies And Tools To Make User Self Service A Reality

Methodologies for Identity Management

Directory Synchronisation

Automated Provisioning

Self Service Management of :-

Groups/Distribution Lists

Attributes

Passwords

Delegated Administration (e.g. for approvals)

Page 13: Methodologies And Tools To Make User Self Service A Reality

• Deliver results in achievable increments

• Centralised source for auditors

• Credential Management

• Enhanced User Experience – Includes self-service password reset

• Account Provisioning and Access Request

Empower

People

Deliver

Agility and

Efficiency

Increase

Security and

Compliance

Summary

Page 14: Methodologies And Tools To Make User Self Service A Reality

Resources

Learn About Identity and Access (IDA)

www.microsoft.com/IDA