unified identit y management - oneloginresources.onelogin.com/pd-onelogin-for-servicenow.pdf ·...

2
PRODUCT DATASHEET Identity Management and Single Sign-On for the Visionary Enterprise SECURITY & AVAILABILITY ACROSS ALL DEVICES With a 99.99% SLA uptime guarantee, ServiceNow customers can feel confident trusting OneLogin to keep their information secure and accessible at all times on all devices. OneLogin’s Active Directory Connector (ADC) also has a high availability feature that allows customers to set multiple connectors to run in parallel meaning if a customer server hosting the primary ADC goes down, one of the secondary connectors is promoted to primary automatically. and Windows Phone to all cloud and enterprise apps with a secure, flexible solution that supports on-the-go users while eliminating enterprise risk. In addition to its own free one-time password app, OneLogin comes pre-integrated with Duo Security, RSA SecurID, and other MFA providers if additional authentication is desired. LEADING ACTIVE DIRECTORY CONNECTOR For many ServiceNow customers, Microsoft Active Directory business applications. When combined with OneLogin, AD takes on powerful new capabilities to control real-time access to web, desktop, and mobile applications– and there’s no need to embark on a complex AD integration project for each new app. OneLogin’s AD connector, unlike other AD cloud connectors, OneLogin is the logical choice for organizations looking for superior functionality, security, and overall ease of use in an AD integration. Microsoft’s Active Directory Federation Services (AD FS) can bridge AD with cloud applications and services, but its complexity hinders IT’s ability to keep pace with the “now” mentality of business. AD FS also lacks key functionality like user provisioning and compliance reporting. Similarly, ServiceNow both expose their on-premises directories as well as build and support a custom infrastructure to maintain the connection. 150 SPEAR STREET, SUITE 1400 SAN FRANCISCO, CA 94105 877 979 0411 ONELOGIN ONELOGIN.COM TRUSTED BY THE WORLD’S MOST INNOVATIVE COMPANIES OneLogin provides the industry’s fastest, easiest, and most secure solution for comprehensive identity management, including single sign-on (SSO). OneLogin’s integration with ServiceNow enables organizations to further accelerate and scale cloud adoption, as well as reduce administrative costs, drive productivity, and increase the security of their data stored outside the firewall in ServiceNow and across all cloud applications. UNIFIED IDENTITY MANAGEMENT This complexity disappears with OneLogin, which offers seamless federation and user provisioning from AD to ServiceNow.

Upload: ledieu

Post on 05-Jun-2018

224 views

Category:

Documents


0 download

TRANSCRIPT

P R O D U C T D A T A S H E E T

Identity Management and Single Sign-On for the Visionary Enterprise

SECURIT Y & AVAIL ABILIT Y ACROSS ALL DEVICES

With a 99.99% SLA uptime guarantee, ServiceNow customers

can feel confident trusting OneLogin to keep their information

secure and accessible at all times on all devices. OneLogin’s Active

Directory Connector (ADC) also has a high availability feature

that allows customers to set multiple connectors to run in parallel

meaning if a customer server hosting the primary ADC goes

down, one of the secondary connectors is promoted to primary

automatically.

and Windows Phone to all cloud and enterprise apps with a secure,

flexible solution that supports on-the-go users while eliminating

enterprise risk. In addition to its own free one-time password app,

OneLogin comes pre-integrated with Duo Security, RSA SecurID,

and other MFA providers if additional authentication is desired.

LE ADING AC TIVE DIREC TORY CONNEC TOR

For many ServiceNow customers, Microsoft Active Directory

business applications. When combined with OneLogin, AD takes

on powerful new capabilities to control real-time access to

web, desktop, and mobile applications– and there’s no need to

embark on a complex AD integration project for each new app.

OneLogin’s AD connector, unlike other AD cloud connectors,

OneLogin is the logical choice for organizations looking for

superior functionality, security, and overall ease of use in an AD

integration. Microsoft’s Active Directory Federation Services

(AD FS) can bridge AD with cloud applications and services, but

its complexity hinders IT’s ability to keep pace with the “now”

mentality of business. AD FS also lacks key functionality like user

provisioning and compliance reporting. Similarly, ServiceNow

both expose their on-premises directories as well as build and

support a custom infrastructure to maintain the connection.

1 50 SPE AR S TREE T, SUITE 1400 SAN FR ANCISCO, C A 94105 87 7 979 0411 ONELOG IN ONELOG IN.COM

T R U S T E D B Y T H E W O R L D ’ S M O S T I N N O V A T I V E C O M P A N I E S

OneLogin provides the industry’s fastest, easiest, and most secure solution for comprehensive identity management, including single sign-on (SSO). OneLogin’s integration with ServiceNow enables organizations to further accelerate and scale cloud adoption, as well as reduce administrative costs, drive productivity, and increase the security of their data stored outside the firewall in ServiceNow and across all cloud applications.

U N I F I E D I D E N T I T Y M A N A G E M E N T

This complexity disappears with

OneLogin, which o�ers seamless federation and user

provisioning from AD to ServiceNow.

COMPLIANT WITH GLOBAL STANDARDS

OneLogin leads the industry in compliance standards. It is the first

cloud-based identity management provider to obtain ISO 27001

certification, an independent verification that a company has

implemented the latest and most rigorous information security

management processes to protect its systems and customers.

OneLogin is also SOC1/ SOC2 and European Data Residency

Compliant. Customers who use OneLogin’s enterprise identity

management solution gain critical support in areas of SOX

compliance that are under IT control, particularly those that are

prone to deficiencies year after year.

ACCESS MANAGEMENT OneLogin uses existing directory structures, or can even serve as a completely

cloud-based directory service, to enable you to immediately and centrally grant,

modify, or remove access based on granular role-based access privileges.

SEGREGATION OF DUTIES Map pre-defined access levels and document any authorized exceptions based on

your organizational structure. OneLogin automatically creates a login audit trail.

AUTHENTICATION Centrally manage multiple password policies, including multi-factor

authentication, to set authentication controls commensurate with each

application’s risk level.

MONITORING Easily access standard or custom user activity reports to show what your users

are doing and which apps they are accessing from the OneLogin portal.

AUDIT EVIDENCE By using OneLogin as your central point of access management and

authentication, you can provide all the IAM reports needed for a SOX audit from a

single data source.

SE AMLESS & AUTOMATED USER PROVISIONING

Enterprises rely on OneLogin to easily and securely manage user

access to the ServiceNow application. With user provisioning,

OneLogin can automatically create user accounts in ServiceNow

for any user synced from AD, LDAP, Workday, or another

directory, thereby eliminating time-consuming and error-prone

processes for creating and deleting user accounts. OneLogin

performs real-time user provisioning, importing, matching and

de-duplication using a Windows service that listens for Active

Directory events (instead of periodic scans, or on-demand

checks initiated by an authentication event). This process ensures

that the instant someone is hired or terminated, the change

is propagated through to OneLogin and connected services

immediately. Immediate off-boarding is especially critical as

popular services like Google Apps allow back-door access

through protocols like IMAP. If a user is not immediately disabled,

unwarranted access to enterprise information can occur. On the

front end, user provisioning allows IT to simplify and accelerate

app deployment resulting in a more seamless on-boarding

experience and higher end user adoption and satisfaction.

DESK TOP SSO

OneLogin’s desktop SSO leverages Integrated Windows

Authentication (IWA) to sign users into OneLogin automatically

once they have signed into their Active Directory domain.

ServiceNow customers define a specific range of IP addresses from

which their users can authenticate with OneLogin automatically,

meaning they can access any applications that are managed by

OneLogin without having to re-enter their credentials, whether

those applications are in the cloud or behind the firewall.

1 50 SPE AR S TREE T, SUITE 1400 SAN FR ANCISCO, C A 94105 87 7 979 0411 ONELOG IN ONELOG IN.COM

O N E L O G I N F O R S E R V I C E N O W A L L O W S YO U T O L E V E R A G E YO U R E X I S T I N G D I R E C T O RY I N F R A S T R U C T U R E

USER SYNC

DELEGATED AUTHENTICATION

USER SYNC

SSO & PROVISIONING

ON-PREMISES CLOUD

AD CONNECTOR

EMPLOYEES REMOTEEMPLOYEES

SERVICENOW

ACTIVE DIRECTORY

ONELOGININTEGRATED

WINDOWSAUTHENTICATION