SlideShare a Scribd company logo
1 of 14
AusCERT 2010 Speaker Presentation Methodologies & Tools to make user self service a reality Paul Conroy – Identity & Access Technology Specialist
Agenda Business Challenges Meta-directory concepts User Self Service Scenarios Automated provisioning Attribute change User self service password reset Deprovisioning Summary Resources
Business Challenges Threats Current Solutions Business Landscape Increased volume Product proliferation Increased regulatory and compliance pressure More connectivity and collaboration Greater need for identity-based protection and access Greater IT choice; lower budgets Greater sophistication Lack of integration High cost of ownership Profit motivated Security not aligned to business needs and new opportunities
• Enhanced User Experience – Includes self-service password reset • Account Provisioning and Access Request  Empower People ,[object Object],Deliver Agility and Efficiency • Centralised source for auditors  • Credential Management  Increase Security and Compliance Goals of an Identity Management project
Methodologies for Identity Management Directory Synchronisation Automated Provisioning Self Service Management of :- Groups/Distribution Lists Attributes Passwords Delegated Administration (e.g. for approvals)
Meta Directory Concept Meta-directory MAINFRAME ACTIVE DIRECTORY FINANCEAPPLICATION EXCHANGE FINANCEPORTAL SMARTCARD iPLANET
Methodologies for Identity Management Directory Synchronisation Automated Provisioning Self Service Management of :- Groups/Distribution Lists Attributes Passwords Delegated Administration (e.g. for approvals)
HR SYSTEM MANAGER APPROVAL PROVISIONING POLICY APPLIED New Employee Scenario Meta-directory MANAGER APPROVAL MAINFRAME ACTIVE DIRECTORY FINANCEAPPLICATION EXCHANGE FINANCEPORTAL SMARTCARD iPLANET
Methodologies for Identity Management Directory Synchronisation Automated Provisioning Self Service Management of :- Groups/Distribution Lists Attributes Passwords Delegated Administration (e.g. for approvals)
iPLANET Password Reset And Synchronisation MELISSA PASSWORD SYCHRONISATION WINDOWSMACHINE Meta-directory  FINANCEAPPLICATION ACTIVEDIRECTORY FINANCEPORTAL
HR SYSTEM  PROVISIONING POLICY APPLIED Attribute Management Meta-directory MAINFRAME ACTIVE DIRECTORY FINANCEAPPLICATION MARKETINGAPPLICATION EXCHANGE FINANCEPORTAL MARKETINGPORTAL SMARTCARD iPLANET
Methodologies for Identity Management Directory Synchronisation Automated Provisioning Self Service Management of :- Groups/Distribution Lists Attributes Passwords Delegated Administration (e.g. for approvals)
Goal of an Identity Management project • Enhanced User Experience – Includes self-service password reset • Account Provisioning and Access Request  Empower People ,[object Object],Deliver Agility and Efficiency • Centralised source for auditors  • Credential Management  Increase Security and Compliance Summary
Resources Learn About Identity and Access (IDA) www.microsoft.com/IDA

More Related Content

Viewers also liked

Tech Ed 2011 Preso
Tech Ed 2011 PresoTech Ed 2011 Preso
Tech Ed 2011 Preso
PAUL CONROY
 
Лекция № 5. Важнейшие элементы периодической системы Д.И. Менделеева, определ...
Лекция № 5. Важнейшие элементы периодической системы Д.И. Менделеева, определ...Лекция № 5. Важнейшие элементы периодической системы Д.И. Менделеева, определ...
Лекция № 5. Важнейшие элементы периодической системы Д.И. Менделеева, определ...
Петрова Елена Александровна
 
Commission electorale
Commission electoraleCommission electorale
Commission electorale
Juanico
 
Gbph restauration-collective
Gbph restauration-collectiveGbph restauration-collective
Gbph restauration-collective
Mounir El Ourak
 

Viewers also liked (16)

Tech Ed 2011 Preso
Tech Ed 2011 PresoTech Ed 2011 Preso
Tech Ed 2011 Preso
 
Life
LifeLife
Life
 
Inco Terms
Inco TermsInco Terms
Inco Terms
 
Java I/O Part 1
Java I/O Part 1Java I/O Part 1
Java I/O Part 1
 
Java I/O Part 2
Java I/O Part 2Java I/O Part 2
Java I/O Part 2
 
JSP : Creating Custom Tag
JSP : Creating Custom Tag JSP : Creating Custom Tag
JSP : Creating Custom Tag
 
Dom Basics
Dom BasicsDom Basics
Dom Basics
 
Network analysis
Network analysisNetwork analysis
Network analysis
 
Ecommerce Monetiser Son Site Philippefloch Technofutur
Ecommerce Monetiser Son Site Philippefloch TechnofuturEcommerce Monetiser Son Site Philippefloch Technofutur
Ecommerce Monetiser Son Site Philippefloch Technofutur
 
Intelligence collective et réseaux sociaux : comment le web 2.0 modifie la tr...
Intelligence collective et réseaux sociaux : comment le web 2.0 modifie la tr...Intelligence collective et réseaux sociaux : comment le web 2.0 modifie la tr...
Intelligence collective et réseaux sociaux : comment le web 2.0 modifie la tr...
 
Лекция № 5. Важнейшие элементы периодической системы Д.И. Менделеева, определ...
Лекция № 5. Важнейшие элементы периодической системы Д.И. Менделеева, определ...Лекция № 5. Важнейшие элементы периодической системы Д.И. Менделеева, определ...
Лекция № 5. Важнейшие элементы периодической системы Д.И. Менделеева, определ...
 
Approche paysagiste
Approche paysagisteApproche paysagiste
Approche paysagiste
 
Commission electorale
Commission electoraleCommission electorale
Commission electorale
 
Baromètre EurObserv’ER 2014 - Etat des énergies renouvelables en Europe
Baromètre EurObserv’ER 2014 - Etat des énergies renouvelables en EuropeBaromètre EurObserv’ER 2014 - Etat des énergies renouvelables en Europe
Baromètre EurObserv’ER 2014 - Etat des énergies renouvelables en Europe
 
Internet en Chine 2013
Internet en Chine 2013Internet en Chine 2013
Internet en Chine 2013
 
Gbph restauration-collective
Gbph restauration-collectiveGbph restauration-collective
Gbph restauration-collective
 

Recently uploaded

Recently uploaded (20)

A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)
 
A Year of the Servo Reboot: Where Are We Now?
A Year of the Servo Reboot: Where Are We Now?A Year of the Servo Reboot: Where Are We Now?
A Year of the Servo Reboot: Where Are We Now?
 
Driving Behavioral Change for Information Management through Data-Driven Gree...
Driving Behavioral Change for Information Management through Data-Driven Gree...Driving Behavioral Change for Information Management through Data-Driven Gree...
Driving Behavioral Change for Information Management through Data-Driven Gree...
 
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
 
Handwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed textsHandwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed texts
 
Scaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organizationScaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organization
 
Slack Application Development 101 Slides
Slack Application Development 101 SlidesSlack Application Development 101 Slides
Slack Application Development 101 Slides
 
From Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time AutomationFrom Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time Automation
 
🐬 The future of MySQL is Postgres 🐘
🐬  The future of MySQL is Postgres   🐘🐬  The future of MySQL is Postgres   🐘
🐬 The future of MySQL is Postgres 🐘
 
2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...
 
08448380779 Call Girls In Civil Lines Women Seeking Men
08448380779 Call Girls In Civil Lines Women Seeking Men08448380779 Call Girls In Civil Lines Women Seeking Men
08448380779 Call Girls In Civil Lines Women Seeking Men
 
Advantages of Hiring UIUX Design Service Providers for Your Business
Advantages of Hiring UIUX Design Service Providers for Your BusinessAdvantages of Hiring UIUX Design Service Providers for Your Business
Advantages of Hiring UIUX Design Service Providers for Your Business
 
Automating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps ScriptAutomating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps Script
 
Exploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone ProcessorsExploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone Processors
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected Worker
 
08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
08448380779 Call Girls In Diplomatic Enclave Women Seeking Men08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
 
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
 
Factors to Consider When Choosing Accounts Payable Services Providers.pptx
Factors to Consider When Choosing Accounts Payable Services Providers.pptxFactors to Consider When Choosing Accounts Payable Services Providers.pptx
Factors to Consider When Choosing Accounts Payable Services Providers.pptx
 
Breaking the Kubernetes Kill Chain: Host Path Mount
Breaking the Kubernetes Kill Chain: Host Path MountBreaking the Kubernetes Kill Chain: Host Path Mount
Breaking the Kubernetes Kill Chain: Host Path Mount
 
GenCyber Cyber Security Day Presentation
GenCyber Cyber Security Day PresentationGenCyber Cyber Security Day Presentation
GenCyber Cyber Security Day Presentation
 

Methodologies And Tools To Make User Self Service A Reality

  • 1. AusCERT 2010 Speaker Presentation Methodologies & Tools to make user self service a reality Paul Conroy – Identity & Access Technology Specialist
  • 2. Agenda Business Challenges Meta-directory concepts User Self Service Scenarios Automated provisioning Attribute change User self service password reset Deprovisioning Summary Resources
  • 3. Business Challenges Threats Current Solutions Business Landscape Increased volume Product proliferation Increased regulatory and compliance pressure More connectivity and collaboration Greater need for identity-based protection and access Greater IT choice; lower budgets Greater sophistication Lack of integration High cost of ownership Profit motivated Security not aligned to business needs and new opportunities
  • 4.
  • 5. Methodologies for Identity Management Directory Synchronisation Automated Provisioning Self Service Management of :- Groups/Distribution Lists Attributes Passwords Delegated Administration (e.g. for approvals)
  • 6. Meta Directory Concept Meta-directory MAINFRAME ACTIVE DIRECTORY FINANCEAPPLICATION EXCHANGE FINANCEPORTAL SMARTCARD iPLANET
  • 7. Methodologies for Identity Management Directory Synchronisation Automated Provisioning Self Service Management of :- Groups/Distribution Lists Attributes Passwords Delegated Administration (e.g. for approvals)
  • 8. HR SYSTEM MANAGER APPROVAL PROVISIONING POLICY APPLIED New Employee Scenario Meta-directory MANAGER APPROVAL MAINFRAME ACTIVE DIRECTORY FINANCEAPPLICATION EXCHANGE FINANCEPORTAL SMARTCARD iPLANET
  • 9. Methodologies for Identity Management Directory Synchronisation Automated Provisioning Self Service Management of :- Groups/Distribution Lists Attributes Passwords Delegated Administration (e.g. for approvals)
  • 10. iPLANET Password Reset And Synchronisation MELISSA PASSWORD SYCHRONISATION WINDOWSMACHINE Meta-directory FINANCEAPPLICATION ACTIVEDIRECTORY FINANCEPORTAL
  • 11. HR SYSTEM PROVISIONING POLICY APPLIED Attribute Management Meta-directory MAINFRAME ACTIVE DIRECTORY FINANCEAPPLICATION MARKETINGAPPLICATION EXCHANGE FINANCEPORTAL MARKETINGPORTAL SMARTCARD iPLANET
  • 12. Methodologies for Identity Management Directory Synchronisation Automated Provisioning Self Service Management of :- Groups/Distribution Lists Attributes Passwords Delegated Administration (e.g. for approvals)
  • 13.
  • 14. Resources Learn About Identity and Access (IDA) www.microsoft.com/IDA

Editor's Notes

  1. State that automated provisioning is of users and resources
  2. State that automated provisioning is of users and resources
  3. Key points we want to illustrate: Melissa is a new employee starting her first day of work at Contoso. She sits down in her assigned office to begin her work which is heavily dependent on LOB applications and being ‘plugged in’ to key DLs.Rather than calling the help desk to get access, groups, etc. Melissa’s accounts and mailbox are automatically provisioned and available at first login, due to preconfigured rules in ILM “2”She is automatically granted access to the LOB apps relevant to her roleShe is dynamically added to key DLsAnimation flow:Data flows in from HR system. Would like a file to pass from HR to ILM “2” with information on the new hire like Name = Melissa Meyers, Employee ID = 122145, Dept = Finance, Title = Analyst, Employee Type = Full Time.Data flows to each of the target systems. For Exchange a mailbox is created. I want icons to travel along the arrow to represent the data passed to Exchange as well mailbox created. Her email address should be filled in as mmeyers@contoso.com.For AD, a password is assigned and sent to her manager. She is also given membership in the “Finance,” “New Hire” and “FTE” groups in AD. I want icons to travel along the arrow to represent the data passed to AD as well as the password and new groups created.A smart card is also provisioned so for remote access and for her to access the finance appFor the other accounts show the data passing along the arrows. Show only her name, employee ID, and department being passed to iPlanet, and show her Name, ID, and Employee Type passing to the mainframe.
  4. State that automated provisioning is of users and resources
  5. New Employee scenarioCreate new userNow invoke set, workflow and management policy rule. All constructs in Identity ManagementCreate second userNB Mention delegated administration
  6. Logon as the newly created userShow how SSPR worksgoto slideShow DL management in OutlookChange MPR and show self service of fax numbergotoattrmgt slide
  7. Key points we want to illustrate: Melissa is a new employee starting her first day of work at Contoso. She sits down in her assigned office to begin her work which is heavily dependent on LOB applications and being ‘plugged in’ to key DLs.Rather than calling the help desk to get access, groups, etc. Melissa’s accounts and mailbox are automatically provisioned and available at first login, due to preconfigured rules in ILM “2”She is automatically granted access to the LOB apps relevant to her roleShe is dynamically added to key DLsAnimation flow:Data flows in from HR system. Would like a file to pass from HR to ILM “2” with information on the new hire like Name = Melissa Meyers, Employee ID = 122145, Dept = Finance, Title = Analyst, Employee Type = Full Time.Data flows to each of the target systems. For Exchange a mailbox is created. I want icons to travel along the arrow to represent the data passed to Exchange as well mailbox created. Her email address should be filled in as mmeyers@contoso.com.For AD, a password is assigned and sent to her manager. She is also given membership in the “Finance,” “New Hire” and “FTE” groups in AD. I want icons to travel along the arrow to represent the data passed to AD as well as the password and new groups created.A smart card is also provisioned so for remote access and for her to access the finance appFor the other accounts show the data passing along the arrows. Show only her name, employee ID, and department being passed to iPlanet, and show her Name, ID, and Employee Type passing to the mainframe.
  8. Now logon as Melissa and run her approval and logon as new user