SlideShare a Scribd company logo
1 of 27
Oracle IAM Suite
- Kali Kishore Gomattam
Agenda
• Oracle Identity & Access Management Concepts
• Fusion Middleware Concepts
• Oracle Access Manager Architecture
• WebLogic Concepts
– Domain, Servers (Admin & Managed)
– Data Sources
– Node Manager
• Repository Creation Utility (RCU)
Oracle IAM Products
Access Control
Oracle Access
Manager
Oracle Identity
Federation
Oracle Adaptive
Access Manager
Oracle
Entitlements
Server
Oracle
Enterprise SSO
Identity
Administration
Oracle Identity
Manager
Oracle
Privileged
Account
Manager
Oracle Identity
Analytics
Mobile Security
Oracle Mobile
Security Suite
Directory
Services
Oracle Unified
Directory
Oracle Internet
Directory
Oracle Virtual
Directory
Oracle Directory
Services EE
Oracle IAM Solutions
Access Control
Authentication
& Authorization
Single Sign-On
Federation
Web Services
Security
Identity
Administration
Identity
Lifecycle
Administration
Role &
Membership
Administration
Provisioning &
Reconciliation
Compliance
Automation
Mobile Security
Access
Corporate Data
from anywhere
Secure
Workspace
Directory
Services
Virtualization
Synchronization
Storage
Oracle Identity Governance
Identity
Governance
Provisioning
Certification
Audit
Access
Request
Password
Management
Privileged
Account
Management
Self Service
Oracle Access Management
Access
Manager
Fine Grained
Entitlements
Federating
Identities
Mobile
Security
Fraud
Prevention
Risk Analysis
Single Sign
On
Social
Integration
Oracle Access Manager
• Java EE application that provides
• Web Single Sign-On Service include Identity Context
• Authentication & Authorization
• Policy, Session, Agent Management
• Authentication & Coarse Grained Authorization
• Product from Oblix acquired in 2005
• Part of Oracle IDAM Software
• Deployed on Oracle Weblogic Server
• Versions: 11gR2 (PS3, PS2, PS1), 11gR1, 10g
Oracle Adaptive Access Manager
• Real Time Risk Analysis & Fraud Prevention
• Multi Factor Authentication
• Offline & Online Risk Analysis
• Product from Bharosa acquired in 2007
• Part of Oracle IDAM Software
• Deployed on Oracle Weblogic Server
• Versions: 11gR2 (PS3, PS2, PS1), 11gR1, 10g
Oracle Identity Federation
• Secure Identity Information exchange
between two parties
• Cross domain SSO
• Supports SAML 2.0
• Was part of Oracle IDM (with
OID/OVD) and now merged with
Oracle Access Management
Oracle Entitlement Server: OES
• Oracle Entitlements Server (OES) is a standards-based, policy-driven security
solution that provides real time fine-grained authorization in Application,
Service-Oriented Architecture (SOA) and Database environments.
• OES fills the need for granular, flexible, and externalized access control.
• The solution provides a comprehensive and centralized approach for managing
access policies with distributed or centralized enforcement.
• Authorization policy management and runtime enforcement is provided for
sensitive applications, databases, containers (such as Java™, .NET), portals
and content management systems (such as WebCenter and SharePoint),
development frameworks, object relational mapping technologies,
intermediaries (such as XML gateways and ESB’s), web services, and SOA
infrastructure.
Oracle Web Service Manager
• Solution for defining policies and securing Web Services
• Web Service security includes authentication, authorization, message
encryption/decryption, and identity propagation
• Component of Oracle SOA suite and installed as part of SOA
Oracle API Gateway (OAG)
• First line of defense securing web services, web APIs deployed in
premise or in the cloud.
• With OAG, internal system and corporate data can be exposed as fully
secure REST API
• OAG integrates with Oracle Access Management core services, Oracle
Web Services Manager and third party Access Management systems
• OAG can be deployed on premise and access APIs hosted in cloud or can
be deployed in cloud
Oracle Access Manager Overview
• Entitlements
Management
• Fine Grained
Authorization
• Risk-based
Authentication
• Real-time
Fraud
Prevention
• Web Access Control
• Single Sign-On
• Security Token
Management
• Identity Propagation
Mobile Security
Mobile
Management
Mobile
Device
Management
Mobile App
Management
Mobile
Content
Management
Mobile
Identity
Oracle Directory Services
Directory
Services
Directory
Servers
Replication
Proxy
Server
Lightweight Directory Access Protocol
• Lightweight Directory Access Protocol
• An application protocol
• For querying and modifying directory services
• Runs over TCP/IP
• Directory
• A set of objects with similar attributes
• Organized in a logical and hierarchical manner
Example: Telephone directory
Directory Services
• Oracle Unified Directory (OUD)
• Oracle Internet Directory (OID)
• Oracle Virtual Directory (OVD)
• Oracle Directory Services EE (ODSEE)
• Oracle Directory Integration Platform (DIP)
Oracle Unified Directory: OUD
• LDAP v3 compliant directory server
with
• Directory Server
• Replication
• Proxy
• No database requirement
• Recommended Directory Server for
new/large deployments
Oracle Internet Directory: OID
• LDAP v3 compliant directory server
• Data is stored in Oracle Database
• Supports Multi Master Replication
Oracle Virtual Directory: OVD
• Virtualisation layer for Multiple User
Repository
• Installed as part of IDM software
(11gR1 latest)
Oracle Directory Integration Platform (DIP)
• J2EE application deployed on
Weblogic Server
• Configure with OID/OUD to synch
with other user repository
• Two Modules
– Synchronization
– Provisioning
Oracle Access Manager Architecture
Oracle Access Manager Architecture
Features
– Web single-sign-on
– Multi-level, multi-factor authentication management
– Web Services interfaces
Benefits
– Centralized and consistent security across heterogeneous environment
– Reduced administration cost
– Improved end user experience
Oracle Access Manager Architecture
• OAM DB: Policy Store & Metadata
• LDAP Store: Users/Groups
• OAM Domain
– Admin Server
– Managed Server (OAM): PDP
• WebServer
• WebGate: PEP
• Application: Resource
Oracle Access Manager Architecture
Application RP
Web Server
Application Server
Application
OAM RP Web
Server
OAM Domain
OAM Server
Admin Server
OAM WebGate
Web Tier Application Tier Data Tier
HTTPS
HTTPS
HTTPS
HTTP
HTTP
OAP
LDAP
DB
DB
Oracle Access Manager Architecture
• PEP
– WebGate
– Mod_OSSO
– Access SDK/AccessGate
• OAM Server
– PCF, Session Management, ATN/ATZ,
OPSS
• Backend
– Identity Store
– Policy Store
– Audit Store
Thanks You !!!

More Related Content

Similar to Oracle Identity and access management overview

NaviSite Services - SnapShot
NaviSite Services - SnapShotNaviSite Services - SnapShot
NaviSite Services - SnapShot
Vikram Somani
 
BPM and SOA are going mobile - An architectural perspective
BPM and SOA are going mobile - An architectural perspectiveBPM and SOA are going mobile - An architectural perspective
BPM and SOA are going mobile - An architectural perspective
OPITZ CONSULTING Deutschland
 
How AD has been re-engineered to extend to the cloud
How AD has been re-engineered to extend to the cloudHow AD has been re-engineered to extend to the cloud
How AD has been re-engineered to extend to the cloud
LDAPCon
 
ESB Evaluation Framework
ESB Evaluation FrameworkESB Evaluation Framework
ESB Evaluation Framework
WSO2
 
Keynote oracle days final 16x9 v3.alain
Keynote oracle days final 16x9 v3.alainKeynote oracle days final 16x9 v3.alain
Keynote oracle days final 16x9 v3.alain
Doina Draganescu
 

Similar to Oracle Identity and access management overview (20)

Weblogic 12c experiences - migrations from iAS-platform
Weblogic 12c experiences - migrations from iAS-platformWeblogic 12c experiences - migrations from iAS-platform
Weblogic 12c experiences - migrations from iAS-platform
 
Oracle Identity Governance Technical Overview - 11gR2PS3
Oracle Identity Governance Technical Overview - 11gR2PS3Oracle Identity Governance Technical Overview - 11gR2PS3
Oracle Identity Governance Technical Overview - 11gR2PS3
 
NaviSite Services - SnapShot
NaviSite Services - SnapShotNaviSite Services - SnapShot
NaviSite Services - SnapShot
 
Framework WSo2 orientato ai servizi
Framework WSo2 orientato ai serviziFramework WSo2 orientato ai servizi
Framework WSo2 orientato ai servizi
 
Oim Poc1.0
Oim Poc1.0Oim Poc1.0
Oim Poc1.0
 
Talking Services with Oracle ADF and Oracle SOA Suite
Talking Services with Oracle ADF and Oracle SOA SuiteTalking Services with Oracle ADF and Oracle SOA Suite
Talking Services with Oracle ADF and Oracle SOA Suite
 
BPM and SOA are going mobile - An architectural perspective
BPM and SOA are going mobile - An architectural perspectiveBPM and SOA are going mobile - An architectural perspective
BPM and SOA are going mobile - An architectural perspective
 
BPM und SOA machen mobil - Ein Architekturüberblick
BPM und SOA machen mobil - Ein ArchitekturüberblickBPM und SOA machen mobil - Ein Architekturüberblick
BPM und SOA machen mobil - Ein Architekturüberblick
 
How AD has been re-engineered to extend to the cloud
How AD has been re-engineered to extend to the cloudHow AD has been re-engineered to extend to the cloud
How AD has been re-engineered to extend to the cloud
 
KoprowskiT_session1_SDNEvent_WASDforBeginners
KoprowskiT_session1_SDNEvent_WASDforBeginnersKoprowskiT_session1_SDNEvent_WASDforBeginners
KoprowskiT_session1_SDNEvent_WASDforBeginners
 
ofm-msft-interop-v5c-132827.ppt
ofm-msft-interop-v5c-132827.pptofm-msft-interop-v5c-132827.ppt
ofm-msft-interop-v5c-132827.ppt
 
20190404 Blockchain GIG #2 Oracle Mark発表資料
20190404 Blockchain GIG #2 Oracle Mark発表資料 20190404 Blockchain GIG #2 Oracle Mark発表資料
20190404 Blockchain GIG #2 Oracle Mark発表資料
 
ESB Evaluation Framework
ESB Evaluation FrameworkESB Evaluation Framework
ESB Evaluation Framework
 
Security on AWS, 2021 Edition Meetup
Security on AWS, 2021 Edition MeetupSecurity on AWS, 2021 Edition Meetup
Security on AWS, 2021 Edition Meetup
 
Security on AWS, 2021 Edition Meetup
Security on AWS, 2021 Edition MeetupSecurity on AWS, 2021 Edition Meetup
Security on AWS, 2021 Edition Meetup
 
SaaS External Presentation
SaaS External PresentationSaaS External Presentation
SaaS External Presentation
 
SANS Institute Product Review: Oracle Entitlements Server
SANS Institute Product Review: Oracle Entitlements ServerSANS Institute Product Review: Oracle Entitlements Server
SANS Institute Product Review: Oracle Entitlements Server
 
13 April 2015 DC-Salesservice power.pptx
13 April 2015 DC-Salesservice power.pptx13 April 2015 DC-Salesservice power.pptx
13 April 2015 DC-Salesservice power.pptx
 
Keynote oracle days final 16x9 v3.alain
Keynote oracle days final 16x9 v3.alainKeynote oracle days final 16x9 v3.alain
Keynote oracle days final 16x9 v3.alain
 
Security on AWS
Security on AWSSecurity on AWS
Security on AWS
 

Recently uploaded

Harnessing Passkeys in the Battle Against AI-Powered Cyber Threats.pptx
Harnessing Passkeys in the Battle Against AI-Powered Cyber Threats.pptxHarnessing Passkeys in the Battle Against AI-Powered Cyber Threats.pptx
Harnessing Passkeys in the Battle Against AI-Powered Cyber Threats.pptx
FIDO Alliance
 
“Iamnobody89757” Understanding the Mysterious of Digital Identity.pdf
“Iamnobody89757” Understanding the Mysterious of Digital Identity.pdf“Iamnobody89757” Understanding the Mysterious of Digital Identity.pdf
“Iamnobody89757” Understanding the Mysterious of Digital Identity.pdf
Muhammad Subhan
 

Recently uploaded (20)

Observability Concepts EVERY Developer Should Know (DevOpsDays Seattle)
Observability Concepts EVERY Developer Should Know (DevOpsDays Seattle)Observability Concepts EVERY Developer Should Know (DevOpsDays Seattle)
Observability Concepts EVERY Developer Should Know (DevOpsDays Seattle)
 
Generative AI Use Cases and Applications.pdf
Generative AI Use Cases and Applications.pdfGenerative AI Use Cases and Applications.pdf
Generative AI Use Cases and Applications.pdf
 
Event-Driven Architecture Masterclass: Integrating Distributed Data Stores Ac...
Event-Driven Architecture Masterclass: Integrating Distributed Data Stores Ac...Event-Driven Architecture Masterclass: Integrating Distributed Data Stores Ac...
Event-Driven Architecture Masterclass: Integrating Distributed Data Stores Ac...
 
The Zero-ETL Approach: Enhancing Data Agility and Insight
The Zero-ETL Approach: Enhancing Data Agility and InsightThe Zero-ETL Approach: Enhancing Data Agility and Insight
The Zero-ETL Approach: Enhancing Data Agility and Insight
 
Overview of Hyperledger Foundation
Overview of Hyperledger FoundationOverview of Hyperledger Foundation
Overview of Hyperledger Foundation
 
How to Check CNIC Information Online with Pakdata cf
How to Check CNIC Information Online with Pakdata cfHow to Check CNIC Information Online with Pakdata cf
How to Check CNIC Information Online with Pakdata cf
 
Cyber Insurance - RalphGilot - Embry-Riddle Aeronautical University.pptx
Cyber Insurance - RalphGilot - Embry-Riddle Aeronautical University.pptxCyber Insurance - RalphGilot - Embry-Riddle Aeronautical University.pptx
Cyber Insurance - RalphGilot - Embry-Riddle Aeronautical University.pptx
 
Microsoft CSP Briefing Pre-Engagement - Questionnaire
Microsoft CSP Briefing Pre-Engagement - QuestionnaireMicrosoft CSP Briefing Pre-Engagement - Questionnaire
Microsoft CSP Briefing Pre-Engagement - Questionnaire
 
AI mind or machine power point presentation
AI mind or machine power point presentationAI mind or machine power point presentation
AI mind or machine power point presentation
 
2024 May Patch Tuesday
2024 May Patch Tuesday2024 May Patch Tuesday
2024 May Patch Tuesday
 
Design Guidelines for Passkeys 2024.pptx
Design Guidelines for Passkeys 2024.pptxDesign Guidelines for Passkeys 2024.pptx
Design Guidelines for Passkeys 2024.pptx
 
Harnessing Passkeys in the Battle Against AI-Powered Cyber Threats.pptx
Harnessing Passkeys in the Battle Against AI-Powered Cyber Threats.pptxHarnessing Passkeys in the Battle Against AI-Powered Cyber Threats.pptx
Harnessing Passkeys in the Battle Against AI-Powered Cyber Threats.pptx
 
WebAssembly is Key to Better LLM Performance
WebAssembly is Key to Better LLM PerformanceWebAssembly is Key to Better LLM Performance
WebAssembly is Key to Better LLM Performance
 
Continuing Bonds Through AI: A Hermeneutic Reflection on Thanabots
Continuing Bonds Through AI: A Hermeneutic Reflection on ThanabotsContinuing Bonds Through AI: A Hermeneutic Reflection on Thanabots
Continuing Bonds Through AI: A Hermeneutic Reflection on Thanabots
 
TEST BANK For, Information Technology Project Management 9th Edition Kathy Sc...
TEST BANK For, Information Technology Project Management 9th Edition Kathy Sc...TEST BANK For, Information Technology Project Management 9th Edition Kathy Sc...
TEST BANK For, Information Technology Project Management 9th Edition Kathy Sc...
 
Extensible Python: Robustness through Addition - PyCon 2024
Extensible Python: Robustness through Addition - PyCon 2024Extensible Python: Robustness through Addition - PyCon 2024
Extensible Python: Robustness through Addition - PyCon 2024
 
The Metaverse: Are We There Yet?
The  Metaverse:    Are   We  There  Yet?The  Metaverse:    Are   We  There  Yet?
The Metaverse: Are We There Yet?
 
Frisco Automating Purchase Orders with MuleSoft IDP- May 10th, 2024.pptx.pdf
Frisco Automating Purchase Orders with MuleSoft IDP- May 10th, 2024.pptx.pdfFrisco Automating Purchase Orders with MuleSoft IDP- May 10th, 2024.pptx.pdf
Frisco Automating Purchase Orders with MuleSoft IDP- May 10th, 2024.pptx.pdf
 
WebRTC and SIP not just audio and video @ OpenSIPS 2024
WebRTC and SIP not just audio and video @ OpenSIPS 2024WebRTC and SIP not just audio and video @ OpenSIPS 2024
WebRTC and SIP not just audio and video @ OpenSIPS 2024
 
“Iamnobody89757” Understanding the Mysterious of Digital Identity.pdf
“Iamnobody89757” Understanding the Mysterious of Digital Identity.pdf“Iamnobody89757” Understanding the Mysterious of Digital Identity.pdf
“Iamnobody89757” Understanding the Mysterious of Digital Identity.pdf
 

Oracle Identity and access management overview

  • 1. Oracle IAM Suite - Kali Kishore Gomattam
  • 2. Agenda • Oracle Identity & Access Management Concepts • Fusion Middleware Concepts • Oracle Access Manager Architecture • WebLogic Concepts – Domain, Servers (Admin & Managed) – Data Sources – Node Manager • Repository Creation Utility (RCU)
  • 3. Oracle IAM Products Access Control Oracle Access Manager Oracle Identity Federation Oracle Adaptive Access Manager Oracle Entitlements Server Oracle Enterprise SSO Identity Administration Oracle Identity Manager Oracle Privileged Account Manager Oracle Identity Analytics Mobile Security Oracle Mobile Security Suite Directory Services Oracle Unified Directory Oracle Internet Directory Oracle Virtual Directory Oracle Directory Services EE
  • 4. Oracle IAM Solutions Access Control Authentication & Authorization Single Sign-On Federation Web Services Security Identity Administration Identity Lifecycle Administration Role & Membership Administration Provisioning & Reconciliation Compliance Automation Mobile Security Access Corporate Data from anywhere Secure Workspace Directory Services Virtualization Synchronization Storage
  • 6. Oracle Access Management Access Manager Fine Grained Entitlements Federating Identities Mobile Security Fraud Prevention Risk Analysis Single Sign On Social Integration
  • 7. Oracle Access Manager • Java EE application that provides • Web Single Sign-On Service include Identity Context • Authentication & Authorization • Policy, Session, Agent Management • Authentication & Coarse Grained Authorization • Product from Oblix acquired in 2005 • Part of Oracle IDAM Software • Deployed on Oracle Weblogic Server • Versions: 11gR2 (PS3, PS2, PS1), 11gR1, 10g
  • 8. Oracle Adaptive Access Manager • Real Time Risk Analysis & Fraud Prevention • Multi Factor Authentication • Offline & Online Risk Analysis • Product from Bharosa acquired in 2007 • Part of Oracle IDAM Software • Deployed on Oracle Weblogic Server • Versions: 11gR2 (PS3, PS2, PS1), 11gR1, 10g
  • 9. Oracle Identity Federation • Secure Identity Information exchange between two parties • Cross domain SSO • Supports SAML 2.0 • Was part of Oracle IDM (with OID/OVD) and now merged with Oracle Access Management
  • 10. Oracle Entitlement Server: OES • Oracle Entitlements Server (OES) is a standards-based, policy-driven security solution that provides real time fine-grained authorization in Application, Service-Oriented Architecture (SOA) and Database environments. • OES fills the need for granular, flexible, and externalized access control. • The solution provides a comprehensive and centralized approach for managing access policies with distributed or centralized enforcement. • Authorization policy management and runtime enforcement is provided for sensitive applications, databases, containers (such as Java™, .NET), portals and content management systems (such as WebCenter and SharePoint), development frameworks, object relational mapping technologies, intermediaries (such as XML gateways and ESB’s), web services, and SOA infrastructure.
  • 11. Oracle Web Service Manager • Solution for defining policies and securing Web Services • Web Service security includes authentication, authorization, message encryption/decryption, and identity propagation • Component of Oracle SOA suite and installed as part of SOA
  • 12. Oracle API Gateway (OAG) • First line of defense securing web services, web APIs deployed in premise or in the cloud. • With OAG, internal system and corporate data can be exposed as fully secure REST API • OAG integrates with Oracle Access Management core services, Oracle Web Services Manager and third party Access Management systems • OAG can be deployed on premise and access APIs hosted in cloud or can be deployed in cloud
  • 13. Oracle Access Manager Overview • Entitlements Management • Fine Grained Authorization • Risk-based Authentication • Real-time Fraud Prevention • Web Access Control • Single Sign-On • Security Token Management • Identity Propagation
  • 16. Lightweight Directory Access Protocol • Lightweight Directory Access Protocol • An application protocol • For querying and modifying directory services • Runs over TCP/IP • Directory • A set of objects with similar attributes • Organized in a logical and hierarchical manner Example: Telephone directory
  • 17. Directory Services • Oracle Unified Directory (OUD) • Oracle Internet Directory (OID) • Oracle Virtual Directory (OVD) • Oracle Directory Services EE (ODSEE) • Oracle Directory Integration Platform (DIP)
  • 18. Oracle Unified Directory: OUD • LDAP v3 compliant directory server with • Directory Server • Replication • Proxy • No database requirement • Recommended Directory Server for new/large deployments
  • 19. Oracle Internet Directory: OID • LDAP v3 compliant directory server • Data is stored in Oracle Database • Supports Multi Master Replication
  • 20. Oracle Virtual Directory: OVD • Virtualisation layer for Multiple User Repository • Installed as part of IDM software (11gR1 latest)
  • 21. Oracle Directory Integration Platform (DIP) • J2EE application deployed on Weblogic Server • Configure with OID/OUD to synch with other user repository • Two Modules – Synchronization – Provisioning
  • 22. Oracle Access Manager Architecture
  • 23. Oracle Access Manager Architecture Features – Web single-sign-on – Multi-level, multi-factor authentication management – Web Services interfaces Benefits – Centralized and consistent security across heterogeneous environment – Reduced administration cost – Improved end user experience
  • 24. Oracle Access Manager Architecture • OAM DB: Policy Store & Metadata • LDAP Store: Users/Groups • OAM Domain – Admin Server – Managed Server (OAM): PDP • WebServer • WebGate: PEP • Application: Resource
  • 25. Oracle Access Manager Architecture Application RP Web Server Application Server Application OAM RP Web Server OAM Domain OAM Server Admin Server OAM WebGate Web Tier Application Tier Data Tier HTTPS HTTPS HTTPS HTTP HTTP OAP LDAP DB DB
  • 26. Oracle Access Manager Architecture • PEP – WebGate – Mod_OSSO – Access SDK/AccessGate • OAM Server – PCF, Session Management, ATN/ATZ, OPSS • Backend – Identity Store – Policy Store – Audit Store

Editor's Notes

  1. Oracle Identity Governance provides Identity Lifecycle Management (Create, Modify, Enable, Disable, password management, provisioning, reconciliation) Simplified Access Request (Self Service, Shopping Cart style, Catalog of resource/roles , Approval based) Advanced Role Lifecycle Management (Role discovery, Role Consolidation, impact analysis of role consolidation, role auditing) Privileged Account Management (Managing, Auditing, Approval based access on privileged accounts like root, sysadmin, system, apps etc..) Identity Certification ( Who has access to what certification, Closed Loop Remediation/revoking un-authorised access) Audit & Monitoring ( Audit on who did what and when including monitoring of system )
  2. Bring Your Own Device Out of the box mobile apps Oracle Mobile Security Container Oracle Mobile Security Access Server (MSAS) Oracle Mobile Security Manager (MSM)
  3. Oracle Unified Directory (OUD) Oracle Internet Directory (OID) Oracle Virtual Directory (OVD) Oracle Directory Integration Platform (DIP)