SlideShare a Scribd company logo
1 of 20
1
2
“Connectors are killing me!”
3
Carlton’s situation
Homegrown
IAM System
4
ERP
CRM
HR
Expenses
Project Management
Vacation Management
Survey Tools
Carlton’s situation
Homegrown
IAM System
5
“I can’t do this anymore!”
6
New
rules
7
“We’ve reached the tipping point.”
8
What is SCIM?
System for Cross Domain Identity Management
SCIM is a standard that defines a
Schema and API for managing identities
REST JSON
9
What is SCIM?
SCIM handles provisioning and deprovisioning
access, and provides a way to read identity
information.
C R U D
10
11
When a user leaves…
On-Premises
Applications
EmployeeHR
SaaS
Applications
12
User is deprovisioned!
On-Premises
Applications
SaaS
Applications
13
Provisioning Evolution – Prehistoric (1999)
14
Provisioning Evolution – Age of Connectors
15
Provisioning Evolution – SCIM
one
16
2.01.1
TODAY
17
SCIM Interop
18
“Carlton, SCIM Can Help!”
19
SCIM – A Better Way
20
¡Viva La Revolución!

More Related Content

Similar to SCIM Smackdown Catalyst 2013

Science agora 20161106 v2
Science agora 20161106 v2Science agora 20161106 v2
Science agora 20161106 v2ISSIP
 
SaltStack - An open source software story
SaltStack - An open source software storySaltStack - An open source software story
SaltStack - An open source software storySaltStack
 
Regain Control of you Digital Strategy with Backbase Engage
Regain Control of you Digital Strategy with Backbase EngageRegain Control of you Digital Strategy with Backbase Engage
Regain Control of you Digital Strategy with Backbase EngageBackbase
 
Nasscom how can you identify fraud in fintech lending using deep learning
Nasscom how can you identify fraud in fintech lending using deep learningNasscom how can you identify fraud in fintech lending using deep learning
Nasscom how can you identify fraud in fintech lending using deep learningRatnakar Pandey
 
101 Webinar - Artificial Intelligence, Deep Learning and Geospatial
101 Webinar - Artificial Intelligence, Deep Learning and Geospatial101 Webinar - Artificial Intelligence, Deep Learning and Geospatial
101 Webinar - Artificial Intelligence, Deep Learning and GeospatialGeospatial Media & Communications
 
Micro service, Containers & Cluster Management
Micro service, Containers & Cluster ManagementMicro service, Containers & Cluster Management
Micro service, Containers & Cluster ManagementVasu Thiyagarajan
 
Big Data Bootcamp 2017 - Atlanta - Flavio Villanustre
Big Data Bootcamp 2017 - Atlanta - Flavio VillanustreBig Data Bootcamp 2017 - Atlanta - Flavio Villanustre
Big Data Bootcamp 2017 - Atlanta - Flavio VillanustreHPCC Systems
 
Sure you’re growing, but are you scaling?
Sure you’re growing, but are you scaling?Sure you’re growing, but are you scaling?
Sure you’re growing, but are you scaling?Publicis Sapient
 
What are distributed ledgers (actually) good for?
What are distributed ledgers (actually) good for?What are distributed ledgers (actually) good for?
What are distributed ledgers (actually) good for?Sebastien Meunier
 
Webinar: Get to the Cloud and Big Data Faster with Modern Data Integration
Webinar: Get to the Cloud and Big Data Faster with Modern Data IntegrationWebinar: Get to the Cloud and Big Data Faster with Modern Data Integration
Webinar: Get to the Cloud and Big Data Faster with Modern Data IntegrationSnapLogic
 
CIS 2015- NAPPS within Public Safety- Adam Lewis
CIS 2015- NAPPS within Public Safety- Adam LewisCIS 2015- NAPPS within Public Safety- Adam Lewis
CIS 2015- NAPPS within Public Safety- Adam LewisCloudIDSummit
 
A People's History of Microservices
A People's History of MicroservicesA People's History of Microservices
A People's History of MicroservicesCamille Fournier
 
Distributesd Tracing in Serverless Systems - Shannon Hogue, Epsagon - Cloud N...
Distributesd Tracing in Serverless Systems - Shannon Hogue, Epsagon - Cloud N...Distributesd Tracing in Serverless Systems - Shannon Hogue, Epsagon - Cloud N...
Distributesd Tracing in Serverless Systems - Shannon Hogue, Epsagon - Cloud N...Cloud Native Day Tel Aviv
 
Welch owasp-feb-2015
Welch owasp-feb-2015Welch owasp-feb-2015
Welch owasp-feb-2015Von Welch
 
The future will be Serverless (FrontConf Munich 2017)
The future will be Serverless (FrontConf Munich 2017)The future will be Serverless (FrontConf Munich 2017)
The future will be Serverless (FrontConf Munich 2017)Luciano Mammino
 

Similar to SCIM Smackdown Catalyst 2013 (16)

Science agora 20161106 v2
Science agora 20161106 v2Science agora 20161106 v2
Science agora 20161106 v2
 
SaltStack - An open source software story
SaltStack - An open source software storySaltStack - An open source software story
SaltStack - An open source software story
 
Regain Control of you Digital Strategy with Backbase Engage
Regain Control of you Digital Strategy with Backbase EngageRegain Control of you Digital Strategy with Backbase Engage
Regain Control of you Digital Strategy with Backbase Engage
 
Nasscom how can you identify fraud in fintech lending using deep learning
Nasscom how can you identify fraud in fintech lending using deep learningNasscom how can you identify fraud in fintech lending using deep learning
Nasscom how can you identify fraud in fintech lending using deep learning
 
101 Webinar - Artificial Intelligence, Deep Learning and Geospatial
101 Webinar - Artificial Intelligence, Deep Learning and Geospatial101 Webinar - Artificial Intelligence, Deep Learning and Geospatial
101 Webinar - Artificial Intelligence, Deep Learning and Geospatial
 
Micro service, Containers & Cluster Management
Micro service, Containers & Cluster ManagementMicro service, Containers & Cluster Management
Micro service, Containers & Cluster Management
 
Big Data Bootcamp 2017 - Atlanta - Flavio Villanustre
Big Data Bootcamp 2017 - Atlanta - Flavio VillanustreBig Data Bootcamp 2017 - Atlanta - Flavio Villanustre
Big Data Bootcamp 2017 - Atlanta - Flavio Villanustre
 
Sure you’re growing, but are you scaling?
Sure you’re growing, but are you scaling?Sure you’re growing, but are you scaling?
Sure you’re growing, but are you scaling?
 
What are distributed ledgers (actually) good for?
What are distributed ledgers (actually) good for?What are distributed ledgers (actually) good for?
What are distributed ledgers (actually) good for?
 
Webinar: Get to the Cloud and Big Data Faster with Modern Data Integration
Webinar: Get to the Cloud and Big Data Faster with Modern Data IntegrationWebinar: Get to the Cloud and Big Data Faster with Modern Data Integration
Webinar: Get to the Cloud and Big Data Faster with Modern Data Integration
 
CIS 2015- NAPPS within Public Safety- Adam Lewis
CIS 2015- NAPPS within Public Safety- Adam LewisCIS 2015- NAPPS within Public Safety- Adam Lewis
CIS 2015- NAPPS within Public Safety- Adam Lewis
 
A People's History of Microservices
A People's History of MicroservicesA People's History of Microservices
A People's History of Microservices
 
Distributesd Tracing in Serverless Systems - Shannon Hogue, Epsagon - Cloud N...
Distributesd Tracing in Serverless Systems - Shannon Hogue, Epsagon - Cloud N...Distributesd Tracing in Serverless Systems - Shannon Hogue, Epsagon - Cloud N...
Distributesd Tracing in Serverless Systems - Shannon Hogue, Epsagon - Cloud N...
 
Welch owasp-feb-2015
Welch owasp-feb-2015Welch owasp-feb-2015
Welch owasp-feb-2015
 
The future will be Serverless (FrontConf Munich 2017)
The future will be Serverless (FrontConf Munich 2017)The future will be Serverless (FrontConf Munich 2017)
The future will be Serverless (FrontConf Munich 2017)
 
Digital Workloads on AWS
Digital Workloads on AWSDigital Workloads on AWS
Digital Workloads on AWS
 

Recently uploaded

GenAI Risks & Security Meetup 01052024.pdf
GenAI Risks & Security Meetup 01052024.pdfGenAI Risks & Security Meetup 01052024.pdf
GenAI Risks & Security Meetup 01052024.pdflior mazor
 
MS Copilot expands with MS Graph connectors
MS Copilot expands with MS Graph connectorsMS Copilot expands with MS Graph connectors
MS Copilot expands with MS Graph connectorsNanddeep Nachan
 
Ransomware_Q4_2023. The report. [EN].pdf
Ransomware_Q4_2023. The report. [EN].pdfRansomware_Q4_2023. The report. [EN].pdf
Ransomware_Q4_2023. The report. [EN].pdfOverkill Security
 
TrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
TrustArc Webinar - Unlock the Power of AI-Driven Data DiscoveryTrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
TrustArc Webinar - Unlock the Power of AI-Driven Data DiscoveryTrustArc
 
Apidays Singapore 2024 - Modernizing Securities Finance by Madhu Subbu
Apidays Singapore 2024 - Modernizing Securities Finance by Madhu SubbuApidays Singapore 2024 - Modernizing Securities Finance by Madhu Subbu
Apidays Singapore 2024 - Modernizing Securities Finance by Madhu Subbuapidays
 
"I see eyes in my soup": How Delivery Hero implemented the safety system for ...
"I see eyes in my soup": How Delivery Hero implemented the safety system for ..."I see eyes in my soup": How Delivery Hero implemented the safety system for ...
"I see eyes in my soup": How Delivery Hero implemented the safety system for ...Zilliz
 
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...apidays
 
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FMESafe Software
 
Corporate and higher education May webinar.pptx
Corporate and higher education May webinar.pptxCorporate and higher education May webinar.pptx
Corporate and higher education May webinar.pptxRustici Software
 
Automating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps ScriptAutomating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps Scriptwesley chun
 
Polkadot JAM Slides - Token2049 - By Dr. Gavin Wood
Polkadot JAM Slides - Token2049 - By Dr. Gavin WoodPolkadot JAM Slides - Token2049 - By Dr. Gavin Wood
Polkadot JAM Slides - Token2049 - By Dr. Gavin WoodJuan lago vázquez
 
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot TakeoffStrategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoffsammart93
 
Manulife - Insurer Transformation Award 2024
Manulife - Insurer Transformation Award 2024Manulife - Insurer Transformation Award 2024
Manulife - Insurer Transformation Award 2024The Digital Insurer
 
A Beginners Guide to Building a RAG App Using Open Source Milvus
A Beginners Guide to Building a RAG App Using Open Source MilvusA Beginners Guide to Building a RAG App Using Open Source Milvus
A Beginners Guide to Building a RAG App Using Open Source MilvusZilliz
 
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemkeProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemkeProduct Anonymous
 
Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...apidays
 
EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWER
EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWEREMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWER
EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWERMadyBayot
 
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost SavingRepurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost SavingEdi Saputra
 
Data Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt RobisonData Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt RobisonAnna Loughnan Colquhoun
 
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...apidays
 

Recently uploaded (20)

GenAI Risks & Security Meetup 01052024.pdf
GenAI Risks & Security Meetup 01052024.pdfGenAI Risks & Security Meetup 01052024.pdf
GenAI Risks & Security Meetup 01052024.pdf
 
MS Copilot expands with MS Graph connectors
MS Copilot expands with MS Graph connectorsMS Copilot expands with MS Graph connectors
MS Copilot expands with MS Graph connectors
 
Ransomware_Q4_2023. The report. [EN].pdf
Ransomware_Q4_2023. The report. [EN].pdfRansomware_Q4_2023. The report. [EN].pdf
Ransomware_Q4_2023. The report. [EN].pdf
 
TrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
TrustArc Webinar - Unlock the Power of AI-Driven Data DiscoveryTrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
TrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
 
Apidays Singapore 2024 - Modernizing Securities Finance by Madhu Subbu
Apidays Singapore 2024 - Modernizing Securities Finance by Madhu SubbuApidays Singapore 2024 - Modernizing Securities Finance by Madhu Subbu
Apidays Singapore 2024 - Modernizing Securities Finance by Madhu Subbu
 
"I see eyes in my soup": How Delivery Hero implemented the safety system for ...
"I see eyes in my soup": How Delivery Hero implemented the safety system for ..."I see eyes in my soup": How Delivery Hero implemented the safety system for ...
"I see eyes in my soup": How Delivery Hero implemented the safety system for ...
 
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
 
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
 
Corporate and higher education May webinar.pptx
Corporate and higher education May webinar.pptxCorporate and higher education May webinar.pptx
Corporate and higher education May webinar.pptx
 
Automating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps ScriptAutomating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps Script
 
Polkadot JAM Slides - Token2049 - By Dr. Gavin Wood
Polkadot JAM Slides - Token2049 - By Dr. Gavin WoodPolkadot JAM Slides - Token2049 - By Dr. Gavin Wood
Polkadot JAM Slides - Token2049 - By Dr. Gavin Wood
 
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot TakeoffStrategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
 
Manulife - Insurer Transformation Award 2024
Manulife - Insurer Transformation Award 2024Manulife - Insurer Transformation Award 2024
Manulife - Insurer Transformation Award 2024
 
A Beginners Guide to Building a RAG App Using Open Source Milvus
A Beginners Guide to Building a RAG App Using Open Source MilvusA Beginners Guide to Building a RAG App Using Open Source Milvus
A Beginners Guide to Building a RAG App Using Open Source Milvus
 
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemkeProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
 
Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...
 
EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWER
EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWEREMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWER
EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWER
 
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost SavingRepurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
 
Data Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt RobisonData Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt Robison
 
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...
 

SCIM Smackdown Catalyst 2013

Editor's Notes

  1. Thanks Ian. A few weeks ago I was up in Napa at the Cloud Identity Summit … which btw, is a great place to visit … HORRIBLEplace for a conference.  Being in the middle of the wine country I only remember half of the conversations I had.But … I vividly remember two of them because they were almost identical. 
  2. I was talking with two really smart, forward-thinking guys that are responsible for the identity side of the IT infrastructure at their companies and they both told me the exact same thing.  They said: “Kelly, connectors are killing me!!!”
  3. One of them, Carlton, told me that his company – with over 82,000 employees - has a home grown identity management system that talks to 3500 target systems.  3500!!! 
  4. Any time a group starts using a new application, it has to get tied into his infrastructure.  ERP, CRM, HR systems, expense tracking, project management… EVERY freaking system has an identity associated with it.
  5. So Carlton told his consumers… “I can’t do this anymore!! Connectors are killing me. In this new world of bring your own application (BYOA), I can’t keep up with bringing all of your applications into my infrastructure.”  So he drew a line in the sand. 
  6. He laid down some new rules, he said:“We’ll continue to support any application that we currently support … however… going forward if you want to tie into our identity infrastructure, your application must be able to talk SCIM.  If it doesn’t, you’re going to be stuck holding the bag to get it connected.”
  7. These new friends of mine from Napa aren’t alone. We have finally hit the tipping point.  It’s too expensive to keep writing or buyingconnectors to every system that your end users want to use.  You still need to be able to manage them to keep some sort of governance controls over them.
  8. That’s where SCIM can help. The System for Cross-domain Identity Management – is a standard that defines a Schema and API for managing identities…. all built using REST and JSON.
  9. Unlike the other standards on stage that handle authentication and authorization…SCIM handles provisioning and deprovisioning access, and provides a way to read identity and group information.Your basic CRUD – create, read, update, delete.
  10. For you geeks out there … if you’re like me your brain thinks in code. If this makes your eyes glaze over … just look away.  This is a SCIM request to read a user named Barbara Jensen.  You see curl doing an HTTP GET to read the user.  To get rid of the user, just change this to a DELETE.
  11. Let’s quickly review the evolution of provisioning starting with a termination use case. An employee is terminated effective immediately due to <insert your favorite HR violation> HR escorts the employee out the door that day.
  12. but all of his accounts to these applications still exist. It’s your job as the identity guy to make sure that his access is shut off immediately and all of his entitlements are effectively removed.How do you do this??
  13. In the early days of provisioning…people knew that they had to manage identities but…they lacked the right tools.So what did they do? They used what they had – EMAIL! This came with obvious problems … latency, human error, forgotten/orphaned accounts…
  14. In 2000, identity management vendors starting popping up to help solve this problem. How? With CONNECTORS!! They started developing connectors for every type of application out there. What’s the problem? COST – somebody is paying for all those custom connectors.
  15. Now we’ve realized that we’re trying to reinvent the wheel. All of these connectors do basically the same thing, just in different ways. If all applications spoke the same language, you would only need one connector!If all applications spoke SCIM, it would be simple to just plug them together.
  16. AdoptionSo … where does SCIM stand today? Last July, the SCIM 1.1 spec was finalized and many companies already have (or are in the process of) implementing it.We’re working on the 2.0 spec to clean up some of the loose endsAnd hope to have it ready in 6 months. [There are 14 known SCIM 1.1 implementations.]
  17. InteropBack in Napa, eight products –including Salesforce, SailPoint, and Ping – participated in a SCIM interop eventshowcasing manyprovisioning use cases. SailPoint was pulling identitiesfrom Salesforce and syncing joiner, mover, leaver, and password events to Ping.
  18. Connectors are killing you…So let's return to my friend, Carlton, being suffocated by connectors. In a world of wide-spread SCIM adoption, here's how his life would be different. Instead of spending all of his time writing connectors or making existing applications speak SCIM, he can focus on real business problems …
  19. …like determining who are the riskiest usersensuring that everyone has the appropriate access … not too much, not too little automating the business processes around the identity lifecycle or giving his users a friendly portal where they can request changes.
  20. It’s time to free ourselves from the bondage of the past 15 years. …and, kill the connector.Tell your vendors to support SCIM or you won’t play ball. Join the Revolution,visit the SCIM site at www.simplecloud.info Thanks!