A New Breed Of Identity ManagementFrom Code to Visual Process Management EmpowerID WF ProcessTraditional Identity ManagementCopyright © 2011. Dot Net Workflow is a trademark of The Dot Net Factory, LLC.  |www.TheDotNetFactory.com1
User Manager: Role-Based User Provisioning and Delegated Administration
Introducing User ManagerWorkflow Automation of User Lifecycle ManagementAccording to the Gartner Group, organizations can save 300% with automated user provisioningThe ChallengeDuring good and bad economic times there is an increase in employee turnover. Provisioning user accounts and granting access across multiple systems is a costly and time consuming process. Quickly and efficiently deprovisioning access when and employee leaves the organization is even more time consuming and error prone, often exposing an organization to security vulnerabilities.EmpowerID SolutionUser Manager is a workflow and role-based solution that automates provisioning access for new employees and deprovisioning access when they change positions or leave the organization.Copyright © 2011. empowerID is a trademark of The Dot Net Factory, LLC.  |www.empowerid.com3
A request is submitted as a ticket to the helpdesk requesting accounts and access for the new employeeThe helpdesk has a large backlog of tickets which delays creation of the accounts and postpones employee productivitycommon ratio for large companies – 1 helpdesk admin/6000 users!In the meantime, the user cannot access resources they need to perform their job – e.g. email, file shares, printers, etc...The helpdesk must search in each system to verify name uniquenessEventually the accounts are created and access is grantedProcess Challenges:Manual provisioning requires the involvement of multiple IT staff and a high level of organizational knowledgeIT is unable to detect security changes in AD and other systemsNo automated removal of application and system accessLack of a good audit trail to attest to why access was granted and who approvedCopyright © 2011. empowerID is a trademark of The Dot Net Factory, LLC.  |www.empowerid.com4When Will I Get Access?Typical Process Before EmpowerID
5ProvisioningRoutine UserAdministrationChangeLocationsNew ProjectForgotPasswordRelationshipEndsPasswordExpiresPasswordManagementDeprovisioningRelationship BeginsPromotionUSERLIFECYCLECopyright © 2011. empowerID is a trademark of The Dot Net Factory, LLC.  |www.empowerid.comIdentity Lifecycle ManagementManage the Lifecycle of a Person and Their Accounts
Identity Lifecycle ManagementManage the Lifecycle of a Person and Their AccountsDiscovers and links a person’s user accounts in all systems
Automates provisioning and deprovisioning with workflow
Synchronizes user information between systems and provides self-service edit
Synchronizes passwords and enables self-service reset and unlock (Password Manager)
Self-service new account registration workflows with approvals
Delegates role-based administration of people and their accounts
Achieves continuous compliance through constant enforcement of policiesPerson6
Automates provisioning, moving, and deprovisioning of user accounts and resources based upon the roles of the userRole membership can be automated based upon mappings to existing authoritative systems, by rules, or assigned via workflows with approvals
Examples of Resource Entitlements:Accounts in connected systemsExchange MailboxesHome Foldersetc…Resource Entitlements are automatically re-calculated and provisioned, moved or deprovisioned when a Person’s roles change
Automated deprovisoning of user accounts prevents accumulation of privileges over time and ensures that access is revoked when an employee leaves the organizationCopyright © 2011. empowerID is a trademark of The Dot Net Factory, LLC.  |www.empowerid.com7Resource EntitlementsAutomatic Provisioning and Deprovisioning of Accounts and Resources

User Manager

  • 1.
    A New BreedOf Identity ManagementFrom Code to Visual Process Management EmpowerID WF ProcessTraditional Identity ManagementCopyright © 2011. Dot Net Workflow is a trademark of The Dot Net Factory, LLC. |www.TheDotNetFactory.com1
  • 2.
    User Manager: Role-BasedUser Provisioning and Delegated Administration
  • 3.
    Introducing User ManagerWorkflowAutomation of User Lifecycle ManagementAccording to the Gartner Group, organizations can save 300% with automated user provisioningThe ChallengeDuring good and bad economic times there is an increase in employee turnover. Provisioning user accounts and granting access across multiple systems is a costly and time consuming process. Quickly and efficiently deprovisioning access when and employee leaves the organization is even more time consuming and error prone, often exposing an organization to security vulnerabilities.EmpowerID SolutionUser Manager is a workflow and role-based solution that automates provisioning access for new employees and deprovisioning access when they change positions or leave the organization.Copyright © 2011. empowerID is a trademark of The Dot Net Factory, LLC. |www.empowerid.com3
  • 4.
    A request issubmitted as a ticket to the helpdesk requesting accounts and access for the new employeeThe helpdesk has a large backlog of tickets which delays creation of the accounts and postpones employee productivitycommon ratio for large companies – 1 helpdesk admin/6000 users!In the meantime, the user cannot access resources they need to perform their job – e.g. email, file shares, printers, etc...The helpdesk must search in each system to verify name uniquenessEventually the accounts are created and access is grantedProcess Challenges:Manual provisioning requires the involvement of multiple IT staff and a high level of organizational knowledgeIT is unable to detect security changes in AD and other systemsNo automated removal of application and system accessLack of a good audit trail to attest to why access was granted and who approvedCopyright © 2011. empowerID is a trademark of The Dot Net Factory, LLC. |www.empowerid.com4When Will I Get Access?Typical Process Before EmpowerID
  • 5.
    5ProvisioningRoutine UserAdministrationChangeLocationsNew ProjectForgotPasswordRelationshipEndsPasswordExpiresPasswordManagementDeprovisioningRelationshipBeginsPromotionUSERLIFECYCLECopyright © 2011. empowerID is a trademark of The Dot Net Factory, LLC. |www.empowerid.comIdentity Lifecycle ManagementManage the Lifecycle of a Person and Their Accounts
  • 6.
    Identity Lifecycle ManagementManagethe Lifecycle of a Person and Their AccountsDiscovers and links a person’s user accounts in all systems
  • 7.
    Automates provisioning anddeprovisioning with workflow
  • 8.
    Synchronizes user informationbetween systems and provides self-service edit
  • 9.
    Synchronizes passwords andenables self-service reset and unlock (Password Manager)
  • 10.
    Self-service new accountregistration workflows with approvals
  • 11.
    Delegates role-based administrationof people and their accounts
  • 12.
    Achieves continuous compliancethrough constant enforcement of policiesPerson6
  • 13.
    Automates provisioning, moving,and deprovisioning of user accounts and resources based upon the roles of the userRole membership can be automated based upon mappings to existing authoritative systems, by rules, or assigned via workflows with approvals
  • 14.
    Examples of ResourceEntitlements:Accounts in connected systemsExchange MailboxesHome Foldersetc…Resource Entitlements are automatically re-calculated and provisioned, moved or deprovisioned when a Person’s roles change
  • 15.
    Automated deprovisoning ofuser accounts prevents accumulation of privileges over time and ensures that access is revoked when an employee leaves the organizationCopyright © 2011. empowerID is a trademark of The Dot Net Factory, LLC. |www.empowerid.com7Resource EntitlementsAutomatic Provisioning and Deprovisioning of Accounts and Resources