SlideShare a Scribd company logo
When IGA meets PAM…
Through their mutual friend SCIM
Kelly Grizzle
Copyright © SailPoint Technologies, Inc. 2017. All rights reserved. 2
Copyright © SailPoint Technologies, Inc. 2017. All rights reserved. 3
You might be starting to feel like…
Copyright © SailPoint Technologies, Inc. 2017. All rights reserved. 4
To avoid this … we’ll have FUN WITH MAD LIBS!!!
Copyright © SailPoint Technologies, Inc. 2017. All rights reserved. 5
Copyright © SailPoint Technologies, Inc. 2017. All rights reserved. 6
Gimme some words!!!
Emotion
Adjective
Plural noun
hung overness
strong
computers
Copyright © SailPoint Technologies, Inc. 2017. All rights reserved. 7
What are we talking about?
• What is IGA?
• What is PAM?
• What’s the problem?
• How do we join these two worlds?
Copyright © SailPoint Technologies, Inc. 2017. All rights reserved. 8
What is IGA?
Copyright © SailPoint Technologies, Inc. 2017. All rights reserved. 9
Identity Governance and Administration
Governance
• Access Review
• Approval
• Policy Checking
• Role Management
• Analytics
• Auditing
Administration
• Access Request
• Account Management
• Password Management
• Identity Lifecycle
Management
• Provisioning
• Automated Workflows
Copyright © SailPoint Technologies, Inc. 2017. All rights reserved. 10
Words!!!
Occupation that starts with “C”
Plural noun
Place
dogs
Coroners
Bars
Copyright © SailPoint Technologies, Inc. 2017. All rights reserved. 11
What is PAM?
Copyright © SailPoint Technologies, Inc. 2017. All rights reserved. 12Copyright © SailPoint Technologies, Inc. 2017. All rights reserved. 12
Privileged Access Management
Controls access to privileged data –
most often credentials for privileged
accounts
Copyright © SailPoint Technologies, Inc. 2017. All rights reserved. 13
Copyright © SailPoint Technologies, Inc. 2017. All rights reserved. 14
Copyright © SailPoint Technologies, Inc. 2017. All rights reserved. 15
Copyright © SailPoint Technologies, Inc. 2017. All rights reserved. 16
Copyright © SailPoint Technologies, Inc. 2017. All rights reserved. 17
Copyright © SailPoint Technologies, Inc. 2017. All rights reserved. 18
Privileged Account Management Provides
• Account sharing
• Tracking and auditing actions taken with privileged accounts
• Passwords become invisible to end users
• Automatic rotation of credentials
• Highly secure passwords
Copyright © SailPoint Technologies, Inc. 2017. All rights reserved. 19
More words!!!
Adverb
Body part
Plural noun
Adjective
fingernail
slowly
identerati
handsome
Copyright © SailPoint Technologies, Inc. 2017. All rights reserved. 20
What’s the problem?
Copyright © SailPoint Technologies, Inc. 2017. All rights reserved. 21
Two Amazing … But Siloed … Technologies
• Historically, IGA and PAM systems have not been integrated
• Most companies that care about security have a need for both
• IGA software is a bit weak in dealing with shared accounts
• Who owns the account?
• How do you request access to a shared account?
• PAM software does not provide governance controls
• No access reviews
• No policy checking
• Etc…
Copyright © SailPoint Technologies, Inc. 2017. All rights reserved. 22
Words Please!!!
Plural noun that starts with “M”
Emotion
Food or drink
fearful
Monkeys
coffee
Copyright © SailPoint Technologies, Inc. 2017. All rights reserved. 23
How to join these
worlds … SCIM!
Copyright © SailPoint Technologies, Inc. 2017. All rights reserved. 24Copyright © SailPoint Technologies, Inc. 2017. All rights reserved. 24
What is SCIM?
System for Cross-Domain Identity Management
Copyright © SailPoint Technologies, Inc. 2017. All rights reserved. 25Copyright © SailPoint Technologies, Inc. 2017. All rights reserved. 25
Identity Management
+
REST
=
Copyright © SailPoint Technologies, Inc. 2017. All rights reserved. 26
SCIM PAM Extension
• SCIM provides a REST API and JSON representations for users
and groups
• The SCIM PAM Extension is a new specification that augments
SCIM 2.0 to bridge IGA and PAM
• New concepts in SCIM PAM extension:
• Privileged data
• Containers
• Access control lists for containers and privileged data
Copyright © SailPoint Technologies, Inc. 2017. All rights reserved. 27
Who is involved?
And more…
Copyright © SailPoint Technologies, Inc. 2017. All rights reserved. 28
The Payoff???
• There is now an industry standard to integrate IGA and PAM
• Standardized API allows any two solutions to plug together easily
• No software upgrades required to support new vendors
• IGA and PAM systems no longer have to be siloed
Copyright © SailPoint Technologies, Inc. 2017. All rights reserved. 29
Final words!!!
Occupation
Place
Positive characteristic
Plural noun
The White House
Movie Critic
enthusiastic
sheep
Copyright © SailPoint Technologies, Inc. 2017. All rights reserved. 30
Do you believe in ___________ at first sight? Well neither did
Iggy or Pam. At least not until that ___________ day six
months ago. You see, both Iggy and Pam grew up believing
that a person can be ___________ in life with any number of
the billions of ___________ on this earth.
When IGA meets PAM …
hung overness
strong
fearful
computers
Copyright © SailPoint Technologies, Inc. 2017. All rights reserved. 31
Iggy and Pam both shared the same profession, and as luck
would have it, they both attended the conference for the
Society of _________________ in favor of ______________
(aka – SCIM). In fact, on Thursday … the last day of the
conference … they happened to sit next to each other in the
session - ____________ are from ___________
___________ are from ______________ - presented by the
brilliant ____________________, Professor Griz.
When IGA meets PAM …
Movie Critic
The White Housesheep
Barsidenterati
MonkeysCoroners
Copyright © SailPoint Technologies, Inc. 2017. All rights reserved. 32
In this session, Pam learned that even though she was very
________________ that she often lacked transparency. Iggy
learned that his most sensitive part – his ________________
_______________ – deserved the same level of attention and
protection as the rest of himself. Through these epiphanies,
Iggy and Pam both realized that they needed each other. Iggy
asked Pam if she would like to join him that evening for
_______________. She said yes, and the rest is history.
They lived ____________ ever after – thanks to SCIM and
Professor Griz.
When IGA meets PAM …
enthusiastic
slowly
coffee
fingernail
handsome
Copyright © SailPoint Technologies, Inc. 2017. All rights reserved. 33
Need more info?
SCIM – http://simplecloud.info
SCIM PAM Extension (early draft) - https://tinyurl.com/scim-pam-ext
SCIM Core Schema - https://tools.ietf.org/html/rfc7643
SCIM Protocol - https://tools.ietf.org/html/rfc7644
Thank You
@kelly_grizzle
kelly.grizzle@sailpoint.com

More Related Content

What's hot

CIS 2015- Understanding & Managing Discretionary Access: The TAO of Entitleme...
CIS 2015- Understanding & Managing Discretionary Access: The TAO of Entitleme...CIS 2015- Understanding & Managing Discretionary Access: The TAO of Entitleme...
CIS 2015- Understanding & Managing Discretionary Access: The TAO of Entitleme...
CloudIDSummit
 
PingOne IDaaS: What You Need to Know
PingOne IDaaS: What You Need to KnowPingOne IDaaS: What You Need to Know
PingOne IDaaS: What You Need to Know
CloudIDSummit
 
Building a Secure Cloud with Identity Management
Building a Secure Cloud with Identity ManagementBuilding a Secure Cloud with Identity Management
Building a Secure Cloud with Identity Management
OracleIDM
 
CIS13: Avoiding the Pitfalls of Managing IAM for a Hybrid Environment
CIS13: Avoiding the Pitfalls of Managing IAM for a Hybrid EnvironmentCIS13: Avoiding the Pitfalls of Managing IAM for a Hybrid Environment
CIS13: Avoiding the Pitfalls of Managing IAM for a Hybrid Environment
CloudIDSummit
 
Securing your Applications for the Cloud Age
Securing your Applications for the Cloud AgeSecuring your Applications for the Cloud Age
Securing your Applications for the Cloud Age
Artur Alves
 
OIM Sizing Guide 11gR2PS1
OIM Sizing Guide 11gR2PS1OIM Sizing Guide 11gR2PS1
OIM Sizing Guide 11gR2PS1
Atul Goyal
 
Self Service Access Control - Help Yourself to More Productivity
Self Service Access Control - Help Yourself to More ProductivitySelf Service Access Control - Help Yourself to More Productivity
Self Service Access Control - Help Yourself to More Productivity
Atul Goyal
 
Round table guide
Round table guideRound table guide
Round table guide
OracleIDM
 
CIS 2015 The IDaaS Dating Game - Sean Deuby
CIS 2015 The IDaaS Dating Game - Sean DeubyCIS 2015 The IDaaS Dating Game - Sean Deuby
CIS 2015 The IDaaS Dating Game - Sean Deuby
CloudIDSummit
 
AWS reInforce 2021: TDR202 - Lessons learned from the front lines of Incident...
AWS reInforce 2021: TDR202 - Lessons learned from the front lines of Incident...AWS reInforce 2021: TDR202 - Lessons learned from the front lines of Incident...
AWS reInforce 2021: TDR202 - Lessons learned from the front lines of Incident...
Brian Andrzejewski
 
Comparing forefront identity manager vs. other identity managers
Comparing forefront identity manager vs. other identity managersComparing forefront identity manager vs. other identity managers
Comparing forefront identity manager vs. other identity managers
InfraMatix Inc.
 
OIM Connector for Webservices
OIM Connector for WebservicesOIM Connector for Webservices
OIM Connector for Webservices
Atul Goyal
 
NoOps in a Serverless World
NoOps in a Serverless WorldNoOps in a Serverless World
NoOps in a Serverless World
Gary Arora
 
Ioug webcast entitlements in check
Ioug webcast entitlements in checkIoug webcast entitlements in check
Ioug webcast entitlements in check
OracleIDM
 
Harness the power of cloud Enterprise IT Program
Harness the power of cloud   Enterprise IT ProgramHarness the power of cloud   Enterprise IT Program
Harness the power of cloud Enterprise IT Program
Adrian Hall
 
DSS - ITSEC conf - Centrify - Identity Control and Access Management - Riga N...
DSS - ITSEC conf - Centrify - Identity Control and Access Management - Riga N...DSS - ITSEC conf - Centrify - Identity Control and Access Management - Riga N...
DSS - ITSEC conf - Centrify - Identity Control and Access Management - Riga N...
Andris Soroka
 
Security for Cloud Computing: 10 Steps to Ensure Success V3.0
Security for Cloud Computing: 10 Steps to Ensure Success V3.0Security for Cloud Computing: 10 Steps to Ensure Success V3.0
Security for Cloud Computing: 10 Steps to Ensure Success V3.0
Cloud Standards Customer Council
 
Centrify Intellect event
Centrify   Intellect eventCentrify   Intellect event
Centrify Intellect event
intellectsecurity
 
What is tackled in the Java EE Security API (Java EE 8)
What is tackled in the Java EE Security API (Java EE 8)What is tackled in the Java EE Security API (Java EE 8)
What is tackled in the Java EE Security API (Java EE 8)
Rudy De Busscher
 
Session 2017 CASB: the Swiss army knife that wants to be a magic wand - en re...
Session 2017 CASB: the Swiss army knife that wants to be a magic wand - en re...Session 2017 CASB: the Swiss army knife that wants to be a magic wand - en re...
Session 2017 CASB: the Swiss army knife that wants to be a magic wand - en re...
Jean-François LOMBARDO
 

What's hot (20)

CIS 2015- Understanding & Managing Discretionary Access: The TAO of Entitleme...
CIS 2015- Understanding & Managing Discretionary Access: The TAO of Entitleme...CIS 2015- Understanding & Managing Discretionary Access: The TAO of Entitleme...
CIS 2015- Understanding & Managing Discretionary Access: The TAO of Entitleme...
 
PingOne IDaaS: What You Need to Know
PingOne IDaaS: What You Need to KnowPingOne IDaaS: What You Need to Know
PingOne IDaaS: What You Need to Know
 
Building a Secure Cloud with Identity Management
Building a Secure Cloud with Identity ManagementBuilding a Secure Cloud with Identity Management
Building a Secure Cloud with Identity Management
 
CIS13: Avoiding the Pitfalls of Managing IAM for a Hybrid Environment
CIS13: Avoiding the Pitfalls of Managing IAM for a Hybrid EnvironmentCIS13: Avoiding the Pitfalls of Managing IAM for a Hybrid Environment
CIS13: Avoiding the Pitfalls of Managing IAM for a Hybrid Environment
 
Securing your Applications for the Cloud Age
Securing your Applications for the Cloud AgeSecuring your Applications for the Cloud Age
Securing your Applications for the Cloud Age
 
OIM Sizing Guide 11gR2PS1
OIM Sizing Guide 11gR2PS1OIM Sizing Guide 11gR2PS1
OIM Sizing Guide 11gR2PS1
 
Self Service Access Control - Help Yourself to More Productivity
Self Service Access Control - Help Yourself to More ProductivitySelf Service Access Control - Help Yourself to More Productivity
Self Service Access Control - Help Yourself to More Productivity
 
Round table guide
Round table guideRound table guide
Round table guide
 
CIS 2015 The IDaaS Dating Game - Sean Deuby
CIS 2015 The IDaaS Dating Game - Sean DeubyCIS 2015 The IDaaS Dating Game - Sean Deuby
CIS 2015 The IDaaS Dating Game - Sean Deuby
 
AWS reInforce 2021: TDR202 - Lessons learned from the front lines of Incident...
AWS reInforce 2021: TDR202 - Lessons learned from the front lines of Incident...AWS reInforce 2021: TDR202 - Lessons learned from the front lines of Incident...
AWS reInforce 2021: TDR202 - Lessons learned from the front lines of Incident...
 
Comparing forefront identity manager vs. other identity managers
Comparing forefront identity manager vs. other identity managersComparing forefront identity manager vs. other identity managers
Comparing forefront identity manager vs. other identity managers
 
OIM Connector for Webservices
OIM Connector for WebservicesOIM Connector for Webservices
OIM Connector for Webservices
 
NoOps in a Serverless World
NoOps in a Serverless WorldNoOps in a Serverless World
NoOps in a Serverless World
 
Ioug webcast entitlements in check
Ioug webcast entitlements in checkIoug webcast entitlements in check
Ioug webcast entitlements in check
 
Harness the power of cloud Enterprise IT Program
Harness the power of cloud   Enterprise IT ProgramHarness the power of cloud   Enterprise IT Program
Harness the power of cloud Enterprise IT Program
 
DSS - ITSEC conf - Centrify - Identity Control and Access Management - Riga N...
DSS - ITSEC conf - Centrify - Identity Control and Access Management - Riga N...DSS - ITSEC conf - Centrify - Identity Control and Access Management - Riga N...
DSS - ITSEC conf - Centrify - Identity Control and Access Management - Riga N...
 
Security for Cloud Computing: 10 Steps to Ensure Success V3.0
Security for Cloud Computing: 10 Steps to Ensure Success V3.0Security for Cloud Computing: 10 Steps to Ensure Success V3.0
Security for Cloud Computing: 10 Steps to Ensure Success V3.0
 
Centrify Intellect event
Centrify   Intellect eventCentrify   Intellect event
Centrify Intellect event
 
What is tackled in the Java EE Security API (Java EE 8)
What is tackled in the Java EE Security API (Java EE 8)What is tackled in the Java EE Security API (Java EE 8)
What is tackled in the Java EE Security API (Java EE 8)
 
Session 2017 CASB: the Swiss army knife that wants to be a magic wand - en re...
Session 2017 CASB: the Swiss army knife that wants to be a magic wand - en re...Session 2017 CASB: the Swiss army knife that wants to be a magic wand - en re...
Session 2017 CASB: the Swiss army knife that wants to be a magic wand - en re...
 

Similar to When IGA meets PAM ... through their mutual friend SCIM

Visão Geral de Inteligência Artificial
Visão Geral de Inteligência ArtificialVisão Geral de Inteligência Artificial
Visão Geral de Inteligência Artificial
Amazon Web Services LATAM
 
The Lima Consulting Group Digital Transformation Maturity Model Presented at ...
The Lima Consulting Group Digital Transformation Maturity Model Presented at ...The Lima Consulting Group Digital Transformation Maturity Model Presented at ...
The Lima Consulting Group Digital Transformation Maturity Model Presented at ...
Lima Consulting Group
 
Life of a Code Change to a Tier 1 Service - AWS Online Tech Talks
Life of a Code Change to a Tier 1 Service - AWS Online Tech TalksLife of a Code Change to a Tier 1 Service - AWS Online Tech Talks
Life of a Code Change to a Tier 1 Service - AWS Online Tech Talks
Amazon Web Services
 
Machine Learning for Auditors
Machine Learning for AuditorsMachine Learning for Auditors
Machine Learning for Auditors
Andrew Clark
 
The seven habits of highly successful builders - AWS Summit Cape Town 2018
The seven habits of highly successful builders - AWS Summit Cape Town 2018The seven habits of highly successful builders - AWS Summit Cape Town 2018
The seven habits of highly successful builders - AWS Summit Cape Town 2018
Amazon Web Services
 
Contratos Inteligentes: passo-a-passo para criação
Contratos Inteligentes: passo-a-passo para criaçãoContratos Inteligentes: passo-a-passo para criação
Contratos Inteligentes: passo-a-passo para criação
Fernando Galdino
 
Rapid Development using Serverless Infrastructure - Tel Aviv Summit 2018
Rapid Development using Serverless Infrastructure - Tel Aviv Summit 2018Rapid Development using Serverless Infrastructure - Tel Aviv Summit 2018
Rapid Development using Serverless Infrastructure - Tel Aviv Summit 2018
Amazon Web Services
 
Keynote StarEast - Testing in the Fast Lane (Transformation)
Keynote StarEast - Testing in the Fast Lane (Transformation)Keynote StarEast - Testing in the Fast Lane (Transformation)
Keynote StarEast - Testing in the Fast Lane (Transformation)
Jennifer L. Scandariato
 
Nimbix AI Cloud and PowerAI
Nimbix AI Cloud and PowerAINimbix AI Cloud and PowerAI
Nimbix AI Cloud and PowerAI
Leo Reiter
 
DITA versus DITA-OT
DITA versus DITA-OTDITA versus DITA-OT
DITA versus DITA-OT
Robert Anderson
 
Postgres Takes Charge Around the World
Postgres Takes Charge Around the WorldPostgres Takes Charge Around the World
Postgres Takes Charge Around the World
EDB
 
Découvrez le Rugged DevOps
Découvrez le Rugged DevOpsDécouvrez le Rugged DevOps
Découvrez le Rugged DevOps
Talent Agile @ Avanade
 
New way to learn Machine Learning with AWS DeepLens & Daniel ZivKovic
New way to learn Machine Learning with AWS DeepLens & Daniel ZivKovicNew way to learn Machine Learning with AWS DeepLens & Daniel ZivKovic
New way to learn Machine Learning with AWS DeepLens & Daniel ZivKovic
Daniel Zivkovic
 
From Inception to RFC – The SCIM Story
From Inception to RFC – The SCIM StoryFrom Inception to RFC – The SCIM Story
From Inception to RFC – The SCIM Story
Nordic APIs
 
Will your agile practices be the death of architecture?
Will your agile practices be the death of architecture?Will your agile practices be the death of architecture?
Will your agile practices be the death of architecture?
Jennifer Lim
 
Data Engineering the Startup Way - AWS Startup Day Chicago 2018
Data Engineering the Startup Way - AWS Startup Day Chicago 2018Data Engineering the Startup Way - AWS Startup Day Chicago 2018
Data Engineering the Startup Way - AWS Startup Day Chicago 2018
Amazon Web Services
 
Identiverse 2018 - Using Identity to Restore Freedom
Identiverse 2018 - Using Identity to Restore FreedomIdentiverse 2018 - Using Identity to Restore Freedom
Identiverse 2018 - Using Identity to Restore Freedom
Matt Topper
 
Innovation at AWS
Innovation at AWS Innovation at AWS
Innovation at AWS
Amazon Web Services
 
Designing for a Data-Driven Economy (AIS307) - AWS re:Invent 2018
Designing for a Data-Driven Economy (AIS307) - AWS re:Invent 2018Designing for a Data-Driven Economy (AIS307) - AWS re:Invent 2018
Designing for a Data-Driven Economy (AIS307) - AWS re:Invent 2018
Amazon Web Services
 
The State of PLM 2017
The State of PLM 2017The State of PLM 2017
The State of PLM 2017
Oleg Shilovitsky
 

Similar to When IGA meets PAM ... through their mutual friend SCIM (20)

Visão Geral de Inteligência Artificial
Visão Geral de Inteligência ArtificialVisão Geral de Inteligência Artificial
Visão Geral de Inteligência Artificial
 
The Lima Consulting Group Digital Transformation Maturity Model Presented at ...
The Lima Consulting Group Digital Transformation Maturity Model Presented at ...The Lima Consulting Group Digital Transformation Maturity Model Presented at ...
The Lima Consulting Group Digital Transformation Maturity Model Presented at ...
 
Life of a Code Change to a Tier 1 Service - AWS Online Tech Talks
Life of a Code Change to a Tier 1 Service - AWS Online Tech TalksLife of a Code Change to a Tier 1 Service - AWS Online Tech Talks
Life of a Code Change to a Tier 1 Service - AWS Online Tech Talks
 
Machine Learning for Auditors
Machine Learning for AuditorsMachine Learning for Auditors
Machine Learning for Auditors
 
The seven habits of highly successful builders - AWS Summit Cape Town 2018
The seven habits of highly successful builders - AWS Summit Cape Town 2018The seven habits of highly successful builders - AWS Summit Cape Town 2018
The seven habits of highly successful builders - AWS Summit Cape Town 2018
 
Contratos Inteligentes: passo-a-passo para criação
Contratos Inteligentes: passo-a-passo para criaçãoContratos Inteligentes: passo-a-passo para criação
Contratos Inteligentes: passo-a-passo para criação
 
Rapid Development using Serverless Infrastructure - Tel Aviv Summit 2018
Rapid Development using Serverless Infrastructure - Tel Aviv Summit 2018Rapid Development using Serverless Infrastructure - Tel Aviv Summit 2018
Rapid Development using Serverless Infrastructure - Tel Aviv Summit 2018
 
Keynote StarEast - Testing in the Fast Lane (Transformation)
Keynote StarEast - Testing in the Fast Lane (Transformation)Keynote StarEast - Testing in the Fast Lane (Transformation)
Keynote StarEast - Testing in the Fast Lane (Transformation)
 
Nimbix AI Cloud and PowerAI
Nimbix AI Cloud and PowerAINimbix AI Cloud and PowerAI
Nimbix AI Cloud and PowerAI
 
DITA versus DITA-OT
DITA versus DITA-OTDITA versus DITA-OT
DITA versus DITA-OT
 
Postgres Takes Charge Around the World
Postgres Takes Charge Around the WorldPostgres Takes Charge Around the World
Postgres Takes Charge Around the World
 
Découvrez le Rugged DevOps
Découvrez le Rugged DevOpsDécouvrez le Rugged DevOps
Découvrez le Rugged DevOps
 
New way to learn Machine Learning with AWS DeepLens & Daniel ZivKovic
New way to learn Machine Learning with AWS DeepLens & Daniel ZivKovicNew way to learn Machine Learning with AWS DeepLens & Daniel ZivKovic
New way to learn Machine Learning with AWS DeepLens & Daniel ZivKovic
 
From Inception to RFC – The SCIM Story
From Inception to RFC – The SCIM StoryFrom Inception to RFC – The SCIM Story
From Inception to RFC – The SCIM Story
 
Will your agile practices be the death of architecture?
Will your agile practices be the death of architecture?Will your agile practices be the death of architecture?
Will your agile practices be the death of architecture?
 
Data Engineering the Startup Way - AWS Startup Day Chicago 2018
Data Engineering the Startup Way - AWS Startup Day Chicago 2018Data Engineering the Startup Way - AWS Startup Day Chicago 2018
Data Engineering the Startup Way - AWS Startup Day Chicago 2018
 
Identiverse 2018 - Using Identity to Restore Freedom
Identiverse 2018 - Using Identity to Restore FreedomIdentiverse 2018 - Using Identity to Restore Freedom
Identiverse 2018 - Using Identity to Restore Freedom
 
Innovation at AWS
Innovation at AWS Innovation at AWS
Innovation at AWS
 
Designing for a Data-Driven Economy (AIS307) - AWS re:Invent 2018
Designing for a Data-Driven Economy (AIS307) - AWS re:Invent 2018Designing for a Data-Driven Economy (AIS307) - AWS re:Invent 2018
Designing for a Data-Driven Economy (AIS307) - AWS re:Invent 2018
 
The State of PLM 2017
The State of PLM 2017The State of PLM 2017
The State of PLM 2017
 

Recently uploaded

Energy Efficient Video Encoding for Cloud and Edge Computing Instances
Energy Efficient Video Encoding for Cloud and Edge Computing InstancesEnergy Efficient Video Encoding for Cloud and Edge Computing Instances
Energy Efficient Video Encoding for Cloud and Edge Computing Instances
Alpen-Adria-Universität
 
Skybuffer AI: Advanced Conversational and Generative AI Solution on SAP Busin...
Skybuffer AI: Advanced Conversational and Generative AI Solution on SAP Busin...Skybuffer AI: Advanced Conversational and Generative AI Solution on SAP Busin...
Skybuffer AI: Advanced Conversational and Generative AI Solution on SAP Busin...
Tatiana Kojar
 
Generating privacy-protected synthetic data using Secludy and Milvus
Generating privacy-protected synthetic data using Secludy and MilvusGenerating privacy-protected synthetic data using Secludy and Milvus
Generating privacy-protected synthetic data using Secludy and Milvus
Zilliz
 
AWS Cloud Cost Optimization Presentation.pptx
AWS Cloud Cost Optimization Presentation.pptxAWS Cloud Cost Optimization Presentation.pptx
AWS Cloud Cost Optimization Presentation.pptx
HarisZaheer8
 
5th LF Energy Power Grid Model Meet-up Slides
5th LF Energy Power Grid Model Meet-up Slides5th LF Energy Power Grid Model Meet-up Slides
5th LF Energy Power Grid Model Meet-up Slides
DanBrown980551
 
Azure API Management to expose backend services securely
Azure API Management to expose backend services securelyAzure API Management to expose backend services securely
Azure API Management to expose backend services securely
Dinusha Kumarasiri
 
Columbus Data & Analytics Wednesdays - June 2024
Columbus Data & Analytics Wednesdays - June 2024Columbus Data & Analytics Wednesdays - June 2024
Columbus Data & Analytics Wednesdays - June 2024
Jason Packer
 
Your One-Stop Shop for Python Success: Top 10 US Python Development Providers
Your One-Stop Shop for Python Success: Top 10 US Python Development ProvidersYour One-Stop Shop for Python Success: Top 10 US Python Development Providers
Your One-Stop Shop for Python Success: Top 10 US Python Development Providers
akankshawande
 
Nunit vs XUnit vs MSTest Differences Between These Unit Testing Frameworks.pdf
Nunit vs XUnit vs MSTest Differences Between These Unit Testing Frameworks.pdfNunit vs XUnit vs MSTest Differences Between These Unit Testing Frameworks.pdf
Nunit vs XUnit vs MSTest Differences Between These Unit Testing Frameworks.pdf
flufftailshop
 
HCL Notes und Domino Lizenzkostenreduzierung in der Welt von DLAU
HCL Notes und Domino Lizenzkostenreduzierung in der Welt von DLAUHCL Notes und Domino Lizenzkostenreduzierung in der Welt von DLAU
HCL Notes und Domino Lizenzkostenreduzierung in der Welt von DLAU
panagenda
 
Presentation of the OECD Artificial Intelligence Review of Germany
Presentation of the OECD Artificial Intelligence Review of GermanyPresentation of the OECD Artificial Intelligence Review of Germany
Presentation of the OECD Artificial Intelligence Review of Germany
innovationoecd
 
How to Interpret Trends in the Kalyan Rajdhani Mix Chart.pdf
How to Interpret Trends in the Kalyan Rajdhani Mix Chart.pdfHow to Interpret Trends in the Kalyan Rajdhani Mix Chart.pdf
How to Interpret Trends in the Kalyan Rajdhani Mix Chart.pdf
Chart Kalyan
 
GraphRAG for Life Science to increase LLM accuracy
GraphRAG for Life Science to increase LLM accuracyGraphRAG for Life Science to increase LLM accuracy
GraphRAG for Life Science to increase LLM accuracy
Tomaz Bratanic
 
Letter and Document Automation for Bonterra Impact Management (fka Social Sol...
Letter and Document Automation for Bonterra Impact Management (fka Social Sol...Letter and Document Automation for Bonterra Impact Management (fka Social Sol...
Letter and Document Automation for Bonterra Impact Management (fka Social Sol...
Jeffrey Haguewood
 
GenAI Pilot Implementation in the organizations
GenAI Pilot Implementation in the organizationsGenAI Pilot Implementation in the organizations
GenAI Pilot Implementation in the organizations
kumardaparthi1024
 
Let's Integrate MuleSoft RPA, COMPOSER, APM with AWS IDP along with Slack
Let's Integrate MuleSoft RPA, COMPOSER, APM with AWS IDP along with SlackLet's Integrate MuleSoft RPA, COMPOSER, APM with AWS IDP along with Slack
Let's Integrate MuleSoft RPA, COMPOSER, APM with AWS IDP along with Slack
shyamraj55
 
Fueling AI with Great Data with Airbyte Webinar
Fueling AI with Great Data with Airbyte WebinarFueling AI with Great Data with Airbyte Webinar
Fueling AI with Great Data with Airbyte Webinar
Zilliz
 
A Comprehensive Guide to DeFi Development Services in 2024
A Comprehensive Guide to DeFi Development Services in 2024A Comprehensive Guide to DeFi Development Services in 2024
A Comprehensive Guide to DeFi Development Services in 2024
Intelisync
 
Deep Dive: AI-Powered Marketing to Get More Leads and Customers with HyperGro...
Deep Dive: AI-Powered Marketing to Get More Leads and Customers with HyperGro...Deep Dive: AI-Powered Marketing to Get More Leads and Customers with HyperGro...
Deep Dive: AI-Powered Marketing to Get More Leads and Customers with HyperGro...
saastr
 
TrustArc Webinar - 2024 Global Privacy Survey
TrustArc Webinar - 2024 Global Privacy SurveyTrustArc Webinar - 2024 Global Privacy Survey
TrustArc Webinar - 2024 Global Privacy Survey
TrustArc
 

Recently uploaded (20)

Energy Efficient Video Encoding for Cloud and Edge Computing Instances
Energy Efficient Video Encoding for Cloud and Edge Computing InstancesEnergy Efficient Video Encoding for Cloud and Edge Computing Instances
Energy Efficient Video Encoding for Cloud and Edge Computing Instances
 
Skybuffer AI: Advanced Conversational and Generative AI Solution on SAP Busin...
Skybuffer AI: Advanced Conversational and Generative AI Solution on SAP Busin...Skybuffer AI: Advanced Conversational and Generative AI Solution on SAP Busin...
Skybuffer AI: Advanced Conversational and Generative AI Solution on SAP Busin...
 
Generating privacy-protected synthetic data using Secludy and Milvus
Generating privacy-protected synthetic data using Secludy and MilvusGenerating privacy-protected synthetic data using Secludy and Milvus
Generating privacy-protected synthetic data using Secludy and Milvus
 
AWS Cloud Cost Optimization Presentation.pptx
AWS Cloud Cost Optimization Presentation.pptxAWS Cloud Cost Optimization Presentation.pptx
AWS Cloud Cost Optimization Presentation.pptx
 
5th LF Energy Power Grid Model Meet-up Slides
5th LF Energy Power Grid Model Meet-up Slides5th LF Energy Power Grid Model Meet-up Slides
5th LF Energy Power Grid Model Meet-up Slides
 
Azure API Management to expose backend services securely
Azure API Management to expose backend services securelyAzure API Management to expose backend services securely
Azure API Management to expose backend services securely
 
Columbus Data & Analytics Wednesdays - June 2024
Columbus Data & Analytics Wednesdays - June 2024Columbus Data & Analytics Wednesdays - June 2024
Columbus Data & Analytics Wednesdays - June 2024
 
Your One-Stop Shop for Python Success: Top 10 US Python Development Providers
Your One-Stop Shop for Python Success: Top 10 US Python Development ProvidersYour One-Stop Shop for Python Success: Top 10 US Python Development Providers
Your One-Stop Shop for Python Success: Top 10 US Python Development Providers
 
Nunit vs XUnit vs MSTest Differences Between These Unit Testing Frameworks.pdf
Nunit vs XUnit vs MSTest Differences Between These Unit Testing Frameworks.pdfNunit vs XUnit vs MSTest Differences Between These Unit Testing Frameworks.pdf
Nunit vs XUnit vs MSTest Differences Between These Unit Testing Frameworks.pdf
 
HCL Notes und Domino Lizenzkostenreduzierung in der Welt von DLAU
HCL Notes und Domino Lizenzkostenreduzierung in der Welt von DLAUHCL Notes und Domino Lizenzkostenreduzierung in der Welt von DLAU
HCL Notes und Domino Lizenzkostenreduzierung in der Welt von DLAU
 
Presentation of the OECD Artificial Intelligence Review of Germany
Presentation of the OECD Artificial Intelligence Review of GermanyPresentation of the OECD Artificial Intelligence Review of Germany
Presentation of the OECD Artificial Intelligence Review of Germany
 
How to Interpret Trends in the Kalyan Rajdhani Mix Chart.pdf
How to Interpret Trends in the Kalyan Rajdhani Mix Chart.pdfHow to Interpret Trends in the Kalyan Rajdhani Mix Chart.pdf
How to Interpret Trends in the Kalyan Rajdhani Mix Chart.pdf
 
GraphRAG for Life Science to increase LLM accuracy
GraphRAG for Life Science to increase LLM accuracyGraphRAG for Life Science to increase LLM accuracy
GraphRAG for Life Science to increase LLM accuracy
 
Letter and Document Automation for Bonterra Impact Management (fka Social Sol...
Letter and Document Automation for Bonterra Impact Management (fka Social Sol...Letter and Document Automation for Bonterra Impact Management (fka Social Sol...
Letter and Document Automation for Bonterra Impact Management (fka Social Sol...
 
GenAI Pilot Implementation in the organizations
GenAI Pilot Implementation in the organizationsGenAI Pilot Implementation in the organizations
GenAI Pilot Implementation in the organizations
 
Let's Integrate MuleSoft RPA, COMPOSER, APM with AWS IDP along with Slack
Let's Integrate MuleSoft RPA, COMPOSER, APM with AWS IDP along with SlackLet's Integrate MuleSoft RPA, COMPOSER, APM with AWS IDP along with Slack
Let's Integrate MuleSoft RPA, COMPOSER, APM with AWS IDP along with Slack
 
Fueling AI with Great Data with Airbyte Webinar
Fueling AI with Great Data with Airbyte WebinarFueling AI with Great Data with Airbyte Webinar
Fueling AI with Great Data with Airbyte Webinar
 
A Comprehensive Guide to DeFi Development Services in 2024
A Comprehensive Guide to DeFi Development Services in 2024A Comprehensive Guide to DeFi Development Services in 2024
A Comprehensive Guide to DeFi Development Services in 2024
 
Deep Dive: AI-Powered Marketing to Get More Leads and Customers with HyperGro...
Deep Dive: AI-Powered Marketing to Get More Leads and Customers with HyperGro...Deep Dive: AI-Powered Marketing to Get More Leads and Customers with HyperGro...
Deep Dive: AI-Powered Marketing to Get More Leads and Customers with HyperGro...
 
TrustArc Webinar - 2024 Global Privacy Survey
TrustArc Webinar - 2024 Global Privacy SurveyTrustArc Webinar - 2024 Global Privacy Survey
TrustArc Webinar - 2024 Global Privacy Survey
 

When IGA meets PAM ... through their mutual friend SCIM

  • 1. When IGA meets PAM… Through their mutual friend SCIM Kelly Grizzle
  • 2. Copyright © SailPoint Technologies, Inc. 2017. All rights reserved. 2
  • 3. Copyright © SailPoint Technologies, Inc. 2017. All rights reserved. 3 You might be starting to feel like…
  • 4. Copyright © SailPoint Technologies, Inc. 2017. All rights reserved. 4 To avoid this … we’ll have FUN WITH MAD LIBS!!!
  • 5. Copyright © SailPoint Technologies, Inc. 2017. All rights reserved. 5
  • 6. Copyright © SailPoint Technologies, Inc. 2017. All rights reserved. 6 Gimme some words!!! Emotion Adjective Plural noun hung overness strong computers
  • 7. Copyright © SailPoint Technologies, Inc. 2017. All rights reserved. 7 What are we talking about? • What is IGA? • What is PAM? • What’s the problem? • How do we join these two worlds?
  • 8. Copyright © SailPoint Technologies, Inc. 2017. All rights reserved. 8 What is IGA?
  • 9. Copyright © SailPoint Technologies, Inc. 2017. All rights reserved. 9 Identity Governance and Administration Governance • Access Review • Approval • Policy Checking • Role Management • Analytics • Auditing Administration • Access Request • Account Management • Password Management • Identity Lifecycle Management • Provisioning • Automated Workflows
  • 10. Copyright © SailPoint Technologies, Inc. 2017. All rights reserved. 10 Words!!! Occupation that starts with “C” Plural noun Place dogs Coroners Bars
  • 11. Copyright © SailPoint Technologies, Inc. 2017. All rights reserved. 11 What is PAM?
  • 12. Copyright © SailPoint Technologies, Inc. 2017. All rights reserved. 12Copyright © SailPoint Technologies, Inc. 2017. All rights reserved. 12 Privileged Access Management Controls access to privileged data – most often credentials for privileged accounts
  • 13. Copyright © SailPoint Technologies, Inc. 2017. All rights reserved. 13
  • 14. Copyright © SailPoint Technologies, Inc. 2017. All rights reserved. 14
  • 15. Copyright © SailPoint Technologies, Inc. 2017. All rights reserved. 15
  • 16. Copyright © SailPoint Technologies, Inc. 2017. All rights reserved. 16
  • 17. Copyright © SailPoint Technologies, Inc. 2017. All rights reserved. 17
  • 18. Copyright © SailPoint Technologies, Inc. 2017. All rights reserved. 18 Privileged Account Management Provides • Account sharing • Tracking and auditing actions taken with privileged accounts • Passwords become invisible to end users • Automatic rotation of credentials • Highly secure passwords
  • 19. Copyright © SailPoint Technologies, Inc. 2017. All rights reserved. 19 More words!!! Adverb Body part Plural noun Adjective fingernail slowly identerati handsome
  • 20. Copyright © SailPoint Technologies, Inc. 2017. All rights reserved. 20 What’s the problem?
  • 21. Copyright © SailPoint Technologies, Inc. 2017. All rights reserved. 21 Two Amazing … But Siloed … Technologies • Historically, IGA and PAM systems have not been integrated • Most companies that care about security have a need for both • IGA software is a bit weak in dealing with shared accounts • Who owns the account? • How do you request access to a shared account? • PAM software does not provide governance controls • No access reviews • No policy checking • Etc…
  • 22. Copyright © SailPoint Technologies, Inc. 2017. All rights reserved. 22 Words Please!!! Plural noun that starts with “M” Emotion Food or drink fearful Monkeys coffee
  • 23. Copyright © SailPoint Technologies, Inc. 2017. All rights reserved. 23 How to join these worlds … SCIM!
  • 24. Copyright © SailPoint Technologies, Inc. 2017. All rights reserved. 24Copyright © SailPoint Technologies, Inc. 2017. All rights reserved. 24 What is SCIM? System for Cross-Domain Identity Management
  • 25. Copyright © SailPoint Technologies, Inc. 2017. All rights reserved. 25Copyright © SailPoint Technologies, Inc. 2017. All rights reserved. 25 Identity Management + REST =
  • 26. Copyright © SailPoint Technologies, Inc. 2017. All rights reserved. 26 SCIM PAM Extension • SCIM provides a REST API and JSON representations for users and groups • The SCIM PAM Extension is a new specification that augments SCIM 2.0 to bridge IGA and PAM • New concepts in SCIM PAM extension: • Privileged data • Containers • Access control lists for containers and privileged data
  • 27. Copyright © SailPoint Technologies, Inc. 2017. All rights reserved. 27 Who is involved? And more…
  • 28. Copyright © SailPoint Technologies, Inc. 2017. All rights reserved. 28 The Payoff??? • There is now an industry standard to integrate IGA and PAM • Standardized API allows any two solutions to plug together easily • No software upgrades required to support new vendors • IGA and PAM systems no longer have to be siloed
  • 29. Copyright © SailPoint Technologies, Inc. 2017. All rights reserved. 29 Final words!!! Occupation Place Positive characteristic Plural noun The White House Movie Critic enthusiastic sheep
  • 30. Copyright © SailPoint Technologies, Inc. 2017. All rights reserved. 30 Do you believe in ___________ at first sight? Well neither did Iggy or Pam. At least not until that ___________ day six months ago. You see, both Iggy and Pam grew up believing that a person can be ___________ in life with any number of the billions of ___________ on this earth. When IGA meets PAM … hung overness strong fearful computers
  • 31. Copyright © SailPoint Technologies, Inc. 2017. All rights reserved. 31 Iggy and Pam both shared the same profession, and as luck would have it, they both attended the conference for the Society of _________________ in favor of ______________ (aka – SCIM). In fact, on Thursday … the last day of the conference … they happened to sit next to each other in the session - ____________ are from ___________ ___________ are from ______________ - presented by the brilliant ____________________, Professor Griz. When IGA meets PAM … Movie Critic The White Housesheep Barsidenterati MonkeysCoroners
  • 32. Copyright © SailPoint Technologies, Inc. 2017. All rights reserved. 32 In this session, Pam learned that even though she was very ________________ that she often lacked transparency. Iggy learned that his most sensitive part – his ________________ _______________ – deserved the same level of attention and protection as the rest of himself. Through these epiphanies, Iggy and Pam both realized that they needed each other. Iggy asked Pam if she would like to join him that evening for _______________. She said yes, and the rest is history. They lived ____________ ever after – thanks to SCIM and Professor Griz. When IGA meets PAM … enthusiastic slowly coffee fingernail handsome
  • 33. Copyright © SailPoint Technologies, Inc. 2017. All rights reserved. 33 Need more info? SCIM – http://simplecloud.info SCIM PAM Extension (early draft) - https://tinyurl.com/scim-pam-ext SCIM Core Schema - https://tools.ietf.org/html/rfc7643 SCIM Protocol - https://tools.ietf.org/html/rfc7644