Senior Director - Security Architecture,
WSO2
Managing the End-to-End Lifecycle of
User Identities Across Your Enterprise
Prabath Siriwardena
• Onboarding
• Provisioning
• SSO & Identity Federation
• Authentication
• Authorization
• Self-Service
• Monitoring & Analytics
• Deprovisioning
End-to-end Lifecycle
Onboarding
• Employees vs.
customers
• Self signup
• Self signup with
verification
• Approval workflows
Provisioning
• Outbound provisioning
• JIT provisioning
• Conditional provisioning
• SCIM 2.0
SSO and Identity Federation
• Identity bridging
• Claim mapping
• JIT provisioning
• Conditional authentication
• SAML/OIDC/WS-
Federation
Authentication
• Multi-factor
authentication
• Adaptive authentication
• FIDO U2F, TOTP,
SMS/Email OTP
• LDAP, Database, AD
Authorization
• Role-based
• Attribute-based
• XACML REST API
• Policy templates
Self-service
• User portal
• Password reset
• Self access requests
• Consent management
• Profile update
• Password reset
• Account recovery
Monitoring
and Analytics
• Login analytics
• Session analytics
• Fraud
detection/prevention
Deprovisioning
• Anonymize all user data
• Automated
deprovisioning with
connected systems
wso2.com

[WSO2Con EU 2017] Managing the End-to-End Lifecycle of User Identities Across Your Enterprise