SlideShare ist ein Scribd-Unternehmen logo
1 von 14
AusCERT 2010 Speaker Presentation Methodologies & Tools to make user self service a reality Paul Conroy – Identity & Access Technology Specialist
Agenda Business Challenges Meta-directory concepts User Self Service Scenarios Automated provisioning Attribute change User self service password reset Deprovisioning Summary Resources
Business Challenges Threats Current Solutions Business Landscape Increased volume Product proliferation Increased regulatory and compliance pressure More connectivity and collaboration Greater need for identity-based protection and access Greater IT choice; lower budgets Greater sophistication Lack of integration High cost of ownership Profit motivated Security not aligned to business needs and new opportunities
• Enhanced User Experience – Includes self-service password reset • Account Provisioning and Access Request  Empower People ,[object Object],Deliver Agility and Efficiency • Centralised source for auditors  • Credential Management  Increase Security and Compliance Goals of an Identity Management project
Methodologies for Identity Management Directory Synchronisation Automated Provisioning Self Service Management of :- Groups/Distribution Lists Attributes Passwords Delegated Administration (e.g. for approvals)
Meta Directory Concept Meta-directory MAINFRAME ACTIVE DIRECTORY FINANCEAPPLICATION EXCHANGE FINANCEPORTAL SMARTCARD iPLANET
Methodologies for Identity Management Directory Synchronisation Automated Provisioning Self Service Management of :- Groups/Distribution Lists Attributes Passwords Delegated Administration (e.g. for approvals)
HR SYSTEM MANAGER APPROVAL PROVISIONING POLICY APPLIED New Employee Scenario Meta-directory MANAGER APPROVAL MAINFRAME ACTIVE DIRECTORY FINANCEAPPLICATION EXCHANGE FINANCEPORTAL SMARTCARD iPLANET
Methodologies for Identity Management Directory Synchronisation Automated Provisioning Self Service Management of :- Groups/Distribution Lists Attributes Passwords Delegated Administration (e.g. for approvals)
iPLANET Password Reset And Synchronisation MELISSA PASSWORD SYCHRONISATION WINDOWSMACHINE Meta-directory  FINANCEAPPLICATION ACTIVEDIRECTORY FINANCEPORTAL
HR SYSTEM  PROVISIONING POLICY APPLIED Attribute Management Meta-directory MAINFRAME ACTIVE DIRECTORY FINANCEAPPLICATION MARKETINGAPPLICATION EXCHANGE FINANCEPORTAL MARKETINGPORTAL SMARTCARD iPLANET
Methodologies for Identity Management Directory Synchronisation Automated Provisioning Self Service Management of :- Groups/Distribution Lists Attributes Passwords Delegated Administration (e.g. for approvals)
Goal of an Identity Management project • Enhanced User Experience – Includes self-service password reset • Account Provisioning and Access Request  Empower People ,[object Object],Deliver Agility and Efficiency • Centralised source for auditors  • Credential Management  Increase Security and Compliance Summary
Resources Learn About Identity and Access (IDA) www.microsoft.com/IDA

Weitere ähnliche Inhalte

Andere mochten auch

Tech Ed 2011 Preso
Tech Ed 2011 PresoTech Ed 2011 Preso
Tech Ed 2011 PresoPAUL CONROY
 
Ecommerce Monetiser Son Site Philippefloch Technofutur
Ecommerce Monetiser Son Site Philippefloch TechnofuturEcommerce Monetiser Son Site Philippefloch Technofutur
Ecommerce Monetiser Son Site Philippefloch TechnofuturTechnofutur TIC
 
Intelligence collective et réseaux sociaux : comment le web 2.0 modifie la tr...
Intelligence collective et réseaux sociaux : comment le web 2.0 modifie la tr...Intelligence collective et réseaux sociaux : comment le web 2.0 modifie la tr...
Intelligence collective et réseaux sociaux : comment le web 2.0 modifie la tr...Fred Colantonio
 
Лекция № 5. Важнейшие элементы периодической системы Д.И. Менделеева, определ...
Лекция № 5. Важнейшие элементы периодической системы Д.И. Менделеева, определ...Лекция № 5. Важнейшие элементы периодической системы Д.И. Менделеева, определ...
Лекция № 5. Важнейшие элементы периодической системы Д.И. Менделеева, определ...Петрова Елена Александровна
 
Approche paysagiste
Approche paysagisteApproche paysagiste
Approche paysagisteHania Zazoua
 
Commission electorale
Commission electoraleCommission electorale
Commission electoraleJuanico
 
Baromètre EurObserv’ER 2014 - Etat des énergies renouvelables en Europe
Baromètre EurObserv’ER 2014 - Etat des énergies renouvelables en EuropeBaromètre EurObserv’ER 2014 - Etat des énergies renouvelables en Europe
Baromètre EurObserv’ER 2014 - Etat des énergies renouvelables en EuropePôle Réseaux de Chaleur - Cerema
 
Internet en Chine 2013
Internet en Chine 2013Internet en Chine 2013
Internet en Chine 2013IZIASIA
 
Gbph restauration-collective
Gbph restauration-collectiveGbph restauration-collective
Gbph restauration-collectiveMounir El Ourak
 

Andere mochten auch (16)

Tech Ed 2011 Preso
Tech Ed 2011 PresoTech Ed 2011 Preso
Tech Ed 2011 Preso
 
Life
LifeLife
Life
 
Inco Terms
Inco TermsInco Terms
Inco Terms
 
Java I/O Part 1
Java I/O Part 1Java I/O Part 1
Java I/O Part 1
 
Java I/O Part 2
Java I/O Part 2Java I/O Part 2
Java I/O Part 2
 
JSP : Creating Custom Tag
JSP : Creating Custom Tag JSP : Creating Custom Tag
JSP : Creating Custom Tag
 
Dom Basics
Dom BasicsDom Basics
Dom Basics
 
Network analysis
Network analysisNetwork analysis
Network analysis
 
Ecommerce Monetiser Son Site Philippefloch Technofutur
Ecommerce Monetiser Son Site Philippefloch TechnofuturEcommerce Monetiser Son Site Philippefloch Technofutur
Ecommerce Monetiser Son Site Philippefloch Technofutur
 
Intelligence collective et réseaux sociaux : comment le web 2.0 modifie la tr...
Intelligence collective et réseaux sociaux : comment le web 2.0 modifie la tr...Intelligence collective et réseaux sociaux : comment le web 2.0 modifie la tr...
Intelligence collective et réseaux sociaux : comment le web 2.0 modifie la tr...
 
Лекция № 5. Важнейшие элементы периодической системы Д.И. Менделеева, определ...
Лекция № 5. Важнейшие элементы периодической системы Д.И. Менделеева, определ...Лекция № 5. Важнейшие элементы периодической системы Д.И. Менделеева, определ...
Лекция № 5. Важнейшие элементы периодической системы Д.И. Менделеева, определ...
 
Approche paysagiste
Approche paysagisteApproche paysagiste
Approche paysagiste
 
Commission electorale
Commission electoraleCommission electorale
Commission electorale
 
Baromètre EurObserv’ER 2014 - Etat des énergies renouvelables en Europe
Baromètre EurObserv’ER 2014 - Etat des énergies renouvelables en EuropeBaromètre EurObserv’ER 2014 - Etat des énergies renouvelables en Europe
Baromètre EurObserv’ER 2014 - Etat des énergies renouvelables en Europe
 
Internet en Chine 2013
Internet en Chine 2013Internet en Chine 2013
Internet en Chine 2013
 
Gbph restauration-collective
Gbph restauration-collectiveGbph restauration-collective
Gbph restauration-collective
 

Kürzlich hochgeladen

Vertex AI Gemini Prompt Engineering Tips
Vertex AI Gemini Prompt Engineering TipsVertex AI Gemini Prompt Engineering Tips
Vertex AI Gemini Prompt Engineering TipsMiki Katsuragi
 
New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024BookNet Canada
 
Connect Wave/ connectwave Pitch Deck Presentation
Connect Wave/ connectwave Pitch Deck PresentationConnect Wave/ connectwave Pitch Deck Presentation
Connect Wave/ connectwave Pitch Deck PresentationSlibray Presentation
 
SIP trunking in Janus @ Kamailio World 2024
SIP trunking in Janus @ Kamailio World 2024SIP trunking in Janus @ Kamailio World 2024
SIP trunking in Janus @ Kamailio World 2024Lorenzo Miniero
 
Are Multi-Cloud and Serverless Good or Bad?
Are Multi-Cloud and Serverless Good or Bad?Are Multi-Cloud and Serverless Good or Bad?
Are Multi-Cloud and Serverless Good or Bad?Mattias Andersson
 
Anypoint Exchange: It’s Not Just a Repo!
Anypoint Exchange: It’s Not Just a Repo!Anypoint Exchange: It’s Not Just a Repo!
Anypoint Exchange: It’s Not Just a Repo!Manik S Magar
 
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024BookNet Canada
 
"Debugging python applications inside k8s environment", Andrii Soldatenko
"Debugging python applications inside k8s environment", Andrii Soldatenko"Debugging python applications inside k8s environment", Andrii Soldatenko
"Debugging python applications inside k8s environment", Andrii SoldatenkoFwdays
 
Dev Dives: Streamline document processing with UiPath Studio Web
Dev Dives: Streamline document processing with UiPath Studio WebDev Dives: Streamline document processing with UiPath Studio Web
Dev Dives: Streamline document processing with UiPath Studio WebUiPathCommunity
 
Nell’iperspazio con Rocket: il Framework Web di Rust!
Nell’iperspazio con Rocket: il Framework Web di Rust!Nell’iperspazio con Rocket: il Framework Web di Rust!
Nell’iperspazio con Rocket: il Framework Web di Rust!Commit University
 
Vector Databases 101 - An introduction to the world of Vector Databases
Vector Databases 101 - An introduction to the world of Vector DatabasesVector Databases 101 - An introduction to the world of Vector Databases
Vector Databases 101 - An introduction to the world of Vector DatabasesZilliz
 
Ensuring Technical Readiness For Copilot in Microsoft 365
Ensuring Technical Readiness For Copilot in Microsoft 365Ensuring Technical Readiness For Copilot in Microsoft 365
Ensuring Technical Readiness For Copilot in Microsoft 3652toLead Limited
 
Streamlining Python Development: A Guide to a Modern Project Setup
Streamlining Python Development: A Guide to a Modern Project SetupStreamlining Python Development: A Guide to a Modern Project Setup
Streamlining Python Development: A Guide to a Modern Project SetupFlorian Wilhelm
 
"LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks...
"LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks..."LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks...
"LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks...Fwdays
 
Developer Data Modeling Mistakes: From Postgres to NoSQL
Developer Data Modeling Mistakes: From Postgres to NoSQLDeveloper Data Modeling Mistakes: From Postgres to NoSQL
Developer Data Modeling Mistakes: From Postgres to NoSQLScyllaDB
 
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)Mark Simos
 
What's New in Teams Calling, Meetings and Devices March 2024
What's New in Teams Calling, Meetings and Devices March 2024What's New in Teams Calling, Meetings and Devices March 2024
What's New in Teams Calling, Meetings and Devices March 2024Stephanie Beckett
 
Unraveling Multimodality with Large Language Models.pdf
Unraveling Multimodality with Large Language Models.pdfUnraveling Multimodality with Large Language Models.pdf
Unraveling Multimodality with Large Language Models.pdfAlex Barbosa Coqueiro
 
My Hashitalk Indonesia April 2024 Presentation
My Hashitalk Indonesia April 2024 PresentationMy Hashitalk Indonesia April 2024 Presentation
My Hashitalk Indonesia April 2024 PresentationRidwan Fadjar
 

Kürzlich hochgeladen (20)

Vertex AI Gemini Prompt Engineering Tips
Vertex AI Gemini Prompt Engineering TipsVertex AI Gemini Prompt Engineering Tips
Vertex AI Gemini Prompt Engineering Tips
 
New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
 
Connect Wave/ connectwave Pitch Deck Presentation
Connect Wave/ connectwave Pitch Deck PresentationConnect Wave/ connectwave Pitch Deck Presentation
Connect Wave/ connectwave Pitch Deck Presentation
 
SIP trunking in Janus @ Kamailio World 2024
SIP trunking in Janus @ Kamailio World 2024SIP trunking in Janus @ Kamailio World 2024
SIP trunking in Janus @ Kamailio World 2024
 
Are Multi-Cloud and Serverless Good or Bad?
Are Multi-Cloud and Serverless Good or Bad?Are Multi-Cloud and Serverless Good or Bad?
Are Multi-Cloud and Serverless Good or Bad?
 
Anypoint Exchange: It’s Not Just a Repo!
Anypoint Exchange: It’s Not Just a Repo!Anypoint Exchange: It’s Not Just a Repo!
Anypoint Exchange: It’s Not Just a Repo!
 
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
 
"Debugging python applications inside k8s environment", Andrii Soldatenko
"Debugging python applications inside k8s environment", Andrii Soldatenko"Debugging python applications inside k8s environment", Andrii Soldatenko
"Debugging python applications inside k8s environment", Andrii Soldatenko
 
Dev Dives: Streamline document processing with UiPath Studio Web
Dev Dives: Streamline document processing with UiPath Studio WebDev Dives: Streamline document processing with UiPath Studio Web
Dev Dives: Streamline document processing with UiPath Studio Web
 
Nell’iperspazio con Rocket: il Framework Web di Rust!
Nell’iperspazio con Rocket: il Framework Web di Rust!Nell’iperspazio con Rocket: il Framework Web di Rust!
Nell’iperspazio con Rocket: il Framework Web di Rust!
 
Vector Databases 101 - An introduction to the world of Vector Databases
Vector Databases 101 - An introduction to the world of Vector DatabasesVector Databases 101 - An introduction to the world of Vector Databases
Vector Databases 101 - An introduction to the world of Vector Databases
 
Ensuring Technical Readiness For Copilot in Microsoft 365
Ensuring Technical Readiness For Copilot in Microsoft 365Ensuring Technical Readiness For Copilot in Microsoft 365
Ensuring Technical Readiness For Copilot in Microsoft 365
 
Streamlining Python Development: A Guide to a Modern Project Setup
Streamlining Python Development: A Guide to a Modern Project SetupStreamlining Python Development: A Guide to a Modern Project Setup
Streamlining Python Development: A Guide to a Modern Project Setup
 
"LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks...
"LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks..."LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks...
"LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks...
 
Developer Data Modeling Mistakes: From Postgres to NoSQL
Developer Data Modeling Mistakes: From Postgres to NoSQLDeveloper Data Modeling Mistakes: From Postgres to NoSQL
Developer Data Modeling Mistakes: From Postgres to NoSQL
 
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)
 
What's New in Teams Calling, Meetings and Devices March 2024
What's New in Teams Calling, Meetings and Devices March 2024What's New in Teams Calling, Meetings and Devices March 2024
What's New in Teams Calling, Meetings and Devices March 2024
 
E-Vehicle_Hacking_by_Parul Sharma_null_owasp.pptx
E-Vehicle_Hacking_by_Parul Sharma_null_owasp.pptxE-Vehicle_Hacking_by_Parul Sharma_null_owasp.pptx
E-Vehicle_Hacking_by_Parul Sharma_null_owasp.pptx
 
Unraveling Multimodality with Large Language Models.pdf
Unraveling Multimodality with Large Language Models.pdfUnraveling Multimodality with Large Language Models.pdf
Unraveling Multimodality with Large Language Models.pdf
 
My Hashitalk Indonesia April 2024 Presentation
My Hashitalk Indonesia April 2024 PresentationMy Hashitalk Indonesia April 2024 Presentation
My Hashitalk Indonesia April 2024 Presentation
 

Methodologies And Tools To Make User Self Service A Reality

  • 1. AusCERT 2010 Speaker Presentation Methodologies & Tools to make user self service a reality Paul Conroy – Identity & Access Technology Specialist
  • 2. Agenda Business Challenges Meta-directory concepts User Self Service Scenarios Automated provisioning Attribute change User self service password reset Deprovisioning Summary Resources
  • 3. Business Challenges Threats Current Solutions Business Landscape Increased volume Product proliferation Increased regulatory and compliance pressure More connectivity and collaboration Greater need for identity-based protection and access Greater IT choice; lower budgets Greater sophistication Lack of integration High cost of ownership Profit motivated Security not aligned to business needs and new opportunities
  • 4.
  • 5. Methodologies for Identity Management Directory Synchronisation Automated Provisioning Self Service Management of :- Groups/Distribution Lists Attributes Passwords Delegated Administration (e.g. for approvals)
  • 6. Meta Directory Concept Meta-directory MAINFRAME ACTIVE DIRECTORY FINANCEAPPLICATION EXCHANGE FINANCEPORTAL SMARTCARD iPLANET
  • 7. Methodologies for Identity Management Directory Synchronisation Automated Provisioning Self Service Management of :- Groups/Distribution Lists Attributes Passwords Delegated Administration (e.g. for approvals)
  • 8. HR SYSTEM MANAGER APPROVAL PROVISIONING POLICY APPLIED New Employee Scenario Meta-directory MANAGER APPROVAL MAINFRAME ACTIVE DIRECTORY FINANCEAPPLICATION EXCHANGE FINANCEPORTAL SMARTCARD iPLANET
  • 9. Methodologies for Identity Management Directory Synchronisation Automated Provisioning Self Service Management of :- Groups/Distribution Lists Attributes Passwords Delegated Administration (e.g. for approvals)
  • 10. iPLANET Password Reset And Synchronisation MELISSA PASSWORD SYCHRONISATION WINDOWSMACHINE Meta-directory FINANCEAPPLICATION ACTIVEDIRECTORY FINANCEPORTAL
  • 11. HR SYSTEM PROVISIONING POLICY APPLIED Attribute Management Meta-directory MAINFRAME ACTIVE DIRECTORY FINANCEAPPLICATION MARKETINGAPPLICATION EXCHANGE FINANCEPORTAL MARKETINGPORTAL SMARTCARD iPLANET
  • 12. Methodologies for Identity Management Directory Synchronisation Automated Provisioning Self Service Management of :- Groups/Distribution Lists Attributes Passwords Delegated Administration (e.g. for approvals)
  • 13.
  • 14. Resources Learn About Identity and Access (IDA) www.microsoft.com/IDA

Hinweis der Redaktion

  1. State that automated provisioning is of users and resources
  2. State that automated provisioning is of users and resources
  3. Key points we want to illustrate: Melissa is a new employee starting her first day of work at Contoso. She sits down in her assigned office to begin her work which is heavily dependent on LOB applications and being ‘plugged in’ to key DLs.Rather than calling the help desk to get access, groups, etc. Melissa’s accounts and mailbox are automatically provisioned and available at first login, due to preconfigured rules in ILM “2”She is automatically granted access to the LOB apps relevant to her roleShe is dynamically added to key DLsAnimation flow:Data flows in from HR system. Would like a file to pass from HR to ILM “2” with information on the new hire like Name = Melissa Meyers, Employee ID = 122145, Dept = Finance, Title = Analyst, Employee Type = Full Time.Data flows to each of the target systems. For Exchange a mailbox is created. I want icons to travel along the arrow to represent the data passed to Exchange as well mailbox created. Her email address should be filled in as mmeyers@contoso.com.For AD, a password is assigned and sent to her manager. She is also given membership in the “Finance,” “New Hire” and “FTE” groups in AD. I want icons to travel along the arrow to represent the data passed to AD as well as the password and new groups created.A smart card is also provisioned so for remote access and for her to access the finance appFor the other accounts show the data passing along the arrows. Show only her name, employee ID, and department being passed to iPlanet, and show her Name, ID, and Employee Type passing to the mainframe.
  4. State that automated provisioning is of users and resources
  5. New Employee scenarioCreate new userNow invoke set, workflow and management policy rule. All constructs in Identity ManagementCreate second userNB Mention delegated administration
  6. Logon as the newly created userShow how SSPR worksgoto slideShow DL management in OutlookChange MPR and show self service of fax numbergotoattrmgt slide
  7. Key points we want to illustrate: Melissa is a new employee starting her first day of work at Contoso. She sits down in her assigned office to begin her work which is heavily dependent on LOB applications and being ‘plugged in’ to key DLs.Rather than calling the help desk to get access, groups, etc. Melissa’s accounts and mailbox are automatically provisioned and available at first login, due to preconfigured rules in ILM “2”She is automatically granted access to the LOB apps relevant to her roleShe is dynamically added to key DLsAnimation flow:Data flows in from HR system. Would like a file to pass from HR to ILM “2” with information on the new hire like Name = Melissa Meyers, Employee ID = 122145, Dept = Finance, Title = Analyst, Employee Type = Full Time.Data flows to each of the target systems. For Exchange a mailbox is created. I want icons to travel along the arrow to represent the data passed to Exchange as well mailbox created. Her email address should be filled in as mmeyers@contoso.com.For AD, a password is assigned and sent to her manager. She is also given membership in the “Finance,” “New Hire” and “FTE” groups in AD. I want icons to travel along the arrow to represent the data passed to AD as well as the password and new groups created.A smart card is also provisioned so for remote access and for her to access the finance appFor the other accounts show the data passing along the arrows. Show only her name, employee ID, and department being passed to iPlanet, and show her Name, ID, and Employee Type passing to the mainframe.
  8. Now logon as Melissa and run her approval and logon as new user