SlideShare ist ein Scribd-Unternehmen logo
1 von 14
AusCERT 2010 Speaker Presentation Methodologies & Tools to make user self service a reality Paul Conroy – Identity & Access Technology Specialist
Agenda Business Challenges Meta-directory concepts User Self Service Scenarios Automated provisioning Attribute change User self service password reset Deprovisioning Summary Resources
Business Challenges Threats Current Solutions Business Landscape Increased volume Product proliferation Increased regulatory and compliance pressure More connectivity and collaboration Greater need for identity-based protection and access Greater IT choice; lower budgets Greater sophistication Lack of integration High cost of ownership Profit motivated Security not aligned to business needs and new opportunities
• Enhanced User Experience – Includes self-service password reset • Account Provisioning and Access Request  Empower People ,[object Object],Deliver Agility and Efficiency • Centralised source for auditors  • Credential Management  Increase Security and Compliance Goals of an Identity Management project
Methodologies for Identity Management Directory Synchronisation Automated Provisioning Self Service Management of :- Groups/Distribution Lists Attributes Passwords Delegated Administration (e.g. for approvals)
Meta Directory Concept Meta-directory MAINFRAME ACTIVE DIRECTORY FINANCEAPPLICATION EXCHANGE FINANCEPORTAL SMARTCARD iPLANET
Methodologies for Identity Management Directory Synchronisation Automated Provisioning Self Service Management of :- Groups/Distribution Lists Attributes Passwords Delegated Administration (e.g. for approvals)
HR SYSTEM MANAGER APPROVAL PROVISIONING POLICY APPLIED New Employee Scenario Meta-directory MANAGER APPROVAL MAINFRAME ACTIVE DIRECTORY FINANCEAPPLICATION EXCHANGE FINANCEPORTAL SMARTCARD iPLANET
Methodologies for Identity Management Directory Synchronisation Automated Provisioning Self Service Management of :- Groups/Distribution Lists Attributes Passwords Delegated Administration (e.g. for approvals)
iPLANET Password Reset And Synchronisation MELISSA PASSWORD SYCHRONISATION WINDOWSMACHINE Meta-directory  FINANCEAPPLICATION ACTIVEDIRECTORY FINANCEPORTAL
HR SYSTEM  PROVISIONING POLICY APPLIED Attribute Management Meta-directory MAINFRAME ACTIVE DIRECTORY FINANCEAPPLICATION MARKETINGAPPLICATION EXCHANGE FINANCEPORTAL MARKETINGPORTAL SMARTCARD iPLANET
Methodologies for Identity Management Directory Synchronisation Automated Provisioning Self Service Management of :- Groups/Distribution Lists Attributes Passwords Delegated Administration (e.g. for approvals)
Goal of an Identity Management project • Enhanced User Experience – Includes self-service password reset • Account Provisioning and Access Request  Empower People ,[object Object],Deliver Agility and Efficiency • Centralised source for auditors  • Credential Management  Increase Security and Compliance Summary
Resources Learn About Identity and Access (IDA) www.microsoft.com/IDA

Weitere ähnliche Inhalte

Andere mochten auch

Tech Ed 2011 Preso
Tech Ed 2011 PresoTech Ed 2011 Preso
Tech Ed 2011 Preso
PAUL CONROY
 
Лекция № 5. Важнейшие элементы периодической системы Д.И. Менделеева, определ...
Лекция № 5. Важнейшие элементы периодической системы Д.И. Менделеева, определ...Лекция № 5. Важнейшие элементы периодической системы Д.И. Менделеева, определ...
Лекция № 5. Важнейшие элементы периодической системы Д.И. Менделеева, определ...
Петрова Елена Александровна
 
Commission electorale
Commission electoraleCommission electorale
Commission electorale
Juanico
 
Gbph restauration-collective
Gbph restauration-collectiveGbph restauration-collective
Gbph restauration-collective
Mounir El Ourak
 

Andere mochten auch (16)

Tech Ed 2011 Preso
Tech Ed 2011 PresoTech Ed 2011 Preso
Tech Ed 2011 Preso
 
Life
LifeLife
Life
 
Inco Terms
Inco TermsInco Terms
Inco Terms
 
Java I/O Part 1
Java I/O Part 1Java I/O Part 1
Java I/O Part 1
 
Java I/O Part 2
Java I/O Part 2Java I/O Part 2
Java I/O Part 2
 
JSP : Creating Custom Tag
JSP : Creating Custom Tag JSP : Creating Custom Tag
JSP : Creating Custom Tag
 
Dom Basics
Dom BasicsDom Basics
Dom Basics
 
Network analysis
Network analysisNetwork analysis
Network analysis
 
Ecommerce Monetiser Son Site Philippefloch Technofutur
Ecommerce Monetiser Son Site Philippefloch TechnofuturEcommerce Monetiser Son Site Philippefloch Technofutur
Ecommerce Monetiser Son Site Philippefloch Technofutur
 
Intelligence collective et réseaux sociaux : comment le web 2.0 modifie la tr...
Intelligence collective et réseaux sociaux : comment le web 2.0 modifie la tr...Intelligence collective et réseaux sociaux : comment le web 2.0 modifie la tr...
Intelligence collective et réseaux sociaux : comment le web 2.0 modifie la tr...
 
Лекция № 5. Важнейшие элементы периодической системы Д.И. Менделеева, определ...
Лекция № 5. Важнейшие элементы периодической системы Д.И. Менделеева, определ...Лекция № 5. Важнейшие элементы периодической системы Д.И. Менделеева, определ...
Лекция № 5. Важнейшие элементы периодической системы Д.И. Менделеева, определ...
 
Approche paysagiste
Approche paysagisteApproche paysagiste
Approche paysagiste
 
Commission electorale
Commission electoraleCommission electorale
Commission electorale
 
Baromètre EurObserv’ER 2014 - Etat des énergies renouvelables en Europe
Baromètre EurObserv’ER 2014 - Etat des énergies renouvelables en EuropeBaromètre EurObserv’ER 2014 - Etat des énergies renouvelables en Europe
Baromètre EurObserv’ER 2014 - Etat des énergies renouvelables en Europe
 
Internet en Chine 2013
Internet en Chine 2013Internet en Chine 2013
Internet en Chine 2013
 
Gbph restauration-collective
Gbph restauration-collectiveGbph restauration-collective
Gbph restauration-collective
 

Kürzlich hochgeladen

Artificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and MythsArtificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and Myths
Joaquim Jorge
 
IAC 2024 - IA Fast Track to Search Focused AI Solutions
IAC 2024 - IA Fast Track to Search Focused AI SolutionsIAC 2024 - IA Fast Track to Search Focused AI Solutions
IAC 2024 - IA Fast Track to Search Focused AI Solutions
Enterprise Knowledge
 
Histor y of HAM Radio presentation slide
Histor y of HAM Radio presentation slideHistor y of HAM Radio presentation slide
Histor y of HAM Radio presentation slide
vu2urc
 
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptxEIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
Earley Information Science
 

Kürzlich hochgeladen (20)

Real Time Object Detection Using Open CV
Real Time Object Detection Using Open CVReal Time Object Detection Using Open CV
Real Time Object Detection Using Open CV
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected Worker
 
Artificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and MythsArtificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and Myths
 
Boost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivityBoost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivity
 
Slack Application Development 101 Slides
Slack Application Development 101 SlidesSlack Application Development 101 Slides
Slack Application Development 101 Slides
 
Tata AIG General Insurance Company - Insurer Innovation Award 2024
Tata AIG General Insurance Company - Insurer Innovation Award 2024Tata AIG General Insurance Company - Insurer Innovation Award 2024
Tata AIG General Insurance Company - Insurer Innovation Award 2024
 
Data Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt RobisonData Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt Robison
 
The Codex of Business Writing Software for Real-World Solutions 2.pptx
The Codex of Business Writing Software for Real-World Solutions 2.pptxThe Codex of Business Writing Software for Real-World Solutions 2.pptx
The Codex of Business Writing Software for Real-World Solutions 2.pptx
 
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdfThe Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
 
IAC 2024 - IA Fast Track to Search Focused AI Solutions
IAC 2024 - IA Fast Track to Search Focused AI SolutionsIAC 2024 - IA Fast Track to Search Focused AI Solutions
IAC 2024 - IA Fast Track to Search Focused AI Solutions
 
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
 
TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law DevelopmentsTrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
 
Presentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreterPresentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreter
 
Histor y of HAM Radio presentation slide
Histor y of HAM Radio presentation slideHistor y of HAM Radio presentation slide
Histor y of HAM Radio presentation slide
 
The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024
 
Advantages of Hiring UIUX Design Service Providers for Your Business
Advantages of Hiring UIUX Design Service Providers for Your BusinessAdvantages of Hiring UIUX Design Service Providers for Your Business
Advantages of Hiring UIUX Design Service Providers for Your Business
 
Boost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdfBoost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdf
 
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptxEIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
 
Workshop - Best of Both Worlds_ Combine KG and Vector search for enhanced R...
Workshop - Best of Both Worlds_ Combine  KG and Vector search for  enhanced R...Workshop - Best of Both Worlds_ Combine  KG and Vector search for  enhanced R...
Workshop - Best of Both Worlds_ Combine KG and Vector search for enhanced R...
 
Finology Group – Insurtech Innovation Award 2024
Finology Group – Insurtech Innovation Award 2024Finology Group – Insurtech Innovation Award 2024
Finology Group – Insurtech Innovation Award 2024
 

Methodologies And Tools To Make User Self Service A Reality

  • 1. AusCERT 2010 Speaker Presentation Methodologies & Tools to make user self service a reality Paul Conroy – Identity & Access Technology Specialist
  • 2. Agenda Business Challenges Meta-directory concepts User Self Service Scenarios Automated provisioning Attribute change User self service password reset Deprovisioning Summary Resources
  • 3. Business Challenges Threats Current Solutions Business Landscape Increased volume Product proliferation Increased regulatory and compliance pressure More connectivity and collaboration Greater need for identity-based protection and access Greater IT choice; lower budgets Greater sophistication Lack of integration High cost of ownership Profit motivated Security not aligned to business needs and new opportunities
  • 4.
  • 5. Methodologies for Identity Management Directory Synchronisation Automated Provisioning Self Service Management of :- Groups/Distribution Lists Attributes Passwords Delegated Administration (e.g. for approvals)
  • 6. Meta Directory Concept Meta-directory MAINFRAME ACTIVE DIRECTORY FINANCEAPPLICATION EXCHANGE FINANCEPORTAL SMARTCARD iPLANET
  • 7. Methodologies for Identity Management Directory Synchronisation Automated Provisioning Self Service Management of :- Groups/Distribution Lists Attributes Passwords Delegated Administration (e.g. for approvals)
  • 8. HR SYSTEM MANAGER APPROVAL PROVISIONING POLICY APPLIED New Employee Scenario Meta-directory MANAGER APPROVAL MAINFRAME ACTIVE DIRECTORY FINANCEAPPLICATION EXCHANGE FINANCEPORTAL SMARTCARD iPLANET
  • 9. Methodologies for Identity Management Directory Synchronisation Automated Provisioning Self Service Management of :- Groups/Distribution Lists Attributes Passwords Delegated Administration (e.g. for approvals)
  • 10. iPLANET Password Reset And Synchronisation MELISSA PASSWORD SYCHRONISATION WINDOWSMACHINE Meta-directory FINANCEAPPLICATION ACTIVEDIRECTORY FINANCEPORTAL
  • 11. HR SYSTEM PROVISIONING POLICY APPLIED Attribute Management Meta-directory MAINFRAME ACTIVE DIRECTORY FINANCEAPPLICATION MARKETINGAPPLICATION EXCHANGE FINANCEPORTAL MARKETINGPORTAL SMARTCARD iPLANET
  • 12. Methodologies for Identity Management Directory Synchronisation Automated Provisioning Self Service Management of :- Groups/Distribution Lists Attributes Passwords Delegated Administration (e.g. for approvals)
  • 13.
  • 14. Resources Learn About Identity and Access (IDA) www.microsoft.com/IDA

Hinweis der Redaktion

  1. State that automated provisioning is of users and resources
  2. State that automated provisioning is of users and resources
  3. Key points we want to illustrate: Melissa is a new employee starting her first day of work at Contoso. She sits down in her assigned office to begin her work which is heavily dependent on LOB applications and being ‘plugged in’ to key DLs.Rather than calling the help desk to get access, groups, etc. Melissa’s accounts and mailbox are automatically provisioned and available at first login, due to preconfigured rules in ILM “2”She is automatically granted access to the LOB apps relevant to her roleShe is dynamically added to key DLsAnimation flow:Data flows in from HR system. Would like a file to pass from HR to ILM “2” with information on the new hire like Name = Melissa Meyers, Employee ID = 122145, Dept = Finance, Title = Analyst, Employee Type = Full Time.Data flows to each of the target systems. For Exchange a mailbox is created. I want icons to travel along the arrow to represent the data passed to Exchange as well mailbox created. Her email address should be filled in as mmeyers@contoso.com.For AD, a password is assigned and sent to her manager. She is also given membership in the “Finance,” “New Hire” and “FTE” groups in AD. I want icons to travel along the arrow to represent the data passed to AD as well as the password and new groups created.A smart card is also provisioned so for remote access and for her to access the finance appFor the other accounts show the data passing along the arrows. Show only her name, employee ID, and department being passed to iPlanet, and show her Name, ID, and Employee Type passing to the mainframe.
  4. State that automated provisioning is of users and resources
  5. New Employee scenarioCreate new userNow invoke set, workflow and management policy rule. All constructs in Identity ManagementCreate second userNB Mention delegated administration
  6. Logon as the newly created userShow how SSPR worksgoto slideShow DL management in OutlookChange MPR and show self service of fax numbergotoattrmgt slide
  7. Key points we want to illustrate: Melissa is a new employee starting her first day of work at Contoso. She sits down in her assigned office to begin her work which is heavily dependent on LOB applications and being ‘plugged in’ to key DLs.Rather than calling the help desk to get access, groups, etc. Melissa’s accounts and mailbox are automatically provisioned and available at first login, due to preconfigured rules in ILM “2”She is automatically granted access to the LOB apps relevant to her roleShe is dynamically added to key DLsAnimation flow:Data flows in from HR system. Would like a file to pass from HR to ILM “2” with information on the new hire like Name = Melissa Meyers, Employee ID = 122145, Dept = Finance, Title = Analyst, Employee Type = Full Time.Data flows to each of the target systems. For Exchange a mailbox is created. I want icons to travel along the arrow to represent the data passed to Exchange as well mailbox created. Her email address should be filled in as mmeyers@contoso.com.For AD, a password is assigned and sent to her manager. She is also given membership in the “Finance,” “New Hire” and “FTE” groups in AD. I want icons to travel along the arrow to represent the data passed to AD as well as the password and new groups created.A smart card is also provisioned so for remote access and for her to access the finance appFor the other accounts show the data passing along the arrows. Show only her name, employee ID, and department being passed to iPlanet, and show her Name, ID, and Employee Type passing to the mainframe.
  8. Now logon as Melissa and run her approval and logon as new user