Security for the Digital Transformation: Cloud, Data, Identity & Access.
Showing posts with label Provisioning. Show all posts
Showing posts with label Provisioning. Show all posts
Tuesday, February 23
"Automated Provisioning Machine" (in quotes)
I like the cartoon at this Imanami blog entry. It's funny and makes a clear point about identity management (provisioning) solutions. I'll let them make the point rather than re-write it here. But like the old cliche says, a (moving) picture is worth a thousand words.
Thursday, September 24
Provisioning to the Cloud
I posted recently about identity in the cloud. Many identity vendors are doing interesting things to get their solutions 'in the cloud' or available 'as a service'. It's a lot of buzz, but there's also some actual cost savings and operational efficiencies at the bottom of these efforts.
Today, Optimal IdM announced their cloud provisioning solution. Similar to what Identropy is doing with IC2, Optimal IdM's solution leverages existing provisioning solutions and acts as a connector to cloud applications.
This use case of acting as a connector for remote, unknown, complex, or varied systems is a perfect fit for virtual directory technology. MaXware released a similar connector for Salesforce in 2006 while I was still an employee. Perhaps they were ahead of their time? The virtual directory solution can be added to virtually (no pun intended) any environment and provide immediate connections up to numerous, complex cloud systems, thus saving cost and effort as compared to developing custom connectors.
Having said all those nice things about the virtual directory approach and once again encouraging IAM integrators to consider virtual directory solutions while whiteboarding on how to meet requirements, I should be fair and point out an alternate viewpoint. If you already have a provisioning solution from the likes of Courion, Novell, Oracle or IBM, and a requirement to provision to cloud applications, you owe it to yourself to take a close look at Identropy's IC2 offering before making any purchase decisions. That's exactly what it's designed to do.
Another interesting note - I spoke to someone from Arcot today (think secure token-less authentication) who informed me that all of their solutions for secure authentication are now available as a service. They already have one of the most widely deployed authentication-as-a-service solutions on the market, so it seems to be a natural migration to offer their other solutions from the cloud as well.
Who recently said there was no more innovation in the IAM space? The latest innovation in this space is in direct response to the market complaints that IAM is too complex. Once simplicity is realized, innovation will no doubt trend elsewhere. I call that a success in meeting customer demand.
Today, Optimal IdM announced their cloud provisioning solution. Similar to what Identropy is doing with IC2, Optimal IdM's solution leverages existing provisioning solutions and acts as a connector to cloud applications.
This use case of acting as a connector for remote, unknown, complex, or varied systems is a perfect fit for virtual directory technology. MaXware released a similar connector for Salesforce in 2006 while I was still an employee. Perhaps they were ahead of their time? The virtual directory solution can be added to virtually (no pun intended) any environment and provide immediate connections up to numerous, complex cloud systems, thus saving cost and effort as compared to developing custom connectors.
Having said all those nice things about the virtual directory approach and once again encouraging IAM integrators to consider virtual directory solutions while whiteboarding on how to meet requirements, I should be fair and point out an alternate viewpoint. If you already have a provisioning solution from the likes of Courion, Novell, Oracle or IBM, and a requirement to provision to cloud applications, you owe it to yourself to take a close look at Identropy's IC2 offering before making any purchase decisions. That's exactly what it's designed to do.
Another interesting note - I spoke to someone from Arcot today (think secure token-less authentication) who informed me that all of their solutions for secure authentication are now available as a service. They already have one of the most widely deployed authentication-as-a-service solutions on the market, so it seems to be a natural migration to offer their other solutions from the cloud as well.
Who recently said there was no more innovation in the IAM space? The latest innovation in this space is in direct response to the market complaints that IAM is too complex. Once simplicity is realized, innovation will no doubt trend elsewhere. I call that a success in meeting customer demand.
Thursday, July 23
Identity in the Cloud
Over the past year, there have been a number of identity management solutions popping up that aim to help companies deal with identities in Software-as-a-Service (SaaS) / Cloud applications. Here's a list of the solutions that I've encountered:
Cloud Identity - SaaS Identity and Access Management solution. Provides provisioning, workflow, audit reporting, and SSO. Leverages existing enterprise credentials. [more info]
Conformity - SaaS Identity and Access Management solution. Provides provisioning, workflow, and audit reporting for select cloud applications. Leverages Active Directory (or other on-premise repository) accounts as the source. [more info]
Identropy IC2 - Identity Management solution for SaaS applications. Leverages existing Identity infrastructure and work flow to provision accounts to cloud applications via the IC2 SPML gateway. [more info]
MyOneLogin - SaaS Identity and Access Management solution. Provides SSO and Secure Logon to cloud applications and web sites. Enables Account Management for select SaaS applications. Tracks SaaS application usage across apps from a single location. [more info]
Nordic Edge Opacus - SaaS Identity and Access Management solution. Provides Secure Logon to cloud applications. Synchronizes accounts from on-premise repository to cloud systems. Enables delegated user administration for cloud applications. [more info]
PingConnect - SaaS SSO solution for Salesforce CRM, Google Apps, and 60+ other SaaS applications. Leverages existing enterprise credentials, Google Apps Logon ID, or Salesforce credentials. [more info]
SecurAct - SaaS Identity and Access Management solution. Provides provisioning, work flow, SSO, and audit reporting for both local and cloud applications. Leverages Active Directory accounts as the source. [more info]
Symplified - SaaS Identity and Access Management solution. Provides provisioning, audit reporting, authentication, and SSO across local and cloud apps. Leverages existing enterprise credentials. Can also prevent side-door access. [more info]
NOTE TO VENDORS - please feel free to reach out if my description above is incorrect. I'm happy to make corrections where appropriate or provide additional differentiators. I also encourage comments that help identify how products stand apart from the others by end-users or vendors.
[Updated Aug 04, 2009]
[Updated Jul 29, 2009]
Cloud Identity - SaaS Identity and Access Management solution. Provides provisioning, workflow, audit reporting, and SSO. Leverages existing enterprise credentials. [more info]
Conformity - SaaS Identity and Access Management solution. Provides provisioning, workflow, and audit reporting for select cloud applications. Leverages Active Directory (or other on-premise repository) accounts as the source. [more info]
Identropy IC2 - Identity Management solution for SaaS applications. Leverages existing Identity infrastructure and work flow to provision accounts to cloud applications via the IC2 SPML gateway. [more info]
MyOneLogin - SaaS Identity and Access Management solution. Provides SSO and Secure Logon to cloud applications and web sites. Enables Account Management for select SaaS applications. Tracks SaaS application usage across apps from a single location. [more info]
Nordic Edge Opacus - SaaS Identity and Access Management solution. Provides Secure Logon to cloud applications. Synchronizes accounts from on-premise repository to cloud systems. Enables delegated user administration for cloud applications. [more info]
PingConnect - SaaS SSO solution for Salesforce CRM, Google Apps, and 60+ other SaaS applications. Leverages existing enterprise credentials, Google Apps Logon ID, or Salesforce credentials. [more info]
SecurAct - SaaS Identity and Access Management solution. Provides provisioning, work flow, SSO, and audit reporting for both local and cloud applications. Leverages Active Directory accounts as the source. [more info]
Symplified - SaaS Identity and Access Management solution. Provides provisioning, audit reporting, authentication, and SSO across local and cloud apps. Leverages existing enterprise credentials. Can also prevent side-door access. [more info]
NOTE TO VENDORS - please feel free to reach out if my description above is incorrect. I'm happy to make corrections where appropriate or provide additional differentiators. I also encourage comments that help identify how products stand apart from the others by end-users or vendors.
[Updated Aug 04, 2009]
[Updated Jul 29, 2009]
Labels:
authentication,
Cloud,
federation,
identity,
identity management,
Provisioning,
SSO
Thursday, October 30
Productivity was the big motivator
If you clicked the link to this page from the article titled Ease your identity management issues in IT World Canada, I wanted to provide a quick pointer to some of the content I *think* you might be interested in.
The link occurs in the line:
You might notice that my ultimate conclusion is a little different than the one in the article. Here's the full paragraph from the IT World Canada article:
In a completely separate post, I also talk about the difference between enabling end-user productivity in some SSO solutions and enabling security in others. ...perhaps that was the motivation for the link?
Either way, thanks to IT World Canada for the link!
The link occurs in the line:
And while user productivity was the "big motivator" behind identity management strategies several years ago...So, I think the writer may have read one of my previous posts which said:
Provisioning has typically been about increased efficiency and reduced cost. But, it's time to extend the ROI into security and compliance as well.I expanded on the theme in a later post and then discussed the topic in an article on eBizQ.
You might notice that my ultimate conclusion is a little different than the one in the article. Here's the full paragraph from the IT World Canada article:
And while user productivity was the "big motivator" behind identity management strategies several years ago, it has now assumed a back seat as the rough economy has brought to the fore the need to reduce help desk and security administrative staff by automating previously manual user access processes, said Shohan. “People at least pay lip service to the idea of regulatory compliance and improving security, although I suspect in many cases, they… are really more interested in ROI and access termination,” he said.So, it sounds like they're saying that the initial drivers for IAM were user-productivity and that has shifted to operational cost savings. In contrast, I would say that the initial driver was operational cost savings, it later included user-productivity, and now the shift is toward greater security and compliance / audit-ability.
In a completely separate post, I also talk about the difference between enabling end-user productivity in some SSO solutions and enabling security in others. ...perhaps that was the motivation for the link?
Either way, thanks to IT World Canada for the link!
Tuesday, September 16
Building a Central Identity Store
The folks at SECUDE Consulting, who are SAP ERM specialists, have an identity practice that focuses on (among other things) SAP NetWeaver Identity Management solutions (the former MaXware products). Matt P, part of SECUDE's IAM team, recently authored a white paper titled Strategies for Creating an Authoritative Store.
If you are building a provisioning system, deploying SAP NetWeaver Identity Management, or designing an enterprise identity store, you should review this paper. Matt discusses terminology like source repositories and target systems, discusses data join techniques, and introduces the concept of layering. The paper provides an overall road map for designing an enterprise identity store, which can be a critical component of a provisioning solution.
You can get a copy via the links or contact info in Matt's blog post about the paper.
If you are building a provisioning system, deploying SAP NetWeaver Identity Management, or designing an enterprise identity store, you should review this paper. Matt discusses terminology like source repositories and target systems, discusses data join techniques, and introduces the concept of layering. The paper provides an overall road map for designing an enterprise identity store, which can be a critical component of a provisioning solution.
You can get a copy via the links or contact info in Matt's blog post about the paper.
Monday, June 16
Value Adding Security to the ROI of Identity Management
Two months ago, I posted about the prospect of extending the ROI on provisioning. The post was inspired by conversations with many smart people and led to additional conversations (like this one) that helped formulate the ideas presented in an article that was published today at eBizQ titled Value Adding Security to the ROI of Identity Management.
The initial draft had a number of quotes, but the quotes didn't read well according to the editor who was concerned that a quote by anyone less famous than Gartner could appear biased. I see his point, but apologies to those who I had requested permission to quote and who might have been expecting to be a part of the article.
I hope the article clarifies what I meant by extending the ROI of provisioning. I led a round table discussion at a CSO conference recently on the topic and I'm not sure that the idea resonated immediately. The bottom line is that provisioning solutions can be augmented to become a true (secure) funnel for account management rather than just the preferred avenue.
The initial draft had a number of quotes, but the quotes didn't read well according to the editor who was concerned that a quote by anyone less famous than Gartner could appear biased. I see his point, but apologies to those who I had requested permission to quote and who might have been expecting to be a part of the article.
I hope the article clarifies what I meant by extending the ROI of provisioning. I led a round table discussion at a CSO conference recently on the topic and I'm not sure that the idea resonated immediately. The bottom line is that provisioning solutions can be augmented to become a true (secure) funnel for account management rather than just the preferred avenue.
Friday, April 18
Extending the ROI on Provisioning
Provisioning has typically been about increased efficiency and reduced cost. But, it's time to extend the ROI into security and compliance as well. I've had a number of conversations over the past two weeks with provisioning vendors and industry consultants. They confirmed that the organizations they work with are asking for this. The same organizations that deploy provisioning solutions are confronted with compliance tasks and demand for improved security. They want the identity infrastructure that enables work flow efficiency to provide the compliance benefits as well. Provisioning vendors have made progress in terms of logging system activity, but there's no way for them to prevent authorized administrators from leveraging direct access to the directory to get around the work flow. Today's niche identity and security vendors have improved on this by providing security and audit-ability on the complete set of activity taking place in the identity infrastructure. I'm in the process of writing an article on this for one of the security trade mags. I'm interested in your feedback on this topic.
Would you like to be quoted? Would you like to be mentioned as a consultant that understands this proposition? Would you like your vendor's technology to be included? Let me know or leave a comment.
Would you like to be quoted? Would you like to be mentioned as a consultant that understands this proposition? Would you like your vendor's technology to be included? Let me know or leave a comment.
Thursday, November 29
Provisioning with SPML
About 18 months ago, I wrote a paper for MaXware about Identity Management in a Service Oriented Architecture (SOA) and described the scenario of initiating provisioning events from enterprise applications via SPML to the provisioning system (now called the Provisioning Service Provider in an SPML scenario).
Martin Raepple of SAP just published an article titled No Limits for Identities. In it, he discusses the process and business value of leveraging SPML for provisioning. He also discusses the role of the Provisioning Service Provider (PSP).
It seems that SAP has done a good job of quickly leveraging one of MaXware's core strengths to enable the NetWeaver platform to act as an open and available PSP for the enterprise. Many of the other major provisioning platforms also support SPML, but I haven't heard of many customers leveraging a service-based provisioning model. I still expect this type of architecture to become more commonly used. Have you seen it in action?
Martin Raepple of SAP just published an article titled No Limits for Identities. In it, he discusses the process and business value of leveraging SPML for provisioning. He also discusses the role of the Provisioning Service Provider (PSP).
It seems that SAP has done a good job of quickly leveraging one of MaXware's core strengths to enable the NetWeaver platform to act as an open and available PSP for the enterprise. Many of the other major provisioning platforms also support SPML, but I haven't heard of many customers leveraging a service-based provisioning model. I still expect this type of architecture to become more commonly used. Have you seen it in action?
Subscribe to:
Posts (Atom)