Identity Management: Services, Tools and Processes Cal Racey

Slides:



Advertisements
Similar presentations
The Ward Group 31 December Agenda Introduction The business problem Sharepoint Q&A.
Advertisements

Next Generation Athens Services Ed Zedlewski UK e-Science Town Meeting, London, 11 April 2005.
April 22nd 2008 Internet2 Spring member meeting Caleb Racey Newcastle University UK Studies in Advanced Access Management.
Microsoft Learning Gateway for HE Rob Miles – Hull University, Lecturer Romola Ganguli – Microsoft Education Technology Advisor.
WHY CMS? WHY NOW? CONTENT MANAGEMENT SYSTEM. CMS OVERVIEW Why CMS? What is it? What are the benefits and how can it help me? Centralia College web content.
1 Integration Made Easy Agile Integration: Connecting Salesforce With Your Enterprise.
Practical Experiences of IAM and Distributed Services Richard James Newcastle University 15 th November 2013.
Shibboleth at Newcastle Caleb Racey Webteam ISS Shibboleth experiences Program  Background  What shib has enabled  Benefits of shib  How to do shib.
1. Failure is when users do not feel they get what they paid for. 2. Failure is when the overall organization fails to adopt the solution.
Information Technology Current Work in System Architecture November 2003 Tom Board Director, NUIT Information Systems Architecture.
Thee-Framework for Education & Research The e-Framework for Education & Research an Overview TEN Competence, Jan 2007 Bill Olivier,
Case Study: Newcastle University
Academic Services Interactive Media Managing the Web with Java JA-SIG Winter 2002 Robert Sherratt Academic Services, Interactive Media.
Identity and Access Management IAM A Preview. 2 Goal To design and implement an identity and access management (IAM) middleware infrastructure that –
NMI-EDIT Outreach: The first five years. Topics for Today  NMI-EDIT background  Activities  Outcomes  Resources.
Avaya Contact Center Control Manager. © 2010 Avaya Inc. All rights reserved. What if you could… 1 Requires purchase of additional connectors  Enable.
Create with SharePoint 2010 Jen Dodd Sr. Solutions Consultant
Colin Clark, Fluid Project Technical Lead, Adaptive Technology Resource Centre, University of Toronto Bridging the Gap: Design & Development in Sakai.
Use case: Federated Identity for Education (Feide) Identity collaboration and federation in Norwegian education Internet2 International Workshop, Chicago,
Athens Building Communities Ed Zedlewski & Lyn Norris UKSG, Warwick, April 2002.
Collaboration tools at Newcastle Caleb Racey
Good practice in Research Data Management Module 6: Tools, training and support.
1 Kuali Identity Management Advanced CAMP: Identity Services Summit for Higher Ed Open / Community-Source Projects.
Identity Management 2.0 George O. Strawn NSF CIO.
BfB: Supporting Collaboration with Infrastructure.
Microsoft Dynamics Snap Michael McClary ISV Developer Evangelist Microsoft Corporation.
Copyright JNT Association 2005Copyright JNT Association An Introduction to Access Management and the UK Federation Simon Cooper.
Copyright © 2004 The McGraw-Hill Companies. All Rights reserved Whitten Bentley DittmanSYSTEMS ANALYSIS AND DESIGN METHODS6th Edition Irwin/McGraw-Hill.
Federated Identity Management for HEP David Kelsey WLCG GDB 9 May 2012.
Information Services support for distance learners Barry Croucher IS Helpdesk Manager.
UCLA Enterprise Directory Identity Management Infrastructure UC Enrollment Service Technical Conference October 16, 2007 Ying Ma
The Brain Project – Building Research Background Part of JISC Virtual Research Environments (Phase 3) Programme Based at Coventry University with Leeds.
Project 2003 Presentation Ben Howard 15 th July 2003.
MEDIU Learning for HE Ahmad Nimer | Project Manager.
Capture the Movement: Banner 7.0 and Beyond Susan LaCour, Senior Vice President, Solutions Development California Community Colleges Banner Group.
IT Staff Survey Overview Over 1,300 responses were received. Staff across all faculties and support services were represented. 50 % of respondents.
EdReNe, 2nd Strategic Seminar (Lisbon, June 2008) (c) 2008, Daniel Weiler, Centre of Technology of Education Luxembourg’s Educational Portal Enabling Connected.

Collaborative Platforms. Collaborations and Virtual Organizations IdM is a critical dimension of collaboration, crossing many applications.
1 The World Bank Internet Services Program Rajan Bhardvaj
Key themes covered Search engines Locating/ assessing suitable resources Information Skills – knowing where to look Free web-based RDN,NLN, Ferl JISC or.
Copyright © 2004 The McGraw-Hill Companies. All Rights reserved Whitten Bentley DittmanSYSTEMS ANALYSIS AND DESIGN METHODS6th Edition Irwin/McGraw-Hill.
GRAPPLE – Public Event Slide 1 Extending Commercial LMSs with Adaptivity Patrick Pekczynski imc information multimedia communication AG.
Supporting further and higher education The Akenti Authorisation System Alan Robiette, JISC Development Group.
Kuali Rice A basic overview…. Kuali Rice Mission First and foremost to provide a consistent development framework and common middleware layer for Kuali.
NA-MIC National Alliance for Medical Image Computing UCSD: Engineering Core 2 Portal and Grid Infrastructure.
Disseminating News Within Your Organisation Brian Kelly UKOLN University of Bath Bath, BA2 7AY UKOLN is supported by: URL
Information Technology Current Work in System Architecture January 2004 Tom Board Director, NUIT Information Systems Architecture.
SAP Identity Management 7.2 Implementation
interactive logbook Paul Kiddie, Mike Sharples et al. The Development of an Application to Enhance.
Ultranet – An Introduction. What’s the BIG Idea? The Ultranet connects people, places, spaces and ideas. It is an online student centred learning environment.
JTC Consulting Group Knowledge Management System Jennifer Leigh Carlos Pena Terry Yong 1.
1 © Xchanging 2010 no part of this document may be circulated, quoted or reproduced without prior written approval of Xchanging. MOSS Training – UI customization.
© Copyright 2012 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice. 1 Automate your way to.
Windows SharePoint Services. Overview Windows SharePoint Services (WSS) Information Worker Infrastructure component delivered in Windows Server 2003 Enables.
University of Washington Collaboration: Identity and Access Management Lori Stevens University of Washington October 2007.
b2access.eudat.eu B2ACCESS The simple and secure authorisation and authentication platform of EUDAT This work is licensed under the Creative.
Google Apps and Tools for the Classroom
© CGI Group Inc. PrimePortal & #define Annika Maltesson, Project Krister Sundkvist,
Introduction to Terra Dotta Applications Integration with Campus Data Systems for institutions beginning their software implementation.
INTRODUCTION TO IDENTITY FEDERATIONS Heather Flanagan, NSRC.
V7 Foundation Series Vignette Education Services.
#SummitNow CMIS in our Research Group Ian Wright University of
Kundan Singh Venkatesh Oct 2013
Knowledge Management Tools
What is SharePoint and why you should care
Modern Collaboration in Teams & Projects Powered by Office 365
Mendeley Overview VISHAL GUPTA Customer Consultant South Asia
Supporting Institutions Towards a Shibbolized Infrastructure
Mendeley Overview VISHAL GUPTA Customer Consultant South Asia
Presentation transcript:

Identity Management: Services, Tools and Processes Cal Racey

Context: Who I am Cal Racey – System Architecture Manager: 9 years experience of Middleware application provision Particular focus on issues of single sign on and access control Project Manager on JISC funded GFIVO, IDMAPS and GRAND projects Collaborate with Internet2/EDUCAUSE on IdM Experienced in use of open source tools C

Presentation Overview Theme: Practical examples of IdM solutions Background: The challenge of IdM Newcastle’s IdM review –Audit –Architectural Gaps Tools and services to enhance IdM –Data integration –Group management –Authentication –Combined integration service

Overview of IDM The Challenge of Implementing IdM Architectures (Thanks to Jens Haeusser UBC.ca for the IKEA Metaphor and slides)

What this workshop is trying to achieve Help add pages to that instructions booklet Build community knowledge and practice around IdM Build portfolio of case studies around IdM Find out what the community needs Provide reusable examples of IdM solutions

Newcastle’s IdM Example Focussed on exploiting our Existing IdM data SAP HR + student data good enough –Poor use in Teaching and Learning apps –needed better integration with applications What we Did: Audit application practice and desired usage Understand requirement – Gap analyses Deploy tools and services to enhance architecture Focus on early benefit realisation

Audit: Systems requiring IdM data AccommodationGrouperS3P Active DirectoryIndividuals project (DMS)Service centre (helpdesk) BlackboardIntralibraryShibboleth CAMAListsSite manager (CMS) DspaceModule Outline formsSmartcard ePortfoliosMyprofiles/My ImpactStudent homepage ePrintsNESS (VLE)Regulations NUcontactsTelecoms Estates ticketing systemPrint creditsTimetabling Exam papersRecapUNIX FMSC VLEsSakai (VRE)Wireless

Initial Architecture: Flow of Identity Data

Desired Architecture

SAP Campus management HR Data warehouse, CAMA Grouper Shibboleth, Grouper, Active Directory Talend

Filling the gaps - Architecture Data warehouse –Combines Identity data from multiple sources –Makes “sense” of data Group management –Adds structure to user population Arranges users into “usable” units Data integration tools –Processes data + Puts it where it needs to be –Captures and expresses business logic Authentication and Authorization service –Based on good user data

Tools: Talend Integration suite Data integration tool Open source like MySQL –Free version + paid for enhancements Replaced many bespoke scripts Supported Existing and desired approaches –Excellent file support –Excellent database connectivity –Excellent Application connectivity (e.g. SAP) –Web services Resources available at

Tools: Talend Integration suite Why Talend? “Visionary” in Gartner’s data management Also Offers Data quality and Master data management solutions Training and consultancy offerings “Middle Man” means they have to integrate with everything ETL and IdM share many problems Data quality, duplicate removal, incomplete data Resources available at

Talend Example

Tools: Talend Benefits End to end connectivity –Control of flow all way through –Transparency of process –No more fragile chains of scheduled tasks Allows team responsibility –Easy to see what a job does –Job stored in versioned store (svn) Many data connectors Interacts with windows and unix (including login) Data integration logic in one place.

Institutional data feed service (IDFS) Single point of contact for IdM data Consultancy Process for asking for data: Meeting to discuss requirements Data integration form (Capture, record data flows) Make application owners aware of responsibilities: Security DPA Freedom of information Data integration tool (Talend)

Tools: Grouper GRAND project Grouper used to structure and enhance IdM data –Organisational Structure –Module enrolment –User maintained e.g. Research teams Groups are the way the university works –“modules, departments, research teams – not users” Use case documents available at

Tools: Grouper Enables use of composite groups Mixing of static institutional groups and user edited groups management interfaces –Web based: “heavy” and “lite” –Web services –Scripts (grouper shell) –Java API Data usable multiple ways –Data exports –Shibboleth attributes –LDAP-PC

Grouper – wireless access

Grouper – Room booking

Tools: Shibboleth Built for Federated use case Provides Authentication and Authorisation Used extensively internally Rich attributes –People on accountancy can access acc101 podcast –People in chemistry can access chemistry wiki –Provides framework for targeted personalisation e.g. Here are your podcasts + exam papers Standards based, allows integration – e.g. Google Apps

Tools: Shibboleth use cases Lecture capture authorisation Portal page personalisation Mailing lists Wikis blogs VREs Reading lists Personal portfolios e.g. MyImpact Don’t have to understand shib to integrate shib’d apps have less to worry about

Systems integration service One place to talk about domesticating applications Combines: –Institutional data feed service –Group management service –Shibboleth service Mix and match services depending on requirement –Focus on need rather than architectural “purity” Goal: –Ease application development and deployment –Make IT applications appear “joined up”

Realising benefits from IdM Problem: Benefit realisation dependant on influencing application owners – Apps Spread across political boundaries e.g. Library, careers, medical school – Apps spread across platforms – good tools not enough Solution: –Wrap tools and processes in a service –Campaign of outreach –Listen to application owners

Realising benefits from IdM Service more important than architecture or tools –Builds relationships better understanding of real service barriers easy future integration –1Hour conversation > 2 weeks work Delivery best influencing technique –Effective IdM dependant on influence Even centralised IT can’t enforce

IDM resources IDMAPS GRAND Identity Management toolkit Identity Management EDUCAUSE list: IT architects in academia (ITANA):

Any Questions?