Centralizing and Automating PeopleSoft Authority Management (Security) Session #20647 March 14, 2006 Alliance 2006 Conference Nashville, Tennessee.

Slides:



Advertisements
Similar presentations
USM Oracle/PeopleSoft MidAtlantic Regional Conference Gettysburg College – June 2, 2009.
Advertisements

LeadManager™- Internet Marketing Lead Management Solution May, 2009.
ISV Partner Alliance Value Policy Policy Management for Microsoft® System Center.
Copyright Ann West This work is the intellectual property of the author. Permission is granted for this material to be shared for non-commercial,
Privilege Management with Signet: Steps to an Application Keith Hazelton University of Wisconsin-Madison Internet2 MACE Broomfield, Colorado 1-July-04.
Lynn McRae Stanford University Lynn McRae Stanford University Stanford Authority Manager Privilege management use.
What can PeopleSoft do for You Tools developed at CSU, San Marcos.
Enterprise Financial System Project Update Council of Research Associate Deans January 17,
© 2005, Cornell University. Rapid Application Development using the Kuali Architecture (Struts, Spring and OJB) A Case Study Bryan Hutchinson
Identity and Access Management IAM A Preview. 2 Goal To design and implement an identity and access management (IAM) middleware infrastructure that –
SiS Technical Training Development Track Technical Training(s) Day 1 – Day 2.
CAMP Med Mapping HIPAA to the Middleware Layer Sandra Senti Biological Sciences Division University of Chicago C opyright Sandra Senti,
Open source administration software for education software development simplified KRAD Kuali Application Development Framework.
Signet and Grouper for Distributed Attribute Administration
Document Management Within PeopleSoft: How the U of Alberta Merged Paper and Personnel eForms Session #26484 March 25, 2009 Anaheim, California.
ArcGIS Workflow Manager An Introduction
Creating Business Workflow Using SharePoint Designer 2007 Presented by Tarek Ghazali IT Technical Specialist Microsoft SQL Server MVP Microsoft SQL Server.
Portal User Group Meeting September 14, Agenda Welcome Updates Reminders.
Authorization Scenarios with Signet RL “Bob” Morgan University of Washington Internet2 Member Meeting, September 2004.
Trimble Connected Community
1 Kuali Identity Management Advanced CAMP: Identity Services Summit for Higher Ed Open / Community-Source Projects.
Introduction to Grouper Part 1: Access Management & Grouper Tom Barton University of Chicago and Internet2 Manager – Grouper Project.
Security Management System for Department Sponsors Session #20244 March 15, 2006 Alliance 2006 Conference Nashville, Tennessee.
Building Adaptable Business Processes with Electronic Forms: Decentralized Hiring Session #10732 March 24, 2005 HEUG 2005 Conference Las Vegas, Nevada.
Integrating Applications with the Directory Andrea Beesing CIT/Integration and Delivery June 25, 2002.
SiS Technical Training Development Track Day 8. Agenda  Quick Overview of PeopleSoft Security  Understand Permission Lists, Roles, User and Tree Security.
#watitis2014 watitisconf.uwaterloo.ca Tracey Sinclair and Joanne Voisin December 3, 2014.
I2/NMI Update: Signet, Grouper, & GridShib Tom Barton University of Chicago.
EDUCAUSE Midwest Regional March 24, 2003 Copyright Ann West This work is the intellectual property of the author. Permission is granted for this.
- 1 - Roadmap to Re-aligning the Customer Master with Oracle's TCA Northern California OAUG March 7, 2005.
Uniting Cultures, Technology & Applications A Case Study University of New Hampshire.
USM Regional PeopleSoft Conference
Kuali Enterprise Notification Aaron Godert (Sr. Software Architect, Cornell University) John Fereira (Programmer/Analyst, Cornell University)
Case Study: DirXML Implementation at Waste Management Rick Wagner Systems Engineer Novell, Inc.
Brent Mosher Senior Sales Consultant Applications Technology Oracle Corporation.
Middleware: Addressing the Top IT Issues on Campus Renee Woodten Frost Internet2 and University of Michigan CUMREC May 13, 2003.
GatorLink Password Management Policy March 31, 2004.
© 2008 IBM Corporation ® IBM Cognos Business Viewpoint Miguel Garcia - Solutions Architect.
Microsoft SharePoint Server 2010 for the Microsoft ASP.NET Developer Yaroslav Pentsarskyy
December 2001 Internet2 Virtual Briefing - 1 -Stanford University Authority Registry December 12, 2001 Stanford University Lynn McRae.
UCLA Enterprise Directory Identity Management Infrastructure UC Enrollment Service Technical Conference October 16, 2007 Ying Ma
Sudha Iyer Principal Product Manager Oracle Corporation.
April 2005 pebb.benefits Project Overview. Page 1  Approx. 129 PEBB agencies  Over 110,000 members  17 databases for benefit administration  Paper.
Using Signet and Grouper for Access Management Using Signet and Grouper for Access Management Tom Barton, University of Chicago Lynn McRae, Stanford University.
PS Security By Deviprasad. Agenda Components of PS Security Security Model User Profiles Roles Permission List. Dynamic Roles Static Roles Building Roles/Rules.
Setting up Privilege Management with Signet Metadata.
Authority Process & Policy   Advanced CAMP July 9, 2003 Copyright Sandra Senti This work is the intellectual property of the author. Permission.
Developing Policy and Procedure Management System إعداد برنامج سياسات وإجراءات العمل 8 Safar February 2007 HERA GENERAL HOSPITAL.
Some Cool Tools for the PeopleSoft Support Team Session #20649 March 13, 2006 Alliance 2006 Conference Nashville, Tennessee.
I Copyright © 2007, Oracle. All rights reserved. Module i: Siebel 8.0 Essentials Training Siebel 8.0 Essentials.
System/SDWG Update Management Council Face-to-Face Flagstaff, AZ August 22-23, 2011 Sean Hardman.
A Word from the Sponsors NMI-EDIT comprises Internet2 and EDUCAUSE –NSF Middleware Initiative (NMI)-Enterprise and Desktop Integration Technologies Consortium.
Bruce Vincent Technical Support Services Strategy & Architecture ITSS Introductory Presentation 9/12/2003 Bruce Vincent, Technology Strategist 25/1/2005.
Course Evaluations Session 397 Monday, 03/17/2003 1:15 to 2:15 p.m. HEUG 2003 Conference - Dallas.
UCLA Office of Instructional Development Web Site Redesign May 20, 2005.
Enterprise Resource Planning - PeopleSoft. An ERP system is a business support system that maintains in a single database the data needed for a variety.
Software sales at U Waterloo Successfully moved software sales online Handle purchases from university accounts Integrated with our Active Directory and.
Windows Active Directory – What is it? Definition - Active Directory is a centralized and standardized system that automates network management of user.
Managing Disputes through Technology
“Hey, an analyst just built my eFORM!”
I2/NMI Update: Signet, Grouper, & GridShib
SERVICE NOW online Training at GoLogica
Privilege Management: the Big Picture
Signet Privilege Management
Technical Topics in Privilege Management
PDI: Intro to Grouper Jeff Ruch Jeff Ruch ACNS Middleware
Signet & Privilege Management
Causelink Enterprise RCA Software Introduction
Signet Privilege Management
SDMX IT Tools SDMX Registry
Presentation transcript:

Centralizing and Automating PeopleSoft Authority Management (Security) Session #20647 March 14, 2006 Alliance 2006 Conference Nashville, Tennessee

2 Your Presenters Kevin Dale – Information System Analyst −At Stanford since July 2001 – Business Analyst for Financial Aid, Student Records and Security. Lead for the Authority Manager Automation Project. Minh Nguyen – Software Architect −At Stanford since June 1997 – Lead the development of Authority Manager, version 3.0 Part of the Signet core development

3 Stanford University Founded in 1891 Founded in 1891 Private university Private university 6,753 undergraduate 6,753 undergraduate 8,093 graduate 8,093 graduate 1,775 faculty 1,775 faculty 7,565 staff 7,565 staff Located 30 miles south of San Francisco and just north of Silicon Valley.

4 Your Organization and Oracle Campus Solutions 8 SP1 PeopleTools PeopleTools Enterprise Portal 8.8 SP1 PeopleTools PeopleTools Enterprise Learning Management 8.8 SP1 PeopleTools PeopleTools Oracle e-Business Suite

5 Agenda Authority Manager – Signet What is Signet?What is Signet? FeaturesFeatures BenefitsBenefits ConceptsConcepts TechnologiesTechnologiesPeopleSoft Before AutomationBefore Automation Project GoalsProject Goals How it Works – Business ProcessHow it Works – Business Process DemoDemo How it Works - TechnicalHow it Works - Technical MetricsMetrics Questions and Answers

Signet Minh Nguyen

7 What is Signet? Privilege Management System Web application Toolkit/API XML Schema Open Source Project from NMI-EDIT Consortium Based on Stanford’s Authority Manager

8 NMI-EDIT Consortium Comprises Internet2 and EDUCAUSE −NSF Middleware Initiative (NMI)-Enterprise and Desktop Integration Technologies Consortium (EDIT) Funded in 2001 by NSF Middleware Initiative Researches and develops inter-institutional Identity and Access Management tools Guided by MACE – Middleware Architecture Committee for Education −Group of R&E IT architects from US, Europe, and Australia

9 Features Grant/Revoke Privileges Grant-only Distributed Delegation Rules-Based Conditions Proxy Grant to Groups

10 Benefits Standard user interface for users to grant privileges Consistent, simplified policy definition via role- based privileges Improved visibility, understandability, and audit ability of privileges across the enterprise Reduces latency in access privileges lifecycle events (activating/deactivating)

11 Building Blocks - Concepts Function - things a person can do; what they are getting privileges for. Scope - organizational hierarchy governing distributed delegation Limits - qualifiers, constraints for a privilege. Permission - atomic units of control that map to specific access rules in systems.

12 Building Blocks – Concepts (cont.) Condition Must be true to retain a privilege Provides automatic revocation of privileges Based on date, person’s status, affiliation, etc. Pre-requisite - pre-conditions that must be met to activate privileges, e.g., training

13 Example By authority of the Dean grantor principal investigators grantee (group/role) who have completed training prerequisite can approve purchases function in the School of Medicine scope up to $100,000 limit until January 1, 2007 as long as a faculty member at… conditions

14 Technologies Java Language Servlet Container, e.g. Tomcat Struts MVC Framework Tiles for UI Customization Hibernate for Data Access Layer

15 Resources NMI-EDIT – MACE – Signet –

PeopleSoft & Authority Manager Kevin Dale

17 Before Automation Totally Manual Process No Tracking Potential for Incorrect Assignment Delay in Assignment No Audit / Validation Process

18 Automation Benefits Prerequisites – Enforcement Assignment Expiration Acting As Auto Revocation - Identity Management Loss of Single Sign-On = Loss of PS Security

19 PeopleSoft - Project Goals Assignments or changes made in authority manager update PeopleSoft directly. The process will no longer require manual intervention. Minimal changes to the Authority Manager user interface, Student Admin will no longer use limit data. Speed up the authority process. Assignments to PeopleSoft are made in near real time.

20 How it works – Business Process 1.Grantor inputs Assignment 2.Authority Sends Data to PS to update Security (Application Messaging) 3.Row Level / Data Permission Security is updated 4.Application Sends Security to Portal

Start Demo Start Demo

objects in project. 30 Records 20 Fields 2 Translate Values 9 Pages 2 Menus 8 Components 24 Record PeopleCode 2 Process Definitions 8 SQL 2 Application Engine Programs 10 Application Engine Sections 1 Message Node 1 Message Channel 1 Message Definition 2 Subscription PeopleCode 2 Application Engine PeopleCode 1 Page PeopleCode

23 How it works – XML from authority  Transformed (XLST)  Application Messaging  Message Definition (STF_USER_PROFILE)  PeopleCode  Security Gets Assigned

24 XML – XLST - XML XML snippet from Authority Manager XML snippet From XSLT XML snippet from PS

25 Application Messaging

26 Metrics Volume On average 38 (includes HR, Student and Financials) new / changes to security assigned each day Latency Events harvested every 10 minutes All updates completed within 1-2 minutes

End Demo End Demo

Questions?

29 Contacts Kevin Dale Information Systems Analyst, Administrative Systems Stanford University Minh Nguyen Software Architect, Administrative Systems Stanford University

This presentation and all Alliance 2006 presentations are available for download from the Conference Site Presentations from previous meetings are also available