Federico Guerrini IDA TSP, EMEA Incubation Team From Identity Synchronization to Identity Management.

Slides:



Advertisements
Similar presentations
© 2009 Microsoft Corporation. All rights reserved. Microsoft, Windows, Windows Vista and other product names are or may be registered.
Advertisements


© 2012 Microsoft Corporation. All rights reserved. Microsoft, Windows, Windows Vista and other product names are or may be registered trademarks and/or.
Preface Demo A Quick Thank You How Did We Do It?
Windows 8 (1) (2) (3) Windows 8 (1) (2) (3)
Feature: Identity Management - Login © 2013 Microsoft Corporation. All rights reserved. Microsoft, Windows, Windows Vista and other product names are or.
© 2012 Microsoft Corporation. All rights reserved. Microsoft, Windows, Windows Vista and other product names are or may be registered trademarks and/or.
© 2010 Microsoft Corporation. All rights reserved. Microsoft, Windows, Windows Vista and other product names are or may be registered.
Microsoft Forefront Identity Manager 2010
Feature: Purchase Requisitions - Requester © 2013 Microsoft Corporation. All rights reserved. Microsoft, Windows, Windows Vista and other product names.
MIX 09 4/15/ :14 PM © 2009 Microsoft Corporation. All rights reserved. Microsoft, Windows, Windows Vista and other product names are or may be registered.
demo Default WANGPSLookup Default WANGPS.
Microsoft Office Sharepoint Server 2007 (MOSS) Overview Momentum Microsoft November 15, 2007.
Christopher Chapman | MCT Content PM, Microsoft Learning, PDG Planning, Microsoft.
Optimizing Business Operations Business Priorities Presentation.
Windows 7 Training Microsoft Confidential. Windows ® 7 Compatibility Version Checking.
Multitenant Model Request/Response General Model.
Announcing Demo Announcing.
Feature: Web Client Keyboard Shortcuts © 2013 Microsoft Corporation. All rights reserved. Microsoft, Windows, Windows Vista and other product names are.
© 2012 Microsoft Corporation. All rights reserved. Microsoft, Windows, Windows Vista and other product names are or may be registered trademarks and/or.
Identity and Access Management Business Ready Security Solutions.
May 30 th – 31 st, 2006 Sheraton Ottawa. Microsoft Certificate Lifecycle Manager Saleem Kanji Technology Solutions Professional - Windows Server Microsoft.
Session 1.
Built by Developers for Developers…. © 2009 Microsoft Corporation. All rights reserved. Microsoft, Windows, Windows Vista and other product names.
 Rico Mariani Architect Microsoft Corporation.
Windows 8 (1) (2) (3) Windows 8 (1) (2) (3)
© 2012 Microsoft Corporation. All rights reserved. Microsoft, Windows, Windows Vista and other product names are or may be registered trademarks and/or.
Connect with life Connect with life
© 2012 Microsoft Corporation. All rights reserved. Microsoft, Windows, Windows Vista and other product names are or may be registered trademarks and/or.
Identity Solution in Baltic Theory and Practice Viktors Kozlovs Infrastructure Consultant Microsoft Latvia.
Feature: Customer Combiner and Modifier © 2013 Microsoft Corporation. All rights reserved. Microsoft, Windows, Windows Vista and other product names are.
Feature: Employee Self Service Timecard Entry © 2013 Microsoft Corporation. All rights reserved. Microsoft, Windows, Windows Vista and other product names.
© 2009 Microsoft Corporation. All rights reserved. Microsoft, Windows, Windows Vista and other product names are or.
demo Instance AInstance B Read “7” Write “8”

Office 365: Identity and Access Solutions Suresh Menon Technology Specialist – Office 365 Microsoft Corporation India.
customer.
AUTOMATING DAAS DESKTOPS WITH CITRIX CORTEX Tony Sanchez WW Alliances Solutions Architecture Citrix Systems Inc SESSION CODE: CLI415 (c) 2011 Microsoft.
demo © 2008 Microsoft Corporation. All rights reserved. Microsoft, Windows, Windows Vista and other product names.
demo Demo.
demo QueryForeign KeyInstance /sm:body()/x:Order/x:Delivery/y:TrackingId1Z
projekt202 © 2009 Microsoft Corporation. All rights reserved. Microsoft, Windows, Windows Vista and other product names are.
The CLR CoreCLRCoreCLR © 2009 Microsoft Corporation. All rights reserved. Microsoft, Windows, Windows Vista and other product.
© 2009 Microsoft Corporation. All rights reserved. Microsoft, Windows, Windows Vista and other product names are or may be registered trademarks.
© 2008 Microsoft Corporation. All rights reserved. Microsoft, Windows, Windows Vista and other product names are or.
Introducing Windows Intune
Almero Steyn Business Manager: IdAM GijimaAst Session Code: SIA 306 Almero Steyn Business Manager: IdAM GijimaAst Session Code: SIA 306.

Chris Louloudakis Solution Specialist Identity & Access Management Microsoft Corporation SVR302.
demo User Signs Up Temporary Account is Created with Verification Link Sent User Clicks Link Account is Activated Login.Register(userName,
SaaS Application Deep Dive
Microsoft Dynamics NAV 2018 – what’s new
Self Service Group Management (SSGM)
SharePoint Online Management and Control
Office 365 Identity Management
Managing Digital Identity
Azure AD Domain Services
Microsoft Ignite NZ October 2016 SKYCITY, Auckland.
Office Mac /30/2018 © 2010 Microsoft Corporation. All rights reserved. Microsoft, Windows, Windows Vista and other product names are or may be registered.
Title of Presentation 12/2/2018 3:48 PM
Enabling the hybrid cloud with remote access appliances
2/27/2019 © 2014 Microsoft Corporation. All rights reserved. Microsoft, Windows, and other product names are or may be registered trademarks and/or trademarks.
8/04/2019 9:13 PM © 2006 Microsoft Corporation. All rights reserved. Microsoft, Windows, Windows Vista and other product names are or may be registered.
One Marketing Template
Виктор Хаджийски Катедра “Металургия на желязото и металолеене”
Шитманов Дархан Қаражанұлы Тарих пәнінің
Title of Presentation 5/24/2019 1:26 PM
Azure AD Simon May Technical Evangelist.
Presentation transcript:

Federico Guerrini IDA TSP, EMEA Incubation Team From Identity Synchronization to Identity Management

Agenda Forefront Identity Manager (FIM) 2010 history and evolution Identity Synchronization: the IT-centric approach Identity Management : the Business-centric approach FIM 2010 Solutions: deploying identity management solutions quickly and effectively

FIM 2010’s Heritage

ILM & FIM History MIIS CLM Beta Once upon a time… Yesterday FIM 2010 User Management Group Management Credential Management Policy Management ILM 2007 MIIS + CLM Today

Problem #1: User Provisioning App Servers Active Directory Human Resources Name Employee ID Cost center ManagerRoles Name Alias Mailboxsettings NameDomainAccountManager App Account App profile1 App profile2 App profile3 Security? Compliancy? Productivity/Cost Reduction? Reporting? IT ADMIN FIM 2010

Problem #2: Certificate and Smart Card Lifecycle Management App serversActive Directory Human Resources Smart card logon Digitally signed Encrypted data Certificate-based web auth Certificate renewal? Lost smart card? Forgotten PIN? Blocked smart card? IT ADMIN FIM-CM 2010

Session Focus: User Provisioning App stores Active Directory Human Resources Name Employee ID Cost center ManagerRoles Name Alias Mailboxsettings NameDomainAccountManager App Account App profile1 App profile2 App profile3 Security? Compliancy? Productivity/Cost Reduction? Reporting? IT ADMIN

The “IT-Centric” Approach

IT-Centric Approach: Identity Synchronization App storesActive Directory Human Resources Name Employee ID Cost center ManagerRoles Name Alias Mailboxsettings NameDomainAccountManager App Account App profile1 App profile2 App profile3 Name Employee ID Cost center ManagerRoles Alias Domain Account App Account App Profile 1 App Profile 2 App Profile 3 Meta Directory + Synch Engine

Identity Synchronization Example App servers Active Directory Human Resources Name Employee ID Cost center ManagerRoles Name Alias Mailboxsettings NameDomainAccountManager App Account App profile1 App profile2 App profile3 Name Employee ID Cost center ManagerRoles Alias Domain Account App Account App Profile 1 App Profile 2 App Profile 3 Meta Directory + Synch Engine 1234

Synch Engine Logical Architecture Connected Directories Management Agents Synch Engine + Repository Synch Engine + Repository

The IT-Centric Approach: Summary App stores Active Directory Human Resources Name Employee ID Cost center ManagerRoles Name Alias Mailboxsettings NameDomainAccountManager App Account App profile1 App profile2 App profile3 Name Employee ID Cost center ManagerRoles Alias Domain Account App Account App Profile 1 App Profile 2 App Profile My organization is far too complex for each and every provisioning process to be described by a synchronization rule!! IT ADMIN Provisioning processes triggered by modifications on connected directories Provisioning processes driven by synchronization rules

The “Business-Centric” Approach

Focus on Business Processes Rich permissions and delegation model System auditing and compliance Users must be given the power to trigger, participate in and drive provisioning processes Route users’ requests to appropriate decision makers Offload IT admin from dealing with users requests Empowering People Delivering Agility and Efficiency Increasing Security and Compliance

How FIM 2010 Extends the Identity Synch Approach Workflow support −FIM 2010 can automate business processes for managing user identities and their entitlements Self-service and delegation −FIM 2010 provides high-level interfaces for end users to request provisioning access to resources, either for themselves or on someone else’s behalf Policy management −FIM 2010 enables IT professionals to create and maintain provisioning policies through simplified, graphical, web-based interfaces

FIM 2010 Logical Architecture FIM 2010 introduces a new repository, referred to as Object Store” connected to ILM 2007 Metadirectory & Synch layer via a dedicated MA FIM 2010 underlying synchronization engine stays the same as in current version (ILM 2007) FIM 2010 introduces a web portal that provides self-service functionalities, workflows, policy management and GUI-based configuration wizards Object Store FIM 2010 MA WSSWSSWSSWSS WSSWSSWSSWSS

Deploying core IDA capabilities quickly

Policy Management Management Policy Rules: Formal description of business processes for managing users, resources, entitlements Typical MPR −When a new employee is hired −AD and RACF accounts created −Mailbox created −Notification sent to employee’s manager −Requests for relevant groups membership sent to owners

Policy Management - Demo

Group Management Dynamic groups / DLs −Membership calculated based on user attributes

Group Management - Demo

Credential Management Self-service password reset integrated in Windows Logon Default pwd reset workflow based on “security questions” −Can be customized

Credential Management - Demo

User Management Self-service user portal −Delegate to end users maintenance of non- security-sensitive attributes Self-service group management tools −“Add me to” −Group −DL −Office Integration

User Management - Demo

© 2010 Microsoft Corporation. All rights reserved. Microsoft, Windows, Windows Vista and other product names are or may be registered trademarks and/or trademarks in the U.S. and/or other countries. The information herein is for informational purposes only and represents the current view of Microsoft Corporation as of the date of this presentation. Because Microsoft must respond to changing market conditions, it should not be interpreted to be a commitment on the part of Microsoft, and Microsoft cannot guarantee the accuracy of any information provided after the date of this presentation. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.