IDM 4.5 What is in the box - ngage · Single Sign On Self service User provisioning Password...

78
© NetIQ - All Rights Reserved IDM 4.5 What is in the box

Transcript of IDM 4.5 What is in the box - ngage · Single Sign On Self service User provisioning Password...

Page 1: IDM 4.5 What is in the box - ngage · Single Sign On Self service User provisioning Password Synchronisation Risk Management Role based management ... Why Identity Management Applications

© NetIQ - All Rights Reserved

IDM 4.5What is in the box

Page 2: IDM 4.5 What is in the box - ngage · Single Sign On Self service User provisioning Password Synchronisation Risk Management Role based management ... Why Identity Management Applications

© nGage - All Rights Reserved

Agenda

2

● What is Identity Management● IDM Family● Integrated installer● IDM Engine● Drivers● Applications: User Application (/IDMProv)● Applications: Home Provisioning Desktop (/landing /dash)● Applications: Role Administration (/rra)● Applications: Identity Reporting (/IDMRPT)● Applications: Self Service Password Reset (/sspr)● EAS● Tools: Designer● Tools: Analyzer● Tools: Validator

Page 3: IDM 4.5 What is in the box - ngage · Single Sign On Self service User provisioning Password Synchronisation Risk Management Role based management ... Why Identity Management Applications

Indentity Manager

Page 4: IDM 4.5 What is in the box - ngage · Single Sign On Self service User provisioning Password Synchronisation Risk Management Role based management ... Why Identity Management Applications

© nGage - All Rights Reserved

Identity Management

HR ERP

PBX

DirectoryMail

OperatingSystem

Database Identity Vault

Page 5: IDM 4.5 What is in the box - ngage · Single Sign On Self service User provisioning Password Synchronisation Risk Management Role based management ... Why Identity Management Applications

© nGage - All Rights Reserved

Identity Management

Page 6: IDM 4.5 What is in the box - ngage · Single Sign On Self service User provisioning Password Synchronisation Risk Management Role based management ... Why Identity Management Applications

© nGage - All Rights Reserved

Identity Management

AuthorisationIdentification

Authentication

Single Sign On Self service

User provisioning

Password Synchronisation

Risk Management

Role based management

Corporate Identity

Federated Identity

Information Store

Access management & control

Compliancy

Attestation

Auditing

Information Consistency

Governance

Regulations & Law

WorkFlow (Businessflow)

Cloud

Claim – Context Based

Page 7: IDM 4.5 What is in the box - ngage · Single Sign On Self service User provisioning Password Synchronisation Risk Management Role based management ... Why Identity Management Applications

© nGage - All Rights Reserved

Identity Management

The Other Stuff● Print credits● Card Access● File Storage Management● Selfservice requests

Page 8: IDM 4.5 What is in the box - ngage · Single Sign On Self service User provisioning Password Synchronisation Risk Management Role based management ... Why Identity Management Applications

© nGage - All Rights Reserved

Why Identity Management

Automated processes (f.e. (de)provisoning)l Self Servicel Auditing

Page 9: IDM 4.5 What is in the box - ngage · Single Sign On Self service User provisioning Password Synchronisation Risk Management Role based management ... Why Identity Management Applications

© nGage - All Rights Reserved

Why Identity Management

ApplicationsDirectories

OS and File Systems

DatabasesTelephone & Access

Help Desk Cloud en SaaS

Business Managers

Employees External employees

Clients-Suppliers

Work-flow Systeem

Identity Vault

White Pages/ Self-Service/ Wachtwoord

beheer

Business Resource aanvraag

Rol-gebaseerd en gedelegeerd

user beheer

Goedkeurings Work-flow

Web Services

Main Components

Connectoren

Gevanceerde rapportage

Identity Information Warehouse

Compliance Content

Open APIs Deployment en Mgmt

Tools

Real-time Data integriteit

Rol en Policy Mapping

RBAC Model

Page 10: IDM 4.5 What is in the box - ngage · Single Sign On Self service User provisioning Password Synchronisation Risk Management Role based management ... Why Identity Management Applications

© nGage - All Rights Reserved

Identity Management Family

Novell Compliance Management Platform

Monitoring and Auditing Compliancy, Access Management

Novell Identity Manager 4.5Advanced Edition

Novell Identity Manager 4.5Standard Edition

RBAC, Rolemanagement, Reporting & Auditing

Real-time identity and password managementDevelopment tools

Page 11: IDM 4.5 What is in the box - ngage · Single Sign On Self service User provisioning Password Synchronisation Risk Management Role based management ... Why Identity Management Applications

© nGage - All Rights Reserved

Identity Management Family

Page 12: IDM 4.5 What is in the box - ngage · Single Sign On Self service User provisioning Password Synchronisation Risk Management Role based management ... Why Identity Management Applications

© nGage - All Rights Reserved

LET'S GO IN !

Page 13: IDM 4.5 What is in the box - ngage · Single Sign On Self service User provisioning Password Synchronisation Risk Management Role based management ... Why Identity Management Applications

© nGage - All Rights Reserved

Page 14: IDM 4.5 What is in the box - ngage · Single Sign On Self service User provisioning Password Synchronisation Risk Management Role based management ... Why Identity Management Applications

© nGage - All Rights Reserved

Architecture

Page 15: IDM 4.5 What is in the box - ngage · Single Sign On Self service User provisioning Password Synchronisation Risk Management Role based management ... Why Identity Management Applications

Integrated installer

Page 16: IDM 4.5 What is in the box - ngage · Single Sign On Self service User provisioning Password Synchronisation Risk Management Role based management ... Why Identity Management Applications

© nGage - All Rights Reserved

Integrated installer

● When to use● Pros & Cons

Page 17: IDM 4.5 What is in the box - ngage · Single Sign On Self service User provisioning Password Synchronisation Risk Management Role based management ... Why Identity Management Applications

© nGage - All Rights Reserved

Integrated installer

Page 18: IDM 4.5 What is in the box - ngage · Single Sign On Self service User provisioning Password Synchronisation Risk Management Role based management ... Why Identity Management Applications

© nGage - All Rights Reserved

Integrated installer

Page 19: IDM 4.5 What is in the box - ngage · Single Sign On Self service User provisioning Password Synchronisation Risk Management Role based management ... Why Identity Management Applications

© nGage - All Rights Reserved

Integrated installer

Page 20: IDM 4.5 What is in the box - ngage · Single Sign On Self service User provisioning Password Synchronisation Risk Management Role based management ... Why Identity Management Applications

IDM Engine

Page 21: IDM 4.5 What is in the box - ngage · Single Sign On Self service User provisioning Password Synchronisation Risk Management Role based management ... Why Identity Management Applications

© nGage - All Rights Reserved

IDM Engine

● Hosts drivers● Event based actions● Time based actions● Redundant

Page 22: IDM 4.5 What is in the box - ngage · Single Sign On Self service User provisioning Password Synchronisation Risk Management Role based management ... Why Identity Management Applications

© nGage - All Rights Reserved

IDM Drivers

Page 23: IDM 4.5 What is in the box - ngage · Single Sign On Self service User provisioning Password Synchronisation Risk Management Role based management ... Why Identity Management Applications

© nGage - All Rights Reserved

IDM Drivers 1999

Page 24: IDM 4.5 What is in the box - ngage · Single Sign On Self service User provisioning Password Synchronisation Risk Management Role based management ... Why Identity Management Applications

© nGage - All Rights Reserved

IDM Drivers 2016

Page 25: IDM 4.5 What is in the box - ngage · Single Sign On Self service User provisioning Password Synchronisation Risk Management Role based management ... Why Identity Management Applications

© nGage - All Rights Reserved

IDM Drivers● DB2● Informix● JDBC (General)● MySQL● Oracle● Postgres● MS SQL● SyBase● ADS/ADAM● Critical Path● eDirectory (2)● IBM Directory● Iplanet● LDAP● NetScape● HP/UX● Linux● RedHat

● NIS● Oracle Directory● SecureWay● SUN Directory● SUN One● GroupWise● Notes● Exchange (AD)● Banner● Blackboard● Google Apps● PUM● Oracle EBS (3)● PeopleSoft● Remedy● SalesForce● Solaris● Suse-Linux

● SAP (6)● Sentinel● Sharepoint● SIF● Active Identity● Honeywell● IAS● PACS/Honeywell● ACF/2● I5/OS● RACF● TopSecret● JMS Mess Bus● AIX● Debian● FreeBSD● Access Review● DCS/MSG

● Entitlements● ID Provider● Loopback/Null● Manual Task● Scripting● State Machine● Workorder● Delimited Text● Generic File● Generic App● HTTP Service● REST Server● SOAP Server● User Application● Roles Service● Custom

Page 26: IDM 4.5 What is in the box - ngage · Single Sign On Self service User provisioning Password Synchronisation Risk Management Role based management ... Why Identity Management Applications

Applications

Page 27: IDM 4.5 What is in the box - ngage · Single Sign On Self service User provisioning Password Synchronisation Risk Management Role based management ... Why Identity Management Applications

© nGage - All Rights Reserved

OSP● One SSO Provider ● Integrated into SSPR / User Application / HPD● eDirectory integration: NMAS-SAML

Page 28: IDM 4.5 What is in the box - ngage · Single Sign On Self service User provisioning Password Synchronisation Risk Management Role based management ... Why Identity Management Applications

© nGage - All Rights Reserved

SSPR● Password change● Password reset● User reset● Self Registration● User activation● User creation● My Profile● Peoplesearch● Helpdesk

Page 29: IDM 4.5 What is in the box - ngage · Single Sign On Self service User provisioning Password Synchronisation Risk Management Role based management ... Why Identity Management Applications

© nGage - All Rights Reserved

SSPR

Page 30: IDM 4.5 What is in the box - ngage · Single Sign On Self service User provisioning Password Synchronisation Risk Management Role based management ... Why Identity Management Applications

© nGage - All Rights Reserved

SSPR

Page 31: IDM 4.5 What is in the box - ngage · Single Sign On Self service User provisioning Password Synchronisation Risk Management Role based management ... Why Identity Management Applications

© nGage - All Rights Reserved

SSPR

Page 32: IDM 4.5 What is in the box - ngage · Single Sign On Self service User provisioning Password Synchronisation Risk Management Role based management ... Why Identity Management Applications

© nGage - All Rights Reserved

SSPR

Page 33: IDM 4.5 What is in the box - ngage · Single Sign On Self service User provisioning Password Synchronisation Risk Management Role based management ... Why Identity Management Applications

© nGage - All Rights Reserved

User Application ● Portal to house: ● Identity Services● Workflows● Role Requests & approvals● Role management

● But also

● Web Services Interfaces for ● Provisioning● Roles● Metrics● Passwords● VDX● Password Management

Page 34: IDM 4.5 What is in the box - ngage · Single Sign On Self service User provisioning Password Synchronisation Risk Management Role based management ... Why Identity Management Applications

© nGage - All Rights Reserved

User Application

Page 35: IDM 4.5 What is in the box - ngage · Single Sign On Self service User provisioning Password Synchronisation Risk Management Role based management ... Why Identity Management Applications

© nGage - All Rights Reserved

User Application

Page 36: IDM 4.5 What is in the box - ngage · Single Sign On Self service User provisioning Password Synchronisation Risk Management Role based management ... Why Identity Management Applications

© nGage - All Rights Reserved

User Application

Page 37: IDM 4.5 What is in the box - ngage · Single Sign On Self service User provisioning Password Synchronisation Risk Management Role based management ... Why Identity Management Applications

© nGage - All Rights Reserved

User Application

Page 38: IDM 4.5 What is in the box - ngage · Single Sign On Self service User provisioning Password Synchronisation Risk Management Role based management ... Why Identity Management Applications

© nGage - All Rights Reserved

User Application for role management

Page 39: IDM 4.5 What is in the box - ngage · Single Sign On Self service User provisioning Password Synchronisation Risk Management Role based management ... Why Identity Management Applications

© nGage - All Rights Reserved

Home Provisioning Desktop

Page 40: IDM 4.5 What is in the box - ngage · Single Sign On Self service User provisioning Password Synchronisation Risk Management Role based management ... Why Identity Management Applications

© nGage - All Rights Reserved

HPD

Page 41: IDM 4.5 What is in the box - ngage · Single Sign On Self service User provisioning Password Synchronisation Risk Management Role based management ... Why Identity Management Applications

© nGage - All Rights Reserved

HPD

Page 42: IDM 4.5 What is in the box - ngage · Single Sign On Self service User provisioning Password Synchronisation Risk Management Role based management ... Why Identity Management Applications

© nGage - All Rights Reserved

HPD

Page 43: IDM 4.5 What is in the box - ngage · Single Sign On Self service User provisioning Password Synchronisation Risk Management Role based management ... Why Identity Management Applications

© nGage - All Rights Reserved

Roles

Page 44: IDM 4.5 What is in the box - ngage · Single Sign On Self service User provisioning Password Synchronisation Risk Management Role based management ... Why Identity Management Applications

© nGage - All Rights Reserved

Roles

Each resource is mapped to an entitlement.– A resource definition can have no more than one entitlement bound to it.– A resource definition can be bound to the same entitlement more than once, with different entitlement parameters for eachresource.

NOTE: The Entitlements table continues to provide the ability to add, edit, and remove entitlements. However, users are encouraged to begin associating Entitlements to resources instead of roles because resources are the new intermediate objects that encapsulate Entitlements. The Resources table is a read-only list of resources associated with a role.

• Resource Model – Detailed Relationship

Page 45: IDM 4.5 What is in the box - ngage · Single Sign On Self service User provisioning Password Synchronisation Risk Management Role based management ... Why Identity Management Applications

© nGage - All Rights Reserved

Role Management

Page 46: IDM 4.5 What is in the box - ngage · Single Sign On Self service User provisioning Password Synchronisation Risk Management Role based management ... Why Identity Management Applications

© nGage - All Rights Reserved

Role Management

Page 47: IDM 4.5 What is in the box - ngage · Single Sign On Self service User provisioning Password Synchronisation Risk Management Role based management ... Why Identity Management Applications

© nGage - All Rights Reserved

Role Management

Page 48: IDM 4.5 What is in the box - ngage · Single Sign On Self service User provisioning Password Synchronisation Risk Management Role based management ... Why Identity Management Applications

© nGage - All Rights Reserved

Identity Reporting

Page 49: IDM 4.5 What is in the box - ngage · Single Sign On Self service User provisioning Password Synchronisation Risk Management Role based management ... Why Identity Management Applications

© nGage - All Rights Reserved

Identity Reporting

Page 50: IDM 4.5 What is in the box - ngage · Single Sign On Self service User provisioning Password Synchronisation Risk Management Role based management ... Why Identity Management Applications

© nGage - All Rights Reserved

Identity Reporting

Page 51: IDM 4.5 What is in the box - ngage · Single Sign On Self service User provisioning Password Synchronisation Risk Management Role based management ... Why Identity Management Applications

© nGage - All Rights Reserved

Identity Reporting

Page 52: IDM 4.5 What is in the box - ngage · Single Sign On Self service User provisioning Password Synchronisation Risk Management Role based management ... Why Identity Management Applications

© nGage - All Rights Reserved

Identity Reporting

Page 53: IDM 4.5 What is in the box - ngage · Single Sign On Self service User provisioning Password Synchronisation Risk Management Role based management ... Why Identity Management Applications

© nGage - All Rights Reserved

EAS & Sentinel

Page 54: IDM 4.5 What is in the box - ngage · Single Sign On Self service User provisioning Password Synchronisation Risk Management Role based management ... Why Identity Management Applications

Tools

Page 55: IDM 4.5 What is in the box - ngage · Single Sign On Self service User provisioning Password Synchronisation Risk Management Role based management ... Why Identity Management Applications

© nGage - All Rights Reserved

Designer● Off line development of IDM Drivers● Point and Click interface● Based on Eclipse, extendable with plugins● Code emulation● Code migration● SVN Plugin

Page 56: IDM 4.5 What is in the box - ngage · Single Sign On Self service User provisioning Password Synchronisation Risk Management Role based management ... Why Identity Management Applications

© nGage - All Rights Reserved

Designer

Page 57: IDM 4.5 What is in the box - ngage · Single Sign On Self service User provisioning Password Synchronisation Risk Management Role based management ... Why Identity Management Applications

© nGage - All Rights Reserved

Designer● Package manager

Page 58: IDM 4.5 What is in the box - ngage · Single Sign On Self service User provisioning Password Synchronisation Risk Management Role based management ... Why Identity Management Applications

© nGage - All Rights Reserved

Designer

Page 59: IDM 4.5 What is in the box - ngage · Single Sign On Self service User provisioning Password Synchronisation Risk Management Role based management ... Why Identity Management Applications

© nGage - All Rights Reserved

Analyzer

Data analyses: Mandatory !Connect to live systemsCompare data sourcesMetrics

Page 60: IDM 4.5 What is in the box - ngage · Single Sign On Self service User provisioning Password Synchronisation Risk Management Role based management ... Why Identity Management Applications

© nGage - All Rights Reserved

Analyzer

Page 61: IDM 4.5 What is in the box - ngage · Single Sign On Self service User provisioning Password Synchronisation Risk Management Role based management ... Why Identity Management Applications

© nGage - All Rights Reserved

Analyzer

Page 62: IDM 4.5 What is in the box - ngage · Single Sign On Self service User provisioning Password Synchronisation Risk Management Role based management ... Why Identity Management Applications

© nGage - All Rights Reserved

Analyzer

62

Identify data integration pointsDetermine condition of dataPrepare data for deploymentEnsure unique identifier for each systemCombine data sourcesCreate clean instance of dataKeep the data in compliance

REPORT MONITOR

Page 63: IDM 4.5 What is in the box - ngage · Single Sign On Self service User provisioning Password Synchronisation Risk Management Role based management ... Why Identity Management Applications

© nGage - All Rights Reserved

Purpose: Identify data integration points• Schema Discovery

– Understand the schema in each system you are connecting to in preparation for schema mapping.

• Data Discovery– Understand the Data– Configure the connections to the data store

Step 1: Discovery

63

Page 64: IDM 4.5 What is in the box - ngage · Single Sign On Self service User provisioning Password Synchronisation Risk Management Role based management ... Why Identity Management Applications

© nGage - All Rights Reserved

Purpose: Identify data integration points• Import

– Flat file– Application specific (LDAP, etc.) – IDM Drivers (IDS) – Import

Designer configuration• Data Browser - Spreadsheet type tool

– Filter, Sort

Step 1: Discovery

64

Page 65: IDM 4.5 What is in the box - ngage · Single Sign On Self service User provisioning Password Synchronisation Risk Management Role based management ... Why Identity Management Applications

© nGage - All Rights Reserved

Purpose: Identify data integration points• Import process allows you customize the search scope.

Step 1: Discovery

65

Page 66: IDM 4.5 What is in the box - ngage · Single Sign On Self service User provisioning Password Synchronisation Risk Management Role based management ... Why Identity Management Applications

© nGage - All Rights Reserved

Purpose: Identify data integration points• Import process allows you customize the search scope.

Step 1: Discovery

66

Page 67: IDM 4.5 What is in the box - ngage · Single Sign On Self service User provisioning Password Synchronisation Risk Management Role based management ... Why Identity Management Applications

© nGage - All Rights Reserved

Purpose: Determine condition of data• Schema Mapping

– match the schema– between the application

• and the identity vault

Step 2: Analyze

67

Page 68: IDM 4.5 What is in the box - ngage · Single Sign On Self service User provisioning Password Synchronisation Risk Management Role based management ... Why Identity Management Applications

© nGage - All Rights Reserved

• Purpose: Determine condition of data• Data Inspector (from Data Browser)

– Visual Data Inspection– Flag – non-conforming – Data

• Data Analysis

Step 2: Analyze

68

Page 69: IDM 4.5 What is in the box - ngage · Single Sign On Self service User provisioning Password Synchronisation Risk Management Role based management ... Why Identity Management Applications

© nGage - All Rights Reserved

Purpose: Determine condition of data• Schema Mapping

– match the schema– between the application

• and the identity vault

Step 2: Analyze

69

Page 70: IDM 4.5 What is in the box - ngage · Single Sign On Self service User provisioning Password Synchronisation Risk Management Role based management ... Why Identity Management Applications

© nGage - All Rights Reserved

• Purpose: Prepare data for deployment• Simple Data Cleaning

– Within Data Browser– Add / Delete / Modify– Multi-value support

Step 3: Clean Data

70

Page 71: IDM 4.5 What is in the box - ngage · Single Sign On Self service User provisioning Password Synchronisation Risk Management Role based management ... Why Identity Management Applications

© nGage - All Rights Reserved

• Update to Applications (or export to flat file)

Step 3: Clean Data

Green is showing update on missing value (missing eMail).

Tan/Olive is showing values changed.

71

Page 72: IDM 4.5 What is in the box - ngage · Single Sign On Self service User provisioning Password Synchronisation Risk Management Role based management ... Why Identity Management Applications

© nGage - All Rights Reserved

Purpose: Ensure unique identifier for each system

Step 4: Matching

72

Page 73: IDM 4.5 What is in the box - ngage · Single Sign On Self service User provisioning Password Synchronisation Risk Management Role based management ... Why Identity Management Applications

© nGage - All Rights Reserved

Unit testing with Validator / IDM Unit

Page 74: IDM 4.5 What is in the box - ngage · Single Sign On Self service User provisioning Password Synchronisation Risk Management Role based management ... Why Identity Management Applications

© nGage - All Rights Reserved

Unit testing with Validator / IDM Unit

Page 75: IDM 4.5 What is in the box - ngage · Single Sign On Self service User provisioning Password Synchronisation Risk Management Role based management ... Why Identity Management Applications

© nGage - All Rights Reserved

Unit testing with Validator / IDM Unit

Page 76: IDM 4.5 What is in the box - ngage · Single Sign On Self service User provisioning Password Synchronisation Risk Management Role based management ... Why Identity Management Applications

© NetIQ - All Rights Reserved

Page 77: IDM 4.5 What is in the box - ngage · Single Sign On Self service User provisioning Password Synchronisation Risk Management Role based management ... Why Identity Management Applications

© NetIQ - All Rights Reserved

Page 78: IDM 4.5 What is in the box - ngage · Single Sign On Self service User provisioning Password Synchronisation Risk Management Role based management ... Why Identity Management Applications

This document could include technical inaccuracies or typographical errors. Changes are periodically made to the information herein. These changes may be incorporated in new editions of this document. NetIQ Corporation may make improvements in or changes to the software described in this document at any time.

Copyright © 2015 NetIQ Corporation. All rights reserved.

ActiveAudit, ActiveView, Aegis, AppManager, Change Administrator, Change Guardian, Compliance Suite, the cube logo design, Directory and Resource Administrator, Directory Security Administrator, Domain Migration Administrator, Exchange Administrator, File Security Administrator, Group Policy Administrator, Group Policy Guardian, Group Policy Suite, IntelliPolicy, Knowledge Scripts, NetConnect, NetIQ, the NetIQ logo, PSAudit, PSDetect, PSPasswordManager, PSSecure, Secure Configuration Manager, Security Administration Suite, Security Manager, Server Consolidator, VigilEnt, and Vivinet are trademarks or registered trademarks of NetIQ Corporation or its subsidiaries in the United States.