Identity Management Solutions 101: User Provisioning
Posted by Ash Motiwala on Thu, Aug 28, 2008
So, you're an IT Manager and need the low down on a new buzzword in the realm of Identity Management, and you need it quick...You've come to the right place! This series is designed especially for you.
This entry is about User Provisioning. Enjoy!
If you need more details on this and other disciplines in the world of Identity Management, or you'd like to get some other folks from your staff to join in on the fun, you might be interested in an on-site Identity Management Workshop.
Alias:
| Automated Provisioning, Account Provisioning, Provisioning |
| Function: | Simply put, it's a fancy term for creating accounts in various systems. Typically, it's for creating user accounts, but can also be used to create any digital account, including computer accounts, badge accounts, etc. |
| Misc.Facts: | User Provisioning is by far the most popular component of the Identity Management stack. According to Gartner, almost 2/3rds of Identity Management projects are in fact User Provisioning projects. |
| Business Benefits: | - Huge cost-avoidance opportunities
- Great tool to replicate/optimize business processes
- Out of the box connectors to target systems
- Flexible framework for targets without OOB connectors
|
Use Cases:
|
- Employee onboarding/offboarding to all targets
- Contractor onboarding
- Employee self-service capabilities to update their own profile
- Bulk offboarding/deprovisioning
- Emergency offboarding/deprovisioning
- Approvals based onboarding per target system
|
High Level Architecture:
| Typically, there is a server that stores the business logic, and connectors to various target systems that typically reside on the same box. Some legacy systems may require an agent to be stored on the target systems themselves. Also, there is a datastore (some vendors provide their own, others utilize AD or an existing data store). |
| Caveats: | Don't understate the business process analysis part of this project. It takes longer than you expect, but can make all the difference in the world for the success of your project! |