PSJA AUTOMATION WORKFLOW AND LESSONS LEARNED

Slides:



Advertisements
Similar presentations
Agenda 2 factor authentication Smart cards Virtual smart cards FIM CM
Advertisements

What’s FIM all about?. Agenda What is FIM Why are we implementing FIM How is FIM related to Office 365 What will FIM do How does FIM differ from ILM (current.
Agenda AD to Windows Azure AD Sync Options Federation Architecture
Kentico CMS 5.5 R2 What’s New. Highlights Intranet Solution Document management package – WebDAV support – Project & task management – Document libraries.
Which server is right for you? Get in Contact with us
1111 Superior Avenue Suite 310 Cleveland Ohio Tel: Fax: Identity Management.
02 | Managing Users, Groups, and Licenses Anthony Steven | Principal Technologist, Content Master Martin Coetzer | Portfolio Architect, Microsoft.
Federated sign-in WS-Federation WS-Trust SAML 2.0 Metadata Shibboleth Graph API Synchronize accounts Authentication.
11 WORKING WITH GROUPS Chapter 7. Chapter 7: WORKING WITH GROUPS2 CHAPTER OVERVIEW  Understand the functions of groups and how to use them.  Understand.
Identity and Access Management
IDENTITY PROBLEM Too Many User Names and Passwords Across Multiple Systems.
Chapter 7 WORKING WITH GROUPS.
Microsoft Identity and Access Solutions Market Trends and Futures
Empower Enterprise Mobility Jasbir Gill Azure Mobility.
SharePoint External Login Access – Forms Authentication vs Azure ACS.
Managing Active Directory Domain Services Objects
Chapter 7: WORKING WITH GROUPS
Deploying Chromebooks RICK NICHOLAS A.
Single Sign-On with Microsoft Azure
A detailed look at the Microsoft Windows Infrastructure at UWE including Active Directory (AD), MIIS, Exchange, SMS, IIS, SQL Server, Terminal Services.
…. PrePlanPrepareMigratePost Pre- Deployment PlanPrepareMigrate Post- Deployment First Mailbox.
Module 5 Configuring Authentication. Module Overview Lesson 1: Understanding Classic SharePoint Authentication Providers Lesson 2: Understanding Federated.
Active Directory Administration Lesson 5. Skills Matrix Technology SkillObjective DomainObjective # Creating Users, Computers, and Groups Automate creation.
Tech Ed North America /24/2017 1:59 AM SESSION CODE: SIA327
Microsoft ® Official Course Module 13 Implementing Windows Azure Active Directory.
Empowering people-centric IT Unified device management Access and information protection Desktop Virtualization Hybrid Identity.
Paul Andrew. Recently Announced… Identity Integration Options 2 3 Identity Management Overview 1.
Microsoft Azure Active Directory. AD Microsoft Azure Active Directory.
Module 9 User Profiles and Social Networking. Module Overview Configuring User Profiles Implementing SharePoint 2010 Social Networking Features.
Identities and Azure AD Premium
BE-com.eu Brussel, 26 april 2016 EXCHANGE 2010 HYBRID (IN THE EXCHANGE 2016 WORLD)
SharePoint and Active Directory Update March 18, 2010.
Managing Office 365 Identities and Requirements.
 Step 2 Deployment Overview  What is DirSync?  Purpose – What does it do?  Understanding Synchronization  Understanding Coexistence  Understanding.
Productivity Architect Meet Chris Bortlik Author, Blogger, Speaker.
Azure Active Directory Uday Hegde 2016 Redmond Summit | Identity Without Boundaries May 26, 2016 Group Program Manager, Azure AD
AD Sync Service V2.0 NEIL CHONG-KIT | PRODUCT MANAGER 1 INTRANET CONNECTIONS You Are Here.
Protect your data Enable your users Desktop Virtualization Information protection Mobile device & application management Identity and Access Management.
Planning, Implementing and Supporting Office 365
Microsoft Azure Active Directory Identity Solutions
Upgrade to Dynamics 365 Online From On Premise
Max Fritz Senior Systems Consultant, Now Micro
Get to know SQL Manager SQL Server administration done right 
#ISUCIT.
What is Cloud Computing - How cloud computing help your Business?
Microsoft - Managing Office 365 Identities and Requirements
Using Microsoft Identity Manger with SharePoint 2016 to fill the User Profile Sync Gap Max Fritz Senior Systems Consultant Now Micro.
ACTIVE DIRECTORY ADMINISTRATION
Active Directory Administration
Exam in just 24 hours!!! Pass your exam in first attempt by the help of our latest braindumps
9/13/2018 4:54 PM BRK How to get Office 365 to the next level with Azure Active Directory Premium Brjann Brekkan Program Manager Lead – Customer.
Automated Azure Licencing
Leverage your on-premise investments with cloud innovation
O365 & AD Integration January 2017.
Get Office 2016 with Office 365 and get down to business
What Is Sharepoint? Mohsen Ashkboos
Cloud Connect Seamlessly
Cloudy with a Chance of Data
Local AD, Azure AD, & Google Suite User Management
Hybrid Search Planning Implementation.
Time Sheets Automated: Office 365 Integration Enables Simplified Time and Activity Tracking “At TIQ we help our users track their time better and more.
Hybrid Search Technical Guidance.
PSC Group, LLc Office 365/SharePoint Online Migration traps and tricks
Migrating to Office 365 from Google mail and exchange
Michael Stephenson DevOps empowered by Microsoft Flow
Matthew Levy Azure AD B2B vs B2C Matthew Levy
Surviving identity management in a hybrid world
SharePoint 2016 in MIM 2016 Robi Vončina Kompas Xnet.
University of Northern Colorado
Office 365 Identity Management
Presentation transcript:

PSJA AUTOMATION WORKFLOW AND LESSONS LEARNED Management of Information Systems Information Technology

Why do we need Identity Management? Today, every change in employee status requires involvement by IT. New hires need access to be granted to the data and apps they need to do their jobs. Separations require access revocation and security changes. Job moves mean shifting status and access changes from one group to another.

Why do we need Identity Management? Identity management solutions help shift that responsibility away from IT. These solutions often place employee status changes back in the hands of those tied most closely to them — HR and sometimes even the employees themselves. Additionally, it provides tighter security and access control measures over the daily tasks of employees. 

P S J A PSJA AT A GLANCE 5000 staff 43 campuses/ Support Sites 32,000 students 5000 staff 43 campuses/ Support Sites Micrsoft Active Directory/Office 365 Google

PROBLEMS AND INCONSISTENCIES PSJA CREDENTIALS INFORMAL PROCESS MULTIPLE SOURCES MULTIPLE BATCH IMPORTS LENGTHY PROCESS NOT REAL TIME (MANUAL PROCESS) INEFFICIENT USE TIME

AUTOMATION SOFTWARE CHOICES 2010 & 2012 NOVELL Microsoft Active Directory Servers 1 – DSS server (automation) 2 – ARMS server group mgmt & password 1 – Database server Microsoft Active Directory Server breakdown 1 – App server (automation) 2 – web front ends group mgmt 1 – SQL Database server Azure Active Directory Premium for self service password (staff & students) 2018

VERSION 1 & 2 OF THE MATRIX 2010 – Version 1 (NOVELL) Identity Automation software Used primarily with our Novell tree 2012 – Version 2 (AD & STUDENT EMAILS) Upgraded and improved logic with Identity Automation Created all accounts in Microsoft Active Directory tree Live@Edu fully automated for student accounts Staff accounts remained on-premise

OLD LOGIC AND NEW DEMANDS 2018 – Version 3 Philosophy and needs had changed since 2012 Outgrew old logic…no longer made sense Powershell scripts were running 40% of the process to meet our demands Migration of on-premise accounts to the cloud broke existing logic (Exchange accounts) Single sign on (SSO) to internal systems created instant demand for end users

What is Microsoft Identity Manager? Microsoft Identity Manager is a tool that… Helps you manage the users, credentials, policies, and access within your organization. Additionally, MIM 2016 adds a hybrid experience, privileged access management capabilities, and support for new platforms.

What does Microsoft Identity Manager do? Fundamentally MIM synchronizes identity data between various systems. It’s very flexible in what it can connect to (like Active Directory, other directories, HR systems, ERP systems, email systems etc.), and what objects it synchronizes (always users, often groups, and maybe roles, permissions, computers etc.). It can provision and de-provision, enable and disable, move, and generally synchronize all types of attributes – even passwords (though passwords are not handled like other attributes – being propagated in real time, while regular attributes are synchronized on a schedule).

GENERAL WORK FLOW - STAFF HR Employee hired (professionals, clerks, Name, Job code, Building, Status AD OU location Sub containers Permissions O365 Account sync (Azure AD Connect) License Activation based on group membership Global groups for email SIS Teacher info (First name, Last Name) Building

GENERAL WORK FLOW - STUDENT SIS Student enrolls Name, Grade, Building, Status AD OU location Sub containers O365 Account sync License Activation Global groups for email

CONTROL POINT IS WITH HUMAN RESOURCES EMPLOYEE HIRED NAME LOGIC JOB CODE BUILDING STATUS PASSWORD LOGIC PLACED IN ACTIVE DIRECTORY PERMISSIONS GRANTED Group Membership on AD Attributes Account is Active Single Sign On Ready

ONE USERNAME AND PASSWORD TO RULE THEM ALL PSJA CREDENTIALS TEACHER ACCESS CENTER EMPLOYEE ACCESS CENTER WEB RESOURCES STUDENT INFO SYSTEM INTRANET SHAREPOINT OFFICE 365 EMAIL And MANY MORE…

Deprovision and Account – Staff member EMPLOYEE RETIRES REMOVED FROM CAMPUS OU REMOVED FROM GROUP MEMBERSHIP ACCOUNT BECOMES DISABLED PLACED IN FINAL PAY LOCATION DELETED AFTER 180 DAYS

Deprovision Account - Student STUDENT GRADUATES REMOVED FROM CAMPUS OU REMOVED FROM GROUP MEMBERSHIP ACCOUNT BECOMES REMAINS ACTIVE FOR 2 YEARS DELETED AFTER 180 DAYS (AFTER 2 YEARS)

LESSONS LEARNED Where does your information live? eSchool (students) eFinance (staff) GIGO – Garbage In, Garbage Out Flowcharts of what you want done Complete life-cycle Understanding your organization procedures Who? What? How? Why? Working with others to facilitate the needed changes Change is hard for organizations/departments

LESSONS LEARNED…..continued Name logic was difficult to include everyone De la Garza, double last names, nick names, etc. Promotions, titles, pictures & renames – O my! Time sensitive and controlled at HR without notice Constant troubleshooting at the beginning Where did it break, what broke it Document your processes and procedures Handling all of the special exceptions Sometimes automation can’t fix everything

How much time would that take? Coordination and Communication Budget $$$ How many individuals would it take to keep up with all data input and changes in the different systems? 2? 3? Or more… What would that cost? How much time would that take? Coordination and Communication