INTEGRATIONS WITH Enterprise HRIS

Slides:



Advertisements
Similar presentations
Dispatcher Conditional Expression Static Request Filter Attribute Filter Portal , DNS Hello User Sample (Gateway)
Advertisements

FIspace Security Components FIspace Security Components NetFutures 2015 FIspace project Javier Romero Negrín Javier Hitado Simarro ATOS Serdar Arslan KoçSistem.
Designed By: Technical Training Department
SIM205. (On-Premises) Storage Servers Networking O/S Middleware Virtualization Data Applications Runtime You manage Infrastructure (as a Service)
Edwin Sarmiento Microsoft MVP – Windows Server System Senior Systems Engineer/Database Administrator Fujitsu Asia Pte Ltd
Copyright © The OWASP Foundation Permission is granted to copy, distribute and/or modify this document under the terms of the OWASP License. The OWASP.
Timothy Heeney| Microsoft Corporation. Discuss the purpose of Identity Federation Explain how to implement Identity Federation Explain how Identity Federation.
Deploying Chromebooks RICK NICHOLAS A.
Montcalm Area Intermediate School District Tom Staten – Billy Willis – October 13, 2011 MAEDS Session 8D.
FIspace SPT Seyhun Futaci. Technology behind FIspace Authentication and Authorization IDM service of Fispace provides SSO solution for web apps, mobile.
Quick Start Guide: Administrator Basics Learn about: 1.Adding users to the LOAMS system 2.How to modify or delete existing users 3.How to reset passwords.
Administrator – Employee Overview September, 2011.
© 2006 Cisco Systems, Inc. All rights reserved.Cisco ConfidentialPresentation_ID 1 Otomo End User SSO - TOI March 2014 Otomo 10.5 – End User SSO Support.
…. PrePlanPrepareMigratePost Pre- Deployment PlanPrepareMigrate Post- Deployment First Mailbox.
Microsoft NDA Confidential Enabling users to be productive, responsibly Finding the right balance Devices & Experiences Users Want Applications and.
The explosion of devices is eroding the standards-based approach to corporate IT. Devices Deploying and managing applications across platforms is.
PAYWARE MOBILE API – APP TO APP INTEGRATION. PAYWARE MOBILE API OVERVIEW VeriFone’s PAYware Mobile API provides iPhone developers the ability to easily.
ACCOUNT ADMINISTRATION. Objectives In this session you will learn how to: –Create Business Units. –Create new users and manage security settings. –Configure.
Secure Mobile Development with NetIQ Access Manager
Agenda  Microsoft Directory Synchronization Tool  Active Directory Federation Server  ADFS Proxy  Hybrid Features – LAB.
AZURE AD Haishi DX, Agenda Basic concepts Exercise 1: Creating a new Azure AD tenant and a new user Exercise 2: Enable web app Azure AD authentication.
Interstage BPM v11.2 1Copyright © 2010 FUJITSU LIMITED ADMINISTRATION.
SaaS apps.
Access Policy - Federation March 23, 2016
SP Business Suite Deployment Kick-off
Using Your Own Authentication System with ArcGIS Online
Azure Active Directory - Business 2 Consumer
Microsoft Dynamics CRM 2016 Online Deployment MB2-710 Exam Questions
CollegeSource Security Application &
Authentication Interact Cloud.
Digital Engagement What Is Your Digital Strategy?
Federation made simple
Prime Service Catalog 12.0 Integration Best Practices – LDAP and SAML Settings.
HMA Identity Management Status
Microsoft - Managing Office 365 Identities and Requirements
Exam in just 24 hours!!! Pass your exam in first attempt by the help of our latest braindumps
New Integration FEATURES Presented By: LOGAN CASHWELL.
9/13/2018 4:54 PM BRK How to get Office 365 to the next level with Azure Active Directory Premium Brjann Brekkan Program Manager Lead – Customer.
SERVICENOW ADMIN & ADVANCED ONLINE TRAINING
1Z0-477 VCE Questions
New Primo Authentication
Cloud Connect Seamlessly
Multi-Farm, Cross-Continent SharePoint Architecture
JDXpert Workday Integration
This presentation document has been prepared by Vault Intelligence Limited (“Vault") and is intended for off line demonstration, presentation and educational.
Public Single Sign-On for EPM Cloud Using Oracle Identity Cloud Service (IDCS) Question: How can I set up single sign-on (SSO) between EPM.
Hybrid Search Planning Implementation.
Adding members to ArcGIS Online
Adding members to ArcGIS Online
SharePoint Online Hybrid – Configure Outbound Search
atEvent + HubSpot Integtration Instructions
Matthew Levy Azure AD B2B vs B2C Matthew Levy
SharePoint Online Authentication Patterns
This presentation document has been prepared by Vault Intelligence Limited (“Vault") and is intended for off line demonstration, presentation and educational.
Adding members to ArcGIS Online
System Center Configuration Manager Cloud Services – Cloud Distribution Point Presented By: Ginu Tausif.
INTEGRATIONS WITH Single Sign-On
INTEGRATIONS WITH WORKDAY
INTEGRATIONS WITH Content Providers
INTEGRATION WITH SABA LMS
INTEGRATIONS WITH SUCCESSFACTORS HRIS
Getting Started With LastPass Enterprise
INTEGRATION WITH SumTotal LMS
INTEGRATION WITH CornerStone LMS
INTEGRATIONS WITH Content Providers
INTEGRATIONS WITH SUCCESSFACTORS HRIS
Adding members to ArcGIS Online
ADMINISTRATION A guide to setup and manage your innovation platform…
Presentation transcript:

INTEGRATIONS WITH Enterprise HRIS AI-Powered Knowledge Cloud

Enterprise HRIS Integration Typically, HRIS Integrations with EdCast comprise of these three aspects: Employee Profile Modelling Setting up a Typical User Profile on LXP Employee Data Synchronization Groups, Users, Managers, Custom Attributes etc SSO Integration SAML, OAuth, OpenID Connect

Employee Profile Modeling

Employee Profile Modeling - Mandatory Attributes The LXP can work with the most minimal amount of employee information - only the following attributes are mandatory Email First Name Last Name A consistent user account can be created using these mandatory attributes

Employee Profile Modeling - Custom Attributes LXP User Account can be enriched to pass some additional information from the customer’s HR record such as: Employee ID Business Unit Functional Manager Custom attributes can be populated using any of our integration modes from the HR record of the Employee

Employee Data Synchronization

HRIS – Modes of Employee Data Synchronization For all HRIS Integrations EdCast synchronizes the user’s data from the customer’s HR system into the LXP It is a unidirectional Integration There are four modes of Integration Mode #1 - Pre-Built connectors – Workday, SuccessFactors etc Mode #2 - SFTP based integration Mode #3 - Push Integration - Customer pushes data through EdCast APIs Mode #4 - Pull Integration - EdCast pulls data from the HRIS APIs

Data Integration – Mode #1 – Pre-Built Connectors Workday SuccessFactors

WorkDay Connector Supports adding/updating users Supports adding/updating custom attributes Supports synchronizing user states Fetches all the user data on day one and then fetches the delta from second day onwards WorkDay connector runs once in every 24 hours

WorkDay Connector - Things to note Doesn’t support fetching profile images Doesn’t support fetching and mapping the manager details

Workday Connector - Configuration Parameters Name Description Sample Value API Endpoint API Endpoint of Workday http://acme.sumtotal.host API Version API version used to fetch users data from workday current 32.1 32.1 Username Username to access Workday API’s admin Encoded Password Base64 Encoded password to access workday API's asdasfdsadas=== Tenant Name of tenant given by workday acme_corp Global Unique ID Unique ID that represents the user (only if SSO is enabled) acme_id

WorkDay Integration Process (Internal) Customer IT administrator share the WorkDay configuration parameters(From slide#7) with EdCast customer support team EdCast support team will configure WorkDay job in https://hrms-prod.edcast.io Create HRMS Source with customer provided values

WorkDay HRMS Source (Internal) Name Description Sample Value Name of the WorkDay Source Workday Acme SB source_config Configuration parameters for the WorkDay connector { "api_version": "v32.1", "username": "ISU_Edcast_01", "encoded_password": "RWRjYXN0MDEhd2Q=", "tenant": "acme", "workday_end_point": "https://wd5-services1.myworkday.com/ccx/service/acme/Human_Resources" } optional_config Optional configuration parameters for the WorkDay connector "sso_enabled": "true", "external_identifier_key": "acme_id", "contingent_workers_enabled": true

WorkDay HRMS Source (Internal) Name Description Sample Value Field Mapping Map the EdCast LXP schema to customer’s WorkDay schema { "first_name": { "external_key": "worker_data_data_first_name" }, "last_name": { "external_key": "worker_data_last_name" }} Organization Organization of the customer deployment 1908 is_enabled The option enables the WorkDay connector Yes

SuccessFactors Connector Supports adding/updating users Supports adding/updating custom attributes Supports synchronizing user states Fetches all the user data on day one and then fetches the delta from second day onwards SuccessFactors connector runs once in every 24 hours

SuccessFactors Connector - Things to note Doesn’t support fetching profile images Doesn’t support fetching and mapping the manager details

SuccessFactors Connector - Configuration Parameters Name Description Sample Value Host URL Host URL used to fetch users data from SuccessFactor API http://acme.sumtotal.host Client ID Client ID given by SuccessFactor 32.1 User ID User ID given by SuccessFactor admin Company ID Company ID_id given by SuccessFactor asdasfdsadas=== Private Key Private Key given by SuccessFactor acme_corp Global Unique ID Unique ID that represents the user (only if SSO is enabled) acme_id

SuccessFactors Integration Process (Internal) Customer IT administrator share the SuccessFactors configuration parameters(From slide#7) with EdCast customer support team EdCast support team will configure SuccessFactors job in https://hrms-prod.edcast.io Create HRMS Source with customer provided values

SuccessFactors HRMS Source (Internal) Name Description Sample Value Name of the SuccessFactors Source SuccessFactors Acme SB source_config Configuration parameters for the SuccessFactors connector { "host_url": "https://api4.successfactors.com", "client_id": "NGUyZjasdasVjZDQzZjYzNWNjMmRmOTZhNDBiZmZiZA", "user_id": "SFAPI_EDCAST", "company_id": "acmeP", "private_key": "" } optional_config Optional configuration parameters for the SuccessFactors connector "sso_enabled": "true", "external_identifier_key": "acme_id"}

SuccessFactors HRMS Source (Internal) Name Description Sample Value Field Mapping Map the EdCast LXP schema to customer’s SuccessFactors schema { "first_name": { "external_key": "worker_data_data_first_name" }, "last_name": { "external_key": "worker_data_last_name" }} Organization Organization of the customer deployment 1908 is_enabled The option enables the SuccessFactors connector Yes

Employee Data Sync – Mode #2 – SFTP Based Customer uploads CSV file to EdCast SFTP folder CSV files need to be encrypted using EdCast Public Key (using PGP encryption) Sample CSV file : https://s3.amazonaws.com/ed-general/bulk_import_sample.csv File with all records on initial launch followed by new or changed (delta) records daily Customer is in control of the users that will be added on to the LXP EdCast platform processes these files on a daily basis

Employee Data Sync – Mode #3 – Push Integration https://documenter.getpostman.com/view/1465156/RW8FERBE?version=latest Customer uses Developer API to create/update users/groups Customer is in control of the users that will be added on to the LXP Real time create/update

Employee Data Sync – Mode #4 – Pull Integrations Customer to provide 2 API’s API which provides list of all users along with their attributes First Name, Last Name, Email are mandatory API which provides the delta of users (added/deleted) for a given time range

SSO Integration

SSO Integration EdCast supports two types of SSO integrations Integration with Customers Identity Provider Integration with Content providers

SSO integration with Customer’s Identity Provider (SP Initiated SSO Flow)

SSO Authentication through SAML (SP Initiated)

SSO Integration Process EdCast Support team creates basic Identity Provider profile for the customer and share below artifacts with customer Service Provider Metadata file ACS URL Entity ID Customer’s IT administrator creates the Service Provider profile in their Identity Provider software and share below artifacts with EdCast Support team Identity Provider Metadata file Single Sign On URL Customer’s IT administrator also updates their Identity Provider software and send SAML assertion with firstName, lastName, email and globally unique identifier (like employee ID) as subjectNameID EdCast Support team updates the customer’s Identity Provider profile with right customer supplied information from step #3

SSO Integration Process (Internal) Note down the IDP Id from the customer’s Identity Provider profile EdCast Support team creates OKTA API token for the customer from OKTA Admin Console->Security->API ->Tokens (Make sure to copy the token offline) Enable OKTA for this customer using below steps Go to organization specific settings page in LXP Super Admin Console Go to OKTA tab and Enable OKTA Update OKTA domain (Production - https://edcast.okta.com and SandBox- https://edcast.oktapreview.com) Update the API Token with value from Step#2 Enable SAML checkbox and update the IDP value with the value from Step#1 Go to Customer’s LXP Admin Settings page and enable SAML (Admin->Settings->Login Page Settings-> Okta saml) For more detailed information, visit https://confluence.edcastcloud.com/display/EP/EP+-+SSO+with+Okta

SSO integration with Content Provider (IDP Initiated SSO Flow)

SSO Authentication through SAML (IDP Initiated)

SSO Integration Process EdCast Support team creates basic SAML 2.0 application for the content provider application (OKTA Admin Console-> Applications->Add Application->Create New App) and share below artifacts with the provider Identity Provider Single Sign-On URL Identity Provider Issuer EdCast public key certificate Content providers IT administrator use the above information and configure their SAML integration and share below artifacts with EdCast Support team Single Sign On URL Service Provider Entity ID (Audience URI) Required Attributes in SAML assertion EdCast Support team updates the content providers application with right customer supplied information from step #3 EdCast Support team to assign the customers group to SAML application created in Step#1