Microsoft Forefront Identity Manager 2010

Slides:



Advertisements
Similar presentations
Agenda 2 factor authentication Smart cards Virtual smart cards FIM CM
Advertisements

Microsoft Forefront Identity Manager 2010 Daniel MEYER Enterprise Technology Architect EMEA.
Feature: Purchase Requisitions - Requester © 2013 Microsoft Corporation. All rights reserved. Microsoft, Windows, Windows Vista and other product names.
MIX 09 4/15/ :14 PM © 2009 Microsoft Corporation. All rights reserved. Microsoft, Windows, Windows Vista and other product names are or may be registered.
Microsoft Forefront Identity Manager 2010 Henk Den Baes Technology advisor Microsoft Belux.
Virtual techdays INDIA │ august 2010 Managing Active Directory Using Microsoft Forefront Identity Manager: Amol R Bhandarkar │ Tech Specialist –
SharePoint Collaboration Features & Workflow
Brjann Brekkan Technical Product Manager Microsoft Corp. Session Code: SIA307.
Microsoft Office Sharepoint Server 2007 (MOSS) Overview Momentum Microsoft November 15, 2007.
Christopher Chapman | MCT Content PM, Microsoft Learning, PDG Planning, Microsoft.
Optimizing Business Operations Business Priorities Presentation.
Understanding Active Directory
Microsoft Identity and Access Solutions Market Trends and Futures
SIM332 UserManagement GroupManagement CredentialManagement Common Platform WorkflowConnectorsLogging Web Service API Synchronization PolicyManagement.
Feature: Web Client Keyboard Shortcuts © 2013 Microsoft Corporation. All rights reserved. Microsoft, Windows, Windows Vista and other product names are.
Windows Azure Networking & Active Directory Nasir (Muhammad Nasiruddin) Developer Evangelist - Azure Microsoft Corporation
Identity and Access Management Business Ready Security Solutions.
May 30 th – 31 st, 2006 Sheraton Ottawa. Microsoft Certificate Lifecycle Manager Saleem Kanji Technology Solutions Professional - Windows Server Microsoft.
Christopher Chapman | MCT Content PM, Microsoft Learning, PDG Planning, Microsoft.
Christian Jäggli Principal Consultant Microsoft Corporation.
Christopher Chapman | MCT Content PM, Microsoft Learning, PDG Planning, Microsoft.
Amol Bhandarkar Technology Solution Professional – IDA | Microsoft
demo Cloud Storage WA Blobs Schema Management APIs & Portal Web Roles Integration Pipeline 3 rd Party Web Services 3 rd Party Store 3 rd Party.
Forefront Identity Manager 2010 Deep Dive
© 2012 Microsoft Corporation. All rights reserved. Microsoft, Windows, Windows Vista and other product names are or may be registered trademarks and/or.
Future of the Server Room Tour. Ottawa Montreal Calgary Vancouver Toronto Future of Your Server Room Three Pillars of Windows Server 2008 Virtualization.
Tech Ed North America /24/2017 1:59 AM SESSION CODE: SIA327
Identity Solution in Baltic Theory and Practice Viktors Kozlovs Infrastructure Consultant Microsoft Latvia.
Feature: Customer Combiner and Modifier © 2013 Microsoft Corporation. All rights reserved. Microsoft, Windows, Windows Vista and other product names are.
Feature: Employee Self Service Timecard Entry © 2013 Microsoft Corporation. All rights reserved. Microsoft, Windows, Windows Vista and other product names.
Empowering people-centric IT Unified device management Access and information protection Desktop Virtualization Hybrid Identity.
© 2009 Microsoft Corporation. All rights reserved. Microsoft, Windows, Windows Vista and other product names are or.

Office 365: Identity and Access Solutions Suresh Menon Technology Specialist – Office 365 Microsoft Corporation India.
Federico Guerrini IDA TSP, EMEA Incubation Team From Identity Synchronization to Identity Management.
Joe Schulman Program Manager Microsoft Corporation Session Code: SIA308 Fred Delombaerde Lead Program Manager Microsoft Corporation.
Service Pack 2 System Center Configuration Manager 2007.
© 2009 Microsoft Corporation. All rights reserved. Microsoft, Windows, Windows Vista and other product names are or may be registered trademarks.
Ellis Paul Technical Solution Specialist – System Center Microsoft UK Operations Manager Overview.
© 2008 Microsoft Corporation. All rights reserved. Microsoft, Windows, Windows Vista and other product names are or.
Almero Steyn Business Manager: IdAM GijimaAst Session Code: SIA 306 Almero Steyn Business Manager: IdAM GijimaAst Session Code: SIA 306.

Chris Louloudakis Solution Specialist Identity & Access Management Microsoft Corporation SVR302.
Microsoft Virtual Academy. Microsoft Virtual Academy First HalfSecond Half (01) Introduction to Microsoft Virtualization(05) Hyper-V Management (02) Hyper-V.
Protect your data Enable your users Desktop Virtualization Information protection Mobile device & application management Identity and Access Management.
People-Centric Management
Microsoft Office SharePoint Server 2007 Enterprise Search
Microsoft /4/2018 8:21 AM BRK3082 Build solutions and apps with Microsoft OneDrive API and Microsoft Graph API Ryan Gregg Principal Program Manger,
Business Connectivity Services in SharePoint 2010 and Office 2010
Develop for the Experience Business with Adobe and Microsoft
Microsoft Intune MAM without Device Enrollment
SharePoint Online Management and Control
11/16/2018 © 2014 Microsoft Corporation. All rights reserved. Microsoft, Windows, and other product names are or may be registered trademarks and/or trademarks.
Microsoft Virtual Academy
Access and Information Protection Product Overview October 2013
Microsoft Virtual Academy
Office 365 Identity Management
12/29/2018 8:46 AM © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN.
Microsoft Virtual Academy
Office 365 Development.
2/27/2019 © 2014 Microsoft Corporation. All rights reserved. Microsoft, Windows, and other product names are or may be registered trademarks and/or trademarks.
Developing for Windows Azure
System Center Marketing
One Marketing Template
TechEd /6/ :24 PM © 2013 Microsoft Corporation. All rights reserved. Microsoft, Windows, and other product names are or may be registered trademarks.
Microsoft Virtual Academy
Azure AD Simon May Technical Evangelist.
Welcome to Architect Insight 2010
Microsoft Virtual Academy
Presentation transcript:

Microsoft Forefront Identity Manager 2010 Elton AGOLLI Chief of Infrastructure Section TETRA Solutions eagolli@tetra.al

Agenda Customer challenges Microsoft’s Identity and Access Strategy Identity and Access Management The business challenges How Identity Manager addresses the challenges Scenarios Summary Resources

Identity & Access Customer Challenges Compliance with regulatory requirements Auditable processes for granting access to resources Reducing help desk burden for end user requests Managing the complexity of distributed identity information Compliance Operational Efficiency IT Security Business Agility Enabling new high business value scenarios Supporting mergers, acquisitions & reorganizations Integrated user provisioning & credential management Ensuring that only authorized users can access resources

Business Ready Security Solutions Secure Messaging Secure Collaboration Secure Endpoint Information Protection Identity and Access Management Active Directory® Federation Services

Identity and Access Management

Business and IT Challenges Simplify user experience for collaboration across networks Provide seamless movement between applications Reduce cost of identity management Extend business resources, especially to the cloud Secure multiple devices and locations Manage complex identity lifecycles Provide secure access to applications from anywhere Manage disparate systems BUSINESS Needs IT Needs Agility and Flexibility Control

Identity and Access Management Create Provision user Provision credentials Provision resources Policy Management Policy authoring Policy enforcement Approvals and notifications Audit trails Role changes Password and PIN reset Resource requests Update De-provision identities Revoke credentials De-provision resources Retire

Identity Lifecycle Manager -> Forefront Identity Manager User Management Group Management Common Platform Workflow Connectors Logging Web Service API Synchronization Credential Management Policy Management Identity Synchronization User Provisioning Certificate and Smartcard Management Office Integration for Self-Service Support for 3rd Party CAs Codeless Provisioning Group & DL Management Workflow and Policy 8

Version Feature Comparison 4/14/2017 Version Feature Comparison MIIS 2003 ILM 2007 FIM 2010 Identity synchronization X Password synchronization Policy authoring and editing solution ILM-CM only Policy enforcement Delegation management solution User provisioning solution Certificate and smart card management solution Group management solution DL management solution Workflow Self-service password reset Localized © 2008 Microsoft Corporation. All rights reserved. Microsoft, Windows, Windows Vista and other product names are or may be registered trademarks and/or trademarks in the U.S. and/or other countries. The information herein is for informational purposes only and represents the current view of Microsoft Corporation as of the date of this presentation. Because Microsoft must respond to changing market conditions, it should not be interpreted to be a commitment on the part of Microsoft, and Microsoft cannot guarantee the accuracy of any information provided after the date of this presentation. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

Forefront Identity Manger - Key Feature Areas Policy Management SharePoint-based console for policy authoring, enforcement & auditing Extensible WS– * APIs and Windows Workflow Foundation workflows Heterogeneous identity synchronization and consistency Credential Management Heterogeneous certificate management with 3rd party CAs Management of AD credentials Self-service password reset integrated with Windows logon User Management Integrated provisioning of identities, credentials, and resources Automated, declarative user provisioning and de-provisioning Self-service profile management Group Management Rich Office-based self-service group management tools Offline approvals through Office Automated group and distribution list updates

Delegation & Permissions Forefront Identity Manger 2010 Architecture Solutions Group Mgmt Credential Mgmt Policy Mgmt Custom User Mgmt Outlook FIM Portal Windows Custom FIM Client Experiences Cert Mgmt ILM-CM DB ILM-CM Portal FIM Service and Portal ILM Sync FIM Service AuthZ Workflow AuthN Delegation & Permissions Action App DB Adapters Request Processor Sync Directories Databases E-Mail Systems Applications Identity and data stores

User scenarios

Credential Management End User Scenarios Example Scenario FIM 2010 Advantages Policy Management Automatic routing of multiple approvals Approval process through Office Audit trail of approvals CFO gives final approval for new user to access app with associated SOX compliance requirement Credential Management Integration with Windows logon No need to call help desk Faster time to resolution Self-service smart card provisioning & management User Management Automatic updating of business applications No need to call help desk Faster time to resolution User changes cell phone number Group Management User asks to join secure distribution list for new product development Request process through Office No waiting for help desk Faster time to resolution

IT Administrator Scenarios Example Scenario FIM 2010 Advantages Policy Management Centralized management Automatic policy enforcement across systems Author policy to require HR approval for job title change Credential Management Generation and delivery of initial one-time use password Integration of smart card & cert enrollment with provisioning Create workflow to automatically issue passwords and smart cards to new users User Management Automatic policy enforcement across systems Management of role changes & retirements Automatically provision new employees with identity, mailbox, and credentials Group Management Automatic management of group membership Secure access to departmental resources, with audit trail Design policy to automatically create departmental security groups

Customizable Identity Portal SharePoint-based Identity Portal for Management and Self Service How you extend it Add your own portal pages or web parts Build new custom solutions Expose new attributes to manage by extending FIM schema Choose SharePoint theme to customize look and feel

FIM PROVISIONING POLICY APPLIED 4/14/2017 9:10 AM New Employee Scenario Given Name Melissa Surname Meyers Title Analyst Department Finance Employee ID 122145 Employee type Full Time email Given Name Melissa Surname Meyers Title Analyst Department Finance Employee ID 122145 Employee type Full Time email mmeyers@ contoso.com Given Name Melissa Surname Meyers Title Analyst Department Finance Employee ID 122145 Employee type Full Time email HR SYSTEM MANAGER APPROVAL FIM PROVISIONING POLICY APPLIED FIM 2010 MANAGER APPROVAL MAINFRAME ACTIVE DIRECTORY FINANCE APPLICATION EXCHANGE FINANCE PORTAL SMART CARD iPLANET © 2004 Microsoft Corporation. All rights reserved. This presentation is for informational purposes only. Microsoft makes no warranties, express or implied, in this summary.

Workflow Create user

Employee Transition Scenario 4/14/2017 9:10 AM Employee Transition Scenario Given Name Melissa Surname Meyers Title Group Marketing Manager Department Marketing Employee ID 122145 Employee type Full Time email mmeyers@ contoso.com Given Name Melissa Surname Meyers Title Analyst Department Finance Employee ID 122145 Employee type Full Time email mmeyers@ contoso.com Given Name Melissa Surname Meyers Title Group Marketing Manager Department Marketing Employee ID 122145 Employee type Full Time email mmeyers@ contoso.com HR SYSTEM FIM PROVISIONING POLICY APPLIED FIM 2010 MAINFRAME ACTIVE DIRECTORY MARKETING APPLICATION FINANCE APPLICATION EXCHANGE FINANCE PORTAL MARKETING PORTAL SMART CARD iPLANET © 2004 Microsoft Corporation. All rights reserved. This presentation is for informational purposes only. Microsoft makes no warranties, express or implied, in this summary.

Separation/Fire Scenario 4/14/2017 9:10 AM Separation/Fire Scenario Given Name Melissa Surname Meyers Title Group Marketing Manager Department Finance EmployeeI D 122145 Employee type Terminated email mmeyers@ contoso.com Given Name Melissa Surname Meyers Title Group Marketing Manager Department Finance Employee ID 122145 Employee type Full Time email mmeyers@ contoso.com Given Name Melissa Surname Meyers Title Group Marketing Manager Department Finance Employee ID 122145 Employee type Terminated email mmeyers@ contoso.com HR SYSTEM FIM PROVISIONING POLICY APPLIED FIM 2010 MAINFRAME ACTIVE DIRECTORY MARKETING APPLICATION EXCHANGE MARKETING PORTAL SMART CARD iPLANET © 2004 Microsoft Corporation. All rights reserved. This presentation is for informational purposes only. Microsoft makes no warranties, express or implied, in this summary.

FIM 2010 In Action Self-service password management User forgets password Requests password reset at Win logon and answers Q/A Does user have permission to reset password? FIM receives XML FIM validates Q/A response from user Request Processor Delegation & Permissions AuthN & AuthZ Workflows FIM makes call to reset password in AD FIM syncs new password to external identity stores Changes committed to FIM app store Sync DB Service DB Management Agents Action Workflow Identity Stores

FIM 2010 In Action Self-service smart card provisioning AuthN & AuthZ Workflows Delegation & Permissions Action Workflow Service DB Sync DB Management Agents New user added in HR app Does user have permission to add user to FIM ? FIM manages manager and dept head approvals Once approved, changes committed to ILM app store FIM sends welcome and confirmation e-mails Identity Stores FIM syncs to external identity stores Sync receives request Approval workflows Card created & printed Certificates requested Self-service notification and One Time Password sent to end user End user downloads certificates onto smart card FIM CM

Self-Service Group Management Situation: User needs to join the Fabrikam Project Virtual Team group Without Forefront Identity Manager 2010 Activity Costs to the Business Melissa Meyers, Business User Calls help desk Lost productivity No resource access when she needs it Chad Rice, Accounts Administrator Manually edits AD Users and Computers to add user to group Risk of error and policy non-compliance Cost of manual administration

Self-Service Group Management Situation: User needs to join the Fabrikam Project Virtual Team group With Forefront Identity Manager 2010 Activity Business Benefits Chad Rice, Accounts Administrator Uses FIM to establish group management policies and workflows Efficiency Security Compliance Melissa Meyers, Business User Request to join Group from Outlook FIM routes approvals and grants appropriate access User productivity Enables effective business interactions

Create Distribution List

Create Distribution List

Create Distribution List

Unauthorized User Attribute Change Situation: IT accidentally makes an unauthorized change to a user’s title Without Forefront Identity Manager 2010 Activity Costs to the Business HR Administrator, Samantha Smith Updates Megan Meyers’ title in SAP Chad Rice, Accounts Administrator Asked to update Megan Meyers titles other systems Accidentally changes Melissa Meyers title in ADUC Risk of error and policy non-compliance Cost of manual admin Ted Smith, Compliance Auditor Discovers error in manual audit process of purchase order application Cost of manual auditing Delay in discovery of non-compliance

Unauthorized Change Situation: IT accidentally makes an unauthorized change to a user’s title With Forefront Identity Manager 2010 Activity Business Benefits Chad Rice, Accounts Administrator Uses FIM to establish policies and workflows to that include management of job title data Efficiency Security Compliance HR Administrator, Samantha Smith Updates Megan Meyers’ title in SAP Title change data flows to other systems that use it, per FIM policy Efficiency Compliance Ted Smith, Compliance Auditor Uses FIM audit trail to audit approvals Efficiency Compliance

Summary: FIM 2010 Software for policy-based management of identities, credentials, and resources across heterogeneous environments Empowers People Provides Office-based self-service tools SharePoint admin console to manage identities Greater productivity through faster time to resolution Delivers Agility and Efficiency Reduces costs through automation and self-service Maximizes existing investments in Identity Infrastructure Integrates with familiar developer tools to enable new scenarios Increases Security and Compliance Integrates identity, credential, and access management Rich permissions and delegation model Enables system auditing and compliance

Resources Learn more about Forefront Identity Manager FIM 2010 Product Page: http://www.microsoft.com/forefront/identitymanager Learn about Microsoft Forefront Identity and Security Forefront Home Page: www.microsoft.com/forefront Evaluate the Identity Manger Visit http://technet.microsoft.com/en-gb/evalcenter/cc872861.aspx

© 2008 Microsoft Corporation. All rights reserved © 2008 Microsoft Corporation. All rights reserved. Microsoft, Windows, Windows Vista and other product names are or may be registered trademarks and/or trademarks in the U.S. and/or other countries. The information herein is for informational purposes only and represents the current view of Microsoft Corporation as of the date of this presentation. Because Microsoft must respond to changing market conditions, it should not be interpreted to be a commitment on the part of Microsoft, and Microsoft cannot guarantee the accuracy of any information provided after the date of this presentation. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.