Manifest – the Service Application Manifest is our new service, with Grouper as its logic engine, to manage populations which are known to us and those.

Slides:



Advertisements
Similar presentations
MFA for Business Banking – Security Questions with 2nd Request Multifactor Authentication: Quick Tip Sheets Note to Financial Institutions: We are providing.
Advertisements

MFA for Business Banking – Security Questions with Reset Multifactor Authentication: Quick Tip Sheets Note to Financial Institutions: We are providing.
Kantara: From IRM to Context. The World of Access Keeps Expanding App sourcing and hosting User populations App access channels SasS apps Apps in public.
Identity and Access Management IAM. 2 Definition Identity and Access Management provide the following: – Mechanisms for identifying, creating, updating.
Identity and Access Management IAM A Preview. 2 Goal To design and implement an identity and access management (IAM) middleware infrastructure that –
Important when you launch Yammer Enterprise Create an engaged and trusted community Decide about User Profile Syncs Various User and Admin.
Identity and Access Management
Widely Distributed Access Management Tom Barton University of Chicago.
Oracle Method | Group Delivery Together. Free your energies New Supplier Registration.
Credential Provider Operational Practices Statement CAMP Shibboleth June 29, 2004 David Wasley.
State of Indiana Business One Stop Process Storyboards To support RFP and Requirements As of September 13, 2013 Prepared by: RFP Attachment L.
Login Screen This is the Sign In page for the Dashboard Enter Id and Password to sign In New User Registration.
A trusted source of health service provider information Demonstration and Scenarios Press any key on any slide to continue Copyright © 2003, Province of.
© 2009 Cisco Systems, Inc. All rights reserved.Cisco Public 1 Service Access Management Tool Tour: Bill to ID and Contract Number September 2009.
© 2009 Cisco Systems, Inc. All rights reserved.Cisco Public 1 September 2009 Service Access Management Tool Tour: Bill to ID.
Identity and Access Management (IAM) What’s in it for Me? NC State University - Computer Security Day October 26, 2009 Mark Scheible Manager, Identity.
Turkey IDA Info-Day PM Session, September 25, 2003 CIRCA 1 CIRCA : The IDA Collaborative Software Tool Grzegorz Ambroziewicz European Commission - DG Enterprise.
Overview of Access and Information Protection
Electronically approve and create Suppliers in Oracle Financials using a combination of APEX and Oracle Workflow. NZOUG Conference 2010 Brad Sayer Team.
AAF Middleware update February Presented by Terry Smith Technical Manager and Heath Marks Manager.
Authorization Scenarios with Signet RL “Bob” Morgan University of Washington Internet2 Member Meeting, September 2004.
SMART Agency Tipsheet Staff List This document focuses on setting up and maintaining program staff. Total Pages: 14 Staff Profile Staff Address Staff Assignment.
Getting started on informaworld™ How do I register my institution with informaworld™? How is my institution’s online access activated? What do I do if.
IAM Online - Grouper Permissions Chris Hyzer University of Pennsylvania / Internet2 September 14, /14/20151.
11-July-2011, SURFnet Heather Flanagan, COmanage Project Coordinator Benn Oshrin, COmanage Developer Scott Koranda, U. Wisconsin – Milwaukee and LIGO.
Group Management at Brown James Cramton Brown University April 24, 2007.
AAI-enabled VO Platform “VO without Tears” Christoph Witzig EGI TF, Amsterdam, Sept 15, 2010.
Presented by: Alicia Goodwin
UCLA Enterprise Directory Identity Management Infrastructure UC Enrollment Service Technical Conference October 16, 2007 Ying Ma
Middleware Support for Virtual Organizations Internet 2 Fall 2006 Member Meeting Chicago, Illinois Stephen Langella Department of.
Invitation Only Conferences Michaela Marx, DESY JACoW Team Meeting Frascati, Italy,November 2005.
Grouper Training Developers and Architects Advanced Topics Chris Hyzer Internet2 University of Pennsylvania This work licensed under a Creative Commons.
Using Grouper and Signet for Access Management Kathryn Huxtable GPN Annual Meeting 30 May 2008
Social Identity Working Group Steve Carmody. Agenda Intro to Using Social Accounts Status and Recent News –Current UT Pilot –Current InCommon Pilot with.
Empowering people-centric IT Unified device management Access and information protection Desktop Virtualization Hybrid Identity.
Erie 1 BOCES / WNYRIC eBOCES applications Visit us at:
Student Attendance System Requirement Analysis Presentation.
Mark Lertvat (Speaker) Mike Jurney Andrew Levine Evan Davis.
Bridget-Anne Hampden | Nov U.S. Department of Education 2012 Fall Conference Enterprise Identity Management – Leveraging Participation Management.
Comprehensive Unit-based Safety Program for CUSP4MVP – VAP HSOPS CONFIDENTIAL Leveraging the MedConcert Social Enterprise Platform to Scale and Spread.
This is a short presentation to explain how and why to login to the CIM website as a member. Benefits are: Access to myCIM (private member area, contains.
Community Sign-On and BEN. Table of Contents  What is community sign-on?  Benefits  How it works (Shibboleth)  Shibboleth components  CSO workflow.
Configuring and Troubleshooting Identity and Access Solutions with Windows Server® 2008 Active Directory®
Set up 2: The shortname space will be created by Jee or Shobha Set up 1: Come up with a shortname (one world is preferred or two words with a hyphen) Discussion.
University of Washington Collaboration: Identity and Access Management Lori Stevens University of Washington October 2007.
Federal Acquisition Service U.S. General Services Administration
Brown University Leveraging Social Identities Steve Carmody CSG, May 15, 2013.
What’s new with Grouper 26-April-2010, Spring Member Meeting Chris Hyzer, Grouper developer.
CERN IT Department CH-1211 Genève 23 Switzerland t Single Sign On, Identity and Access management at CERN Alex Lossent Emmanuel Ormancey,
Networks ∙ Services ∙ People Mandeep Saini TNC15, Porto, Portugal Virtual organisation Authorisation Management Practices in Research and.
1 CEPT portal and family websites: An overview October 2011 CEPT portal: Committee sites: ECO site
1 Name of Meeting Location Date - Change in Slide Master Authentication & Authorization Technologies for LSST Data Access Jim Basney
Community Sign-On and BEN. Table of Contents  What is community sign-on?  Benefits  How it works (Shibboleth)  Shibboleth components  CSO workflow.
L’Oreal USA RSA Access Manager and Federated Identity Manager Kick-Off Meeting March 21 st, 2011.
Collaboration and Federated Identity Two powerful forces being leveraged – the rise of federated identity – the bloom in collaboration tools, most particularly.
Knowledge Hub Walkthrough August
MOBILE ACCESS & PDS CONNECTS
Introducing Access Management
Campus Administrator Training March 2, 2012
BIM 360 Glue Migration to BIM 360 Account Administration (HQ)
eduTEAMS platform for collaboration Niels Van Dijk
THE STEPS TO MANAGE THE GRID
Identity and Access Management Services
TBR Institution Guide to Updating Existing TSM Vendors and Entering New TSM Vendors Existing in Banner.
ESA Single Sign On (SSO) and Federated Identity Management
Chris Hyzer, University of Pennsylvania
Ohio Web Portal Ohio Edison, Illuminating Company, Toledo Edison
Management Application for all segments
TBR Institution Guide to Updating Existing TSM Vendors and Entering New TSM Vendors Existing in Banner.
Presentation transcript:

Manifest – the Service Application Manifest is our new service, with Grouper as its logic engine, to manage populations which are known to us and those which will be new to us. Manifest will enable administrators to provide service entitlements to groups.

Why Grouper?

Grouper: selection criteria Number of requirements 129 Keith 92/71% Unicon 100/78% Most of the contrary responses have to do with workflow requirements and reporting requirements. Grouper does not provide workflow. Grouper provides access to its data logs for an external reporting agent external reporting agent.

Grouper: problem addressed -Grouper will house the business rules, replacing views and code -Exposing that logic in a simpler manner will help Middleware manage the complexity -Campus consumers will get a better idea of what they are getting and how their data might be better tuned -Campus consumers will become more engaged in the data that they receive -The same goes for providing campus services to groups formed within Grouper

Manifest roadmap

Release 1.0 (Announced December 2012) -Create a group -Manage a group -Add members to a group who have NetID, by invitation or by directly entering their NetID into the application -Add a SAML2 Entity ID to a group, enabling the group to control access to web applications using the NetID Login ServiceSAML2 Entity ID

Release 1.1 (Announced March 2013) -Ability for authorized groups to invite someone to join the group and make them eligible for a NetID if they don't already have one.

Release 2.0 (Expected Release late Spring 2013) - Ability to place start and end dates on group memberships -Enables shared enterprise services to register their service in Manifest -Enables administrators to browse a menu of registered services/groups -Provides a process for requesting a group’s access to a service -Workflow has been uploaded to the wiki here ersity+of+Wisconsin+- +Madison+Grouper+Project+Page

Future 1/2 - A user interface that allows the management of service entitlements -Ability to use federated or social identity in lieu of NetID while being a member of a group -Composite groups, involving group math that uses Data Driven Groups (e.g., the entire student population or all classified staff) that have been loaded into Manifest from the campus Person Hub (a database that houses information about people, populated from various source systems on campus) -Reports and auditsfederated

Future 2/2 -Attestation (auditing of account data to remove inactive or invalid users) -Ability to use Manifest group data to provision campus applications -Direct connection to departmental databases that contain person data -Use Manifest to determine whether an authenticated user should have access to non-web applications/systems -Self-service account linking (linking non-NetID accounts to a user’s NetID) -For application developers: supplemental attribute delivery for display, application authorization, just in time provisioning, etc.

The Infrastructure

Hosts 2 instances of Grouper, load balanced Virtualized Oracle database

Name space Visit madison+stem+and+group+naming+standards

Usage (March 8) Grouper daily report OVERALL: memberships: 2,622 groups: 219 members: 620 folders: 60 unresolvable subjects: 0 bad memberships: 0 WITHIN LAST DAY: new memberships: 20 new groups: 3 updated groups: 0 new folders: 0

Challenges - Onboarding campus services so that they receive eligibility information from one place -Loading Data Driven Groups into Grouper and maintaining that data -Design and development of a User Interface that satisfies workflow requirements and invitations

Best practices -Enroll in lists -Participate in wiki munity+Contributions -Engage governance bodies (WARG / IVG) -For project health use tools like Jira and Wiki, with PM practices