Gartner: Setting Objectives for a Directory Services Project John Enck Vice President and Research Director Server and Directory Strategies Gartner, Inc.
Key Issues What business issues will be successfully addressed by directories? How can enterprises successfully address the integration of Active Directory and eDirectory? What roles will metadirectories and e-provisioning play in enterprises during the next five years?
Key Issues What business issues will be successfully addressed by directories? How can enterprises successfully address the integration of Active Directory and eDirectory? What roles will metadirectories and e-provisioning play in enterprises during the next five years?
The Ideal World: One Directory for Everything Voice Directory Extranet/Intranet Authentication White Pages Application Enabling Systems/User Management Certificate Enabling Legacy Connectivity Platform Authentication...
Voice Directory Extranet/Intranet Authentication White Pages Application Enabling Systems/User Management Certificate Enabling Legacy Connectivity Platform Authentication... The Real World: Multiple Directories!
Two Main Categories of Directories Extranet/IntranetNOS Buying Center: Rollout: ROI Argument: Scalability: Design Goal: Users: Business unit Months Application enabling, Business agility Millions of entries, Few servers Authenticate/Authorize, Personalize Customers, Partners, Employees, Contractors Central IS Years Infrastructure, Security, Application enabling Thousands of entries, Hundreds of servers Authenticate/Authorize, Resource management Employees, Contractors
The NOS Directory The Enterprise Directory The Intranet/Extranet Directory ? The Missing Link?
Key Issues What business issues will be successfully addressed by directories? How can enterprises successfully address the integration of Active Directory and eDirectory? What roles will metadirectories and e-provisioning play in enterprises during the next five years?
Directory Functionality Time 2003 Active Directory Extranet/Intranet Capabilities Directory functionality that is “good enough” for typical enterprise extranet requirements 2004 Windows 2000 Windows.NET Server Longhorn Active Directory as an Extranet/Intranet Directory
Oracle Internet DirectoryChallengersLeaders Microsoft Active Directory Ability to Execute Completeness of Vision Sun-iPlanet As of 1/02 Critical Path IBM Domino Novell eDirectory Siemens DirX IBM SecureWay Niche Players Visionaries DCE/CDS OpenLDAP Syntegra Aphelion CA eTrust Syntegra GDS Nexor Extranet/Intranet Directory Services Magic Quadrant
Number of Supported Users Time ,000 50, ,000 Mainstream (Type B) Active Directory deployments (estimate) Economic Slow Down Original (2000) growth forecast NT 4.0 Domain to AD Migration Active Directory as a NOS Directory
NDS Active Directory GroupWise eDirectory ZENworks DirXML iChain SSO Exchange 2000 IntelliMirror Certificates Passport App dev IIS Active Directory versus NDS? A Complex Question
(e)Provisioning Single Sign-On Extranet Access Management Directories Password Synchronization/Reset Access360 Business Layers Netegrity Securant Novell PassLogix RSA Security Waveset Courion M-Tech Blockade Novell Meta- directories iPlanet, Novell, Microsoft, Critical Path, Siemens BMC Oblix Directory Integration Strategies
Metadirectories and (e)Provisioning Single Sign-On Directories Password Synchronization/Reset Extranet Access Management (e)Provisioning Meta- directories
Key Issues What business issues will be successfully addressed by directories? How can enterprises successfully address the integration of Active Directory and eDirectory? What roles will metadirectories and e-provisioning play in enterprises during the next five years?
Generic text file Native OS directories (e.g., Unix and mainframe) Oracle, Microsoft SQL Server, DB2 native access or ODBC This is an example of a text file that is not meant to be read on the screen The second line is different than the first and the third line is different than the first two by some amount This is an example of a text file that is not meant to be read on the screen The second line is different than the first This is an example of a text file that is not meant to be read on the screen The second line is different than the first and the third line is different than the first two by some amount and the third line is different than the first two by some amount and some more This is an example of a text file that is not meant to be read on the screen The second line is different than the first and the third line is different than the first two by some amount This is an example of a text file that is not meant to be read on the screen Generic LDAP-enabled directories (e.g., Netscape) ERP (e.g., PeopleSoft and SAP) Active Directory NDS/eDirectory... Single point of administration Data accuracy and precedence Password synchronization Single sign-on Metadirectory Products
Niche Players Visionaries ChallengersLeaders Microsoft MMS Ability to Execute iPlanet Metadirectory As of 8/01 Critical Path InJoin Novell DirXML Siemens DirXmetahub Middleware Metamerge Syntegra V-Directories Radiant Logic MaXware Completeness of Vision Metadirectory Services Magic Quadrant
(e)Provisioning Provisioning is similar to metadirectory in that it provides (in most cases) multi-directional synchronization, however provisioning also provides: Workflow features to tie in other business processes (e.g., automated procurements, approvals, etc.) Security context mapping (e.g., knowing that a user of type "sales" belongs to specific NOS groups and has specific levels of access in key applications) Optionally synchronizing passwords between respositories
The advantages and disadvantages of a metadirectory solution PLUS the option to embed business logic Generic text file Native OS directories (e.g., Unix and mainframe) Oracle, Microsoft SQL Server, DB2 native access or ODBC This is an example of a text file that is not meant to be read on the screen The second line is different than the first and the third line is different than the first two by some amount This is an example of a text file that is not meant to be read on the screen The second line is different than the first This is an example of a text file that is not meant to be read on the screen The second line is different than the first and the third line is different than the first two by some amount and the third line is different than the first two by some amount and some more This is an example of a text file that is not meant to be read on the screen The second line is different than the first and the third line is different than the first two by some amount This is an example of a text file that is not meant to be read on the screen Generic LDAP directories ERP (e.g., PeopleSoft and SAP) Your Code Here! APIs Triggers SDKs File I/O Change logs Stored procs Custom or commercial middleware Active Directory NDS/eDirectory... The Do-It-Yourself Alternative
1Survey data sources and assess the needs of people, applications and network infrastructures. 2Rank all of the enterprise’s directories in terms of strategic importance. Look for the “80% solution.” 3Identify the information stored in these directories and categorize unique and overlapping information. 4Identify the authoritative sources of this information. 5Design a name space that uniquely identifies user objects in each directory and develop cross-references between directories as needed. 6 Define specific projects and identify related products. White pages? Human Resources integration? Windows 2000 deployment? 7-99 Define the business value!!! First Steps Toward a Multiple Directory Strategy
Tie to a new internal application (e.g., ) Tie to a new extranet application (e.g., CRM) Tie to a defined TCO reduction project (e.g., ZENworks) Agility for future mergers and acquisitions Agility to deploy future applications Facilitate cross-communications ( , white pages) Faster employee start time (hire) Reduce security exposure for exiting employees (fire) Support web services or portal initiatives Reduced administration (are you ready to cut employees?) Infrastructure upgrade Selling Directory Projects
Accept that a single directory is not achievable, and focus on the issues of directory management and synchronization Recognize that if you are deploying Windows servers, dealing with Active Directory is unavoidable Weigh the attraction of an “enterprise directory” strategy against the flexibility of an integrated metadirectory or provisioning solution Be prepared to show real business value to a metadirectory or provisioning solution Remember: Directory projects involve both politics and technology! Summary