Showing posts with label idm. Show all posts
Showing posts with label idm. Show all posts

Friday, May 02, 2008

A case for Identity Federation for the Enterprise

When it comes to identity management enterprises today tend to only care about user provisioning, compliance and (worst of all) single-sign-on.

Identity Federation - like Liberty - is usually not really considered. And I neglected it, too, since customers were not really interested in it, or asking for it.

However, there is a good use-case for federated identities across within enterprises... I choose to say "within" because the case I'm about to make is when the user should not see enterprise borders:

Consider an outsourced process - like HR in our case at Sun - where your employees have to access an application that is outsourced as well. People then have to sign on to computers that are not being operated by you (your IT).

Big deal... those application can easily access my directory (LDAP or AD)... so why should I need identity federation there?
And you might even trust those external application to securely access your directory this way.

But you don't want your users to enter their corporate userid and password at any remote site - even if you trust that company.

If you do, you open up big potential for fishing... By using federation you keep the input mask for your userids and password within your IT, operated by your staff, transported only over your network. There is no chance that the password can get intercepted... or at least the risk is not higher than within your own network.
That's the point.

Wednesday, November 28, 2007

Enterprise Identity Trends

I have been working with/in/for enterprise (!) identity management (IdM) for the past 4 years or so. What I noticed from recent developments and discussions with partners and customers is:
  1. The market is now moving from a vendors to consultants and integrators. They finally got it. And the enterprises as well. We are no longer discussing whether Sun or Novell or Oracle are better, and which to deploy, but customers now first try to identify what their organizational needs are and pick a tool afterwards.
  2. The focus is moving (right now) from pure user provisioning to a more full identity management including role management. See the recent acquisitions from Sun (Vaau) and Oracle (Bridgestream)
  3. This means that the tool market will become “ commoditized”:
    Customers can now (see bullet 1.) focus on the higher layers first, while having the confidence that later they will be able to implement that on any on the top tools (Sun, Novell, Oracle, ...).

Well, my 0.02€ at least.

(For the sake of full disclosure: I work for Sun Microsystems)

Tuesday, November 13, 2007

Sun to acquire Vaau

So, Sun decided to broaden their Identity portfolio by acquriring Vaau... finally we will see some decent role management capabilities in the Sun portfolio.
Actually, this is a must, after Oracle bought Bridgestream this summer...

If you are into corporate press-releases then you might want to endure this: Sun Microsystems Strengthens Market-Leading Identity Management Portfolio with Intent to Acquire Vaau

(In the interest of full disclosure: I am a Sun Microsystems employee)

Thursday, August 02, 2007

Burton interop report on user centric identity

Burton Group Identity Blog: Recapping the Catalyst user-centric interop:
The Burton Group hosted a User-Centric Identity Interop at the Catalyst Conference in San Francisco during the week of 23 - 29 June 2007; a public demo session was held on the evening of Wednesday 27 June to showcase the accomplishments of the participants in this event.

Read the whole story here.

Thursday, May 31, 2007

Planet Identity

Planet Identity: "Planet Identity is an aggregation of public weblogs related to Identity Management."

Wednesday, May 16, 2007

SAP wants to go Idenity Management

hear, hear, ... SAP likes to join the IDM vendor league by acquiring MaXware.

This is only interesting insofar as
  • SAP is a bit late to the game
  • they did not really acquire a player in the IDM space (as e.g. Sun did when they bought Waveset, and others).
  • If they still pursue their monolithic approach, then good luck with Identity Management, it just wont work that way...

Wednesday, March 28, 2007

What a non-event...

CXOtoday.com > News > Business > BEA, CA Ally for IAM: "BEA Systems, Inc. and CA, Inc. have announced a partnership for identity and access management (IAM) across the enterprise."

so what...