Oracle Identity Manager (OIM) as Enterprise Security Platform - A Real World Implementation Approach for Success



Similar documents
Oracle IDM Integration with E-Business Suite & Middleware Technologies

Oracle Fusion Middleware 11g Release 1 IDM Suite

Oracle E-Business Suite Single Sign On Using Oracle Access Manager

Enabling Single Sign-On for Oracle Applications Oracle Applications Users Group PAGE 1

Oracle Identity Governance - Complete Identity Lifecycle Management

Oracle Identity Manager, Oracle Internet Directory

Oracle E-Business Suite (R12) Integration with OID/OAM 11g

The Unique Alternative to the Big Four. Identity and Access Management

Oracle Privileged Account Manager 11gR2. Karsten Müller-Corbach

Centralized Oracle Database Authentication and Authorization in a Directory

Identity Management and Single Sign-On

Enterprise Identity Management Reference Architecture

WebLogic Server System Administration Top Ten Fundamentals Concepts Session ID# 11579

Key New Capabilities Complete, Open, Integrated. Oracle Identity Analytics 11g: Identity Intelligence and Governance

Integrating OID/SSO with E- Business Suite and Third-Party SSO Solutions. Presented by Paul Jackson (Norman Leach)

Banner, BEIS and Active Directory Identity Integration

Directory Integration with Okta. An Architectural Overview. Okta Inc. 301 Brannan Street San Francisco, CA

Manage Oracle Database Users and Roles Centrally in Active Directory or Sun Directory. Overview August 2008

USER GUIDE. Lightweight Directory Access Protocol (LDAP) Schoolwires Centricity

Directory Integration with Okta. An Architectural Overview. Okta White paper. Okta Inc. 301 Brannan Street, Suite 300 San Francisco CA, 94107

Oracle Platform Security Services & Authorization Policy Manager. Vinay Shukla July 2010

Government of Canada Directory Services Architecture. Presentation to the Architecture Framework Advisory Committee November 4, 2013

IDENTITY MANAGEMENT AND WEB SECURITY. A Customer s Pragmatic Approach

How to leverage SAP NetWeaver Identity Management and SAP Access Control combined solutions

Integrating Biometrics into the Database and Application Server Infrastructure. Shirley Ann Stern Principal Product Manager Oracle Corporation

Integrating OID with Active Directory and WNA

OracleAS Identity Management Solving Real World Problems

Oracle Identity Management: Integration with Windows. An Oracle White Paper December. 2004

State of Vermont Guidance on the Re-use of Software Products, Shared Components, and Hosted Platform Environment Capabilities

An Oracle White Paper January Oracle Identity Manager Business Overview

Protected Trust Directory Sync Guide

Getting Started with AD/LDAP SSO

Sun and Oracle: Joining Forces in Identity Management

Kenneth Hee Director, Business Development Security & Identity Management. Oracle Identity Management 11g R2 Securing The New Digital Experience

Install and Configure Fusion Applications - DBA perspective. Masthan Babu Phani Kottapalli AST Corporation August 14, 2014

Identity Management Basics. OWASP May 9, The OWASP Foundation. Derek Browne, CISSP, ISSAP

Gabriel Magariño. Software Engineer. Overview Revisited

Introduction to Identity and Access Management for the engineers. Radovan Semančík April 2014

CA Single Sign-On r12.x (CA SiteMinder) Implementation Proven Professional Exam

Oracle Business Intelligence Enterprise Edition LDAP-Security Administration. White Paper by Shivaji Sekaramantri November 2008

Federated single sign-on (SSO) and identity management. Secure mobile access. Social identity integration. Automated user provisioning.

Oracle Identity Management 11gR2 Sizing and Capacity Planning

Mitigating Information Security Risks of Cloud Computin

A Technical Roadmap for Oracle Fusion Middleware, E-Business Suite Release 12 and Oracle Fusion Applications

Entitlements Access Management for Software Developers

Oracle Application Express and Oracle E-Business Suite. Love and Mariage!

Identity Governance Evolution

Oracle Identity Management Securing The New Digital Experience

MICROSOFT HIGHER EDUCATION CUSTOMER SOLUTION

Oracle Enterprise Single Sign-on Technical Guide An Oracle White Paper June 2009

identity management in Linux and UNIX environments

How To Get A Single Sign On (Sso)

USING FEDERATED AUTHENTICATION WITH M-FILES

Vermont Enterprise Architecture Framework (VEAF) Identity & Access Management (IAM) Abridged Strategy Level 0

IBM SPSS Collaboration and Deployment Services Version 6 Release 0. Single Sign-On Services Developer's Guide

Highmark Unifies Identity Data With Oracle Virtual Directory. An Oracle White Paper January 2009

The Top 3 Identity Management Considerations When Implementing Google Apps for the Enterprise

Oracle Identity Management Concepts and Architecture. An Oracle White Paper December 2003

<Insert Picture Here> Oracle Identity And Access Management

Open Source Identity Management

Assumptions. It is assumed that:

A SECURITY MODEL THAT WORKS FOR YOU!

OBIEE 11g Security it s as easy as 1-2-3!

Only LDAP-synchronized users can access SAML SSO-enabled web applications. Local end users and applications users cannot access them.

Single Sign On. SSO & ID Management for Web and Mobile Applications

Configuring and Using the TMM with LDAP / Active Directory

midpoint Overview Radovan Semančík December 2015

Identity and Access Management Integration with PowerBroker. Providing Complete Visibility and Auditing of Identities

The School Board of Palm Beach

STATE OF NEW YORK IT Transformation. Request For Information (RFI) Enterprise Identity and Access Management Consolidated Questions and Responses

Copyright

MICROSOFT HIGHER SOLUTION

Extending Identity and Access Management

Identity Management with midpoint. Radovan Semančík FOSDEM, January 2016

IBM Tivoli Identity Manager

State of Tennessee Sourcing Event #9160 ServiceNow Preliminary Statement of Work (SOW)

Speeding Office 365 Implementation Using Identity-as-a-Service

Egnyte Single Sign-On (SSO) Configuration for Active Directory Federation Services (ADFS)

Documentation. CloudAnywhere. Page 1

Course 50382A: Implementing Forefront Identity Manager 2010 OVERVIEW

Total Cloud Control with Oracle Enterprise Manager 12c. Kevin Patterson, Principal Sales Consultant, Enterprise Manager Oracle

Microsoft vs. Red Hat. A Comparison of PKI Vendors

Cloud Standards. Arlindo Dias IT Architect IBM Global Technology Services CLOSER 2102

HP Software as a Service. Federated SSO Guide

Agenda. How to configure

IQS Identity and Access Management

Oracle Directory Services Integration with Database Enterprise User Security O R A C L E W H I T E P A P E R F E B R U A R Y

Strategic Identity Management for Industrial Control Systems

Foundation ACTIVE DIRECTORY AND MICROSOFT EXCHANGE PROVISIONING FOR HEALTHCARE PROVIDERS HEALTHCARE: A UNIQUELY COMPLEX ENVIRONMENT

Single Sign-on (SSO) technologies for the Domino Web Server

Oracle Fusion Applications Security Leveraging Oracle Identity Management

Oracle Data Integrator 11g New Features & OBIEE Integration. Presented by: Arun K. Chaturvedi Business Intelligence Consultant/Architect

White Paper. What is an Identity Provider, and Why Should My Organization Become One?

Aurora Hosted Services Hosted AD, Identity Management & ADFS

Novell to Microsoft Conversion: Identity Management Design & Plan

JD Edwards Security Best Practices

INTEGRATION GUIDE. IDENTIKEY Federation Server for Juniper SSL-VPN

Windows 7 Hula POS Server Installation Guide

Creating a Single Sign on Web Portal using Azure. Robert Crane Office 365

Transcription:

Oracle Identity Manager (OIM) as Enterprise Security Platform - A Real World Implementation Approach for Success Manvendra Kumar AST Corporation, IL Scott Brinker College of American Pathologist, IL August 17, 2012

Agenda Oracle Identity Management Components Case Study: Oracle Security Product Implementation at College of American Pathologist (CAP) Business Challenges Architecture Implementation Strategy Implementation Challenges Recommended Approach for Oracle Security Product Implementation Questions 2

WHAT IS ENTERPRISE SECURITY? 3

Oracle Identity Management Components Enables enterprise to Manage data about users, devices and services in a accurate and secure manner Configure and manage identity data Control access to applications and resources Synchronize and combine data from different resources Share data across domains 4

Directory Services (OID/OVD) Oracle Internet Directory (OID) is a specialized database that stores and retrieves collections of identity and security information about objects (can be user, resource, etc.) OID is built on Oracle Database and uses LDAP (Lightweight Directory Access Protocol) interface for data retrieval Oracle Virtual Directory (OVD) is an LDAP service that provides a single, abstracted view of enterprise directory servers and databases from a variety of vendors OVD addresses the challenge of lack of single source for identity data within enterprise 5

Oracle Identity Manager (OIM) Identity Provisioning Automates the administration of user access privileges across a company's resources from initial on-boarding to final de-provisioning of an identity Who, What, When & Why Rules & Access Policies Integration framework Identity Administration Delegated Administration Self-Registration & Self- Service User & Group Management 6

Oracle Access Manager (OAM) Replacement for OSSO solution offered by Oracle for EBS Suite Provides Single Sign-On (SSO) for Web Applications 11g enables Microsoft Internet Explorer users to automatically authenticate to their SSO Web applications using desktop credentials Enables application protection using Authentication & Authorization 7

Other Oracle Identity Management Components OIF OES OAAM OIA etc... 8

Oracle Identity Manager (OIM): A Real World Implementation Approach for Success CASE STUDY: ORACLE SECURITY PRODUCT IMPLEMENTATION AT COLLEGE OF AMERICAN PATHOLOGIST (CAP) 9

About CAP The College of American Pathologists (CAP) is the leading non-profit organization of board-certified pathologists, serving patients, pathologists, and the public CAP has about 18,000 members and 600 staff members CAP has a total of 4 legacy environments and 5 oracle environments which contains a variety of oracle applications from EBS, OBIEE, Hyperion, WCS, UCM and SOA 10

Business Challenges At CAP Multiple Identity Repositories Tactical OID RedHat LDAP Microsoft Active Directory (AD) Application Specific local Identity Stores End User having multiple identities across enterprise License Management & Limitations Supporting different technologies Manual User on-boarding, provisioning and de-provisioning process causing Loss of productivity Incomplete and inconsistent access control Lack of single source of truth for user identity Ceridian HR System for Staff and Temps Tactical OID & AD for Staff, Consultants, Contractors and Temps RedHat LDAP & TCA for Staff, External Users, Members, Inspectors Duplication of Identities across enterprise for users with multiple roles 11

Solution Identified to address Business Challenges Consolidation of multiple identity repositories Have single identity for every user across enterprise (one set of user id & password across all application) Automation around User On-boarding, provisioning and de-provisioning processes Enable single sign-on functionality across critical applications 12

Physical Architecture 13

Logical Architecture: User Provisioning 14

Logical Architecture: User Access Management (SSO) 15

Implementation Strategy Phased Implementation Approach Phase 1 Planning & Discovery Phase 2 Implementing Security Infrastructure, User provisioning, Single Sign On and Identity Federation Phase 3 Role based provisioning & Delegated Administration Creating Application Software Version Matrix Identifying Applications (Oracle & Non-Oracle) for Security Integration Engagement Plan For Oracle Support Escalation Team For Interfacing Application SMEs For Interfacing Application Test Resources Detailed Test Plan Communication Plan for different group of users 16

Application Software Version Matrix 17

Implementation Challenges Technical Challenge Timely response and patch delivery from Oracle for issues like o o o o o LDAP SYNC do not work as stated Trusted Source Reconciliation connector fails when user id is blank OIM SPML Web Service operations not supported Undesired error logs during execution of configuration and install scripts Event Handler limitations for Trusted Source Reconciliation Multiple integration paths o o o o Connectors Adaptors SPML Services Custom Web Services for Legacy application Keep Staging Environments up to date with all patches Not all Oracle Applications (to be integrated) configured the same way Identifying source of truth for provisioning 18

Implementation Challenges (cont.) Requirement Challenges Identifying all potential interfacing applications (oracle and non-oracle) Identifying target applications for automated provisioning Identifying applications as a valid candidate for Single Sign-On Engagement Challenges Identifying technical SMEs for every identified application Identifying Testing resources for every identified application Ensuring SMEs and Testing resources availability for the project Follow-up with SMEs and Testing resources 19

Recommendations Oracle Security Solution is for Enterprise and not a point solution (Ensure Value Preposition) Phased Approach for Oracle Identity Management Implementation can avoid failure and cost overrun Selecting correct Software Version can avoid compatibility issues (11.1.1.5 & 11.1.1.6 are certified versions available for use) Having a good escalation path to address Oracle Support issues can help in keeping the project on schedule Having an engagement strategy plan can help in addressing unknowns during early phase of implementation cycle Defining Testing Scope can avoid duplicate testing effort as well as ensure completeness Utilizing ticketing system for application integration, if available 20

Questions & Answers 21

Contact Information Presenter s Name: Manvendra Kumar mkumar@astcorporation.com www.astcorporation.com Scott Brinker sbrinke@cap.org www.cap.org 22