Jump to content

Recommended Posts

Posted (edited)
Just wondering what people are using to manage identities in your systems? if you do use a solution, Are you managing the entire lifecycle and using one "golden source" for all of your systems? if so who manages that "golden source"? Do you use an identity solution to provision those identities into other systems like access control/ catering systems and the like? Do you automate the deprovisioning of identities? Edited by HPlum78
Posted

So I would consider all of those things as part(s) of an identity and access lifecycle,

 

So a typical user (Identity) story would be something like this:-

 

New (identity) person added to the HR system (directory) - I guess that no one is using their AD as the Golden Source for identities.

That (identity) person is then provisioned in AD (manually/ automated)

The (identity) person is then added to any number of other systems (directories) these could include Access Control system/ print systems, finance systems, Office 365, Google Apps...... (manual / automated provisioning)

Identity is consumed by the user, this will include access to the above systems and resources protected by the identity (Could be via SSO (ADFS/ Shib) or require some use of 2FA.

 

I suppose what I am getting at is what if any thing are people doing about managing all of these desperate systems (directories) is there a lot of manual process or a number of automation scripts being run to create identities in these? how is everyone dealing with changes? what about deprovisioning?

Posted

Our story is, pupil/staff get added to MIS

Salamander runs at night to create user accounts

Azure AD Connect syncs up to O365

Most things run off O365 now. If it is onsite it is tied in with AD.

There are a few standalone systems that don't interact with AD or O365 but we are working to replace them. The biggest bug bear is online systems that don't talk to anything and expect you manage them in isolation (I'm looking at you OUP and GL)

Posted

Not much response to this, I guess that people use Salamander/ Scripts to provision accounts.... I just wanted to try and understand if anyone has looked at using MIM (FIM) to manage the Joiners/ Movers /Leavers processes?

 

It's the same sync engine used for Azure AD Connect!

Posted

I'd like to link a few systems there are just some I don't feel comfortable touching.

HR is done by HR and its archaic not going there with any scripts.

Door fobs requite someone programming the fob anyway so still manual. But I'd like to automate the deactivation of them if I could. Again not one easy to link with.

 

The golden system so to speak would be MIS / AD.

Staff are created with a script so they are consistent, but not automatic. Its a script I run and fill in the details HR give me.

Students are automatic with MIS to AD

AD goes to Google

MIS goes to clever

MIS also goes to kitchens / busing software

A few stubborn sites require I upload a csv direct to them.

When a student leaves their account is disabled automatically.

 

Every summer I create / share a spreadsheet with HR tracking any new and leaving staff.

Give HR a list of staff accounts to verify.

On the rare occasion staff leave mid year I'm usually notified and asked to remove their access.

Posted
I'd like to link a few systems there are just some I don't feel comfortable touching.

HR is done by HR and its archaic not going there with any scripts.

Door fobs requite someone programming the fob anyway so still manual. But I'd like to automate the deactivation of them if I could. Again not one easy to link with.

 

The golden system so to speak would be MIS / AD.

Staff are created with a script so they are consistent, but not automatic. Its a script I run and fill in the details HR give me.

Students are automatic with MIS to AD

AD goes to Google

MIS goes to clever

MIS also goes to kitchens / busing software

A few stubborn sites require I upload a csv direct to them.

When a student leaves their account is disabled automatically.

 

Every summer I create / share a spreadsheet with HR tracking any new and leaving staff.

Give HR a list of staff accounts to verify.

On the rare occasion staff leave mid year I'm usually notified and asked to remove their access.

 

Can your HR system automatically output to folder? You could then script from that output, into AD? Alternatively do staff get entered into the MIS and by whom? If HR do that as well I would use something like Salamander to update AD, that way HR just do their thing and your systems get updated.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...