HPlum78 Posted October 13, 2017 Posted October 13, 2017 (edited) Just wondering what people are using to manage identities in your systems? if you do use a solution, Are you managing the entire lifecycle and using one "golden source" for all of your systems? if so who manages that "golden source"? Do you use an identity solution to provision those identities into other systems like access control/ catering systems and the like? Do you automate the deprovisioning of identities? Edited October 13, 2017 by HPlum78
TechMonkey Posted October 13, 2017 Posted October 13, 2017 Do you mean a password manager, Active Directory, 2FA or Single Sign-on service?
HPlum78 Posted October 13, 2017 Author Posted October 13, 2017 So I would consider all of those things as part(s) of an identity and access lifecycle, So a typical user (Identity) story would be something like this:- New (identity) person added to the HR system (directory) - I guess that no one is using their AD as the Golden Source for identities. That (identity) person is then provisioned in AD (manually/ automated) The (identity) person is then added to any number of other systems (directories) these could include Access Control system/ print systems, finance systems, Office 365, Google Apps...... (manual / automated provisioning) Identity is consumed by the user, this will include access to the above systems and resources protected by the identity (Could be via SSO (ADFS/ Shib) or require some use of 2FA. I suppose what I am getting at is what if any thing are people doing about managing all of these desperate systems (directories) is there a lot of manual process or a number of automation scripts being run to create identities in these? how is everyone dealing with changes? what about deprovisioning?
TechMonkey Posted October 13, 2017 Posted October 13, 2017 Our story is, pupil/staff get added to MIS Salamander runs at night to create user accounts Azure AD Connect syncs up to O365 Most things run off O365 now. If it is onsite it is tied in with AD. There are a few standalone systems that don't interact with AD or O365 but we are working to replace them. The biggest bug bear is online systems that don't talk to anything and expect you manage them in isolation (I'm looking at you OUP and GL)
HPlum78 Posted October 13, 2017 Author Posted October 13, 2017 Not much response to this, I guess that people use Salamander/ Scripts to provision accounts.... I just wanted to try and understand if anyone has looked at using MIM (FIM) to manage the Joiners/ Movers /Leavers processes? It's the same sync engine used for Azure AD Connect!
ADMaster Posted October 13, 2017 Posted October 13, 2017 I'd like to link a few systems there are just some I don't feel comfortable touching. HR is done by HR and its archaic not going there with any scripts. Door fobs requite someone programming the fob anyway so still manual. But I'd like to automate the deactivation of them if I could. Again not one easy to link with. The golden system so to speak would be MIS / AD. Staff are created with a script so they are consistent, but not automatic. Its a script I run and fill in the details HR give me. Students are automatic with MIS to AD AD goes to Google MIS goes to clever MIS also goes to kitchens / busing software A few stubborn sites require I upload a csv direct to them. When a student leaves their account is disabled automatically. Every summer I create / share a spreadsheet with HR tracking any new and leaving staff. Give HR a list of staff accounts to verify. On the rare occasion staff leave mid year I'm usually notified and asked to remove their access.
TechMonkey Posted October 19, 2017 Posted October 19, 2017 I'd like to link a few systems there are just some I don't feel comfortable touching. HR is done by HR and its archaic not going there with any scripts. Door fobs requite someone programming the fob anyway so still manual. But I'd like to automate the deactivation of them if I could. Again not one easy to link with. The golden system so to speak would be MIS / AD. Staff are created with a script so they are consistent, but not automatic. Its a script I run and fill in the details HR give me. Students are automatic with MIS to AD AD goes to Google MIS goes to clever MIS also goes to kitchens / busing software A few stubborn sites require I upload a csv direct to them. When a student leaves their account is disabled automatically. Every summer I create / share a spreadsheet with HR tracking any new and leaving staff. Give HR a list of staff accounts to verify. On the rare occasion staff leave mid year I'm usually notified and asked to remove their access. Can your HR system automatically output to folder? You could then script from that output, into AD? Alternatively do staff get entered into the MIS and by whom? If HR do that as well I would use something like Salamander to update AD, that way HR just do their thing and your systems get updated.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now