Mt26 identity management as a service

28
Dell World 2014 Identity and Access Management MT26 Identity management as a service Jackson Shaw, Senior Director of Product Management, November, 2014 Dell World 2014

description

Sure, you would love to have an identity management solution for provisioning, but those frameworks are just too expensive and difficult to implement. If you’ve ever had this conversation at your organization, then this is for you.  Learn about Dell One Identity as a Service and how this newly available solution can give your organization the advantages of the big guys at a fraction of the cost and ramp up time.

Transcript of Mt26 identity management as a service

Page 1: Mt26 identity management as a service

1 Dell World 2014

Identity and Access Management

MT26 Identity management as a service

Jackson Shaw, Senior Director of Product Management, November, 2014

Dell World 2014

Page 2: Mt26 identity management as a service

2 Dell World 2014

IAM challenges in the real world

• For many growing organizations, access control needs have grown beyond their staff’s ability to efficiently and securely enforce them

• More applications are moving to the cloud

• With the “jack-of-all-trades” approach to IAM, efficiency, security and compliance inevitably suffer. The smaller the IT staff, the more broadly their skill set is required to spread.

• The further the line-of-business moves away from provisioning, governance and access management, the more likely it is that their “real world” of IAM is a mess.

• The skills, time, and tools needed to execute enterprise provisioning and governance are not there

• The possibility of a big capital investment to address these problems isn’t realistic

Page 3: Mt26 identity management as a service

Dell World 2014

When does a SaaS offering make sense?

Page 4: Mt26 identity management as a service

4 Dell World 2014

Dell One Identity as a Service

• Addresses your most pressing security, provisioning/de-provisioning, access control, governance and compliance needs as an operational expense not a capital investment.

• Delivered through a partnership with Simeio, an end-to-end IAM services and solutions provider, leveraging Simeio’s Identity as a Service expertise and DirectAxs cloud computing platform

• Technology • Sales • Marketing • Branding

• Hosting • Integration/customization • Support

Page 5: Mt26 identity management as a service

5 Dell World 2014

Three modules available

Dell One Identity as a Service

For Provisioning For Governance For Access Control

• Enterprise provisioning

• Access request portal

• Business-driven access decisions

• Unified workflow and policy

• Self-service password resets

• Reporting

• Attestation/recertification

• Separation of duties

• Role management

• Role-based access control

• Compliance reporting

• Web SSO

• Just-in-time cloud provisioning

• Access control for web apps

• Self-service password resets

• Reporting on WAM rights and activity

Page 6: Mt26 identity management as a service

6 Dell World 2014

How it works

Page 7: Mt26 identity management as a service

7 Dell World 2014

Provisioning use cases Use Cases Description

Identity Origination

External user self registration Integration with HR/Authoritative source User created in IAM solution

Self Service & Password Management

• User sets password & challenge response questions • User forgets password and is able to reset password to all

provisioned applications • Help desk is able to reset password for user based on

shared secret

Access Request Catalogue Application access request process 2 Level approval Workflow

Provisioning & Deprovisioning

Creates, modifies and deletes accounts on applications and infrastructure following the completion of workflow

Supports on-premises and SAAS applications Provisions based on roles defined by customer

Reporting Out of the box “who has access to what reports” Custom reports based on requirements

Page 8: Mt26 identity management as a service

8 Dell World 2014

Provisioning and attestation/recertification

Page 9: Mt26 identity management as a service

9 Dell World 2014

Attestation

Page 10: Mt26 identity management as a service

10 Dell World 2014

Self Service Request

Page 11: Mt26 identity management as a service

11 Dell World 2014

Self-service password reset

Page 12: Mt26 identity management as a service

12 Dell World 2014

Governance use cases Use Cases Description

Identity Seeding Integration with HR/Authoritative source User created in IAM solution

Application & Entitlement Synch

• Integration with applications through connector or flat file synch • Load account and entitlements and correlate to users • Define risk level for entitlements

Risk Based Access Certification

User – Manager access certification Risk based view Ability for reviewer to certify/revoke access Mark accounts for termination

Segregation of Duties Define segregation of duty policies Enforce SOD compliant provisioning Run detective SOD checks

Role Mining Role mining using top down and bottom up attributes

Reporting Out of the box “who has access to what reports” Custom reports based on requirements

Page 13: Mt26 identity management as a service

13 Dell World 2014

Organization Dashboard

Page 14: Mt26 identity management as a service

14 Dell World 2014

IT Shop Dashboard

Page 15: Mt26 identity management as a service

15 Dell World 2014

Identity Audit

Page 16: Mt26 identity management as a service

16 Dell World 2014

Auditing

Page 17: Mt26 identity management as a service

17 Dell World 2014

Access control use cases Use Cases Description

Identity Seeding Integration with HR/Authoritative source User created in IAM solution

AD/LDAP Integration • Integration with On Premise Authentication Directory

Self Service & Password Management

• User sets password & challenge response questions • User forgets password and is able to reset password to all

provisioned applications • Help desk is able to reset password for user based on shared secret

Web Single Sign On & Federation

Integrations with On Premise and SAAS Applications for providing Single Sign On

Support for SAML, Form Fill, LDAP, Kerberos Authentication mechanisms

Reporting Out of the box “who has access to what reports” Out of the box “Who accessed what reports” Custom reports based on requirements

Page 18: Mt26 identity management as a service

18 Dell World 2014

Web single sign-on, federation and access control

Page 19: Mt26 identity management as a service

19 Dell World 2014

Create new application for Web SSO

Page 20: Mt26 identity management as a service

Dell World 2014

Benefits of a SaaS delivery approach

Page 21: Mt26 identity management as a service

21 Dell World 2014

Why Identity as a Service (SaaS) make sense

• Operational vs. capital expenditures • With the subscription model for SaaS, the payment for IAM services moves from a capital

expenditure to an operational expense. Approvals and accounting for operational spending is often faster and smoother than capital investments.

• Solution management and maintenance • No need for an organization to manage on-premises software. Critical tasks such as software

patches, updates, and more fall to the service provider, not your IT team.

• Staff expertise • Burden on IT staff to learn and become experts on new software is dramatically reduced. In

fact, with IAMaaS, IT can be entirely removed from some tasks, such as provisioning, access management, and governance.

• Near-immediate deployment • Most SaaS options can be deployed quickly, delivering value in a fraction of the time of their

on-premises counterparts

Page 22: Mt26 identity management as a service

22 Dell World 2014

Why chose Dell One Identity as a Service? • Built to help organizations move from the tactical to the

strategic and agility-enabling ideal of governance

• Place visibility and control required of IAM in the hands of those that know “why” things should happen (line-of-business personnel) not simply those that know “how” to make them happen (IT)

• Designed with simplicity in mind. Modules are simple to deploy and use, but also decrease the overall complexity

• Modular and integrated, so you can start where needed and build from there. There’s no need for a heavy investment in an underlying technology framework, or extensive customization to make solutions work together

Page 23: Mt26 identity management as a service

23 Dell World 2014

Validation • By the end of 2017, 20% of IAM purchases will use the IDaaS delivery model, up from less than 10%

in 2014.

• Gartner, “Magic Quadrant for IDaaS,” June 2, 2014, Gregg Kreizman

• The average user must access 27 different applications to do his or her job, and has an average of six enterprise-issued passwords. The same survey concluded that, on average, it takes more than a day and a half to provision a new user, and more than half a day to de-provision a user.

• Aberdeen Group

• “We recognize Dell’s leadership when it comes to delivering a comprehensive IAM solution, and we are pleased to partner with an industry leader to offer a full-featured Identity as a Service solution to organizations that typically struggle to address IAM needs. The Simeio Business-Ready IAM Cloud delivered via the industry's first and only Identity Intelligence Center, provides our clients with a higher level of security and reliability.”

• Hemen Vimadalal, Simeio Solutions, CEO

Page 24: Mt26 identity management as a service

Dell World 2014

Thank you.

Page 25: Mt26 identity management as a service

25 Dell World 2014

Provisioning module

Page 26: Mt26 identity management as a service

26 Dell World 2014

Governance module

Page 27: Mt26 identity management as a service

27 Dell World 2014

Access control module

DEFENDER

DELL INTERCEPTOR

Primary

ON PREMISE ENTERPRISE

APPLICATIONS

ACTIVE DIRECTORY

Oracle

EBS

MAINFRAME

SAP

DB NODE 1 DB NODE 2

DELL

INTERCEPTOR

Disaster Recovery

Customer Data Centre

SECURED VPN TUNNELS

Cloud

SAAS

APPS

SAM

L

DELL IDaaS

ACCESS CONTROL

SERVICE

CAM PM

DATABASE

CLUSTER

(Load

Balancer)

Page 28: Mt26 identity management as a service

Want to learn more about Dell’s identity protection solutions?

Learn more via email. Start here.

Sign me up!