Oracle has published an interesting article on the changing IDM Trends. Its a good read.
Showing posts with label Identity Governanace. Show all posts
Showing posts with label Identity Governanace. Show all posts
January 30, 2013
January 21, 2013
The Amazing Security Race
Have you been watching OTN for these interesting stuff, recently? Some of the links are here. Rest are for you to search, view and have fun.
http://medianetwork.oracle.com/video/player/507044355001
http://medianetwork.oracle.com/video/player/507042060001
http://medianetwork.oracle.com/video/player/507044355001
http://medianetwork.oracle.com/video/player/507042060001
October 26, 2012
Certification/Attestation on an iPad
Some innovations are smart. One of Oracle's partner did something really smarter.
For those who do not understand what Identity Governance or Certifications or Attestations or Access Reviews, it is a process of ensuring that every individual is verified to check if he/she has the right accesses to the systems according to his job role and also to check and remediate unnecessary/toxic ones.
Oracle has a cool product to help Organizations solve this issue/problem of Certification. Its web based. Now a partner brought this to an iPad. I wouldn't like to talk anymore but let you watch the video. It would be very interesting for you if you already know a little bit about Oracle Identity Analytics.
September 10, 2010
Sailpoint IdentityIQ: Revoke a Policy Violation from Certification
If you had Policy Violations recorded in IdentityIQ and have included them in a Certification then normally it would be displayed as below.
You have only two options. Approve or Delegate. A general option of REVOKE is not provided for a policy violation.
However, there is a option to revoke the same if the certifier wishes to. Of course this is not told and not given. But its a simple change :-)
Open the Policy object and you would see something like below in the first line after XML declaration.
Notice the certificationActions tag?
Modify the same to look as below shown.
Once you add the Remediated word to the tag, your certification automatically shows up the revoke button. Here's a screen shot of how it looks.
Hope this helps.
Categories:
Identity Governanace,
SailPoint,
SailPoint Tips,
Tech
September 9, 2010
SP Identity IQ: Certification not updated to show revocations done
Okay! I am trying to be pretty descriptive here.
Suppose you have created a certification in Sailpoint's Identity IQ.
An email is sent to the administrator to revoke the entitlement/account.
Administrator, being a good employee has done the revocation right away.
Problem:
Solution:
In every Certification configuration there is a parameter named nextRevocationsScantime
This has a default setting which is inherited from a SystemConfiguration setting.
nextRevocationsScantime attribute is created along with remediationsKickedOff="2"
Later in the cert you will not see nextRevocationsScantime. Rather you would see this. remediationsCompleted="1" remediationsKickedOff="1"
Hope this helps to few consultants.
Suppose you have created a certification in Sailpoint's Identity IQ.
The Certification Owner has revoked a user and saved the certification. Then the certification header would be something like this.
An email is sent to the administrator to revoke the entitlement/account.
Administrator, being a good employee has done the revocation right away.
A scheduled Account Aggregation, in the next few hours, get kicked off and brings in the new data regarding the revocation.
An Identity refresh scheduled for the same night, updates the entitlements for the users.Problem:
You still do not notice the update in the Certification header. It still shows a list of items, which were completed, as due.
Solution:
In every Certification configuration there is a parameter named nextRevocationsScantime
This has a default setting which is inherited from a SystemConfiguration setting.
remediationScanInterval set to 86400000 milliseconds
nextRevocationsScantime attribute is created along with remediationsKickedOff="2"
The above attribute is created, once you revoke someone and save the cert.
Later when you remove the entitlements in database and do an account aggregation and identity refresh; it shall not directly reflect in your cert. Once the nextRevocationsScantime is complete and PERFORM MAINTENANCE TASK runs then it scans and completes the process.
Later when you remove the entitlements in database and do an account aggregation and identity refresh; it shall not directly reflect in your cert. Once the nextRevocationsScantime is complete and PERFORM MAINTENANCE TASK runs then it scans and completes the process.
Later in the cert you will not see nextRevocationsScantime. Rather you would see this. remediationsCompleted="1" remediationsKickedOff="1"
Hope this helps to few consultants.
Categories:
Identity Governanace,
SailPoint,
SailPoint Tips,
Tech
September 6, 2010
Attention Sun IdM Customers - "What's Your "Plan B"?
This is what Sailpoint says about SUN Identity Manager, its customers and the solutions they can offer to these customers. Interesting read.
It's always sad to see SUN Technologies dying.
Categories:
Identity Governanace,
Identity Management,
SailPoint,
SUN
September 1, 2010
epoch conversion tool
What is epoch time?
Short description from Wikipedia:
Unix time, or POSIX time, is a system for describing points in time, defined as the number of seconds elapsed since midnight proleptic Coordinated Universal Time (UTC) of January 1, 1970, not counting leap seconds.
Where do you find with respect to IAM parlance?
I have found that Sailpoint's IdentityIQ uses this convention for all dates. examples are create date, expiration date etc.
So if you want to understand what are the exact dates?
Categories:
Identity Governanace,
Identity Management,
SailPoint,
Tech
August 24, 2010
An important tip for Sailpoint implementors - Requests Page
I was recently working on integrating Remedy with Sailpoint's IdentityIQ 5.0. Other than getting a weird error in the log I was unable to trace the root cause. One of my colleague tried having a look and suggested I should see in https://localhost:8080/identityiq/monitor/requests/requests.jsf. I could actually see all the items that are queued up there. Here is a screen shot.
It is suggested to have a look at this page when you are trying to debug something and unable to go ahead from the usual check points.
It is suggested to have a look at this page when you are trying to debug something and unable to go ahead from the usual check points.
Categories:
Identity Governanace,
SailPoint,
Tech
March 26, 2010
Sailpoint's IIQ 5.0
Finally, Sailpoint is coming up with its fully geared up Entitlement management software, Identity IQ 5.0. It is going to be released next week. It boasts of many exciting new features like Provisioning, Access Request Manager integration etc.
Need to wait and watch how the product would be after this release. One quick doubt (may be too early) I have is, are they trying to bring new Provisioning product along? Then why (as there are already a lot of products available and deployed)?
I have worked on versions from 2.5 to 4.0
Categories:
Identity Governanace,
SailPoint
May 29, 2009
Identity Governance - Buyer's Guide
Sailpoint has recently released the Identity Governance Buyer's guide. Try and give a read ...
Categories:
Identity Governanace,
SailPoint
Subscribe to:
Posts (Atom)