As usual, events here at TechEd have caught up with me and I missed a post. Sorry, folks!
This does not mean that there has been a lack of activity here at TechEd. Yesterday, I attended an excellent hands on workshop based on Context Based provisioning. Any organization that is looking into SAP IDM for the purpose of managing SAP Roles over multiple locations or positions needs to look into Context Based provisioning. I think one can make an excellent comparison between IDM contexts and the Derived Role concept within SAP. I'll have to write some more on that later, either here or on the SCN Blog. I've also come up with some other interesting ideas for Contexts which I will be working on over the next few weeks. Hopefully, I'll have something to share soon.
There were also a number of good Q&A sessions where users could go one-on-one with some of the SAP IDM experts that came over from SAP Labs in Trondheim, Norway. For those that don't know, NetWeaver IDM was born as MaXware Identity Server in Trondheim back in the 1990s and core development still happens there to this day. Concepts such as Assignments, Approvals and Virtual Directory Server were covered.
Today I was able to attend a session on the use of the Provisioning Framework. Not too much new there, but it was good to hear that SAP is committed to the Framework and feels that IDM is the best way to provision users to SAP systems. During the presentation, the following general IDM points were brought up that I would like to comment on:
Users should consider IDM over CUP if connections to external applications are required (e.g., Microsoft Active Directory)
IDM should be used over other provisioning methodologies for Audit and compliance reasons
Do not think of SAP or non-SAP roles, privileges, provisioning etc., it is all Enterprise provisioning
I'll have a wrap of of TechEd tomorrow with some closing thoughts.
Showing posts with label CUA. Show all posts
Showing posts with label CUA. Show all posts
Thursday, October 18, 2012
Tuesday, February 22, 2011
Strategic IDM
Interesting post on SAP's IDM Blog. Basically. the author is stating that if you want to plan your SAP implementation in a strategic manner, you must use IDM and not CUA (Central User Administration). This is a nice follow up to SCI104 from TechEd, which I reported about as well.
Nice to see that SAP is starting to get a little more aggressive here. If you are a SAP Shop and rely on CUA, it might be time to start thinking about how you plan to deploy. Additionally, if you're a SAP Shop on SUN IDM, and not too keen on a switch to Oracle, SAP IDM might be the something to look into!
As always, leave a comment or email me if you have questions about what needs to happen in these implementations!
Nice to see that SAP is starting to get a little more aggressive here. If you are a SAP Shop and rely on CUA, it might be time to start thinking about how you plan to deploy. Additionally, if you're a SAP Shop on SUN IDM, and not too keen on a switch to Oracle, SAP IDM might be the something to look into!
As always, leave a comment or email me if you have questions about what needs to happen in these implementations!
Labels:
best practices,
CUA,
IdM,
implementation,
NW IDM,
SAP TechEd 2010,
Tips
Wednesday, December 29, 2010
2010 and the Year in Identity
As the year draws down, I've been thinking a bit about the year and what's it's meant in Identity Management. There's certainly been a bit of discussion about the nature of Identity, authentication and authorization controls. As technology, process and legislation grow closer, there's a greater need for Governance and Compliance controls than ever before. We're also seeing the beginning of the Cloud truly being a part of the IdM solution.
We're also seeing consolidation on the business side in both the product and implementation branches with Oracle, SAP and Microsoft all making purchases.
Related to this, one thing I've been wondering is what will happen with SAP systems if you rely on either CUA or SUN Identity Manager. What are your plans, if any, for migrating off? I've started a discussion on LinkedIn about this. Please take a moment and share your thoughts about what you are considering or planning.
On a personal note, I wish all of my readers a happy and healthy New Year.
Labels:
Audit,
Compliance,
consolidation,
CUA,
governance,
GRC,
Identity,
IdM,
managed services,
Oracle,
Personal,
post-provisioning,
provisioning,
risk,
risk management,
SaaS,
Security,
summary
Friday, October 22, 2010
Final report from Las Vegas
Sorry to say I'm wrapping my my stay here in Las Vegas. It's been a great time to catch up with some of my friends from Trondheim Labs and SAP Consulting. Also a pleasure to meet some folks that I've communicated with only by email and SDN from the RIG and SAP Waldorf.
I'm going to hit on two main items in this post. Best Practices and CUA.
I attended a great best practices session which talked about a number of things, most of which are fairly obvious (but still bears repeating) and a couple of interesting items. (Emphasis is mine)
The CUA picture has been murky ever since the acquisition of MaXware. It's going away, it's staying, it's on maintenance... Well, you get the picture.
Based on recent reports from SAP, I think we can safely assume that it's on life support. CUA will not be further developed, and even experienced CUA hands are endorsing the use of NetWeaver Identity Management.
That's not to say that IDM is the perfect replacement for CUA. It would seem that a fair amount of development is needed to have IDM do everything that CUA does. However, the good news is that based on the way Identity Management works, that development will not be huge.
Based on what I saw, organizations should begin planning on moving CUA operations to IDM, even if they are using another Identity Management system. One of the things that was established about NetWeaver Identity Management is the fact that it is the only system that can offer complete provisioning to both the ABAP and JAVA stacks for SAP. I know that there are many partners to SAP that offer connectivity, but I think only SAP will be able to offer a holistic approach to provisioning, particularly when provisioning to CRM and SRM. This is because the Provisioning framework that comes with NetWeaver Identity Management offers the only connectors that will work with both Technical and Business roles.
So to wrap up the coverage of TechEd, I think we can safely assume that NetWeaver IDM is evolving quite nicely and that it is in a position to gain greater acceptance from the SAP community as a whole.
As always, feel free to contact me with your NetWeaver Identity Management questions and thoughts. I am, of course available for assessment and consulting projects. Feel free to contact me at matt (-at-) cticorp (-dot-) com, for more information or check out the CTI website!
I'm going to hit on two main items in this post. Best Practices and CUA.
I attended a great best practices session which talked about a number of things, most of which are fairly obvious (but still bears repeating) and a couple of interesting items. (Emphasis is mine)
- Approach the project from the business standpoint, not from IT
- Successful IDM efforts encapsulate both technology and process, so address the initiative as a Program, not a project
- Executive sponsorship is a must
- Start with data cleansing
- Don't think that all roles need to be identified right away. Set up the roles that are most critical and will have the biggest impact. (To be honest, I had not really thought about that one before and it makes a whole lot of sense.)
The CUA picture has been murky ever since the acquisition of MaXware. It's going away, it's staying, it's on maintenance... Well, you get the picture.
Based on recent reports from SAP, I think we can safely assume that it's on life support. CUA will not be further developed, and even experienced CUA hands are endorsing the use of NetWeaver Identity Management.
That's not to say that IDM is the perfect replacement for CUA. It would seem that a fair amount of development is needed to have IDM do everything that CUA does. However, the good news is that based on the way Identity Management works, that development will not be huge.
Based on what I saw, organizations should begin planning on moving CUA operations to IDM, even if they are using another Identity Management system. One of the things that was established about NetWeaver Identity Management is the fact that it is the only system that can offer complete provisioning to both the ABAP and JAVA stacks for SAP. I know that there are many partners to SAP that offer connectivity, but I think only SAP will be able to offer a holistic approach to provisioning, particularly when provisioning to CRM and SRM. This is because the Provisioning framework that comes with NetWeaver Identity Management offers the only connectors that will work with both Technical and Business roles.
So to wrap up the coverage of TechEd, I think we can safely assume that NetWeaver IDM is evolving quite nicely and that it is in a position to gain greater acceptance from the SAP community as a whole.
As always, feel free to contact me with your NetWeaver Identity Management questions and thoughts. I am, of course available for assessment and consulting projects. Feel free to contact me at matt (-at-) cticorp (-dot-) com, for more information or check out the CTI website!
Labels:
Conference,
CUA,
IC,
implementation,
MaXware,
NW IDM,
SAP,
SAP TechEd 2010,
summary,
Tips
Subscribe to:
Posts (Atom)