Showing posts with label SAP. Show all posts
Showing posts with label SAP. Show all posts

Friday, February 16, 2024

Regarding the recent SAP IDM Announcement

 “Life begins like a dream, becomes a little real, and ends like a dream.” ― Michael Bassey Johnson, The Oneironaut’s Diary

As many of you already know, SAP has made public its plans on how SAP IDM will be retired as a supported offering. I’ve been stewing on this for a bit as I try to figure out exactly how I feel about this and what needs to happen next.

To be fair, I haven’t worked with the product much for just over four years, and even then, I was working more with Version 7 than with Version 8. My opinions are completely my own and do not represent my current employer, any previous employer, or SAP.

While IDM is certainly showing its age, there are some very good things about it that I would love to see as an open-source offering. First is the Batch Processing capabilities of IDM, based on the old MaXware Data Synchronization Engine/MetaCenter solutions. It features some powerful functionality to synchronize and cleanse data. It sets up fairly easily and is quite easy to configure. I’m sure the open-source community could do well with maintaining the UI (It definitely should be JAVA-based rather than the old Windows MMC) that will fit better in today’s Enterprise setting. Also, easy integration with SaaS services is a needed upgrade.

The other thing that should be released into the wild is the Virtual Directory. It also provides powerful functionality for several use cases, from pass-through authentication to assisting in M&A use cases. It’s the perfect example of a “Black Box” offering that just works. It also makes it much easier to synchronize and cleanse data by representing many different back ends via the easy-to-consume LDAP standard.

It saddens me that SAP is choosing to move away from IDM, as one of the key selling points of SAP IDM is its ability to integrate seamlessly with the SAP ecosystem. I hope SAP will help all LCM/IGA vendors connect more easily with systems. SaaS integration should be easy or standards-based, but we still need to be concerned for organizations still using on-premises SAP tools.

SAP has indicated that Microsoft’s Entra ID will be the main partner in the future, but I hope they make this information open to all vendors and that there will be continuing support of standard protocols. This article gives me some hope, but actions speak louder than words. I do have some concerns that SAP, known as a vast software ecosystem that supports itself and tends to ignore the enterprise, is handing off to another large software provider whose management tools tend to support their software ecosystem first and consider the enterprise second. Let’s face it: most of Microsoft’s Identity and Access Management efforts have been about supporting the Office 365 family of products. Don’t get me wrong; it’s better than SAP in this regard, but it’s not that high of a level to meet. For what it’s worth, I am guardedly optimistic, but I always try to remain hopeful.

Finally, I think it’s important to thank the IDM team in Sofia for all their hard work over the years, which, of course, would not have been possible without the vision and effort of the original MaXware team based in Trondheim, Norway, and associated teams in the UK, Australia, and the US. The production from these small teams helped define what Identity Management is to this day.

Will this be my last blog entry on the topic of SAP IDM? I don’t know. Part of it will depend on if there are any moves towards the Open Source world. There have been at least three times in my life when I thought I was done with this tool, and deep down, I’m pretty sure there is a little more in my future. 

In the meantime, I hope to resume blogging more regarding the Identity and Access Management field in the near future. Time will tell.



Monday, February 01, 2016

You've read my ramblings, now listen to them!

You've been reading my ramblings for years here and on SCN. Now you have a chance to listen to some of my thoughts on SAP IDM and a bit on SAP IDM 8 I was recently interviewed by long time colleague and fellow IDM Expert,Scott Eastin for his IDM Masters Interview Series

Please take a moment to listen to the interview and support Scott's efforts!

BTW, please let me know if this is interesting and if we should consider a regular podcast / YouTube discussion of SAP IDM, along with topics that you would like to see covered!

Thanks!

Friday, October 19, 2012

TechEd 2012 Wrapup

Quicker than I thought possible, another TechEd has come and gone. It's been a fantastic TechEd this year.

From the SAP Identity Management perspective we saw some exciting new things this year:
  • NW IDM Service Pack 6 is scheduled to be released in the next couple of weeks with some nice new features.
  • Longer term enhancements will see the end of the dreaded MMC console! I don't think we'll see this in the next couple of enhancements, but I think we'll see it by the end of 2013!
  • Virtual Directory received a renewed focus with sessions not only on standard SAP use cases but also in dealing with Identity Services.
  • SAP SSO got some nice attention as well.  I'd expect that next year we'll have some hands-on sessions as well.
One thing that I did notice this year was a near complete lack of attention to GRC.  This has me wondering many things.  I don't think that GRC is going away, as the compliance space is very hot right now with all the big companies (IBM, EMC, Oracle, CA, etc.) involved and some other small players (SailPoint, Aveksa) are growing at a rapid pace.

I've not been able to get any confirmation from anyone at SAP, but if I put my thinking cap on, I would say that we're looking at the beginning of a re-alignment of how GRC is being included in workflow. Stay tuned!

Thursday, October 18, 2012

SAP TechEd Days 2 and 3

As usual, events here at TechEd have caught up with me and I missed a post. Sorry, folks!

This does not mean that there has been a lack of activity here at TechEd. Yesterday, I attended an excellent hands on workshop based on Context Based provisioning.  Any organization that is looking into SAP IDM for the purpose of managing SAP Roles over multiple locations or positions needs to look into Context Based provisioning. I think one can make an excellent comparison between IDM contexts and the Derived Role concept within SAP.  I'll have to write some more on that later, either here or on the SCN Blog. I've also come up with some other interesting ideas for Contexts which I will be working on over the next few weeks.  Hopefully, I'll have something to share soon.

There were also a number of good Q&A sessions where users could go one-on-one with some of the SAP IDM experts that came over from SAP Labs in Trondheim, Norway.  For those that don't know, NetWeaver IDM was born as MaXware Identity Server in Trondheim back in the 1990s and core development still happens there to this day.  Concepts such as Assignments, Approvals and Virtual Directory Server were covered.

Today I was able to attend a session on the use of the Provisioning Framework.  Not too much new there, but it was good to hear that SAP is committed to the Framework and feels that IDM is the best way to provision users to SAP systems. During the presentation, the following general IDM points were brought up that I would like to comment on:

Users should consider IDM over CUP if connections to external applications are required (e.g., Microsoft Active Directory)
IDM should be used over other provisioning methodologies for Audit and compliance reasons
Do not think of SAP or non-SAP roles, privileges, provisioning etc., it is all Enterprise provisioning


I'll have a wrap of of TechEd tomorrow with some closing thoughts.

Monday, October 15, 2012

SAP TechEd: Preview

I'm here in Las Vegas, Nevada for SAP TechEd 2012 and I could not be happier. It's looking like quite the busy week of IDM related training.  Attendees are arriving and I've already seen a few people I know from SAP, past projects and the greater IDM Community.  From what I've already heard we're in for a week of exciting learning, future product direction and late breaking functionality in the product. In addition to working with IDM this week, I'll be attending several sessions on the SSO solution that SAP purchased from SECUDE last year.  Now that a year has gone by, the product should be fully integrated into the SAP universe and I'm very interested in learning more about it. I was strangely surprised to see very few, if any, SAP GRC solutions in the session listings.  Hopefully, I'll be able to find out what's going on with that. On the other hand, there will be several Virtual Directory Server related sessions which should be quite informative about connecting to various systems and web services.

I'm sure that we will hear the latest news about SAP IDM 7.2.  Service Pack 6 is due shortly and I'm looking forward to getting a few rumors confirmed.  Probably the one to be confirmed first will be around DB2 support. This will be very good for IBM shops where DB2 is used to the exclusion of the other supported databases in IDM, Microsoft SQL Server and Oracle.  This adds greater flexibility to my thoughts in choosing an IDM solution, as one can now expand the database criteria and will answer the pleas for support from many SAP customers that want to get involved with IDM. There are also some rumors about new and improved tools along the lines of the Configration Analyzer.


Also rumored are some MMC improvements, although I have not yet gotten even a rumor of when a redesigned administrative console will be available, although I am assured that it is indeed on the list. I'm hoping to get some information on this during the SAP  NetWeaver ID Management - Latest Functionality and Demo session scheduled for tomorrow.  Hopefully, I'll have some exciting news for the SAP IDM community.

I'm looking forward to seeing / learning / connecting and reconnecting during the week.  Odds are you'll find me at the various IDM and SSO sessions this week if you're here.  Please feel free to introduce yourselves.  I'd like to try and organize some sort of IDM meet up this week, maybe a drink or two one night.  I've received some interest in this.  If you have not contacted me yet, please leave a comment or email me privately.


Friday, January 21, 2011

Good to see SAP IDM movement!

Just saw this courtesy of Google Alerts. Always nice to see a big win!  Just like to see more of them here in North America.  (For my international followers, I am open to consulting abroad :) )

I have just started a new project down in South Carolina.  Should be some good things coming out of this one that I will be blogging about shortly.  Also  upcoming will be some thoughts on the management of identity based on some conversations I've been having with some folks over the past few weeks.

Thursday, January 13, 2011

Some quick reads in SAP IDM and IdM in general.

Reporting, Metrics, Audit, whatever you want to call it, relies on being able to extract information from your identity management systems.  This article is a brief discussion on the topic.  I was fortunate to meet one of the authors, Gerlinde, during TechEd last year.

It's also nice to know our market is growing!

Friday, October 22, 2010

Final report from Las Vegas

Sorry to say I'm wrapping my my stay here in Las Vegas.  It's been a great time to catch up with some of my friends from Trondheim Labs and SAP Consulting.  Also a pleasure to meet some folks that I've communicated with only by email and SDN from the RIG and SAP Waldorf.

I'm going to hit on two main items in this post. Best Practices and CUA.

I attended a great best practices session which talked about a number of things, most of which are fairly obvious (but still bears repeating) and a couple of interesting items.  (Emphasis is mine)
  • Approach the project from the business standpoint, not from IT
  • Successful IDM efforts encapsulate both technology and process, so address the initiative as a Program, not a project
  • Executive sponsorship is a must
  • Start with data cleansing
  • Don't think that all roles need to be identified right away.  Set up the roles that are most critical and will have the biggest impact. (To be honest, I had not really thought about that one before and it makes a whole lot of sense.)
The other significant presentation I attended was on CUA.

The CUA picture has been murky ever since the acquisition of MaXware.  It's going away, it's staying, it's on maintenance... Well, you get the picture.

Based on recent reports from SAP, I think we can safely assume that it's on life support. CUA will not be further developed, and even experienced CUA hands are endorsing the use of NetWeaver Identity Management.

That's not to say that IDM is the perfect replacement for CUA.  It would seem that a fair amount of development is needed to have IDM do everything that CUA does.  However, the good news is that based on the way Identity Management works, that development will not be huge. 

Based on what I saw, organizations should begin planning on moving CUA operations to IDM, even if they are using another Identity Management system. One of the things that was established about NetWeaver Identity Management is the fact that it is the only system that can offer complete provisioning to both the ABAP and JAVA stacks for SAP.  I know that there are many partners to SAP  that offer connectivity, but I think only SAP will be able to offer a holistic approach to provisioning, particularly when provisioning to CRM and SRM. This is because the Provisioning framework that comes with NetWeaver Identity Management offers the only connectors that will work with both Technical and Business roles.

So to wrap up the coverage of TechEd, I think we can safely assume that NetWeaver IDM is evolving quite nicely and that it is in a position to gain greater acceptance from the SAP community as a whole.

As always, feel free to contact me with your NetWeaver Identity Management questions and thoughts.  I am, of course available for assessment and consulting projects.  Feel free to contact me at matt (-at-) cticorp (-dot-) com, for more information or check out the CTI website!

Wednesday, October 20, 2010

SAP TechEd on Wednesday, October 20th

As promised, I'm going to follow up on some of the challenges that Gregg Dippold had commented on. To the best of my knowledge, all of the information that I have reported here is public as of TechEd. I have chosen not to share some information as I felt that it was still to tentative to report. All of this information, of course, subject to change.

The short answer is: SAP NetWeaver Identity Management 7.2 is a huge leap forward.  It will be more customizable, have better tools for managing roles and connect to more systems than ever before. So here's Gregg's list of challenges and what I've learned so far.

Challenge 1: Self Service is Not Intuitive for Unsophisticated Users

Version 7.2 will be adding additional functionality to create custom user interfaces using an Open API. It might not make it into the initial release, but look for it in one of the 7.2 Service packs.

Challenge 2: Fragmented Documentation
 
Don't know about this one, but I can say that the documentation has been getting steadily better, so I'm cautiously optimistic.

Challenge 3: Limitations in the Staging Environment

I think we're all aware of some of the limitations in the Import/Export.  Look for some changes that will make transferring configurations between environments much easier. Among these will be an interface from the Web UI to export the entire configuration including repositories to a single XML file. Also to be included in 7.2 is a configuration analyzer which will review the entire configuration and check for objects 7.1 that will not work in 7.2 and do some basic checking for inefficient practices (such as queries that use aValue rather than SearchValue.

Note: I forgot to add that this utility will also export associated VDS configurations as well.

Challenge 4: Job Customization Frequently Requires Custom JavaScript

I don't know that this can ever really go away, as there needs to be some mechanism for implementing transformations of attributes and back end processing.  To make things more interesting, we'll also see more use of the extension framework which will be JAVA based and open up some new and exciting possibilities.  We can also expect to see some changes to the standard provisioning framework that will make connectivity to SAP and non-SAP systems a bit easier.

Challenge 5: Few Useful Reports Available in Default Installation


This could also be a big item as 7.2 will now talk to the Business Warehouse. From what I saw during the presentation these reports will be much better than the previous Jasper and Crystal based reports.

That's about it for the moment.  Heading to a session on VDS shortly.  Hopefully, I'll get some more information that I'm free to share.

Saturday, July 10, 2010

Talk Down, Build Up

No, it’s not a new self esteem program; rather what I think is the best methodology for developing SAP NetWeaver Identity Management Workflows.

First, let’s review the basic components of a NW IDM Workflow

Screens represent the top most level and what most people routinely deal with. Here’s where we present the attributes (populated and empty) Descriptions and other UI related features. Starting with NetWeaver IDM 7.1, this is handled by the Web Dynpro engine. Before that PHP was used.

Tasks are what give the workflow their structure. Ordered Tasks, Un-Ordered tasks, Conditionals, Approvals, etc go here.

Action Tasks are the real muscle of the workflow. Action tasks execute the actual operations of the workflow. Writing information to a Target System, a Report or the Identity Store itself all gets done from these tasks.

Of course there are many workflows of various complexities that come with the SAP Provisioning framework, but as we all know this will not cover all circumstances and sometimes custom workflows will need to be created. Fortunately, NW IDM makes it rather easy since Screen, Tasks and Action Tasks can all be linked and re-linked together over and over.

Over time I’ve found that the design and creation of workflows can be best summarized by what I refer to as the “Talk Down, Build Up” approach.

When discussing the formulation of a workflow it is generally best to discuss the workflow top down. That is start with what the user sees and then what happens after they press “Submit.” People find it easy to follow the workflow and its branches (if any) when we start from this approach. Given the way that the workflows correspond to a flowchart, this seems to be somewhat of a no-brainer. The following screenshot, gives one an idea about this:

Development, however does not work the same way. Trying to develop top down becomes fairly confusing since the developer is linking to objects that might not exist yet. Development, it seems works best, from the bottom up. In general I recommend creating NW IDM workflow objects in the following order:

  1. Action Tasks
  2. Privileges
  3. Roles
  4. Conditional/Approval/Switch Tasks
  5. Ordered tasks (I seldom make use of unordered ones)
  6. Screens

As a general best practice, I also reccomend using folders as organizational containers to group related tasks together. Usually I like to do this by target system (AD, SAP, SunONE, NW IDM, Notifications, etc.)

So there we have it. We talk down about the structure, but we build from the bottom up. I’m wondering how other SAP NW IDM architects approach this. What about other IdM products?

Thursday, May 13, 2010

SAP + Sybase = Oracle

I've been wondering when SAP would finally acquire a decent database. I was quite astounded when SAP passed on MYSQL and letting it go to SUN. (A complete waste in my opinion since now it's a 3rd class citizen in Oracle-land)

Now we see that SAP has purchased Sybase. An interesting purchase to be sure and one that will have some far reaching implications. First off, I think SAP will have the ability to go toe-to-toe with Oracle on almost all fronts (Still think they lack a strong access control piece)

It also allows them to include the missing piece to the entire SAP ecosystem, the environment that everything will live in. Now one wonders if they will pick up a Linux of some sort (SUSE/Novell) to compete with Solaris and maybe a hardware vendor to compete with SUN servers.

SAP in a box, anyone?

Monday, May 03, 2010

Glad to see them getting into the act

It was fantastic to see SAP actively stepping into the Identity Management discussion in the article Better services in higher education? Without Identity Management: no chance!

I've long been a proponent of bringing IdM to Higher Education. With constantly changing user populations, complex access management needs, and many disparate systems to connect to, usage of an IdM system seems to be a no-brainer. Add on need for Compliance controls given HIPAA, Student Loans, etc, there's an even greater need.

Here in the US, it seems that Oracle has been the 500 pound gorilla pushing IdM in the Higher Education space. Nice to see that there is another vendor stepping up!

Monday, April 19, 2010

SailPoint Training

Not too bad when you get to go to two training classes in a row. Even better when they are on cool technologies like SAP NetWeaver Identity Manager and SailPoint's Identity IQ.

Had a great time and learned lots of stuff down in Austin, TX with the SailPoint team. Clearly, the IdM field continues to expand and redefine itself as a combination of regulation and security concerns demand better audit and compliance rules. Corporate Governance policies are finding themselves enforced as IT tools embrace certification and audit along with "old school" concepts such as user provisioning, password management and access control. I think SailPoint will be aggressively moving forward to complete this integration to produce a new "Compliance Driven" IdM model.

Given these developments, I find it hard to understand how Burton Group feels that "IdM is not aging gracefully" as pointed out in an abstract on Bob Blakely's latest paper, "Identity and Privacy Strategies Assessment (Single Instance Use Case)"

While I have the greatest respect for the folks at Burton, I have to say I cannot disagree more with this assessment. (Disclosure: I am not currently a Burton Group customer and as such only have access to the abstract and have not read the whole article)

IdM is rising to meet several challenges, as I have indicated above, and if there are architectural flaws it is due more to the fact that current providers are channeling the products to reflect their application suites. Oracle, SAP and Microsoft all embrace some part of their technologies for application serving or the front end or require specialized programming in the form of JAVA, Xpress or ABAP and are increasingly being engineered to work first with their own products and then addressing the rest of the enterprise (SAP is particularly guilty here)

I also foresee additional growth as IdM embraces new technologies in User Identification. A tighter integration between Biometrics, Smart Cards and other identifiers becomes more mainstream. However, before this can begin, IT and IS have to agree on standards and adoption of these identification methods.

Also let's not forget about the Specter of Federated Identity Services. While there have been several successful architectures developed, it's still one of the most complicated IdM scenarios out there. Perfecting the Federation Use Case and its easy deployment will kick off another chapter in IdM's steady evolution.

Thursday, September 03, 2009

(Database - Sun) + Oracle = Acquisition

It seems that the Europeans are putting their two cents into the pending acquisition of Sun by Oracle.

Can't say I'm surprised as many businesses in Europe and around the world use MySQL. I've often thought that this more than anything else would get in the way of the acquisition. Of all the areas of overlap, this seems to be the one that matters the most.

Oracle already owns one of the biggest databases around, now it stands to acquire another one with world wide appeal. As the article quoted above mentions:

Regulators must “examine very carefully the effects on competition in Europe when the world’s leading proprietary database company proposes to take over the world’s leading open-source database company,”
It's also a key part of the SAP system (in the form of MaxDB), which I am sure is part of the European investigation whether it is specifically mentioned or not, as the article also states:

“the enquiry will focus on the extent to which open-source software developers would be able to continue to develop software based on the open-source MySQL database,” which Sun bought last year and which is widely used.
I'm still thinking that the simplest solution to to sell MySQL to SAP. It would create a level playing field between Microsoft, Oracle/Sun and SAP.

All would have ERP and database tools. Microsoft and Oracle/Sun would still have operating systems, but I don't think this is a big issue for SAP since they not only run just fine on both. Additionally I think we all realize that SAP drives purchases of operating systems and tools from the other companies.

Can't wait to see what happens...