Showing posts with label summary. Show all posts
Showing posts with label summary. Show all posts

Friday, February 16, 2024

Regarding the recent SAP IDM Announcement

 “Life begins like a dream, becomes a little real, and ends like a dream.” ― Michael Bassey Johnson, The Oneironaut’s Diary

As many of you already know, SAP has made public its plans on how SAP IDM will be retired as a supported offering. I’ve been stewing on this for a bit as I try to figure out exactly how I feel about this and what needs to happen next.

To be fair, I haven’t worked with the product much for just over four years, and even then, I was working more with Version 7 than with Version 8. My opinions are completely my own and do not represent my current employer, any previous employer, or SAP.

While IDM is certainly showing its age, there are some very good things about it that I would love to see as an open-source offering. First is the Batch Processing capabilities of IDM, based on the old MaXware Data Synchronization Engine/MetaCenter solutions. It features some powerful functionality to synchronize and cleanse data. It sets up fairly easily and is quite easy to configure. I’m sure the open-source community could do well with maintaining the UI (It definitely should be JAVA-based rather than the old Windows MMC) that will fit better in today’s Enterprise setting. Also, easy integration with SaaS services is a needed upgrade.

The other thing that should be released into the wild is the Virtual Directory. It also provides powerful functionality for several use cases, from pass-through authentication to assisting in M&A use cases. It’s the perfect example of a “Black Box” offering that just works. It also makes it much easier to synchronize and cleanse data by representing many different back ends via the easy-to-consume LDAP standard.

It saddens me that SAP is choosing to move away from IDM, as one of the key selling points of SAP IDM is its ability to integrate seamlessly with the SAP ecosystem. I hope SAP will help all LCM/IGA vendors connect more easily with systems. SaaS integration should be easy or standards-based, but we still need to be concerned for organizations still using on-premises SAP tools.

SAP has indicated that Microsoft’s Entra ID will be the main partner in the future, but I hope they make this information open to all vendors and that there will be continuing support of standard protocols. This article gives me some hope, but actions speak louder than words. I do have some concerns that SAP, known as a vast software ecosystem that supports itself and tends to ignore the enterprise, is handing off to another large software provider whose management tools tend to support their software ecosystem first and consider the enterprise second. Let’s face it: most of Microsoft’s Identity and Access Management efforts have been about supporting the Office 365 family of products. Don’t get me wrong; it’s better than SAP in this regard, but it’s not that high of a level to meet. For what it’s worth, I am guardedly optimistic, but I always try to remain hopeful.

Finally, I think it’s important to thank the IDM team in Sofia for all their hard work over the years, which, of course, would not have been possible without the vision and effort of the original MaXware team based in Trondheim, Norway, and associated teams in the UK, Australia, and the US. The production from these small teams helped define what Identity Management is to this day.

Will this be my last blog entry on the topic of SAP IDM? I don’t know. Part of it will depend on if there are any moves towards the Open Source world. There have been at least three times in my life when I thought I was done with this tool, and deep down, I’m pretty sure there is a little more in my future. 

In the meantime, I hope to resume blogging more regarding the Identity and Access Management field in the near future. Time will tell.



Thursday, October 18, 2012

SAP TechEd Days 2 and 3

As usual, events here at TechEd have caught up with me and I missed a post. Sorry, folks!

This does not mean that there has been a lack of activity here at TechEd. Yesterday, I attended an excellent hands on workshop based on Context Based provisioning.  Any organization that is looking into SAP IDM for the purpose of managing SAP Roles over multiple locations or positions needs to look into Context Based provisioning. I think one can make an excellent comparison between IDM contexts and the Derived Role concept within SAP.  I'll have to write some more on that later, either here or on the SCN Blog. I've also come up with some other interesting ideas for Contexts which I will be working on over the next few weeks.  Hopefully, I'll have something to share soon.

There were also a number of good Q&A sessions where users could go one-on-one with some of the SAP IDM experts that came over from SAP Labs in Trondheim, Norway.  For those that don't know, NetWeaver IDM was born as MaXware Identity Server in Trondheim back in the 1990s and core development still happens there to this day.  Concepts such as Assignments, Approvals and Virtual Directory Server were covered.

Today I was able to attend a session on the use of the Provisioning Framework.  Not too much new there, but it was good to hear that SAP is committed to the Framework and feels that IDM is the best way to provision users to SAP systems. During the presentation, the following general IDM points were brought up that I would like to comment on:

Users should consider IDM over CUP if connections to external applications are required (e.g., Microsoft Active Directory)
IDM should be used over other provisioning methodologies for Audit and compliance reasons
Do not think of SAP or non-SAP roles, privileges, provisioning etc., it is all Enterprise provisioning


I'll have a wrap of of TechEd tomorrow with some closing thoughts.

Wednesday, October 17, 2012

SAP TechEd 2012: Day 1

Day 1, all I can really say is Wow! I attended sessions on the latest addition to the SAP's Identity Management line up, some of it's oldest technology and the future of the NetWeaver IDM.  After today's session, my mind is completely blown away.

I started the day with two informative sessions on SAP's Single Sign-on Offering based on the technology asset acquisition from SECUDE about 18 months ago. SAP has clearly recognized that information security must begin at the login and proceed from there.  I'm looking forward to learning more about it over the next year or so.  It's a major technology on my radar and should be considered as a key strategic goal for all SAP implementations.

The next session was based on a favorite technology of mine, the Virtual Directory Server (VDS).  Virtual Directory technology has been the "next big thing" in Identity Management for many years now. It appears that SAP's use of Virtual Directory not only as an LDAP proxy, but also as a Web Services Proxy could very well make this the case, particularly in the SAP ecosystem. Miroslav Jokic, SAP's VDS expert, back to the MaXware days gave a great presentation. In an hour long session, Misa gave a thorough overview of VDS, explaining it's architecture, basic use cases and extended use cases when working with Web Services. Clearly this is a technology whose time has come.

The third session of the day dealt with best practices for implementing SAP IDM. While focused on consultants, Kåre Indrøy, presented a good 10 point plan that is applicable to any IDM implementation. In the second half of the presentation, we received an excellent briefing on the new SAP Rapid Deployment Framework for IDM developed by SAP Consulting. While somewhat limited in scope, it certainly does appear to be something that can be quickly implemented for most small to mid-sized clients if all of the pre-requisites are met.

All of these new features will be available in NetWeaver IDM SP 6 which should be available in 2-3 weeks.  Most are also available in SP 5, but not through the Web UI.

Now we come to the Crown Jewel of the day, which was a 2 hour presentation by Kåre and John Erik Setsaas showing the latest functionality to be released shortly in Service Pack 6 for NetWeaver IDM 7.2 and what we can expect to see in the next 6-9 months. Approvals are being enhanced again, making them more functional than ever, particularly where declines and assignments are involved.  Automatic Delegation is now available to designate temporary approvers when the primary approver will not be available.  
NOTE: Everything that follows is conceptual and is not guaranteed to be in any future version of NetWeaver Identity Management.
Trace functionality is also improved with additional control from the Web UI, which will be a boon to IDM developers. Also added to the Web UI is a new SQL Execution reporting interface that will report on database queries that last longer than a predefined limit.  This is a significant enhancement of the Configuration Analyzer's ability to detect inefficient queries and will be something that IDM Administrators will be very interested in.

The last part of the presentation was the really exciting part.  Kåre and John showed us some of the functions that we could be seeing beyond Service Pack 6. Access to the Administration Console looks like it will be getting some tightening along with some locking of objects being worked on in the Admin console. It's been a long standing issue that only one user should be accessing an IDM object in the MMC console at a time (Personally, I'm not found of two people looking at the same configuration at the same time) When the user is done editing and checks the object back in, it becomes available for editing by another IDM administrative user, Additional UME based security is being considered to restrict access to the IDM administrative objects as well.

Also it has been confirmed that DB2 will be supported by IDM in the near future.  The DB2 version will only work if the DB2 Database has been prepared to run in "Oracle Mode"  I'm sure we will be getting more information soon.

The Pièce de résistance of the afternoon was a brief overview of an early alpha version of a new Development UI. I'm not going into a lot of detail here since it was such an early release, but suffice it to say that a 21st century, eclipse based interface is on the horizon, and for those like me who have been working with this interface for the last 8+ years it appears that this will be the answer to our prayers.

I did not cover everything mentioned in these presentations for a couple of reasons.  One, I'd be writing for hours and I need to get some sleep tonight so I can be ready for tomorrow's sessions.  Two, this is SAP TechEd and you should be here.  If you're wondering is it worth it, I say YES! Hopefully this information will make you feel the same way!

Sunday, May 01, 2011

The Crew of the Enterprise

Enterprise projects require Enterprise tools.  We all know this. There's no way you're running an Identity Management system in an Enterprise Environment on Microsoft Access (No insult intended, Microsoft!)

By the same token, Enterprise projects require Enterprise Staff.  Your Identity Management project requires top of the line staff.  A team of talented DBAs, Operating System Admins and local security experts are required to make your project run smoothly.

Several times in this blog I've talked about what goes into a successful project.  We can plan all we want, outline the project and put in proper controls, but without the right team in place, the project won't go anywhere.

Here's to the supporting staff of the IDM project, the DBAs, system admins, and IT security staff.  Thanks, folks!

Wednesday, December 29, 2010

2010 and the Year in Identity

As the year draws down, I've been thinking a bit about the year and what's it's meant in Identity Management. There's certainly been a bit of discussion about the nature of Identity, authentication and authorization controls.  As technology, process and legislation grow closer, there's a greater need for Governance and Compliance controls than ever before.  We're also seeing the beginning of the Cloud truly being a part of the IdM solution.

We're also seeing consolidation on the business side in both the product and implementation branches with Oracle, SAP and Microsoft all making purchases.

Related to this, one thing I've been wondering is what will happen with SAP systems if you rely on either CUA or SUN Identity Manager. What are your plans, if any, for migrating off?  I've started a discussion on LinkedIn about this. Please take a moment and  share your thoughts about what you are considering or planning.

On a personal note, I wish all of my readers a happy and healthy New Year.

Friday, October 22, 2010

Final report from Las Vegas

Sorry to say I'm wrapping my my stay here in Las Vegas.  It's been a great time to catch up with some of my friends from Trondheim Labs and SAP Consulting.  Also a pleasure to meet some folks that I've communicated with only by email and SDN from the RIG and SAP Waldorf.

I'm going to hit on two main items in this post. Best Practices and CUA.

I attended a great best practices session which talked about a number of things, most of which are fairly obvious (but still bears repeating) and a couple of interesting items.  (Emphasis is mine)
  • Approach the project from the business standpoint, not from IT
  • Successful IDM efforts encapsulate both technology and process, so address the initiative as a Program, not a project
  • Executive sponsorship is a must
  • Start with data cleansing
  • Don't think that all roles need to be identified right away.  Set up the roles that are most critical and will have the biggest impact. (To be honest, I had not really thought about that one before and it makes a whole lot of sense.)
The other significant presentation I attended was on CUA.

The CUA picture has been murky ever since the acquisition of MaXware.  It's going away, it's staying, it's on maintenance... Well, you get the picture.

Based on recent reports from SAP, I think we can safely assume that it's on life support. CUA will not be further developed, and even experienced CUA hands are endorsing the use of NetWeaver Identity Management.

That's not to say that IDM is the perfect replacement for CUA.  It would seem that a fair amount of development is needed to have IDM do everything that CUA does.  However, the good news is that based on the way Identity Management works, that development will not be huge. 

Based on what I saw, organizations should begin planning on moving CUA operations to IDM, even if they are using another Identity Management system. One of the things that was established about NetWeaver Identity Management is the fact that it is the only system that can offer complete provisioning to both the ABAP and JAVA stacks for SAP.  I know that there are many partners to SAP  that offer connectivity, but I think only SAP will be able to offer a holistic approach to provisioning, particularly when provisioning to CRM and SRM. This is because the Provisioning framework that comes with NetWeaver Identity Management offers the only connectors that will work with both Technical and Business roles.

So to wrap up the coverage of TechEd, I think we can safely assume that NetWeaver IDM is evolving quite nicely and that it is in a position to gain greater acceptance from the SAP community as a whole.

As always, feel free to contact me with your NetWeaver Identity Management questions and thoughts.  I am, of course available for assessment and consulting projects.  Feel free to contact me at matt (-at-) cticorp (-dot-) com, for more information or check out the CTI website!

Tuesday, April 20, 2010

More on SailPoint

In reviewing yesterday's post, I realized I got a little off my intended track of talking about my SailPoint training, and spent more time talking about IdM Architecture.

In light of that, let me talk a little bit more about SailPoint and what they have to offer.

The SailPoint product seems pretty darn interesting. It does a fantastic job of linking in to various types of repositories (LDAP, Database, ERP, flat files, etc) that are found in the Enterprise and brings them into a common repository known as the Identity Cube (love this name, BTW)

Once the data is in the Identity Cube, all the fun begins, we can then do Role Mining, Segregation of Duties and other forms of Compliance analysis, and most importantly, Certification/ Attestation. It's easy to do all sorts of searches and analysis on the information held within the Cube and produce everything from application centric user role reports to IT Security oriented Risk scores based on role, application and group membership.

I'm going to find it pretty darn hard to believe that Enterprise IT and auditing departments will be able to work without a tool such as this in the future. This application is a great add on to add to current Identity and Risk Management projects and I'm looking forward to working with it.

Monday, April 19, 2010

SailPoint Training

Not too bad when you get to go to two training classes in a row. Even better when they are on cool technologies like SAP NetWeaver Identity Manager and SailPoint's Identity IQ.

Had a great time and learned lots of stuff down in Austin, TX with the SailPoint team. Clearly, the IdM field continues to expand and redefine itself as a combination of regulation and security concerns demand better audit and compliance rules. Corporate Governance policies are finding themselves enforced as IT tools embrace certification and audit along with "old school" concepts such as user provisioning, password management and access control. I think SailPoint will be aggressively moving forward to complete this integration to produce a new "Compliance Driven" IdM model.

Given these developments, I find it hard to understand how Burton Group feels that "IdM is not aging gracefully" as pointed out in an abstract on Bob Blakely's latest paper, "Identity and Privacy Strategies Assessment (Single Instance Use Case)"

While I have the greatest respect for the folks at Burton, I have to say I cannot disagree more with this assessment. (Disclosure: I am not currently a Burton Group customer and as such only have access to the abstract and have not read the whole article)

IdM is rising to meet several challenges, as I have indicated above, and if there are architectural flaws it is due more to the fact that current providers are channeling the products to reflect their application suites. Oracle, SAP and Microsoft all embrace some part of their technologies for application serving or the front end or require specialized programming in the form of JAVA, Xpress or ABAP and are increasingly being engineered to work first with their own products and then addressing the rest of the enterprise (SAP is particularly guilty here)

I also foresee additional growth as IdM embraces new technologies in User Identification. A tighter integration between Biometrics, Smart Cards and other identifiers becomes more mainstream. However, before this can begin, IT and IS have to agree on standards and adoption of these identification methods.

Also let's not forget about the Specter of Federated Identity Services. While there have been several successful architectures developed, it's still one of the most complicated IdM scenarios out there. Perfecting the Federation Use Case and its easy deployment will kick off another chapter in IdM's steady evolution.

Saturday, April 10, 2010

SAP IdM Training - Wrapup

The last day of the training was an excellent conclusion. We spent a few hours connecting to SAP JAVA and ABAP systems. In general the SAP connectors work quite well. I'll be much happier, however if the Trondheim development team creates real to/from SAP passes rather than relying on custom connectors, and of course, the end of the MMC management interface!

I also had more exposure to the new UI and as one SAP insider commented to me, what it lacks in flexibility, it makes up for in security and language localization, which I cannot disagree with. Even if a company in need of Identity Management is not a SAP shop, it should consider SAP NetWeaver IDM in environments where multiple languages need to be supported.

In general, I think the product is moving in the right direction. Looking forward to getting on some planned projects in the next few weeks, plus whatever else might come up!

Thursday, April 08, 2010

SAP IdM Training Continued

Still impressed with the training class. I’ve found it interesting how they’ve been able to give the class a good flavor of how NetWeaver IdM works. I think the folks in the class are getting a solid foundation in what the product can do. Everyone in the class is looking forward to working with the SAP Provisioning framework which is the emphasis of the last day of class.

I also received a nice tip today. Take a look at this new document from SAP (I believe it is a general access document)

An interesting discussion of reconciliation from an ERP context. Most people typically reconcile against an enterprise directory, but when working with an ERP system as the authoritative source, it makes sense to have a reconciliation process against this system as well.

It's also been interesting seeing the general improvements to the product. While I miss the ease of installation, speed and flexibility of NW IDM 7.0 (Not to mention MaXware Identity Center) the new version shows better scalability than ever before. Little tweaks like adjusting the attention dispatchers should give to different task types, to improved role / management handling and event handling. The interface is not terrible and the WebDynPro UI lacks the flexibility of the old PHP, but it is a heckuva lot more functional, particularly where mutli-valued attributes , roles and privileges are concerned.

After SailPoint training and some customer facing work (gotta earn some money!) I'll be looking forward to setting up a lab environment for the rest of the IdM team at CTI. Once that's done we'll be up to giving some demonstrations to clients and other interested parties.

Long time since I ran an IdM demo...

I'll be sure to comment on the SAP Provisioning Framework sometime over the weekend.


Monday, March 29, 2010

News Update

I'm happy to say that I've started what I hope will be a long and successful association with Commercium Technology Inc. I am now working with them as a Senior Principal Consultant in the Identity and Access Management group.

I'm looking forward to working with SAP Identity Management, Virtual Directory and other exciting technologies like SailPoint. I'm looking forward to learning (and writing) about all of this in the weeks and months to come.

Please feel free to reach out if we can help you or your organization with your Identity Management or Compliance needs!


Monday, September 21, 2009

Project Listening

At the end of my last post I made a reference to pay attention to the customer's needs when planning and executing an Identity Management project:

...Whether you are a consultant helping a client with their solution or an internal employee building your firm's Identity Management strategy, you still have a client, and their needs should always come first...

I recently took part in a Linkedin discussion where the person posting the question asked the question:

...I would be interested in your take on the latest and greatest products to implement for Identity and Access Management needs across the enterprise. Thoughts / comments...

I gave a pretty straightforward answer which covered some informative (in my opinion) basics centering on looking at the basic systems in the enterprise and advised the questioner to move forward from there.

There were a lot of people who went on another tangent, which was a more consultative answer... Find out what you need and then go to match technology.

Sounds like we have a chicken and the egg here.We cannot determine what technology fits until we determine how the technology is to be used. We also cannot determine how to use the technology unless we know what the technology can do.

Who is right? Who is wrong? I don't think either viewpoint is wrong. The fact is the first questions should have been along the lines of:

  • Have you determined use cases?
  • Have you begun to look at what technologies are out there?
  • Who is using the system?

Nothing about management, systems, or anything else. The initial basic tasks must be this broad outline. Once these big questions are answered we can do to then fill in the holes and determine how to answer all the little questions.

Incidentally, my answer came from the fact that the questioner specifically wanted to know about technology. Since the initial posting he has not made any comments on which approach he needed, but I did see that my good friend and fellow blogger, Matt Flynn posted as well!


Sunday, May 17, 2009

Identity Abroad

I'll be spending the next few weeks doing some work in Germany doing some custom connector work with NetWeaver Identity Manager at our offices in Darmstadt, Germany. I'm hoping to have the chance to learn more about how Identity Management works in a different environment. I'll be posting my observations from time to time, along with the usual reporting on news and NW IDM tips.

Thursday, May 07, 2009

New School Identity Management?

I'm all for a discussion of changes in the Identity Management world, in fact I encourage them. I think it's a pretty dynamic world. As Mark Diodati mentions in his article "Changing times for identity management" (login required) There are elements of IdM that are established parts of IT infrastructure, and then there is "New School Identity Management, where he talks about Privileged account Management, AD Bridges and Virtual Directories"

All due respect to Mark, who I know has been around the IdM world for some time, but none of these elements should be considered New School and have been around for quite some time.
  • Privileged Account Management - I don't know of an engagement I've worked on in the last 5 years that did not have some concern about the creation and management of both Privileged and Service accounts. If anything, because of their nature, these accounts have a greater need to be created in such a way that they are done according to mandated processes and recorded for audit and review.
  • AD Bridges - While not a technology I've gotten to work with a lot I know that many a mixed UNIX/Microsoft shop consider the Vintella/Quest tools to be indispensable.
  • Virtual Directories - Again, a technology that's been around for a long time. I've been working with Virtual Directory technologies since 2004, where I would commonly show customers how to map information, provide access controls and even used the Virtual Directory as a write back mechanism to supported repositories.
I can say that I'm glad these Identity Management technologies are finally getting their time in the sun. Some of these technologies have not been considered as interesting or sexy since they worked with a subset of users. I think we can all agree that there are more end users than UNIX accounts or system accounts so they should receive some more attention.

However, in the end, the design and implementation of an Identity Management solution must be holistic in nature. Regardless of one's opinion on the New School qualities of the all the technologies Mark mentions in his article, they must all be considered and planned for in the final design.

Tuesday, December 23, 2008

Recent Article

I did not think I'd have anything else to say before the end of the year. However, this was not to be the case... Some months ago I was interviewed, along with several others for an article that has appeared in Information Security Magazine. The article, by Robert Westervelt, talks about Identity Management challenges an economy full of Layoffs and Mergers. It's a very nice high level treatment of some of the strategic reasons to have Identity Management Solutions in place.

You might need to register in order to view the material however, there is no charge to view the content.

Monday, December 22, 2008

Happy Holidays

It's been  the end of a great year of working with Identity Management this year.  Sun, Oracle, Novell, IBM and of course, SAP are all in the mix and doing well.  Companies are recognizing that not only is IdM useful, but a strategic business goal as well.

Personally, I've gone from Project Management, to Independent work, to working with a fine organization, SECUDE Global Consulting.  I've had a great year with them, and am looking forward to more challenging work in the coming year.

I'd like to wish everyone a happy, safe and sweet holiday and New Year.  Even if you don't celebrate a particular holiday, take a moment and reflect (which you should do often anyway)  

On a lighter note, I saw this humorous post at CSOOnline.  Hope it brings a chuckle!