<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"
    xmlns:dc="http://purl.org/dc/elements/1.1/"
    xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
    xmlns:admin="http://webns.net/mvcb/"
    xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"
    xmlns:content="http://purl.org/rss/1.0/modules/content/">

    <channel>
    
    <title>iDENTiTY AUTOMATiON &#45; Blog Feed</title>
    <link>http://identityautomation.com</link>
    <dc:language>English</dc:language>
    <dc:rights>Copyright 2011</dc:rights>
    <dc:date>2011-08-12T19:22:40+00:00</dc:date>
    <admin:generatorAgent rdf:resource="http://expressionengine.com/" />
    

    <item>
      <title>Why SAML Is Important To Your Organization</title>
      <link>http://www.identityautomation.com/site/single/why-saml-is-important-to-your-organization</link>
      <guid>http://www.identityautomation.com/site/single/why-saml-is-important-to-your-organization#When:20:22:40Z</guid>
      <description>
      	<p>Many of our customers are implementing or considering the implementation of hosted application services (aka SaaS).&nbsp; The benefits are obvious because your support burden is reduced whether that be due to increased resource utilization, hardware savings, software savings or otherwise.&nbsp; </p>

<p>For the sake of this article, let&#8217;s use the example of implementing hosted email services by Google.&nbsp; Google Apps is a great solution for commercial, non-profit and public organizations.&nbsp; The Google infrastructure is better than most organizations could provide themselves.&nbsp; Your internal customers have 24/7 access to their email, calendar, docs and other services provided by the Google Apps offering.&nbsp; As an IT department, you no longer maintain your email infrastructure.&nbsp; You no longer have to keep internal resources trained on your email system and you can now take back those resources that were dedicated to supporting email and reassign them to other projects.&nbsp; All of this is great and seems like a no-brainer for many organizations.</p>

<p>The truth is, you do still have some management burden.&nbsp; Even though you don&#8217;t support a local email system, you still are responsible for setting up and managing your user accounts for Google Apps.&nbsp; You will still get the call when users can&#8217;t access Google Apps because they don&#8217;t have an account, they are disabled or they don&#8217;t recall their password.&nbsp; Many IT departments are disappointed to see the lack of tools available to automate this process.&nbsp; Google does provide a directory synchronization tool but it isn&#8217;t perfect.&nbsp; Password management is an all together different issue.&nbsp; Although this isn&#8217;t the basis for this article, it is worth noting that Identity Automation has a Google Adapter for DSS the can fully automate the management of users and groups in Google.&nbsp; This solution absolutely deals with much of the pain associated with managing Google Apps accounts, but I digress.&nbsp; The point of this article is to specifically discuss passwords regarding hosted services.</p>

<p>Back to our Google Apps example, our adapter is capable of taking passwords from your internal directory service and synchronizing those to the matching Google Apps account.&nbsp; This is a great solution but it can raise security concerns.&nbsp; Google hosts their Google Apps in a high security facility.&nbsp; Their employees are well vetted.&nbsp; That doesn&#8217;t mean every hosted services provider goes through the same pains regarding security.&nbsp; The alternative?&nbsp; SAML!</p>

<p>Many hosted services providers support SAML for authentication.&nbsp; Google Apps, Salesforce.com, Zendesk and Zoho to name a few.&nbsp; A system that supports SAML as a means for authentication is referred to as a Service Provider (SP).&nbsp; An SP requires the availability of an Identity Provider (IdP).&nbsp; When a user accesses Google Apps (with SAML configured), they will not authenticate directly against the Google servers.&nbsp; Instead the SP (Google in this case) will refer the user&#8217;s browser to the IdP.&nbsp; Our ARMS and/or DSS products both act as an IdP.&nbsp; The IdP is configured to authenticate users against your internal directory service such as Active Directory.&nbsp; That means when a user accesses Google, to a redirected to your ARMS (or DSS) appliance where they will log in with their network credentials.&nbsp; The same credentials they use to log into their office workstations.&nbsp; Once authenticated, the IdP passes a secure token that tells the SP that you successfully authenticated and informs the SP who you are in its system.</p>

<p>SAML is important to your organization as you move more towards relying on hosted services.&nbsp; Without SAML you are storing credentials in an untrusted environment.&nbsp; You don&#8217;t always know how those credentials are stored and secured.&nbsp; A user&#8217;s credentials in these systems likely match the same credentials used for in internal systems.&nbsp; If the passwords in the hosted system are stored in an insecure fashion you&#8217;ve basically exposed access to internal systems as well.&nbsp; With SAML, there is no credential stored in the hosted service providers facility.&nbsp; There is zero risk of credentials being exposed and stolen.</p>

<p>By combining our Google Apps Adapter for DSS and ARMS with the SAML IdP service, you now have a viable option fully automating the management of accounts and providing secure SSO without the risk of storing user credentials &#8220;in the cloud&#8221;.&nbsp; </p>

<p><a href="/company/contact-us">Contact Us</a> today to find out how we can provide this solution for your organization for Google Apps or other hosted services solutions.
</p>
      </description> 
      <dc:subject></dc:subject>
      <dc:date>2011-08-12T20:22:40+00:00</dc:date>
    </item>

    <item>
      <title>ARMS SAML Identity Provider</title>
      <link>http://www.identityautomation.com/site/single/arms-saml-identity-provider</link>
      <guid>http://www.identityautomation.com/site/single/arms-saml-identity-provider#When:16:26:47Z</guid>
      <description>
      	<p>Not a day goes by that we don&#8217;t have a conversation with a customer about some service they want to connect to that exists in the &#8220;cloud&#8221;.&nbsp; There are numerous ways to handle the authentication for those services and there is increasing interest in the use of SAML for this purpose.</p>

<p>If you&#8217;re not familiar with SAML (Security Assertion Markup Language 2.0), it&#8217;s a &#8220;standard for exchanging authentication and authorization data between security domains. SAML 2.0 is an XML-based protocol that uses security tokens containing assertions to pass information about a principal (usually an end-user) between an identity provider and a web service. SAML 2.0 enables web-based authentication and authorization scenarios including single sign-on (SSO).&#8221; <sup><a href=http://en.wikipedia.org/wiki/SAML_2.0>1</a></sup></p>

<p>One of the big questions when considering the use of SAML is who are you going to trust to be your SAML provider?&nbsp; As we hear of more security &#8220;incidents&#8221;, organizations that we talk to are questioning the wisdom of allowing someone else to host their credential data and are interested in being their own SAML provider. With the upcoming release of ARMS 2.1.0 you will now be able to be your own SAML provider and able to direct applications that can leverage SAML for authentication, such as Salesforce.com, Google Apps, Zendesk, etc, to your system for authentication.</p>

<p>If you want to learn how you can implement your own SAML Authentication Provider, please <a href="/company/contact-us">contact</a> our Sales Team today! 
</p>
      </description> 
      <dc:subject></dc:subject>
      <dc:date>2011-06-15T16:26:47+00:00</dc:date>
    </item>

    <item>
      <title>Identity in Education</title>
      <link>http://www.identityautomation.com/site/single/identity-in-education</link>
      <guid>http://www.identityautomation.com/site/single/identity-in-education#When:16:36:11Z</guid>
      <description>
      	<p>As school districts across the United States grapple with budget shortfalls, these same organizations face increased expectations for services to staff, students and parents.</p>

<p>Over the past three to five years we have seen an increase in the need for Identity Lifecycle Management needs for all district staff and we have been actively engaged with districts all across the US to implement solutions that facilitate the fulfillment of this need without creating a bottleneck in IT and minimizing the impact to the IT organization.&nbsp; As districts step out to provide services to students, the need for automation becomes increasingly important due to the sheer number of accounts that must be managed.&nbsp; Adding parents to the list of users makes the task of automated account management absolutely paramount.&nbsp; We have also found that it is just as important to provide facilities for users to manage their accounts (e.g. password recovery, user association, etc) so the users are able to achieve their goals as quickly as possible without having to rely on Helpdesk or other staff to manage their accounts for them.</p>

<p>Our Data Synchronization System and Access Request Management System are the most cost effective tools on the market today that achieve these goals without adversely impacting your budget.</p>

<p>If you want to learn how you can implement a fully automated Identity Lifecycle Management system in these lean times so you are able to meet the demands of your customers yet do so at a very reasonable cost, please <a href="/company/contact-us">contact</a> our Sales Team today!
</p>
      </description> 
      <dc:subject></dc:subject>
      <dc:date>2011-04-04T16:36:11+00:00</dc:date>
    </item>

    <item>
      <title>Data Access Management Failure</title>
      <link>http://www.identityautomation.com/site/single/data-access-failure</link>
      <guid>http://www.identityautomation.com/site/single/data-access-failure#When:00:22:14Z</guid>
      <description>
      	<p>Protection of your organization&#8217;s data assets is critical to ensuring your competitive edge as well as to fulfilling your fiduciary responsibility.&nbsp; Failure to implement systems to guarantee the enforcement of company policies for data access can cause serious legal troubles and shake the confidence of your customers.</p>

<p>Following is a recent story that documents how a terminated employee still has access to his former employer&#8217;s  computers systems months after his departure.</p>

<p><a href="http://www.nzherald.co.nz/nz/news/article.cfm?c_id=1&amp;objectid=10701805" onclick="return ! window.open(this.href);">New Zealand Herald - Telecom&#8217;s customer data open to ex staff</a></p>

<p>Identity Automation&#8217;s Identity, Data and Access Management solutions can ensure that your organization enforces best practices to mitigate these types of risks.</p>

<p>For more information, <a href="/company/contact-us">contact</a> our Sales Team today!</p>


      </description> 
      <dc:subject></dc:subject>
      <dc:date>2011-02-25T00:22:14+00:00</dc:date>
    </item>

    <item>
      <title>The Value of Automated Provisioning</title>
      <link>http://www.identityautomation.com/site/single/the-value-of-automated-provisioning</link>
      <guid>http://www.identityautomation.com/site/single/the-value-of-automated-provisioning#When:17:04:39Z</guid>
      <description>
      	<p>Recently I was reviewing some provisioning statistics for one of our customers using our ARMS and DSS products.&nbsp; I see these statistics on a daily basis because we build that into all of our IDM solutions.&nbsp; This week I took a minute more to really look at the numbers and put them in perspective.&nbsp; Here are the statistics for student provisioning at this customer site for a 24-hour period:</p>

<div style="width:50%;">
<table>
<tr><td>Accounts Created:</td><td align="left">532</td></tr>
<tr><td>Accounts Updated:</td><td>1,104</td></tr>
<tr><td>Accounts Moved (campus change):</td><td>227</td></tr>
<tr><td>Group Membership Changes:</td><td>56</td></tr>
</table></div>

<p>Now these numbers are only a subset of the total transactions that are automated or delegated outside of the IT department using our products.&nbsp; For example, these numbers don&#8217;t include staff provisioning transactions or password resets.</p>

<p>With that in mind, how many staff would be required to deal with this many transactions on a DAILY basis?&nbsp; The reality is that each transaction, when done manually, takes quite a bit of time.&nbsp; It requires time to request the change, review the change, implement the change, validate the change and communicate the change.&nbsp;  To put a number to that, let&#8217;s say each transaction requires a total person effort of 10 minutes.&nbsp; Using the numbers above, that totals 19,190 minutes (or 319 hours or 40 days)!!</p>

<p>The reality is no organization can handle that load from a resource perspective.&nbsp; The obvious deduction then is that these transactions just aren&#8217;t occurring without &#8220;full&#8221; automation.&nbsp; By that I mean an automated solution that deals with all of these transactions, not just one or two transactions.&nbsp; That means many accounts are not getting created, updated, moved, disabled, etc. either in a timely manner or at all.</p>

<p>Another way to look at the value is to put a cost to each transaction.&nbsp; How much does is cost an organization to deal with these transactions manually?&nbsp; Research firms often use $25 as a per transaction cost.&nbsp; This includes factors such as the salaries, benefits, lost work, etc.&nbsp; Using our transaction numbers above, the daily cost for handling every transaction would be $47,975/day or a whopping $12,473,500/year!!</p>

<p>Now, I&#8217;m not saying you&#8217;ll save $12 million a year by automating your account management.&nbsp; The point is that automation is absolutely a great value for any organization.&nbsp; Again, this is only one piece of the IDM puzzle.&nbsp; This doesn&#8217;t cover other features offered by our ARMS and DSS products to provide delegated administration, group membership automation, contingent worker management and workflow.&nbsp; It also doesn&#8217;t cover the audit and compliance benefits that are gained by keeping track of all events related to identity.</p>

<p>I sent an email to the customer who&#8217;s numbers are reflected above.&nbsp; Here&#8217;s the response:</p>

<p><strong><em>&#8220;Incredible. I did not think we had that much volume.&nbsp; A very effective investment!&#8221;</em></strong></p>

<p>The reality is that most organizations don&#8217;t have a baseline for how many identity-type transactions they manage on a daily basis.&nbsp; That is usually not realized until after the automated solution is put into place (assuming the solution tracks those statistics).&nbsp; Every organization is different.&nbsp; The volume of transactions is also going to be different.&nbsp; Regardless, identity management is important to all organizations. The primary benefit for each organization could be costs savings, reducing errors, compliance, improved customer satisfaction or some other factor.&nbsp; All of these are valid and the reality is that all of them are achieved every time we implement our products.</p>

<p>For more information about our solutions, <a href="/company/contact-us">contact</a> our Sales Team today!
</p>
      </description> 
      <dc:subject></dc:subject>
      <dc:date>2011-01-07T17:04:39+00:00</dc:date>
    </item>

    <item>
      <title>Increasing List of Mandates</title>
      <link>http://www.identityautomation.com/site/single/increasing-list-of-mandates</link>
      <guid>http://www.identityautomation.com/site/single/increasing-list-of-mandates#When:15:58:51Z</guid>
      <description>
      	<p>The list of regulatory and other mandates that require some level of Identity Management is ever growing. Having a documented process and then relying on people to follow those processes is not enough to ensure compliance to these mandates. The only real solution to mitigate process breach is to implement systems to guarantee access controls.</p>

<p>If your organization is subject to CFATS, SOX, HIPPA, FISMA, FERPA, PCI or any other mandate that requires auditable access controls then the implementation of an Identity Management and Workflow system are imperative to ensuring compliance.&nbsp; That being said, all IDM and Workflow solutions are not the same!&nbsp; Before making a technology choice, be sure that the solution you choose is easy to use and does not overly burden your staff or create bottlenecks and roadblocks that could hinder productivity.</p>

<p>Identity Automation has years of experience implementing solutions to fully manage the Identity Lifecycle within computing systems across the enterprise and are experts at access control and workflow which are at the heart of effective implementations of these systems.</p>

<p>For more information, <a href="/company/contact-us">contact</a> our Sales Team today!</p>


      </description> 
      <dc:subject></dc:subject>
      <dc:date>2010-11-19T15:58:51+00:00</dc:date>
    </item>

    <item>
      <title>Delegating Account Management</title>
      <link>http://www.identityautomation.com/site/single/delegating-account-management</link>
      <guid>http://www.identityautomation.com/site/single/delegating-account-management#When:16:59:05Z</guid>
      <description>
      	<p>As we have the privilege of talking to customers about their Identity Management needs, one of the requests that comes up over and over again is around the delegation of Account Management.&nbsp; </p>

<p>There are many use cases where delegation makes sense. One that we run into daily is the need for teachers to be able to unlock accounts or reset passwords for students. Allowing this capability to flow to the teacher level greatly improves user experience, ensures immediate resolution to the user&#8217;s problem while freeing IT up to focus on more strategic initiatives.</p>

<p>Another use case is giving managers the ability to reset passwords for employees.&nbsp; Just like the example above, delegating this responsibility improves user experience while shifting the responsibility to those closest to the challenge.</p>

<p>If you need a solution that requires a some level of delegated account administration with complete audit capabilities, give us a <a href="/company/contact-us">shout</a> and let us see how we can help.
</p>
      </description> 
      <dc:subject></dc:subject>
      <dc:date>2010-10-15T16:59:05+00:00</dc:date>
    </item>

    <item>
      <title>Managing the Cloud</title>
      <link>http://www.identityautomation.com/site/single/managing-the-cloud</link>
      <guid>http://www.identityautomation.com/site/single/managing-the-cloud#When:12:31:27Z</guid>
      <description>
      	<p>We work with organizations every day that consume a number of their services from &#8220;the cloud&#8221;.&nbsp; For many commercial and government customers these are services like Google Apps or Zendesk.&nbsp; For education customers, we see a lot of Live@EDU, Google Apps and Raptor V-Soft but the list of service providers is endless.</p>

<p>We all know that managing identity and access within our internal systems is challenging enough and the idea of extending this to cloud based services can be the cause of a lot of concern.</p>

<p>One way to deal with this is to implement an on premise Identity Management solution using tools such as our Data Synchronization System (DSS) and Access Request Management System (ARMS). Another option is to leverage our hosted solutions for synchronization, which we offer for systems such as Zendesk, KeepnTrack, Google Apps, Live@EDU and Raptor V-Soft. </p>

<p>Taking this approach means quick implementation, reduced burden on IT staff, increased service-levels and fast ROI.</p>

<p>If you would like to learn more about our hosted and on premise Identity, Data and Access Management solutions please <a href="/company/contact-us">contact us</a> today.</p>


      </description> 
      <dc:subject></dc:subject>
      <dc:date>2010-09-29T12:31:27+00:00</dc:date>
    </item>

    <item>
      <title>Privileged User Access</title>
      <link>http://www.identityautomation.com/site/single/privileged-user-access</link>
      <guid>http://www.identityautomation.com/site/single/privileged-user-access#When:15:54:07Z</guid>
      <description>
      	<p>I have been around Information Technology for 20 years and managing Privileged User Access has always been a challenge.</p>

<p>Different organizations handle this issue in different ways.&nbsp; Some choose to share the password for super user accounts (root / administrator) with folks across the IT department so work can be done without hindrance.&nbsp; The problem with this approach is you can&#8217;t tell who did what since the logs don&#8217;t actually reveal who the account user was.&nbsp; There is also the issue around password changes for these accounts which oftentimes never occurs because communication of those changes is too painful.&nbsp; Other organizations come at the problem from another perspective.&nbsp; Rather than sharing the password for the super user account, they instead, perpetually elevate certain users to a super user status.&nbsp; This approach is better since activity is now logged at the user level but having too many users with such highly elevated privileges is not a best practice and depending on your organizations account management process could leave the organization at risk if one of these users is terminated.</p>

<p>A far better approach is to grant access to super user privileges only when it&#8217;s required and for a limited period of time.&nbsp; Identity Automation&#8217;s ARMS Workflow system provides a way of doing exactly that.&nbsp; Implementation can be as unique as the organization; following are some examples.</p>

<ul>
<li>Create a workflow request that allows members of a certain group to be automatically granted super user status for a limited duration of time upon initiating their request.&nbsp; After the prescribed amount of time has elapsed, super user access will automatically be revoked.</li>
<li>Create a workflow that allows members of IT to request super user access but require approval from an IT manager or Director before access is granted. After a certain amount of time, the access would be automatically revoked.</li>
<li>Create a workflow that allows certain members of IT to &#8220;check out&#8221; the Administrator account so they can perform certain administrative functions.&nbsp; After a prescribed period of time the Administrator account password is automatically changed and the Administrator &#8220;assignment status&#8221; is reset.</li></ul>

<p>The possible implementation scenarios are endless but the important thing is to have a viable solution in-place that ACTUALLY works and limits risk to the organization, is scalable and is fully auditable.</p>

<p>For more information on how you can use ARMS Workflow to manage Privileged User Access, please <a href="/company/contact-us">submit your contact information</a> and one of our sales representatives will contact you.
</p>
      </description> 
      <dc:subject></dc:subject>
      <dc:date>2010-08-13T15:54:07+00:00</dc:date>
    </item>

    <item>
      <title>Total Cost of Ownership</title>
      <link>http://www.identityautomation.com/site/single/total-cost-of-ownership</link>
      <guid>http://www.identityautomation.com/site/single/total-cost-of-ownership#When:15:43:45Z</guid>
      <description>
      	<p>Taking on a new solution, even one designed to lower costs, manage growing complexities, and mitigate ongoing risks, always carries a cost of ownership.&nbsp; This is seen in software maintenance costs, often times an increased server footprint, and even in continued staff training and keeping their skill sets current on the technology.&nbsp; More and more, we have to look beyond the benefit of the solution to the organization, and weigh carefully the total costs of owning the solution. </p>

<p>We consider all information technology assets and solutions moving in the direction of &#8220;the cloud.&#8221;&nbsp; Organizations want to capitalize IT, and remove it from their overhead as much as possible. To do this organizations are looking more and more at hosted solutions, software-as-a-service vendors, and outsourced IT. </p>

<p>A couple of years ago, there was no strategy to deliver Identity Management Solutions in any way other than a significant server footprint on-site, typically occupying multiple servers (physical and VM) with high availability and fail-over.&nbsp; This data center growth to accommodate the solution impinged on any immediate ROI, and made the solution more costly to manage in the long term.&nbsp;  </p>

<p>With our shift in strategy we fully embrace the new hosted and service oriented delivery of identity management, giving our customers a turn-key identity management solution without the need to parse out data center space, or to keep their staff resources concerned with new technology.&nbsp; Identity management for our customers is now a service that is out of the day to day concern, and provides automated provisioning and workflow management through a simple web-UI that is both intuitive and clean.&nbsp; As customer needs shift, or changes are required to the solution to accommodate internal policy, we manage the solution to bring it into alignment. </p>

<p>This strategy is proven to lower TCO, and allows our customers to achieve a real ROI in a fraction of the time of a traditional IDM deployment.</p>

<p>For more information on how our solutions can help lower your TCO, please <a href="/company/contact-us">submit your contact information</a> and one of our sales representatives will contact you.
</p>
      </description> 
      <dc:subject></dc:subject>
      <dc:date>2010-07-02T15:43:45+00:00</dc:date>
    </item>


    
    </channel>
</rss>
