Oracle Identity and Access Management

Similar documents
1z0-479 oracle. Number: 1z0-479 Passing Score: 800 Time Limit: 120 min.

COMPONENTS/PRODUCTS IN OIM

OpenIAM Identity and Access Manager Technical Architecture Overview

Oracle Identity Governance 11g R2: Develop Identity Provisioning

1Z Oracle Identity Governance Suite 11g PS3 Implementation Essentials Exam Summary Syllabus Questions

Increase user productivity and security by integrating identity management and enterprise single sign-on solutions.

Question: 1 Which item must be enabled on the client side to allow users to complete certification in offline mode?

Oracle Identity Governance 11g R2 PS2

Oracle Identity Manager 11g R2: Essentials

X100 ARCHITECTURE REFERENCES:

Novell Access Manager 3.1

Oracle WebLogic Server 12c: Administration I

Oracle Access Manager Integration Oracle FLEXCUBE Payments Release [Feb] [2018]

Contents Introduction... 5 Configuring Single Sign-On... 7 Configuring Identity Federation Using SAML 2.0 Authentication... 29

Oracle Access Manager Oracle FLEXCUBE Universal Banking Release [May] [2017]

Oracle Identity Governance 11g R2: Develop Identity Provisioning

Oracle Access Manager Configuration Guide

DreamFactory Security Guide

Introduction... 5 Configuring Single Sign-On... 7 Prerequisites for Configuring Single Sign-On... 7 Installing Oracle HTTP Server...

SAP Security in a Hybrid World. Kiran Kola

hidglobal.com HID ActivOne USER FRIENDLY STRONG AUTHENTICATION

The Modern Web Access Management Platform from on-premises to the Cloud

Office 365 and Azure Active Directory Identities In-depth

Sentinet for Microsoft Azure SENTINET

Inside Symantec O 3. Sergi Isasi. Senior Manager, Product Management. SR B30 - Inside Symantec O3 1

Oracle Identity Manager 11gR2-PS2 Hands-on Workshop Tech Deep Dive Upgrade

Integration Framework. Architecture

API Manager Version May User Guide

BEYOND AUTHENTICATION IDENTITY AND ACCESS MANAGEMENT FOR THE MODERN ENTERPRISE

Sentinet for BizTalk Server SENTINET

DigitalPersona Altus. Solution Guide

Oracle Adaptive Access Manager Basic Oracle Access Manager Integration

Oracle Access Management 12c Frequently Asked Questions (FAQ)

CA IdentityMinder. Programming Guide for Java. r12.6.1

Identity Provider for SAP Single Sign-On and SAP Identity Management

Integrating Hitachi ID Suite with WebSSO Systems

Copyright 2013, Oracle and/or its affiliates. All rights reserved.

1 Copyright 2011, Oracle and/or its affiliates. All rights reserved. Insert Information Protection Policy Classification from Slide 7

1 Hitachi ID Group Manager. 2 Agenda. Managing the User Lifecycle Across On-Premises and Cloud-Hosted Applications

Oracle Payment Interface Token Proxy Service Security Guide Release 6.1 E November 2017

CA CloudMinder. Administration Guide 1.52

DEPLOYMENT GUIDE DEPLOYING F5 WITH ORACLE ACCESS MANAGER

Actual4Test. Actual4test - actual test exam dumps-pass for IT exams

Build Mobile Cloud Apps Effectively Using Oracle Mobile Cloud Services (MCS)

Introduction With the move to the digital enterprise, all organizations regulated or not, are required to provide customers and anonymous users alike

CA IdentityMinder. Glossary

Oracle Web Service Manager Implementation Guide Oracle FLEXCUBE Universal Banking Release [April] [2014]

Ramnish Singh IT Advisor Microsoft Corporation Session Code:

Advanced Service Design. vrealize Automation 6.2

Integration Patterns for Legacy Applications

As you learned in Chapter 1, the architectural variations you can construct using

Implementing Security for ArcGIS Server Java Solutions

ENTERPRISE NETWORKS WLAN Guest Management Software

DEPLOYMENT GUIDE Version 1.0. Deploying the BIG-IP Access Policy Manager with Oracle Access Manager

BEAAquaLogic. Service Bus. JPD Transport User Guide

ORACLE IDENTITY MANAGER SIZING GUIDE. An Oracle White Paper March 2007

Oracle Access Management

Using the vrealize Orchestrator Operations Client. vrealize Orchestrator 7.5

Oracle WebCenter Interaction: Roadmap for BEA AquaLogic User Interaction. Ajay Gandhi Sr. Director of Product Management Enterprise 2.

Identity Management as a Service

John Heimann Director, Security Product Management Oracle Corporation

ActiveVOS Technologies

UiB 1. april 04. Sun Microsystems

Managing the Risk of Privileged Accounts and Passwords

SnapCenter Software 4.0 Concepts Guide

CA SSO Cloud-Enabled with SSO/Rest

Oracle WebLogic Server 11g: Administration Essentials

Chapter 2 WEBLOGIC SERVER DOMAINS. SYS-ED/ Computer Education Techniques, Inc.

1 Copyright 2011, Oracle and/or its affiliates. All rights reserved.

W H IT E P A P E R. Salesforce Security for the IT Executive

WebSphere Application Server, Version 5. What s New?

Getting Started with. Oracle SOA Suite 11g. R1 -AHands-On Tutorial. composite application in just hours!

Setting up Property File Oracle FLEXCUBE Universal Banking Version 12.0 [May] [2012]

CA SiteMinder Federation

<Insert Picture Here> Forms Strategies: Modernizing Your Oracle Forms Investment

IBM Exam IBM Tivoli Identity Manager V5.1 Implementation Version: 5.0 [ Total Questions: 158 ]

Contents Using the Primavera Cloud Service Administrator's Guide... 9 Web Browser Setup Tasks... 10

IBM Tivoli Identity Manager V5.1 Fundamentals

Integrating Legacy Assets Using J2EE Web Services

Copyright 2013, Oracle and/or its affiliates. All rights reserved. Insert Information Protection Policy Classification from Slide 12

E TRANS_ENTERPRISE PORTAL SECURITY MANAGEMENT

Goal: Offer practical information to help the architecture evaluation of an SOA system. Evaluating a Service-Oriented Architecture

Oracle Service Bus Integration Implementation Guide Oracle FLEXCUBE Universal Banking Release [April] [2014]

VMWARE HORIZON CLOUD WITH VMWARE IDENTITY MANAGER QUICK START GUIDE WHITE PAPER MARCH 2018

WHITE PAPER AIRWATCH SUPPORT FOR OFFICE 365

Oracle Fusion Middleware

XD Framework (XDF) Overview. For More Information Contact BlueSpace at Tel: (512) Web:

Technical Overview. Access control lists define the users, groups, and roles that can access content as well as the operations that can be performed.

A. ORA addresses all four (Business, Application, Information, and Technical) equally.

ShareFile Technical Presentation

Contents at a Glance. vii

Oracle Oracle Identity Manager 11g

Business White Paper IDENTITY AND SECURITY. Access Manager. Novell. Comprehensive Access Management for the Enterprise

Centrify for Dropbox Deployment Guide

Lab 1 - Getting started with OIM 11g

Oracle Mobile and Social Access Management

Laserfiche Rio 10.3: Deployment Guide. White Paper

The Value of Migrating from Cisco Tidal Horizon to Cisco Process Orchestrator

API, DEVOPS & MICROSERVICES

Oracle Communications Services Gatekeeper

Transcription:

Oracle Identity and Access Management

AGENDA Overview Features Components Customizations APIs Oracle Identity Manager Connectors High Availability Concepts High Availability Architecture

OVERVIEW Identity & Access manager is a framework of business processes that facilitates the management of electronic or digital identities. What is your Identity? National ID Email Title Mobile Identity Date of Birth Name Credit Card No

OVERVIEW Identity & Access manager is a framework of business processes that facilitates the management of electronic or digital identities. What is your Identity on all these applications?

OVERVIEW Identity Self Service allows users to access the Unauthenticated Self Service Console by clicking the Forgot User Login?, Forgot Password?, New User Registration, or Track My Information links. What if you register only once?

OVERVIEW IDAM provides an authentication process that allows a user to access multiple applications with one set of login credentials. What if you Sign in only once?

OVERVIEW IDAM incorporates three major concepts: identification, authentication and authorization. Use of IDAM in Organizations?

FEATURES No Need to Change Existing Infrastructure Simplified Self Service Self registration, password management & request tracking. Eliminates Ghost Accounts/Access or Privileges Account effective dates. Comprehensive User Administration User, role and organization management. Reduces IT Operational Costs and Administration Overhead Centralize Audit Trails of Security Events Automatic Policy Enforcement Across Systems

COMPONENTS List of basic components required to deploy an IDAM solution. All of these components are deployed on WebLogic server. Oracle Access Manager (OAM) Oracle Identity Manager (OIM) Oracle Adaptive Access Manager (OAAM) Oracle Identity Federation (OIF) Oracle Unified Directory (OUD) Business Intelligence Publisher (BIP) Service Oriented Architecture (SOA) Oracle HTTP Server (OHS)

COMPONENTS- Oracle Access Manager Oracle Access Manager s Access System provides centralized authentication, authorization, and auditing to enable single sign-on and secure access across enterprise resources such as web and J2EE resources(jsp, Servlets, EJBs, etc.) and legacy systems. Single Sign On Session management, session expiration and timeout Password policies, password expiration Custom authentication plugins

COMPONENTS- Oracle Identity Manager Oracle Identity Management enables organizations to effectively manage the endto-end lifecycle of user identities across all enterprise resources, both within and beyond the firewall and into the cloud. User management Role management Organization management Provisioning & Reconciliation Connectors LDAP sync Track requests Pending approvals Password policies

COMPONENTS- Oracle Adaptive Access Manager Oracle Adaptive Access Manager is an innovative, comprehensive feature set to help organizations prevent fraud and misuse. It provides standard authentication mechanisms, innovative risk-based challenge methods. Real time risk analysis Security questions & answers One Time Password (OTP) Device fingerprinting Virtual authentication devices Search & compare transactions Policy management

COMPONENTS- Oracle Identity Federation Oracle Identity Federation enables business partners to achieve integration in the identity management realm, by providing a mechanism for companies to share identity information across their respective security domains. Transient Federation Session based federation May or may not have account with IDP/SP. Mapped Federation One to one linking of user account on IDP/SP. User account on IDP/SP with common attributes. Linked Federation No common attributes. Account linking based on UID, Employee code etc. Role Based Federation Based on Role of Identity manager/developer.

COMPONENTS- Oracle Unified Directory Oracle Unified Directory is a comprehensive next generation directory service. It is designed to address large deployments and to provide high performance, and is highly extensive. Oracle Unified Directory is easy to deploy, manage, and monitor. Data replication High availability Indexing Access control Virtualization Directory service schema Schema mapping

COMPONENTS- BI Publisher Oracle BI Publisher is the reporting solution to author, manage, and deliver all your reports and documents easier and faster than traditional reporting tools. Create any kind of report with any kind of data Generate report in any kind of format (excel, pdf, csv etc.) View at any kind of platform Link & filter with any kind of data Reports creation with no coding/scripting

COMPONENTS- SOA Oracle SOA Suite enables services to be created, managed, and orchestrated into SOA composite applications. Messaging Service discovery Orchestration Web services management & security Business rules Events framework Business activity monitoring

COMPONENTS- Oracle HTTP Server Oracle HTTP Server is deployed at top of IDAM components to accept and manage user requests based on internal configuration. HTTP listener Load balancing URL rewriting Proxy server capabilities mod_wl_ohs plugin

Customization This section describes utilities used to customize various components and features of Oracle Identity Manager. Event handlers Types: Preprocess, post process, validation, finalization Schedulers Plugins UI customization using ADF Custom workflows OIM, OAM & OAAM APIs Notification service Reports & audit

APIs Oracle provides a network-aware, Java-based application programming interface (API) that exposes Services. These APIs can be used for building clients for Oracle Identity Manager and for integrating third-party products with the Oracle Identity Manager platform. OIM API OAM API OAAM API

APIs- Oracle Identity Manager OIMClient Library is the entry point for accessing the APIs available in Oracle Identity Manager. It is used to make initial connection with Oracle Identity Manager to perform different tasks. UserManager API RequestService API RoleManager API OrganizaitionManager API SchedulerService API NotificationService API

APIs- Oracle Access Manager The oracle.security.am.asdk & com.oblix.access package provides the Oracle Access Manager 10g & 11g version of the Application Programming Interface (API). Oracle Access Manager Access SDK Java API Provides authentication and authorization API for compatibility with the OAM 10g and 11g. Oracle Access Manager Extensibility Java API Provides a set of authentication plugin interfaces and SDK tooling for customers to build customized authentication plugins, and to plug the customized authentication plugins into the system. Oracle Security Token Service Java API Allows developers to write classes that allow OSTS to issue and validate custom tokens.

APIs- Oracle Adaptive Access Manager OAAM native integration involves customizing the client application to include OAAM API calls at various stages of the login process. Native Integration SOAP service wrapper API for Java or.net applications In-Proc API for Java applications only Non Native Integration VCryptCommon contains the common APIs. VCryptTracker contains the APIs for fingerprinting and collecting authentication and transaction logs. VCryptAuth contains the APIs for accessing the Authenticator and KBA modules. VCryptRulesEngine contains the APIs for running the rules. VCryptCC contains the APIs for invoking customer-care-related requests.

Oracle Identity Manager Connectors Identity Connectors are used to integrate Oracle Identity Manager with external, identityaware applications. Provisioning You can use Oracle Identity Manager to create, maintain, and delete users on target systems. In this configuration, Oracle Identity Manager acts as the front-end entry point for managing user data on the target systems. Reconciliation Oracle Identity Manager periodically poll target systems data for maintaining an up-to-date profile of all accounts that exist on those systems.

High Availability Concepts High-availability clusters (also known as HA clusters or fail-over clusters) are groups of computers that support server applications that can be reliably utilized with a minimum amount of down-time. Protection from downtime Saves you from lost revenue Simplify maintenance Maximum flexibility Improve agility Lets have a look at IDAM high availability architecture on next slide

IDAM High Availability Architecture

Thank You GenX Info Technologies Pvt. Ltd. 411, 4 th Floor, Bestech Cyber Park National Highway-8 Gurgaon, Haryana, INDIA www.gen-xt.com, sales@gen-xt.com +91-124-2656001, +91-9810402267