Skip the navigation
)
Review

Hands on with Microsoft Forefront Identity Manager 2010

The tool's key differentiators: User self-service and broad compatibility with other software

By Jonathan Hassell
July 21, 2011 06:00 AM ET

Computerworld - Identity management is the bane of many an IT administrator's existence. Employees come and go. Workers from partner companies require access to the network in a time-limited but secure way. Users forget their passwords and lose their smartcards. And new services come online all the time. It's a wonder anyone can get anything done.

There have been tools available for a while that purport to manage the total life cycle of user identity -- from hiring and first authorization to use of new applications until suspension, termination or separation -- all from one system. Microsoft's entry into this market, Forefront Identity Manager 2010, shows itself as a capable product with a few drawbacks.

Forefront Identity Manager 2010, or FIM, relies on a couple of features to differentiate itself from competitors: It gives users the ability to perform a variety of tasks themselves via self-service Web portals, and it's compatible with existing Web standards, enabling it to work with just about any other system.

How we tested

I reviewed FIM in a Hyper-V virtual environment with two Active Directory domain controllers, an Exchange machine and FIM 2010 servers in two different Windows domains. All of this was housed on a single Dell rack-mounted server. While this is clearly not a production setup, it was a useful testbed for ensuring that FIM worked as advertised. In addition, over the course of 2010, I had the opportunity to deploy FIM in a production environment with a business-services firm that has four heterogeneous systems and more than 2,500 users. I found that my experiences with the client deployment and the tests in my lab environment were very similar.

Users can, for example, change their passwords on a variety of systems through native Windows tools like the log-on prompt. They can also manage group memberships easily through an intranet-based website that supports restricted group memberships and the approval workflows required.

Behind the scenes, FIM takes care of managing encrypted properties like certificates, smartcards, security life cycles and compliance, while wrapping it up in a nice bow with a good, logically arranged administrative user interface.

Policy management

FIM's view of identity management is that employees, their roles and their eventual authorizations and authentication should all fall under the purview of policies. Administrators familiar with Group Policy in Windows will find this metaphor holds well. These policies consist of rules that you, as the administrator, can create to dictate what happens when certain actions take place.

For example, a new-hire rule will create a user account and place him or her into appropriate groups based on date of hire, job position, work location and other factors. The same rule will query and direct the payroll system, via Web services, to add the requisite user information and will interface with the building security system to add the user's smartcard certificate to allow access to the building. Finally, the rule will generate a message to human resources to create a new-hire packet and send it to the new user.

Identity management

You can imagine similar policies for, say, maternity leave, where, for a defined period of time, a user's building access would be suspended, her e-mail would be redirected, and pay and other HR policies would be modified as necessary and so on. But perhaps most important for security is the ability to manage separations from the company -- turning off access, removing users from security groups and cleanly and tidily processing financial matters.

Policies within FIM can dictate the actions that happen when any of these events -- or any other event that you define -- occur.

These policies that you define are kicked off and then subsequently managed by the Windows Workflow Foundation, or WF (part of the .Net Framework 3.5). WF provides a powerful base for all sorts of interesting and complex workflows, with nesting, conditions and multiple branches. If your group has already invested in creating rules via WF, you can very simply import them into FIM and use and further customize them from within FIM, saving you from reinvesting the time necessary to create the workflows again in a different tool. If you have a proficient developer staff, you can also create workflows in Visual Studio and export them for use within FIM.

Data synchronization

The core of any identity management product, FIM included, is the ability to keep multiple systems --often on different platforms, from different vendors, with different databases -- synchronized as often as possible. The goal is for changes initiated by any system to be replicated accurately and efficiently up and down the chain of related systems.

FIM's predecessor, Microsoft Identity Lifecycle Manager 2007, did a pretty good job of handling such synchronization among Microsoft products. FIM 2010 goes a step further and offers help with making sure databases like Novell eDirectory, Sun Directory Server, Lotus Notes, SQL Server, Oracle, Exchange, Active Directory, SAP and any other database or flat-file systems are updated via policies and workflows.

FIM's core, a synchronization service, manages the data coming into and out of FIM and handles communicating with the target systems -- and in most cases it does so using standards or direct API support with each system. In other words, no messy agents need run on most of these systems.



What is Tech Briefcase?
TechBriefcase is a new, free service where IT Professionals can Search, Store and Share IT white papers and content like this. Learn more
Bookmark content
Speed up your research efforts with content across the web.
Search and Store
Find the white papers you need. Create folders for any topic.
View Anywhere
Open your briefcase on your iPhone, tablet or desktop. Share with colleagues.
Don't have an account yet?
Additional Resources
Security KnowledgeVault
WHITE PAPER
Security is not an option. This KnowledgeVault Series offers professional advice how to be proactive in the fight against cybercrimes and multi-layered security threats; how to adopt a holistic approach to protecting and managing data; and how to hire a qualified security assessor. Make security your Number 1 priority.

Read now.

Cut Communications Costs Once and for All
WHITE PAPER
New IP-based communications systems are being deployed by small and midsized businesses at a rapid rate. Learn how these organizations are enabling faster responsiveness, creating better customer experiences, speeding office or mobile interactions, and dramatically reducing existing communications costs.

Read now.

Infrastructure Management White Papers
Database Activity Monitoring Is Evolving
Read the analyst report and learn how you can leverage the core capabilities of a DAP solution for better database security.
Thinking Outside The Data Warehouse
This high level, business problem focused eBook uses 5 customer scenarios to show how people and organizations are tackling real issues using IBM...
Using BD for Smarter Decision Making
This paper looks at new developments in business analytics and discusses the benefits analyzing big data bring to the business.
Virtualizing the Client - The HP Way
HP VirtualSystem delivers best-in-class virtualization, with integrated software, services, infrastructure, and management - all delivered as one proven solution.

Intel and the Intel logo...
Gartner on the Network Infrastructure Market
The network infrastructure market has evolved rapidly, from one in which most organizations adhered to a single-vendor architecture to a more business-driven network...
All Infrastructure Management White Papers
Infrastructure Management Webcasts
Distributed Database Security with Real-time Monitoring
View this demo and learn how IBM InfoSphere Guardium database activity monitoring can help protect your sensitive data in distributed DBMS environments with...
InfoSphere Warehouse Packs Demo
These flash modules make warehousing more tangible and relevant to business users through detailed explanations of the InfoSphere Warehouse Packs.
Delivery Management -- Extending Lifecycle Management
Date: Wednesday, June 20, 2012, 1:00 PM EDT

Siloed organizations continue doing the wrong things and doing things wrong, leading to increased costs,...
Improve Data Center Efficiency through Building-Performance Lighting and an Intelligent Infrastructure
IT managers are under pressure to improve efficiency in their data centers. Please join Redwood Systems, CommScope and MegaWatt Consulting to learn how...
Leverage automation today to reduce IT complexity
Date: Tuesday, June 5, 2012, 2:00 PM EDT

Whether your B2B complexity is caused by multiple technologies due to M&A, business or application specific...
All Infrastructure Management Webcasts
Newsletter Sign-Up

Receive the latest news test, reviews and trends on your favorite technology topics

Choose a newsletter
  1. View all newsletters | Privacy Policy
IT Jobs