Authoritative source or Identity store is the source of the data that flow down to the Identity Management System. An authoritative source or identity store is simply a directory or database that contains people’s identity detail. Usually this Authoritative source contains information like employeeId, fistname, lastname, telephone, e-mail, department, etc.
One of the challenges to implement the Identity Management solutions is to determine what the Authoritative source is. Sometimes the information or the identity data is not consolidated in one place and the Identity Management system needs to pull out identity data from multiple locations (Human Resource System, Directory Server System, Paper or any other company identity source).
A good practice when the company doesn’t have a unique authoritative source is to use a virtual directory, database view or table just for identity management system.
Some common authoritative sources are:
- Microsoft’s Active Directory, Novell’s eDirectory, the SunONE directory
- MySQL , DB2 for MVS applications, Oracle for Oracle applications, SQL for .NET applications
To start gathering the requirements from the Authoritative source on identity management solution, you need to ask:
o Do you have identified your authoritative sources?
o What’s your authoritative source?
o Is there an HR database involved?
o How unique id’s are generated for employees?
o What is my corporate identity store?
o Is there a single authoritative identity store where all my users reside?
o Do you have more than one authoritative resource?
o How many data sources are there?
o How often is the data updated?
o What attribute are available?
o Which attributes uniquely identify users?
o Which attribute identify a user state? What states exist?
o In what format is the data available?
o Which attributes are unique?
o Which attributes are required?
o Which attributes are multi-valued?
o How will missing values is handled?
o Are there default values?
o Do we need a clean up before push those data into the identity management solution?
o Which attribute will always have values? Which might have multiple values?
o Are there attributes that must be set on create, but not when modifying a person?
- Discover Silent Identity and Access Management
- Idaho State University to Outsource Identity & Access Management to Fischer International Identity
- SailPoint Successfully Completes ISO/IEC 27001:2013 Certification
- Entersekt Partners With ForgeRock
- One Identity Password Manager 5.7.1 Public Hotfix for Solution 240434 – Dictionary rule does not work when SYSVOL folder is not in the default location
- Microsoft, the ID2020 Alliance, universal digital identification and you
Top Posts & Pages
- Installing Dell One Identity Manager 7.0
- Gartner Magic Quadrant for Identity Governance and Administration 2014
- Oracle 11g error WFMLRSVCApp.ear file missing during Installation
- Installing PWM (Open Source Password Self Service for LDAP directories)
- ImportError: no module named security during the OPSS Oracle Identity Manager 11gR2 Installation