18 questions to ask for Active Directory implementation with an Identity Manager tool

Active Directory is the most popular target system to be integrated with any identity solution ( One Identity Manager ,OpenIDM by Forgerock, IdentityIQ or IdentityNow by Sailpoint, Okta, One Login,etc.) . As part of your vendor initial discovery phase to identify the company business cases, your team needs to be prepared to respond the following questions:

  1. Who/Which team is the owner of Active Directory?
  2. What’s their availability to participate in this project?
  3. What is your Active Directory version?
  4. Are there any plans for upgrading/migrating/updating AD?
  5. Does your AD schemas was extended? Which attributes? is there any custom extended attribute required to be handled by the identity solution?
  6. Do you have development, test, and prod Active Directory environments?
  7. are the data in the lower environment Production-like?
  8. What will be the effort to refresh the lower environments with production-like data?
  9. Who has permission to create AD Accounts? Only admins? Help Desk?
  10. Is your AD synchronized with external systems/3rd party vendors? i.e Okta, AzureAD, ServiceNow
  11. Is the Active Directory single or multiple domains?
  12. How is your OU structure?
  13. How many AD Users? are all the users populated with a manager?
  14. How many AD Groups? are all the groups populated with Group Owner?
  15. Can users have multiple accounts in Active Directory? How do you identify them?
  16. What user types are supported by Active Directory? Employees, Non-employees, Contractors, Vendors, etc.
  17. Do you write back any AD attribute to other systems?
  18. Describe the process for creating, updating & terminating Active Directory accounts.

All these question will help you to start your conversation and drive the discovery phase. Certainly there are a lot more question that can be addressed, but we will talk about them in future posts.

If you want to include more questions on this list, please send us an email to aidy.allidm@gmail.com

We are available to support your company and provide our best practices during this phase if you need.