Welcome

Thank you for taking time to visit my blog. My name is Drew Olson and I hope to use this space to share ideas and generate conversation regarding identity and access management

This form does not yet contain any fields.
    Recent Postings
    « Can an identity management solution save lives? | Main | New Account Request - Parent Accounts Becoming the Norm? »
    Thursday
    Feb102011

    Cloud Computing and Identity Management - Live@edu 

    By far, one of the biggest and most talked about trends over the past few years has been the shift to cloud computing and the proliferation of SaaS across almost all vertical industries. Although, there is still much debate centering around security and how to best manage these new systems, it is apparent that most organizations are still eagerly moving forward to the cloud. 

    Some of the biggest shifts and perhaps least surprising, have been the move to hosted email and storage solutions from Google Apps and Microsoft Live@edu and Outlook Live, especially in the education and government sectors.  The cost benefits here seem to be the driving factor in these markets and with good reason. However, this makes it much more imperative that these organizations employ measures to better manage user identity and data security to prevent unnecessary risks and a loss of functionality to their users. It makes sense then that these clients either leverage their existing provisioning solutions or employ a new process as part of their implementation.

    A good number of these organizations have approached Tools4Ever in order to incorporate their Live@edu connector as part of the rollout of this hosted solution. A major component of these implementations is the use of Live@EDU Dynamic Distribution Groups (“DDGs”) which can be very powerful because they allow you to have large mailing lists without the need to maintain individual memberships.

    As consultant Ivan Jouikov noted though, traditionally, if you wanted to maintain large mailing lists per-school, you would simply set up a group like BlackHawk@mydistrict.com, and then add all the students’ emails into that group.  You would also have to maintain that membership list, as students change the schools or graduate.

    DDGs use filters to determine their members, rather than maintaining an actual membership list.  When an email is sent to a DDG, it finds its members by running a search like “all users whose Live@EDU Department is set to BlackHawk”.  This lets you maintain many various DDGs, without having to manage their membership lists.

    However, what if the student changes their school?  Unless their Live@EDU Department is set to the new school, they will keep receiving mail from the old DDG, but not the new one.  This means that to truly leverage the power of DDGs, you need to constantly keep the “Department” attribute updated for all of the student accounts. These and other changes do occur, and this can create an overhead nightmare keeping updates in check and data consistent.

    That’s where UMRA comes in and something the solution has been doing for some time now  -  provisioning accounts and their attributes.  In case of schools, we would constantly provision students’ Live@EDU Departments (from SIS data) to fully leverage DDGs.

    This way you can have mailing lists like:

    -          Per-school

    -          Per-grade

    -          Per-class

    -          Per-any-SIS-attribute

    -          Per-School & Per-Grade

    -          Any combination of the above

    -          …all with memberships maintained automatically

    Take it one step further –with UMRA we can provision the DDGs themselves! This means we can set up something like class-driven DDGs that get created and deleted automatically, as classes are created and removed in the SIS. 

    DDGs are a “hidden” feature of Live@EDU – they don’t appear on the administrator GUI (though they will show up in GAL (global address book), if that’s what we want).

    A process as simple as this can really help you make the most of your Live@edu solution and greatly simplify the management of users and groups in this system.  I will be posting much more information regarding to Live@edu and Google Apps, so please follow this blog for future information.

     

    PrintView Printer Friendly Version

    EmailEmail Article to Friend

    Reader Comments (3)

    Thanks for this post Drew. I had known about Live@EDU, and am pushing to try to do something like this for our students. I hadn't looked into it too closely yet to find out about DDGs yet.

    When we do go that route though, I'm glad that UMRA already has the connectors for provisioning and management!

    February 13, 2011 | Unregistered CommenterGeorges Khairallah

    Thanks for responding Georges! Yeah, definitely the majority of our K-12 and Higher Ed implementations include integration with Google Apps and Live@edu. I personally believe both are and will continue to be tremendous options for school districts. I will be continuing to post information here regarding both.

    Thanks again!

    February 14, 2011 | Registered CommenterDrew Olson

    I really do appreciate your feedback. I'm still struggling with the technology but I wish everyone all luck with this competition. I've been pinned down with a sick grandchild and today a very sick daughter - both with gastric flu which afflicts us all at this time of year - so this is the first moment I've had to get to the computer anqytw anqytw - mulberry bags outlet.

    December 17, 2011 | Unregistered Commenterykwung ykwung

    PostPost a New Comment

    Enter your information below to add a new comment.

    My response is on my own website »
    Author Email (optional):
    Author URL (optional):
    Post:
     
    Some HTML allowed: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <code> <em> <i> <strike> <strong>