Welcome

Thank you for taking time to visit my blog. My name is Drew Olson and I hope to use this space to share ideas and generate conversation regarding identity and access management

This form does not yet contain any fields.
    Recent Postings

    Entries in identity management (4)

    Monday
    Aug222011

    Identity Management Webinar - September 22, 2011. 11am PST

    View Details and Register Here

    Polluted user account databases, endless calls to the helpdesk for password resets, forgotten log in credentials to applications and systems – do these situations sound familiar? Organizations today are faced with a myriad of identity and access management issues. From managing the user lifecycle to single sign-on and even password reset options. No organization is immune to the need to implement organized, effective and cost efficient solutions to combat these issues. 

    Join Gary Oppel as he discusses the challenges his company faced with managing thousands of user accounts and how they brought in solutions that would allow for quick implementation with fast ROI. You will learn how Dwight & Church implemented an identity management solution that:

    • Automated the user lifecycle, provided provisioning and organized the Active Directory environment

    And how Dwight & Church plan to implement additional solutions to:

    • Reduce calls to the helpdesk for password related issues by implementing a password reset solution
    • Provide a single sign on solution to increase productivity and reduce calls to the helpdesk for access management issues
    Thursday
    Jul282011

    Summer Fun - From Helping the Helpdesk

    I came across a blog posting from a few years back at the Helping the Helpdesk blog and I thought it was worth reposting. Little has changed and we are still inundated with calls from school districts struggling to find a way to manage users accounts before the start of the new year. The approach described below follows Tools4ever's method for synchronizing student information systems such as PowerSchool, Infinite Campus, and Aeries with your Active Directory and other resources like Google Apps, Live@edu, Destiny and so on.  I hope you find the post helpful!


    Summer Fun

    The summer time means vacations, no school, hitting the beach, and all kinds of great fun. Unless of course, you are a system administrator for a school district. The summer then means you are squeezing in every major project that you can before school starts up again in August or September, depending on the region in which you reside. As such, the last thing you have time for is dealing with student active directory accounts.

    Yet, you will have an influx of new students. And depending on your organizational unit structure, you may need to roll over these accounts into new OU’s based on graduation year or grade level. Maybe these grad year or grade level OU’s are within a higher level OU for each school in the district. Perhaps each grad year or grade level has a specific share somewhere, on which the user’s home directories must reside. These home directories need to move with the student throughout his or her career in the district.Then, of course, there are group memberships, which most likely created within the same design as the OU structure.

    Manually provisioning all of this can take weeks. Scripting these tasks in visual basic is slow and tedious as well. With User Management Resource Administrator’s Automation module, you can streamline these tasks, and have them occur on a scheduled basis. Here is a high level overview of such a process:

    • UMRA queries the SIS system, or csv export of student information
    • This data is compared to AD
    • New accounts are created based upon existence in the SIS system and not AD
    • Updates to accounts occur based upon existence of the user in the SIS and AD
    • Account disables are based upon either an inactive flag in the SIS, or the lack of the account existing in the SIS when it exists in AD

    Processes for group and home directory provisioning can be based up a graduation year or grade level, even if this information is not necessarily provided (to be detailed in a coming post). Automation can be scheduled nightly, or more or less frequently as needed. All actions against AD accounts and their resources are logged for auditing and troubleshooting purposes. It can even generate email alerts for you.

    You are now free to (not) enjoy your summer break doing other tasks.

    You’re welcome. ;)


    For more information, please visit Tools4ever

    Friday
    Jul152011

    Data Breach #3: Patient Records Stolen at Univ. of Maryland Medical Center

    This breach outlines the dire consequences that can result when critical and extremely private personal data can be accessed by the wrong people.  In this case, employees who had open access to not only confidential patient data, but also billing information, were able to steal account info and rob elderly and vulnerable victims.

    The hospital contends that this was the result of a crime and not due to hospital procedures and this may be the case.  But health care organizations are going to have to change policies quick to restrict access to this type of information, or these type of stories will only increase with dire results for patients and the hospital alike.

    I contend that organizations should perform a review of their current identity management and protection policies to see how easy and how many employees could potentially compromise data, such as happened here at the University of Maryland Medical Center. I believe that an identity management solution that is well planned and implemented can allow health care organizations to restrict and monitor access to critical systems containing confidential information. In my own consulting work, I have heard from many security officers admissions of improper access; that too many people can easily access patient data.  An organization without an identity management policy is giving a huge advantage to these criminals.

    The story below is from the Baltimore Sun, July 14. http://www.baltimoresun.com/health/bs-md-identity-theft-20110714,0,3173292.story

     

     

    For information on Tools4ever identity management solutions and how they can benefit any health care organization, please click here.