Many organizations today already have web forms in place to handle requests for user accounts, access rights or other resources. Typically a manager can use such web forms from their intranet to announce the arrival or departure of an employee. They can request an account, mailbox, shares, groups or application rights. At the end of the form or workflow, a ticket arrives at the helpdesk who will then create the account and resources or request that this be done by the system administrators.
This time consuming and error prone work is directly entered in Active Directory or on other systems, and what’s more, it involves entering the same data as already exists in the help desk ticket.
Although UMRA has its own work flow management systems and the option to create web forms, we recently found a way to deploy UMRA in an existing situation. In the example of a financial institution, we configured UMRA to automatically process all the new tickets related to users, and their rights and resources.
The advantages:
• A short implementation time of 2 days to automatically process all tickets related to users and access rights;
• Saves a lot of time for the system administrators;
• Guarantees that all the standards are respected;
• Eliminates manually keying in the same information twice with possible errors;
• Possible to process the request in different systems (Active Directory, Mail system, databases and applications).
Using this methodology, all the available information from the request is utilized in the optimal way.
A potential disadvantage of this situation lies in the fact that web forms that are managed within the company’s intranet are often not dynamic, creating a ‘static’ ticket. The configuration data such as departments, OU’s or groups in the Active Directory, and relationship between an employee and his manager, have to be managed separately and often manually. By utilizing UMRA forms, which are fully dynamic, and able retrieve information real time from the Active Directory or the HR system, the data can be used to create the appropriate drop down lists, eliminating another potential for errors and manual entry.
To learn more about this application of Identity Management and many others, please visit our website; Tools4ever, Inc.
Wednesday, March 16, 2011
Friday, March 11, 2011
Keeping Active Directory Clean
One of the issues that frequently arise, especially in larger organization, is the need to provide contractors, consultants and temporary employees with access to network resources and email. The concept of automating the lifecycle by integrating with a Human Resource system breaks down because these types of employees are rarely entered there.
We have solved this dilemma numerous times for companies by implementing a web-based workflow. The hiring manager access an internal web page and completes the relevant information - name, department, type of employee, expected length of service, etc. Once the form is submitted, the IT or helpdesk can review the information and process it automatically. An email is delivered back to the hiring manager with the username, email address and initial password.
The key element here to keep AD clean is the expected length of service date. As that date approaches a notification can be delivered to the manager asking if the date should be extended. If yes, the manager clicks on a link in the email and can enter a new end date. If no, the process automatically disables the user on the last day of service. A manger can also be given an option to disable or terminate immediately if the person has already left.
After sitting in a disabled status for a period of 60 to 90 days, the record can automatically be purged from AD. Implementing a process like this saves time, potential licensing costs and increases security all while making life easier for the OIT department.
To learn more about this application of Identity Management and many others, please visit our website; Tools4ever, Inc.
We have solved this dilemma numerous times for companies by implementing a web-based workflow. The hiring manager access an internal web page and completes the relevant information - name, department, type of employee, expected length of service, etc. Once the form is submitted, the IT or helpdesk can review the information and process it automatically. An email is delivered back to the hiring manager with the username, email address and initial password.
The key element here to keep AD clean is the expected length of service date. As that date approaches a notification can be delivered to the manager asking if the date should be extended. If yes, the manager clicks on a link in the email and can enter a new end date. If no, the process automatically disables the user on the last day of service. A manger can also be given an option to disable or terminate immediately if the person has already left.
After sitting in a disabled status for a period of 60 to 90 days, the record can automatically be purged from AD. Implementing a process like this saves time, potential licensing costs and increases security all while making life easier for the OIT department.
To learn more about this application of Identity Management and many others, please visit our website; Tools4ever, Inc.
Can an identity management solution save lives?
Can an identity management solution save lives?
Managing double entries in hospital information / medical systems
In the field of Identity Management we are usually concerned with the management of employees and their user accounts, access rights and authorizations. Sometimes it occurs that the same principles and tools that we use in identity and Access management projects can be applied to a wider range of situations not usually associated with identity management. Here’s a recent example:
A hospital has to be very secure about the management of access rights for its employees, but also when it comes to the patient data within their applications. Recently when meeting with IT management of a big hospital the question was asked whether we could also prevent double entries of ‘patients’ in Hospital Information Systems (HIS) like Meditech, McKesson, Epic, CPSI, Sage Health, EClinical Works, Allscripts and Eclipsys.
Imagine a patient existing two times in the hospital information system due to a typo or other mistake. That means the patient has two files containing different information. The doctors may then miss important information if they don’t access the right patient file. Imagine a patient that is allergic to penicillin being given a penicillin treatment just because of a typo in the HIS.
Using the same mechanisms and tooling used by identity management solutions in this case Tools4ever’s UMRA, and applying UMRA’s capacity to detect doubles or possible double entries in various systems, can save lives. And with the different kinds of matching mechanisms in UMRA this is quite easy to do - a possible double can then be detected very early and a notification be sent to the person managing that particular data to validate whether or not we are really talking about the same patient. UMRA can of course also manage all the tracking and tracing required regarding the alerts and the way they have been dealt with.
To learn more about Tools4ever solutions, please visit our website,
Tools4ever, Inc.
Managing double entries in hospital information / medical systems
In the field of Identity Management we are usually concerned with the management of employees and their user accounts, access rights and authorizations. Sometimes it occurs that the same principles and tools that we use in identity and Access management projects can be applied to a wider range of situations not usually associated with identity management. Here’s a recent example:
A hospital has to be very secure about the management of access rights for its employees, but also when it comes to the patient data within their applications. Recently when meeting with IT management of a big hospital the question was asked whether we could also prevent double entries of ‘patients’ in Hospital Information Systems (HIS) like Meditech, McKesson, Epic, CPSI, Sage Health, EClinical Works, Allscripts and Eclipsys.
Imagine a patient existing two times in the hospital information system due to a typo or other mistake. That means the patient has two files containing different information. The doctors may then miss important information if they don’t access the right patient file. Imagine a patient that is allergic to penicillin being given a penicillin treatment just because of a typo in the HIS.
Using the same mechanisms and tooling used by identity management solutions in this case Tools4ever’s UMRA, and applying UMRA’s capacity to detect doubles or possible double entries in various systems, can save lives. And with the different kinds of matching mechanisms in UMRA this is quite easy to do - a possible double can then be detected very early and a notification be sent to the person managing that particular data to validate whether or not we are really talking about the same patient. UMRA can of course also manage all the tracking and tracing required regarding the alerts and the way they have been dealt with.
To learn more about Tools4ever solutions, please visit our website,
Tools4ever, Inc.
Tuesday, February 22, 2011
Manage Outlook Office Assistant without direct access to the mailbox
A common situation in organizations: an employee is ill and/or absent for a long period of time and his/her Outlook Assistant is not activated. Result: e-mails are not answered, poor service and angry customers.
Because of data protection, it is not possible to turn on the Outlook Office Assistant without direct access to the mailbox. Another employee must be aware of the login credentials of the absent worker to read e-mails, forward e-mails and turn on the Outlook Office Assistant.
This can create an insecure situation. However, this situation can be easily resolved with Out of Office Manager Tool (OOMT) by Tools4ever, .
With OOMT, administrators or helpdesk personnel can turn on Outlook Office assistant wizard without logging into the mailbox of the user. This task can also be delegated to departments, even without additional admin rights.
It is also possible to integrate OOMT in Tools4ever’s User Management Resource Administrator (UMRA) in order to make a connection with the HR system of the company. The HR system keeps up with employees that are sick, on vacation or on business trip, and when an employee leaves the organization. Thanks to this integration, UMRA can automatically install the Out of Office Assistant and forward e-mails so they can be answered promptly.
Professional handling of email traffic in your organization is guaranteed.
Because of data protection, it is not possible to turn on the Outlook Office Assistant without direct access to the mailbox. Another employee must be aware of the login credentials of the absent worker to read e-mails, forward e-mails and turn on the Outlook Office Assistant.
This can create an insecure situation. However, this situation can be easily resolved with Out of Office Manager Tool (OOMT) by Tools4ever, .
With OOMT, administrators or helpdesk personnel can turn on Outlook Office assistant wizard without logging into the mailbox of the user. This task can also be delegated to departments, even without additional admin rights.
It is also possible to integrate OOMT in Tools4ever’s User Management Resource Administrator (UMRA) in order to make a connection with the HR system of the company. The HR system keeps up with employees that are sick, on vacation or on business trip, and when an employee leaves the organization. Thanks to this integration, UMRA can automatically install the Out of Office Assistant and forward e-mails so they can be answered promptly.
Professional handling of email traffic in your organization is guaranteed.
Monday, January 31, 2011
A school system registers parents...
As part of this blog, I strive to present unique cases where clients have requirements that are “outside” the box of normal Identity Management solutions and I think this one definitely fits the bill.
One of the top 10 school districts in the State of Florida, and top 25 in the country, had an Identity Management issue that did not involve students or faculty/ staff but rather the parents. Legislation had been passed that required any parent wanting access to their child's on line learning environment present themselves in person with identification and request an account. With over 125 physical locations and 500 + users that would be handling the process, a paper system was out of the question.
The solution that was settled on was a combination of standard Tools4ever products and just a little bit of custom web work.
Tools4ever worked very closely with the technical staff of the district to insure the requirements were very detailed to avoid any missed components. In the end, a solution was delivered utilizing User Management Resource Administrator (UMRA ), in about 30 hours of consulting that fully met their needs.
Here is a brief overview of the solution:
As part of the project, Self Service Reset Password Manager (SSRPM ) was also deployed for the parents to allow them to enroll and reset their passwords via challenge questions and avoid an unnecessary burden on the help desk staff.
Additional web forms were delivered to allow administrative staff to reset passwords for parent’s accounts, check their SSRPM enrollment status, to run last logon reports, disable accounts, update accounts and SSRPM enrollment reporting.
Since deploying the system, over 100,000 parents have been successfully enrolled and can access their child’s records with ease. Paperwork that had previously utilized for the process has been eliminated and, through SSRPM, the additional burden on the help desk has been non-existent.
To learn more about Tools4ever solutions, please visit our website,
Tools4ever, Inc.
One of the top 10 school districts in the State of Florida, and top 25 in the country, had an Identity Management issue that did not involve students or faculty/ staff but rather the parents. Legislation had been passed that required any parent wanting access to their child's on line learning environment present themselves in person with identification and request an account. With over 125 physical locations and 500 + users that would be handling the process, a paper system was out of the question.
The solution that was settled on was a combination of standard Tools4ever products and just a little bit of custom web work.
Tools4ever worked very closely with the technical staff of the district to insure the requirements were very detailed to avoid any missed components. In the end, a solution was delivered utilizing User Management Resource Administrator (UMRA ), in about 30 hours of consulting that fully met their needs.
Here is a brief overview of the solution:
- A parent shows up at a school and requests an account to access their child(s) information.
- A secretary or administrator verifies their ID and enters relevant information into a web page including:
- Name
- ID type, number and expiration date
- Phone number(s)
- Address
- The secretary then searches for the student(s) using name or student ID criteria and verifies with the parent the correct name is displayed.
- The individual then hits a “Create Parent Record” and, if no duplicate entries are found, the record is created in Active Directory and the student information system and a link between the parent and child is created.
- A temporary password is returned and the secretary records the information, along with the user name, and delivers it to the parent.
As part of the project, Self Service Reset Password Manager (SSRPM ) was also deployed for the parents to allow them to enroll and reset their passwords via challenge questions and avoid an unnecessary burden on the help desk staff.
Additional web forms were delivered to allow administrative staff to reset passwords for parent’s accounts, check their SSRPM enrollment status, to run last logon reports, disable accounts, update accounts and SSRPM enrollment reporting.
Since deploying the system, over 100,000 parents have been successfully enrolled and can access their child’s records with ease. Paperwork that had previously utilized for the process has been eliminated and, through SSRPM, the additional burden on the help desk has been non-existent.
To learn more about Tools4ever solutions, please visit our website,
Tools4ever, Inc.
Wednesday, January 26, 2011
UMRA & Controlled Assessment
UMRA & Controlled Assessment
Traditionally, schools and colleges use Tools4ever Identity Management Suite is UMRA Forms, a secure interface to quickly and accurately manage the life cycle of a user. However, when a school links Active Directory to their student information system, all student account changes are automated, with no need for manual intervention. This negates the requirement for UMRA Forms.
However, a couple of months ago we were approached by a school with an interesting problem regarding controlled assessment. The school’s IT Manager creates exam accounts for pupils, with home directories shared in the normal way to each user. In the home directory he creates a series of "Exam" folders, which the pupil should only access during a Controlled Assessment session. As a boarding school, the pupil may need to use their exam account outside of a controlled assessment period, so enabling and disabling the account as required is not a suitable solution.
What the IT Manager really required, was a way to control NTFS permissions on the exam folders within the home directory for each account. So, Tools4ever built a simple interface, delegated to teaching staff, that switches access to the exam folders on and off at the click of a button.
Now he has shifted the tedious task of controlling exam accounts back to teaching staff. More importantly UMRA is logging every action to keep the auditors happy.
To learn more on Tools4ever solutions, visit our website:
Identity Management
Traditionally, schools and colleges use Tools4ever Identity Management Suite is UMRA Forms, a secure interface to quickly and accurately manage the life cycle of a user. However, when a school links Active Directory to their student information system, all student account changes are automated, with no need for manual intervention. This negates the requirement for UMRA Forms.
However, a couple of months ago we were approached by a school with an interesting problem regarding controlled assessment. The school’s IT Manager creates exam accounts for pupils, with home directories shared in the normal way to each user. In the home directory he creates a series of "Exam" folders, which the pupil should only access during a Controlled Assessment session. As a boarding school, the pupil may need to use their exam account outside of a controlled assessment period, so enabling and disabling the account as required is not a suitable solution.
What the IT Manager really required, was a way to control NTFS permissions on the exam folders within the home directory for each account. So, Tools4ever built a simple interface, delegated to teaching staff, that switches access to the exam folders on and off at the click of a button.
Now he has shifted the tedious task of controlling exam accounts back to teaching staff. More importantly UMRA is logging every action to keep the auditors happy.
To learn more on Tools4ever solutions, visit our website:
Identity Management
Wednesday, January 5, 2011
Password Management Leads to More!
A recent pilot project at a large Canadian manufacturing firm, with about 3,500 employees, resulted in successful implementation and purchase. After evaluating numerous vendors over a 6 month period, this diverse, global manufacturer decided on a pilot implementation of Tools4ever products as a proof of concept. We deployed several of our standard products, along with professional services, to meet the client requirements. Here is a brief synopsis of their requirements and how we set about providing a total solution.
The first phase of the project was to provide a standard methodology to allow end user to reset their Active Directory passwords without calling the helpdesk. In addition to modifying the Windows login screen, a web portal was also required to facilitate resets from machines that were not part of the domain. Further, both components needed to be available in English, French, Spanish, German and Finnish. Self Service Reset Password Manager (SSRPM) provided the needed functionality out of the box with the only shortfall being native support for Finnish. However, as all the text for the Enrollment and Rest Wizards is contained in a locale file, the modification for Finnish was accomplished by the client in about 45 minutes.
The second phase of this project involved the use User Management Resource Administrator (UMRA) Web for Employee Self Service and Delegation and Password Synch Manager. The desired result of this phase was to be able to reset a user’s SAP password at the same time and using the same password as the AD password. In order to accomplish this, it was necessary to collect the SAP user name form the end users as there was no relationship established between the AD and SAP credentials. A number of other attributes, such as manager’s name and cell phone were also collected for populating AD. Once this phase was completed, an end user could perform a normal password reset through ALT-CTRL-Del or reset a forgotten password through SSRPM, and the password would automatically be reset in both AD and SAP.
The third and final phase of the project involves the UMRA Delegation and Workflow components. The company has a large number of consultants and temporary employees. When their accounts are created in AD, they will be tagged with an anticipated expiration date in Active Directory. Two weeks prior to this date, the manager will be notified of the pending action and given an opportunity to extend the date. If no action is taken a second notice will be generated one1 week and then again the day prior to expiration. If no action is taken prior, the account is automatically disabled and moved to a separate OU. After 30 days in a disabled state, the account is automatically deleted from AD. This process allows an automated methodology for keeping AD clean.
Shortly after wrapping up Phase 3, the company will begin to look at other Tools4ever solutions including Enterprise Single Sign on and automated user account provisioning. To learn more on Tools4ever solutions, visit our website:
Identity Management
The first phase of the project was to provide a standard methodology to allow end user to reset their Active Directory passwords without calling the helpdesk. In addition to modifying the Windows login screen, a web portal was also required to facilitate resets from machines that were not part of the domain. Further, both components needed to be available in English, French, Spanish, German and Finnish. Self Service Reset Password Manager (SSRPM) provided the needed functionality out of the box with the only shortfall being native support for Finnish. However, as all the text for the Enrollment and Rest Wizards is contained in a locale file, the modification for Finnish was accomplished by the client in about 45 minutes.
The second phase of this project involved the use User Management Resource Administrator (UMRA) Web for Employee Self Service and Delegation and Password Synch Manager. The desired result of this phase was to be able to reset a user’s SAP password at the same time and using the same password as the AD password. In order to accomplish this, it was necessary to collect the SAP user name form the end users as there was no relationship established between the AD and SAP credentials. A number of other attributes, such as manager’s name and cell phone were also collected for populating AD. Once this phase was completed, an end user could perform a normal password reset through ALT-CTRL-Del or reset a forgotten password through SSRPM, and the password would automatically be reset in both AD and SAP.
The third and final phase of the project involves the UMRA Delegation and Workflow components. The company has a large number of consultants and temporary employees. When their accounts are created in AD, they will be tagged with an anticipated expiration date in Active Directory. Two weeks prior to this date, the manager will be notified of the pending action and given an opportunity to extend the date. If no action is taken a second notice will be generated one1 week and then again the day prior to expiration. If no action is taken prior, the account is automatically disabled and moved to a separate OU. After 30 days in a disabled state, the account is automatically deleted from AD. This process allows an automated methodology for keeping AD clean.
Shortly after wrapping up Phase 3, the company will begin to look at other Tools4ever solutions including Enterprise Single Sign on and automated user account provisioning. To learn more on Tools4ever solutions, visit our website:
Identity Management
Subscribe to:
Posts (Atom)