Wednesday, April 27, 2011

Password Management - Self Service and Single Sign On

According to a number of recent studies, calls to the help desk for password reset assistance make up 10 to 30% of the total call volume. Further research asserts that the costs associated with each call range from $51 to $147 in labor costs, not to mention loss of productivity while the employee attempts to login, gives up, waits in the help desk queue and, eventually resets the password. One further complication, the average employee is required to maintain 8 unique combination of user ID’s and passwords, usually with varying complexity and expiration rules.

So, how can the typical organization reduce the costs associated with password management and maintain the highest level of security? The answer lies in the Password Management solutions form Tools4ever and includes Self Service Password Reset Manager (SSRPM) and Enterprise –Single Sign On Manager (E-SSOM).

The first application, SSRPM, is an enrollment based application that allows users to register by answering a series of challenge questions – much like they would do for an on-line banking site. Once enrolled, they can reset their own password directly from the Windows login screen by clicking on a “Forgot My Password” link. Alternate methods of service can be found from either a website or via Outlook Web Access integration. To insure high adoption rates, such organizations elect to pre-enroll employees by pulling personal information form the HR system. This software is extremely secure and is in use by organizations ranging from25 to 350,000 employees worldwide.

The second application, E-SSOM, reduces the number of user name password combinations form the average of 8, to exactly one – the AD credentials. By securely capturing and storing a user’s credentials for all applications they are authorized to access, E-SSOM eliminates the need for a user to right passwords on a sticky note or attempt to remember them. E-SSOM can automatically handle password changes at required time intervals and allow user to delegate credentials to a specific app for a period of time – such as a vacation.

When both SSRPM and E-SSOM are used in combination, the number of calls to the help desk drops to nearly zero. The result is a tremendous savings of time, money and an overall increase in security.

For more information on the complete Tools4ever Identity and Access Management suite, please visit our website.

Tuesday, April 26, 2011

School Districts save time and resources by embracing network automation

I have been getting more questions about streamlining IT department operations and finding ways to be more efficient with fewer resources. We have many implementations across the country for automated network account provisioning by synchronizing authoritative data sources to different directory services. Utilizing Tools4ever’s User Management Resource Administrator (UMRA), our consultants bridge the gap between student information systems like Skyward and Active Directory.

School districts often struggle to create and manage user accounts in a timely manner due to lack of resources, data integrity or out-dated scripts. Additionally, when districts rely on third party scripts, they become vulnerable when the author of those scripts departs the district. Suddenly the scripts are unsupported and when the infrastructure changes the scripts break leaving the district in a bind.

UMRA protects the integrity of the district network data by providing easily supported projects files rather than scripts or code. UMRA’s enhanced development environment allows for rapid deployment of identity management systems at a very competitive price point. As school districts look for additional ways to save money they tend to stop hiring and incorporate more automated processes.

Benefits of UMRA for Education:
•Manual IT procedures are automated via student information system connectors;
•Connecting the student information system with various teaching applications, such as Destiny, library system, access system, Live@edu, Google Apps, etc. ;
•User account uniformity;
•Reduced input time by system and application managers through the automated of tasks;
•100 percent logging of all activities in the domain;
•Enhanced data integrity: the domain is always fully up-to-date and pollution free;
•Complete implementation within a few days for immediate ROI.

Common UMRA Connected Student Information Systems
•Banner
•Infinite Campus
•PowerSchool
•Aeries
•Jenzabar
•Pentamation
•DataTel
•Campus Management
•Teams

To learn more about UMRA please visit our website,. To read about how one school district implemented UMRA read our Lewisville Independent School District case study.

Friday, April 1, 2011

Identity and Password Management in Healthcare

As of late, Tools4ever has been implementing more solutions on the healthcare market and I wanted to take a look at our clients and ascertain if there are common issues that this market sector needs to address. Not surprisingly, there were a number of common themes in these accounts.

Shared User Accounts
One of the top reasons for implementing Identity Management in healthcare is the need to eliminate the “shared” accounts. Quite frequently, all the nurses on a floor will have one or more shared computers. Everyone utilizes the machine utilizing a common, generic account. The issue becomes security and privacy. It is impossible to restrict access or determine who is doing what and when.
Identity management solves this issue typically by linking an HR application to the Active Directory and creating individual logon accounts. Fast user switching, available in Vista and 7 makes this a quick process for busy healthcare professionals. Further, the Tools4ever Single Sign On product allows for credentials of users to be provided automatically fro authorized applications when utilizing fast user switching.

Downstream Provisioning

Active Directory and email systems are just one of the many applications that require user accounts. Pharmacy, medical records, radiology and IP phone systems are just the surface of what users need to have access accounts set-up and managed. By setting simple templates based on department and titles, it is possible to configure accounts in a majority of the applications and assign appropriate group and distribution lists as well. In more complex environments, the use of web-based workflow utilizing single or multi-level approval can be the first step in completing and advance Role Based Active Control (RBAC) matrix.

Stale Accounts
By far one of the most common issues, and the one with the most potential for security breaches, is the potential for stale accounts – accounts still active when an employee, consultant or temporary employee leaves. Tools4ever provides several of options for dealing with this issue. The first is to detect a terminate date or flag in the HR system during a daily synch and immediately disable the account. Another option is to scan the Active directory daily for unused accounts. IF an account has not been used in for example, 60 days, automatically send an email to the user’s manager notifying that the account will be disabled the next day if no action is taken. Finally, by implementing a strict policy of requiring a “disable on” date when creating accounts for consultants or temporary employees, automated email notification can take place warning of the impeding disable at 5 ,3 and day prior, allows time for an extension to be entered.

For further information please visit our website Tools4ever, Inc., or Click Here to download a health care case study or brochure.

Monday, March 28, 2011

Education and Free Email Services

One of the recent trends in the Education market over the last couple of years are the free email offerings from Google and Microsoft. While Gmail and MSlive@edu offer a number of tangible benefits to schools and universities, including a permanent account for alumni, creating and managing the accounts can be a challenge. Adding to this issue, password from Active Directory are no longer automatically synchronized and, especially if you were using Exchange, an additional burden can be placed on the helpdesk to reset email passwords.

Tools4ever offers solutions to both of these common issues when moving to Gmail or MS Live. Our User Management Resource Administrator can take a feed from your Student Information System and use data from there to automatically create user accounts in the hosted email solution. Further, when students graduate, their AD accounts can programmatically be moved to an Alumni OU and the appropriate indication made in either Gmail or MS Live.

Our PSM (Password Synch Manager) and SSRPM (Self Service Reset Password Manager) also have links in both of these email applications. IF a user forgets a password in AD or the email solution they can visit a web page, answer a series of challenge questions, and reset both passwords simultaneously. Although not as common for students, faculty and staff typically will have expiration dates on passwords and will need to reset them on a regular basis. PSM allows the capturing of this new AD password and can send it off to the email application to insure the passwords remain in synch.
To learn how Tools4ever can help prevent your free mail system from costing a fortune in maintenance and help desk time, please visit our website: Tools4ever, Inc.

Tuesday, March 22, 2011

Your Identity Management Strategy: What’s on the Menu?

Identity Management projects have a reputation for being long, costly and technically complex. What if the benefits of an Identity Management strategy could be yours without the hassle, including overhead that goes with technically complex projects; and within the limits of your budget?

Thanks to hundreds of Identity Management projects managed by our technical consultants, Tools4ever has been able to create a number of Identity Management best practices, aiming at achieving the maximum result with minimal effort.
One best practice is establishing a real Identity Management maturity model. Another result is the Tools4ever Identity Management à la carte menu, demonstrating Tools4ever’s capacity to deliver point solutions as well as integrated Identity Management approach.

Here are some examples of the Identity Management à la carte menu of solutions that have been implemented. (The estimated implementation time refers to average size organizations of about 2000 users.

• Delegation and tracing of the management of all user accounts and their resources(2 days);
• Synchronization with HR system(2 days);
• Identity Management Self Service Portal and Workflow Management(5 days);
• RBAC - Role Based Access Control level 1(3-5 days);
• Web portal for auditing and managing NTFS rights or Group Management(2 days);
• Single Sign-On for your 10 main applications(3 days);
• Self Service Password Management(1-3 days);
• Password Synchronization(1 day).

Interested? Please visit our website; Tools4ever, Inc. to learn more about our solutions and how they will help you achieve your Identity Management goals.

Doing More with Less

In Identity Management, balancing efficiency and security can be a tough and expensive proposal. IdM projects are complex, require broad support and can very easily fail, so it's understandable that many organizations have resisted these changes in favor of business as usual. Although this is changing due to countless regulatory standards and industry trends, many businesses still relying on antiquated and painfully manual processes for performing simple tasks such as updating phone numbers or removing access for an employee on leave.

Just last week, a colleague met with a hospital whose onboarding process for a new employee involved at least 3-5 different people, two sheets of paper, several emails and a response time of two days. On top of this, it was expected that parties involved would provide accurate information and do their own error checking. With over 1400 employees, you don't need to do much calculating to realize how much time is involved with this one process and the risk that is created. The good news is that the hospital is beginning the one year process of assessing and evaluating identity management options, however, it is still unclear what role of workflow automation will play in their eventual solution.

Any organization, like the hospital visited can easily implement a project that provides a series of web forms and automatic notifications that will provide a means to request, verify and approve facilities and implement network changes independently. Using a provisioning package such as Tools4ever's UMRA, these changes can be executed across the network according to predefined rule sets. The graphic below outlines such a process.

A solution like this is easy to implement and can be an inexpensive way to manage security risks and improve the speed in which user management functions can be accomplished.

For more information, visit our workflow page: Tools4ever, Inc.

Friday, March 18, 2011

We want to automate everything, but …

With an increasing frequency, we hear from our prospects the desire to automate every aspect of their Identity Management process. Inevitably, during the discovery phase, specific items are uncovered that are exceptions to the rule and difficult, or in some cases, impossible to address programmatically. It is conceivable that the vast majority of new user accounts will be handled systematically and only a rare exception will need special treatment.

To this end, Tools4ever can offer a hybrid solution of automating the account lifecycle management. AS new users are entered into the Human Resource (HR) system an automated process occurs that generates the new user account automatically based on the predefined criteria but instead o factually committing the account in Active Directory, a “request” is queued for further review.

An email is delivered to a group stating there are pending items to be reviewed. At that point, a Systems Administrator or Help Desk person accesses a web portal and reviews the request. If all appears correct, simply clicking a submit button will execute the account creation in AD, email (Exchange, Google, Lotus) and numerous other systems. If further details are necessary – possibly specific group memberships, larger mailbox store or distribution list access to name a few – the Sys Admin or Help Desk person can add the required resources and then click submit to complete the processing.

Extending this concept further, particularly to schools, college and universities, the account creation for students is often straightforward and can be automated entirely – without the queued request. While account creations for faculty and staff are often more complex, lower in frequency and can be handled using the queued process.
By utilizing this hybrid methodology, it is extremely easy to handle both simple and complex account creation scenarios.

To learn more about this application of Identity Management and many others, please visit our website; Tools4ever, Inc.