by Mandy Andress, Network World Lab Alliance

Oracle jumps to the forefront of ID-management market

Reviews
Jan 22, 20077 mins

New version of Oracle product upgrades deployment, workflow and diagnostic wares

The latest edition of Oracle’s Identity Manager builds on the core provisioning functionality the company acquired with its 2005 purchase of Thor Technologies with new deployment, workflow, diagnostics and attestation tools.

How we tested Oracle Identity Manager

Archive of Network World tests

Subscribe to the Network Product Test Results newsletter


OIM contains the standard provisioning functions: automated user-provisioning capabilities through the use of policies, roles and workflows; the ability to manage user accounts across many systems and applications from a single interface; and user self-services, such as registration and password reset. OIM differentiates itself through the addition of the attestation process, which lets IT management perform certification of user access with a full audit trail, a requirement of the Sarbanes-Oxley Act.

ID MANAGEMENT ORACLE IDENTITY MANAGER 9.0.1

Oracle

4.08
Price: $60 per user and $40,000 per connector.
Pros: Integrated access-control attestation process; flexible engine for rules, workflows and reconciliation.
Cons: Custom reports not accessible within the product console; lacks GUI-based workflow building tool.
The breakdown
Provisioning workflow 30% 4.5 Scoring Key: 5: Exceptional4: Very good3: Average2: Below average1: Subpar or not available
Provisioning configuration 35% 4.0

System management 15%

3.5
Reporting 20% 4.0
TOTAL SCORE 4.08
See how Oracle’s OIM compares with other ID management products in our Buyer’s Guide.
 

For testing, Oracle provided a Windows 2003 server VMware image comprising instances of all necessary product components. See the highlighted information below.

How we tested Oracle Identity Manager

Oracle provided a VMware environment running on a Windows 2003 server that we ran on a 3GHz, 1.6GB RAM server, with Oracle Identity Manager installed.

Oracle also provided a test environment of directories (Active Directory and Sun Directory Server) and other provisioning targets (Oracle Application Server and Oracle Portal 10.1.2.0.2), Oracle Internet Directory 10.1.4 and Exchange 2003. For user population, we tested about 10 accounts.

We tested the provisioning process from beginning to end, testing reconciliation by adding new resources to the human-resources system and having it reconcile with OIM. We looked at provisioning policies and role changes to set basic entitlements and adjusted them based on defined role. We then looked at self-service account registration and password control.

This was followed by testing the various report options available within the product. Our final level of testing involved defining and completing an attestation process to review, approve and/or deny user access.

Those components included Oracle Identity Manager 9.0.1, Identity Manager Connector Pack and JBoss 4.0.2. Included in the installation as examples of provisioning sources and targets were Microsoft Exchange 2003, Sun Java System Directory Server, Oracle Internet Directory 10.1.4 and Oracle Portal 10.1.2.0.2. Sun performs the installation and connector setup on customer sites, which is why we permitted the company to supply a preinstalled image for the test.

OIM is a Java 2 Platform Enterprise Edition-based application and is managed through an easy-to-navigate Web-based console. We tested end-to-end provisioning processes in OIM, starting with a feed comprising employee name, organization and role within the company from a human-resources system, and generated a basic text file of changes to be reconciled within OIM. Therefore, when we added a new employee to the organization, a new record was created in OIM. When we changed a role for an existing employee, OIM adjusted the role and provisioned or revoked any access as defined by policy.

We then created provisioning policies based on different roles within the organization. A user in a consultant role received an Active Directory account, while a full-time employee received an Active Directory account as well as an Exchange account. Within Active Directory, the two employment types were placed in different Active Directory groups, which is standard. This was an easy process to define and modify provisioning policies.

Using the Oracle tools we then changed a user’s status from consultant to full-time employee and confirmed the Exchange account was added and the Active Directory groups were changed as expected.

In our test of the self-registration functionality within OIM, we completed a Web form to create a user account. As part of this process, we answered several security questions prompted by the OIM to help validate us as the appropriate user in the event we’d need to reset our password. Once the request was submitted, we logged on to the OIM management console and approved the pending self-registration request. We confirmed that all accounts were properly created and provisioned.

Within the OIM password-management scheme, a single password can be synched to all accounts managed by OIM, with a centralized password policy, including challenge questions, defined within OIM. We set the policy, changed our user password and confirmed the password was appropriately reset on our target accounts.

Oracle’s workflows allow approvals or other actions (send an e-mail, for example) to be taken during the provisioning process. Logging on as our test user, we requested a Lightweight Directory Access Protocol (LDAP) account. This kicked off a workflow process that required administrator approval before the account could be granted. We then logged on to the management console as the administrator, approved the request and confirmed the account was created.

Next, we modified the workflow to add a step, requiring manager and administrator approval. It was easy to customize workflow processes, especially with the addition of the graphical workflow visualizer. This provides a picture of a workflow process, so it is easier to understand what takes place each step of the way. However, creation of the workflow is still manual. We would like to see drag-and-drop capabilities within the workflow visualizer to easily change workflows. According to Oracle, this functionality is expected in an upcoming release.

The reporting console is accessed through the OIM Web-based management console and is easy to use. Standard reports can be manipulated by using different query parameters, such as a specific resource (Active Directory or LDAP) or limiting the search to a specific time frame. The Oracle reporting engine is useful in responding to audit requests, because its standard reports include the ability to quickly report on the history of many components, such as user membership, user resource and user profile history. We ran reports showing user entitlements and user-profile history without issue.

OIM supports the ability to create custom reports, but not within the standard management console. Custom reports can be run by directly querying the OIM repository and using such tools as Crystal Reports.

The best feature of OIM is the integrated attestation engine. This lets a company send reports to managers that list all the accounts and access privileges their employees have. The manager can approve or deny access and OIM will deprovision accordingly. OIM is quite flexible, allowing the ability to define the scope of a process in terms of looking at all resources or a single resource. You also can define a single reviewer or have each user’s manager responsible for reviewing access. Within the attestation process, audit history and attestation reports are stored and quickly available through OIM reports.

OIM is a strong, well-rounded product and worthy of a close look for any provisioning project.

Andress is president of ArcServer Technologies, a security company focusing on product reviews and analysis. She can be reached at mandy@arcsec.com.

Andress is also a member of the Network World Lab Alliance, a cooperative of the premier reviewers in the network industry, each bringing to bear years of practical experience on every review. For more Lab Alliance information, including what it takes to become a member, go to www.networkworld.com/alliance.