* Letter from Thor Technologies' Ranjeet Vidwans
In this newsletter a couple of weeks ago, I asked whether we are looking for network management for identity. Today, I’ll share the responses I received, and examine a possibility for monitoring offered by an existing technology that most of us are very familiar with.
One of the first responses in my inbox was from Ranjeet Vidwans, Thor Technologies director of product management. Sometimes, though, I think his title should be “director of Dave Kearns management” since he seems to spend an inordinate amount of time reading (and commenting on) my writings. Nevertheless, his thoughts were appropriate even though he began by saying: “This is something a few of us have actually mulled over a couple of times (typically over the last glass of wine after a good meal).”
Vidwans goes on, “Most of the clients and prospects that I’ve worked with have already made significant investment in monitoring solutions, typically from HP or IBM. In parallel, sensitive target systems (such as Siebel, SAP, or PeopleSoft) already have rich entitlements and permission models that are optimized for those systems.” He seems to be leading to the conclusion that the connector between these two is where audit log monitoring could occur. Specifically, he thinks that provisioning vendors (and we all know what Thor’s Xellerate product does, don’t we?) are best positioned to solve this problem.
As Vidwans puts it: “I believe that provisioning solutions have the ability to serve as the integration point that allows these firms to maximize the benefits they derive out of these existing investments (the very point you were discussing in your column). However, rather than the conceptual model that you were outlining in the column, I think there’s a much more literal approach that actually leverages SNMP.” Hmm, you say, SNMP and identity management all wrapped up together? Do tell, Ranjeet, how will we do that?
He explains: “As we’ve discussed in the past, Xellerate [as well as other provisioning systems – Dave] is optimized to automate how users are provisioned to resources, even at the fine-grained entitlements level. Our adapters for systems such as SAP, Siebel, and PeopleSoft (among many others) are calibrated to allow clients to leverage the rich and unique entitlements models that each of those vendors have defined for their systems. More importantly, we reconcile the changes that are made to user privileges directly in the target systems.
“For instance, assume that user dkearns is initially provisioned to an application (App1) with certain entitlements (E1). Now an administrator directly uses the App1 administration interface to bump the user’s entitlement to E2. Xellerate reconciles this change back into the system and any reporting done on this individual’s provisioning history will reflect that he has E2, not E1 level of access in App1. In addition, Xellerate allows system admins to define policies that can calculate whether or not dkearns should have E1 vs. E2 access (or no access at all) to App1 – We can also surface reports that show the delta between the user’s ‘as-is’ vs. ‘ought-to-be’ provisioning state. This is all available today.”
Vidwans continues: “What if I were to publish a MIB [Management Information Base] for Xellerate – one that would allow me to leverage the same concepts (traps, alerts, threshold exceptions, congestion conditions) that make SNMP such an invaluable protocol for NetMon purposes? I could update monitoring stations on the following kinds of changes or situations: inappropriate privilege levels detected; high degree of provisioning activity in sensitive systems; license (number of deployed seats) for an expensive system; approaching license threshold; and there are many more. Can you imagine a world where auditors and InfoSec personnel would have monitoring windows on their portal or desktop and would get real-time alerts based on policy violations (or roll-ups of policy violations if we want to leverage another SNMP concept)?
“In this model, neither the native target applications, nor the monitoring infrastructure need to be aware of new standard or protocols. They don’t even need to entertain feature enhancement requests to support this kind of capability. The ‘only’ thing needed would be to define what an error condition (or exception condition or anything that would be considered ‘actionable’) means to me, and publish the appropriate MIB. It sounds a bit far-fetched, but much more grounded in reality than many of the ideas we tend to throw around.”
A provisioning MIB, why didn’t I think of that? Why didn’t you? Tell me what you think about this possibility.
Next issue, we’ll examine another monitoring possibility, one directly connected to both standards bodies and audit logs. Hurry back.




