How ADAM avoids politics

Opinion
Nov 19, 20033 mins

* Microsoft’s ADAM technology sidesteps office politics

Last issue, I mentioned in passing that Passlogix’s v-GO had been “ADAM-enabled,” meaning it works with Microsoft’s new Active Directory Application Mode product to bypass some of the “office political” arguments that often develop when someone wants to use the enterprise directory structure to support a new application or service.

Right after writing that, I was sifting through press releases and came upon one from OctetString touting a customer win. (Boeing is licensing OctetString’s Virtual Directory Engine (VDE) to use as part of its Enterprise Directory Service, which is used by more than 700 directory-enabled production applications.) I normally don’t talk about “customer wins” unless a customer has come up with a new, different or otherwise interesting use for an identity product. That didn’t happen here, but I was drawn to quotes attributed to OctetString CTO Clayton Donley, who said the win validates virtual directories at the expense of meta-directories. Well, I’ve been blowing the horn for virtual directories (as opposed to meta-directories) for years.

The Microsoft ADAM technology puts a new spin on this virtual-vs.-meta battle.

Meta-directory installations take many years and millions of dollars, mostly because of political discussions about who will give up control and who will gain control over bits and pieces of corporate information. Virtual directories get around this discussion by leaving the authority for information just where it is today and simply reading out the data as needed.

ADAM avoids political battles altogether because it co-exists with, but doesn’t need to be affected by, the corporate directory structure – whether that’s monolithic, meta- or virtual. At the same time, ADAM can be brought into an overall Active Directory scheme by becoming affiliated with an AD Forest at any time. Thus, you can quickly and efficiently roll out a directory-enabled service or application and take on the politics only after people see the benefit.

The ability to institute wide-ranging (or precisely targeted) identity management technology (single sign-on, value chain interoperability, federated identity schemes, etc.) without upsetting the corporate dinosaurs who control the enterprise identity repositories is something that other directory vendors need to be exploring.

Active Directory only works on a Windows platform. Should eDirectory or Sun’s directory (Sun Java System Identity Server, formerly Sun ONE Identity Server, formerly iPlanet Identity Server, formerly Netscape Directory Server – and you think you have an identity problem) acquire the abilities of ADAM, the entire Identity Management landscape could burst forth in a huge round of customer wins. And not only “wins,” but also actual implementations. Think about it.