* Identity management penny drops over at Redmond
endif; ?>The vagaries of deadlines and U.S. public holidays means that while you are reading this I’m already halfway through the second day of the Burton Group’s Catalyst conference. Worse, I’m writing this before Microsoft’s Very Important Identity Management Announcement of last week and long before I can talk to anyone about what the news means. So we’ll have to go with the pre-announcement speculation (which, after all, is informed speculation) as reported, for example, by Network World’s John Fontana (see story link below).
According to Fontana (as well as other commentators I’ve spoken with), Microsoft has suddenly “discovered” identity management, just as it “discovered” the Internet back in 1995, security in early 2002, and spam just last month. Because of the short attention span of the general press (TV, newspapers, “People Magazine”, etc.), the impression will be given that Microsoft invented identity management at the mid-point of 2003 and we should all be grateful that it did.
In fact, what Microsoft is announcing is mostly a re-packaging of older services as well as a re-announcement of the Microsoft metadirectory services all rolled into something called Microsoft Identity Information Server (MIIS, but sure to be called IIS). You’d think someone at Redmond would notice that the company already had a product called “IIS,” but that’s what happens in big companies – the right side of the campus doesn’t know what the left side is doing.
Evidently, Microsoft’s vision that Windows (and therefore Active Directory) would be globally installed on every computing platform isn’t being implemented fast enough. In fact, odds are it never will be. So Microsoft’s strategy of, essentially, ignoring integrated identity management has in reality exacerbated the problem.
Customers have heterogeneous environments that they want to administer from a single platform and Microsoft’s refusal (until now) to recognize the existence of other identity management and directory environments (such as Sun ONE and Novell’s eDirectory) has increased demand for such competitive products. Microsoft’s (non) actions mean that people try as hard as they can to delay installing AD. That’s not good for Microsoft.
The message Microsoft wants to get out is that the key feature of MIIS would be its ability to allow AD to communicate with other Lightweight Directory Access Protocol (LDAP)-enabled directories. Well, as we all know, LDAP communications between AD and other LDAP-enabled directory systems has been happening for the past three years or more. The difference now is that Microsoft wants you to use its tools, rather than those of its competitors or (shudder) open source applications, to provide that communication.
Microsoft has hemmed and hawed over AD and metadirectory services for years. Even now, Redmond is touting Active Directory Application Mode (ADAM) as one of the major benefits of Windows Server 2003. ADAM, lest you forget, allows application vendors to use their own instance of AD for a data repository – sort of like a network-wide registry (or .INI file!). While most of us struggle to consolidate directories, Microsoft is encouraging vendors to make them proliferate.
I’ll have more on the Microsoft announcement in the weeks to come, but for now don’t expect any major changes in the identity management landscape.




