PWN
- IAM as a Service
- We were able to switch off the old and malfunctioning IAM system
- There are fewer helpdesk calls for accounts that were not created (on time)
What was the project at PWN?
We implemented a hybrid IAM solution for a water company to support the onboarding, internal mobility, and offboarding processes. The Identity Management component was implemented on-premises, and the Access Management component was delivered in the cloud. We used Microsoft Identity Manager for Identity Management and to connect both on-premises systems and cloud solutions. RBAC (role-based access), ABAC (attribute-based access), and ZBAC (zone-based access) functionality was provided in the cloud by ID-Driven.
What were the challenges in implementing Trusted-ID solutions?
Connecting a new Access Management system API: Here we developed an Extensible Connectivity Management Agent for exchanging users, accounts, and groups between the on-premise and cloud systems.
Phased implementation of RBAC, ABAC, and ZBAC: In collaboration with ID-Driven, we incorporated additional metadata into the exchange between MIM and ID-Driven so we know on-premises which groups are authorized for management. This enabled the client to implement access management in phases.
What are the results?
A working hybrid IAM solution to support the joiner, mover and leaver processes
Link to Youforce (via an Enterprise Service Bus) for retrieving source data
Link to Active Directory to manage the lifecycles of accounts, groups, and their memberships
Link to the access pass printing system
Connection to access control systems
