MANAGING IDENTITIES IN THE CLOUD
MANAGING IDENTITIES IN THE CLOUD
Embry-Riddle Aeronautical University educates more than 35,000
FEDERATED SERVICES MAXIMIZE OPTIONS
students annually in undergraduate and graduate programs at Next up, according to Fisher, is cross-domain user access with Oracle residential campuses in Prescott, Arizona, and Daytona Beach,
Identity Federation 11g, a multiprotocol federation server that will Florida; through its worldwide campus at more than 170 centers in
extend the university’s existing identity and access-management the United States, Europe, Canada, and the Middle East; and through
systems. “LDAP authentication is a good first-generation online learning. This diverse and geographically dispersed learning
solution, but we’re interested in using SAML to support federated environment challenges the IT department to provide secure access
authentication,” he says. With Oracle Identity Federation 11g, the to campus services and applications as well as to meet student and
university will be able to securely share identities among vendors employee demands for online self-service functionality.
and hosting models without increasing the cost of managing, “Oracle Identity Management Suite doesn’t care where a server
maintaining, and administering user identities and credentials. is located,” says Fisher. “By utilizing this Oracle software, we have
Embry-Riddle also plans to use Oracle Access Manager been able to implement a single-sign-on solution to our hosted
to centralize its single sign-on process so it can more easily e-mail service and several other applications, both on premises and
accommodate additional information systems and applications, off. Within a couple of milliseconds, Oracle can create, update, and
both on premises and off. “If a particular department comes to us manage user accounts just as we do for our internal directory.”
with a new vended application, Oracle gives us a lot of different ways
he university used Oracle Identity Management to streamline
that we can manage accounts,” Fisher says.
authentication for its public cloud–based e-mail service. “We This flexibility also maximizes the effectiveness of the university’s use Oracle Identity Management to create and manage all the
IT staff since it means they can outsource responsibility for third- accounts in real time on this cloud system, and we use a token
party applications along with much of their routine maintenance, API mechanism written for Oracle Portal to provide single sign-on,”
leaving the IT team to focus on issues of strategic importance. Fisher says Fisher. Students can log in to the university portal, click on a
cites the university’s learning management system as an example. link, and be placed into their e-mail accounts
The system is hosted and managed by an without presenting another credential. “This
application service provider, but Embry- virtual infrastructure minimizes the amount
Riddle’s users can access it directly through of support calls we receive from people trying
SNAPSHOTS
Embry-Riddle Aeronautical University
the university portal.
to access their mail,” Fisher adds.
“Clearly, the application service provider The new identity management system
erau.edu
knows its software better than we do, so replaces a manual process for implementing
Location: Prescott, Arizona, and Daytona
we prefer to let it handle upgrades and so nearly 2,000 account changes each day, Industry: Education and research
Beach, Florida
forth,” Fisher says. “Once you have worked which previously took at least 24 hours
Employees: 4,310
out issues of identity and access control, to complete and resulted in a delay in
Oracle products: Oracle Identity and
obtaining services from a public cloud can delivering updates to students. Fisher’s team
Access Management Suite, Oracle Identity
be very cost effective. The cloud provider now spends about 30 minutes per day on
Management, Oracle Access Manager, Oracle
already has the facilities, the bandwidth, the these activities. The Oracle software has also Oracle Virtual Directory, Oracle Database,
Identity Manager, Oracle Internet Directory,
data storage—all of which we would have decreased the number of account-related
Oracle Real Application Clusters, Oracle Portal
to duplicate ourselves to provide that same help desk calls by 40 percent, thanks to
service. Oracle has opened the door for us to the improved self-service options available
Advanced Innovations
utilize a lot more of these types of services in through Oracle Identity Manager.
advancedinnovationsinc.com
Location: Limerick, Ireland
the future.”
In addition, the university uses Oracle Industry: Supply chain management
Employees: 40
Virtual Directory to provide account and
Oracle products: Oracle Database, MySQL,
EVOLUTIONARY TECHNOLOGY
authentication services for its cloud-based
Public and private clouds are enabled antispam solution, as well as for hosted
Oracle SOA Suite, Oracle WebCenter, Oracle
by proven Oracle technologies that have applications such as a flight management
enterprise collaboration, Agile product lifecycle
been evolving for years: grid computing, system, self-help/help desk system, Suite, Oracle business intelligence solutions virtualization, SOA, and management
management applications, Oracle E-Business
ORACLE MAGAZINE MAY/JUNE 2010