Integration Solutions Features of Oracle Identity Manager

1-6 Oracle Fusion Middleware Users Guide for Oracle Identity Manager Oracle Identity Manager to create the connector. For detailed information about GTC, see Generic Technology Connectors on page 5-2.

1.1.6 User Provisioning

Provisioning provides outward flow of user information from Oracle Identity Manager to a target system. Provisioning is the process by which an action to create, modify, or delete user information in a resource is started from Oracle Identity Manager and passed into the resource. The provisioning system communicates with the resource and specifies changes to be made to the account. Provisioning includes the following: ■ Automated user identity and account provisioning: This manages user identities and accounts in multiple systems and applications. For example, when an employee working in the payroll department is created in the human resources system, accounts are also automatically created for this user in the e-mail, telephone, accounting, and payroll reports systems. ■ Workflow and policy management: This enables identity provisioning. Administrators can use interfaces provided by provisioning tools to create provisioning processes based on security policies. ■ Reporting and auditing: This enables creating documentation of provisioning processes and their enforcement. This documentation is essential for audit, regulatory, and compliance purposes. ■ Attestation: This enables administrators to confirm users access rights on a periodic basis. ■ Access deprovisioning: When the access for a user is no longer required or valid in an organization, Oracle Identity Manager revokes access on demand or automatically, as dictated by role or attribute-based access policies. This ensures that a users access is promptly terminated where is it no longer required. This is done to minimize security risks and prevent paying for access to costly resources, such as data services.

1.1.7 Organization and Role Management

An organization entity represents a logical container of other entities such as users, roles, and policies in Oracle Identity Manager. In other words, organizations are containers that can be used for delegated administrative model. In addition, organizations define the scope of other Oracle Identity Manager entities, such as users. Oracle Identity Manager supports a flat organization structure or a hierarchical structure, which means that an organization can contain other organizations. The hierarchy can represent departments, geographical areas, or other logical divisions for easier management of entities. Roles are logical groupings of users to whom you can assign access rights within Oracle Identity Manager, provision resources automatically, or use in common tasks such as approval and attestation. Roles can be independent of organizations, span multiple organizations, or can contain users from a single organization. See Also: Oracle Fusion Middleware Developers Guide for Oracle Identity Manager for more information about generic technology connectors 2 Architecture 2-1 2 Architecture The architecture of Oracle Identity Manager provides a number of compelling technical benefits for deploying a provisioning solution as part of the identity and access management architecture. Oracle Identity Manager platform automates access rights management, security, and provisioning of IT resources. Oracle Identity Manager connects users to resources and revokes and restricts unauthorized access to protect sensitive corporate information. This chapter consists of the following sections: ■ Key Features and Benefits ■ How Oracle Identity Manager Works: The Tiers of Oracle Identity Manager ■ System Components

2.1 Key Features and Benefits

Oracle Identity Manager architecture is flexible and scalable, and provides the following features: ■ Ease of Deployment ■ Flexibility and Resilience ■ Maximum Reuse of Existing Infrastructure ■ Extensive User Management ■ Web-Based User Self-Service ■ Modular and Scalable Architecture ■ Based on Leading Software Development Standards ■ Powerful and Flexible Process Engine ■ Built-In Change Management

2.1.1 Ease of Deployment

Oracle Identity Manager provides a flexible Deployment Manager utility to assist in the migration of integration and configuration information between environments. The utility exports integration and configuration information as XML files. These files are then imported into the destination environment, which can be staging or production. You can use the XML files to archive configurations and maintain versions, as well as replicate integrations.