Tuesday, July 21, 2009

Microsoft Directory Synchronization Tool

I came across the Microsoft Directory Synchronization Tool a few days ago and, of course, I dove into the basic information about what this tool is and does. The description is:
The Microsoft Directory Synchronization Tool 9.1 synchronizes valid end-user proxy addresses (and their Safe Senders if available) from Active Directory to the Forefront Online Security for Exchange (FOSE) and Exchange Hosted Archive (EHA) network and populates the Administration Center with these accounts. This tool should be used if you have a subscription to the FOSE Filtering service or the post-8.1 Exchange Hosted Archive service.
This is a pretty innocuous scenario that this tool solves for customers but what I don't get is why big companies - like Microsoft (and Quest!) - don't re-use the technology they already have rather than developing new tools? So, in this particular case my question is why isn't the Microsoft Directory Synchronization Tool built on Microsoft's Identity Lifecycle Manager?

Why does it matter? Well, if it was my "tool" I'd want to use it to up-sell the full ILM to the customer that was using the tool. After all, I would expect they'd have other directory synchronization issues that I might be able to monetize. Or security tools that I could cross-sell to them since, after all, ILM is now part of the Forefront suite. Plus, if I were a customer would I want to be running this tool and possibly also ILM to solve other identity problems? Remember, simpler is better - one tool is better than two!

Maybe it is built on ILM and I'm just not "in the know"...

Technorati Tags:
, , , , , ,

Monday, July 20, 2009

Reality tour returns to Redmond

The temporary stopover of the reality tour to Paris is over and we've returned to our normal location across the street from Microsoft's Redmond campus. Jetlag is being fought at every corner. The search for a decent baguette and croissant is on. Wine consumption is returning to its normal (lower) level of consumption.

If you're interested in the details of the Paris stopover visit our other blog...

Monday, June 29, 2009

CLEAR is still unCLEAR

Mainstream press has started reporting on the CLEAR debacle that I mentioned in a previous post: Clear is dead. What about my retinal scans?
On Thursday, the House Committee on Homeland Security sent a letter to TSA Assistant Secretary Gale Rossides expressing concern about the handling of Clear members personal data.
I guess the good news is there is a lot of visibility regarding what's happening to my data and the data of 250,000 of my closest friends...

Technorati Tags:
, , , ,

Friday, June 26, 2009

Enterprise-Class SaaS Provisioning

I happened across this white paper - Enterprise-Class SaaS Provisioning - over at Conformity's website. The first paragraph of the executive summary caught my attention:
User provisioning provides the foundation for effective lifecycle management of user identity and access rights in complex IT environments. Historically, enterprises have addressed this critical need through a combination of business process and integration of premise-based applications with management tools. These tools have included local directory services, identity services and user provisioning and role management solutions. The recent rapid adoption of SaaS and cloud-based applications is now significantly straining the on-premise capabilities of existing IT models and approaches.
I think there are lots of executives and IT staff who are running around thinking that SaaS is the promised land. If you consider an SaaS application as "just another application" you will understand that your end-user identities still must be managed in that SaaS application. How are you going to provision, de-provision and update those identities? How are you going to manage the namespace of your corporate identities and the namespace of your SaaS application's identities? (Don't make me break out the Venn diagrams!)

We have a standard called "Services Provisioning Markup Language" (SPML) which was specified to help provision identities via a web service. Does your SaaS vendor support that standard? I'll bet they do not! What do you do then? I've met with hundreds of customers over the years and many are still struggling with provisioning inside the enterprise! Throw in SaaS provisioning - via some hairbrained interface because the vendor doesn't support SPML - and it only adds to the organization's identity management complexity.

Don't get me wrong. There's lots of promise with SaaS. Unfortunately, the road to the SaaS promised land passes through a few mine fields on the way...

Technorati Tags:
, , , ,