Optimal IdM User Conference - Following TEC - May 3rd 2012 Home | Contact Us

Virtual Identity Server for Identity Lifecycle Manager

(VIS for ILM) - Multi-forest connectivity and enhanced group population

Features



Multi-Forest connectivity
  • Using a single management (VIS MA), ILM can easily connect to multiple Active Directory forests, domains, or LDAP directories. This greatly simplifies the deployment and configuration of ILM.

Enhanced Active Directory Group Management within the ILM environment
  • The management agent allows ILM to manage group membership by updating user objects directly instead of managing group objects.
  • Users are added or removed from AD groups by directly modifying the “memberOf” user attribute that is made read and write capable by the VIS for ILM management agent.
  • Eliminates the need to project AD Group objects into the metaverse, reducing complexity of the ILM deployment.
  • Extremely fast processing, especially with Very Large Groups (VLG) - Customer simulations have reduced 2+ hour run-times to minutes.

Enhanced metaverse functionality - Read/Write Reciprocal link attributes
  • Formerly “read-only" reciprocal relationship attributes are now writable via the management agent, reducing complexity and the number of objects in the metaverse.
  • Any extensible code within ILM can leverage the VIS MA and update the attributes directly. Examples are: Memberof (user) – Member (group) and Directreport (user) – Manager(user)