Upgrade to Pro — share decks privately, control downloads, hide ads and more …

End to End Identity Management in a Cloud-First Landscape

End to End Identity Management in a Cloud-First Landscape

With ever more enterprise data and functions moving from on-premises data centres to the cloud, the corporate firewall is no longer an effective demarcation of company-internal assets from the rest of the world. Identity has rapidly become the next security perimeter – the passport which systems inspect to grant or deny access to information assets. But such an approach demands robust processes for managing identities throughout their lifecycle.

This presentation outlines how Orica evolved from largely manual processes without much visibility, to fully-automated identity management, with provisioning and de-provisioning of job-based authorisations in both SAP and non-SAP systems, how this changed the way we look at security, and what challenges remain.

Sascha Wenninger

July 28, 2021
Tweet

More Decks by Sascha Wenninger

Other Decks in Technology

Transcript

  1. End to End Identity Management in a Cloud-first Landscape Sascha

    Wenninger http://slides.sufw.me/e2eidentity
  2. Lots to Consider… • Who works in the company? •

    Onboarding • Access provisioning • Authen:ca:on • Monitoring • Data security • O=oarding 👩⚕👨💼👩💼🧟👩🏭 🧕👷👷🧑⚕👩💻 🧑🏭👩💻👩🔧👨💼🥷 👩🔬🧑💼👨💻👩💼🧑💻 ?
  3. User Provisioning (2016) Service Now Office 365 SAP ECC Etc.

    👩💼 👩💻 👨💻 🧑💻 Ac6ve Directory
  4. The Problem • Extremely manual • Leaky o=oarding process •

    “Copy from template user” approach • IT Security seen as a board-level enterprise risk
  5. The Opportunity 25-year old system ➧ Greenfield system Dis-integrated processes

    ➧ Integrated processes within & across systems Undocumented processes ➧ All processes modelled in BPMN 0 workflows ➧ 54 workflows Security by copying users ➧ Deterministic security Username/password login ➧ Single Sign-On everywhere
  6. Technology is the Easy Part… Login accounts & Office 365

    ➧ SailPoint Identity IQ SAP User accounts ➧ SAP Identity Management Single Sign-On ➧ SAML & Azure AD Segregation of Duties ➧ SAP GRC
  7. Process How to make sure data is maintained? Make it

    easy to do the right thing Make it hard to do the wrong thing
  8. Process How to make sure data is maintained? Must be

    in SuccessFactors to get a Login Single Sign-On everywhere Access to SAP systems determined by Job and Org assignment Automated provisioning - no manual exceptions
  9. Change is Hard! • HR didn’t want contractors in “their”

    SuccessFactors • No business owner for identity • Some people didn’t “need” logon account • Exceptions – “we are special”
  10. What Worked for us • Influence from Non-HR Execs whose

    processes rely on accurate Org Data • Multiple systems run workflows • Compliance monitoring of safety training for all workers • Audit pressure
  11. User Provisioning (2020) SuccessFactors Office 365 SAP S/4HANA etc. 👩💼

    👨💻 Active Directory Fieldglass SAP IdM SailPoint IIQ ServiceNow SAC IBP SAP GRC AC etc. SCCM AD Groups 🖥
  12. One Source of Truth SuccessFactors Office 365 SAP S/4HANA etc.

    👩💼 👨💻 Ac0ve Directory Fieldglass SAP IdM SailPoint IIQ ServiceNow SAC IBP SAP GRC AC etc. SCCM AD Groups 🖥
  13. Make it Imperative SuccessFactors Office 365 SAP S/4HANA etc. 👩💼

    👨💻 Active Directory Fieldglass SAP IdM SailPoint IIQ ServiceNow SAC IBP SAP GRC AC etc. SCCM AD Groups 🖥
  14. You may have > 1 Tool… SuccessFactors Office 365 SAP

    S/4HANA etc. 👩💼 👨💻 Ac0ve Directory Fieldglass SAP IdM SailPoint IIQ ServiceNow SAC IBP SAP GRC AC etc. SCCM AD Groups 🖥
  15. SAP IdM vs. SAP Cloud Identity Services • SAP IdM

    is abandonware, but known & extensible • SAP Cloud Iden:ty is new & unknown è Use the boring tool. Is this where you want to spend your innova2on budget? ⚖ 👺 👹
  16. Challenges • SAP IdM Skills Availability • Missing connectors to

    SaaS systems à custom Java code • Incomplete APIs in SaaS systems à clunky provisioning • Mindset shift for Support and End Users
  17. Summary Data One Org Chart Process Make it hard to

    do the wrong thing Executive Sponsorship From outside IT and HR! Tooling Be pragmatic – use what works Change Management for IT Change Management for Business users
  18. How to Connect with Me E: [email protected] M: +65 8799

    1446 Li: linkedin.com/in/saschawenninger @sufw