IBM Security Access Manager for Enterprise Single Sign-On, Version 8.2

Provisioning Agent features

This topic describes the high-level specifications of the IBM® Security Access Manager for Enterprise Single Sign-On provisioning Active Directory agent, as well as the various deployment options.

No administrative costs for Active Directory-based user de-provisioning
The solution does not add administrative costs for user de-provisioning through the Active Directory management console.
No modification to existing Active Directory and provisioning infrastructure
The solution does not require modification to existing Active Directory and provisioning infrastructure. This feature eliminates the need to obtain approvals for infrastructure modifications, which are typically tedious and might take too long.
Complete de-provisioning of accounts

When users are de-provisioned on Active Directory, the solution performs a complete de-provisioning of the corresponding IMS Server users. Complete de-provisioning includes revoking the authentication factors of users, disabling user Wallets and creation of audit logs. It ensures that de-provisioning complies with relevant legislations, such as SOX.

IMS Server users can be either revoked or deleted.
Note: To retain audit log information for compliance initiatives, when de-provisioning, you can revoke an account instead of deleting it. IBM Security Access Manager for Enterprise Single Sign-On accounts that you revoke cannot be reactivated.

If a customer has an ADAM server, install the Provisioning Agent on the same machine as the ADAM. Search and directory lookup operations can complete faster because the ADAM host has its own cached copy of the user directory. However, the Provisioning Agent can also be configured to communicate directly with Active Directory.

An enterprise might have one or more ADAMs. If there are multiple ADAMs supporting multiple domains, each ADAM machine hosts one Provisioning Agent.

Prerequisites for Provisioning Agent

In the Provisioning Agent solution:

How provisioning agent works

Provisioning Agent with IBM Security Access Manager for Enterprise Single Sign-On supports only de-provisioning IMS Server user when the Active Directory account is de-provisioned.

When the administrator or help desk employee de-provisions a user in the Active Directory management console, the following process occurs:
  1. In the Active Directory management console, the user is deprovisioned.
  2. The Provisioning Agent detects (through periodic polling) that a user has been de-provisioned on Active Directory.
  3. The Provisioning Agent invokes the provisioning API of the IMS Server to deprovision the IMS Server user.
  4. The authentication factors of the user are automatically revoked.
  5. When the user attempts to log on with AccessAgent, the user is informed that the account has been revoked.


Feedback