Policy acknowledgment by the Enterprise Federation business owner

Once the appropriate Enterprise Federation (EF) Business Owner is identified for the EF partner, IBM requires the EF Business Owner to review our IBMid Enterprise Federation Policies document and respond to the EF Specialist assigned to their onboarding case with their acknowledgment. (Example: “I acknowledge the IBMid Enterprise Federation Policies”)

Note: The Enterprise Federation Policies acknowledgment is not a formal agreement, but rather an acknowledgement of the responsibilities the EF Business Owner is tasked with in onboarding with IBMid Enterprise Federation service for their entire company.

Summary of IBMid Enterprise Federation (EF) Policies

This section should not be interpreted as the definitive or complete set of Policies. Detailed policy information is available in the IBMid Enterprise Federation Policies Distribution document. Policies summary is available in the following IBMid Enterprise Federation Policies Summary document.

Identities

  • Individual identities are managed by the user.
  • Enterprise identities are managed by the EF partner.
  • Individual identities which match an EF partner verified domain can, at the EF partner’s option, be converted to an enterprise identity (with appropriate user notification).
  • IBMid discourages the use of “test” identities in the IBMid Production environment.

IBMid supports the following types of requests for user identity information

  • User List (convertible individual IDs)
  • User List (enterprise IDs)
  • Selected User Report (specific users)

Domains

  • IBM requires verification of all email domains configured for EF.
  • IBM will only provide user information for verified domains.
  • IBM will only configure JIT or link individual IDs for verified domains.
  • Domain verification may be performed through various means. In the case that IBM cannot verify the domain through other means, a DNS-based verification may be required.
  • IBM must be notified within 30 days of any divestiture or acquisition which may affect the verification status of a domain (for example, transfer of ownership).

Authentication and Session Management

  • Enterprise IDs are authenticated by the IdP.
  • For multi-factor authentication, the specific factors used are controlled by the IdP.
  • EF partner IdPs should consider typical timeouts in setting their own session lifetimes.

Establishing a Federated Relationship with IBM

To establish an IBMid Enterprise Federation configuration, IBM requires the following:
  • An IBM Sponsor.
  • Specific EF partner contacts, including an EF Business Owner and an EF Technical Owner.
  • EF partner acknowledgment of IBMid Enterprise Federation Policies.
  • An “onboarding” process to implement the appropriate configuration.
  • IBMid Product Owner and IBMid Technical Owner approvals.

The Enterprise Federation onboarding process consists of the following steps

  • Process Initiation
  • Solution Kickoff Meeting
  • IBM Pre-Approvals (IBMid Preproduction)
  • IBMid Preproduction Integration and Testing
  • IBM Pre-Approvals (IBMid Production)
  • IBMid Production Integration and Testing

EF partners have ongoing responsibilities

  • Informing IBM of special situations, such as freeze periods.
  • Maintaining the EF partner IdP configuration.
  • User communication.
  • Annual EF Revalidation.
  • Informing IBM of certain contracted relationships.

Other information

  • IBM does not implement Service Level Agreements (SLAs) for IBMid EF.
  • IBM provides “best effort” support for IBMid EF.
  • IBM assumes EF partners have appropriate knowledge and skills required to administer their IdP configurations.
  • IBM does not provide support for EF partner IdP configurations, including end user login to those services.
  • IBM requires the configuration to be operated in compliance with IBM’s Enterprise Federation Policies.
  • Any future IBM updates to the Policies will supersede the prior Policies.