Identity management represents an integrated infrastructure using various products and means in order to achieve security for users and applications. Authentication, authorization and applied security policy are basic methods in achieving the safety. To achieve such a goal in a complex environment that comprises variety of non-homogenous applications, takes application of several processes, i.e. identity and authorization consolidation, single-sign-on solution and the like.
Portfolio of the above mentioned solution usually comprises products such as address service LDAP, provisioning services and SSO modules.
Design can be based either on the already existing complex solution, such as Oracle Identity Management, or, with regard to current and planned client environment, on a flexible combination of commercial and open source products.
Last but not least, it is necessary to note that SOA (service oriented architecture) implementation rises the inevitability to sustain the identity management.
Identity management centralizes and automates many of the above mentioned tasks and so the administration costs are decreased and security and accuracy rises. Moreover, the identity management enables faster implementation of new applications. Usually, implementation of a new application means managing of stand-alone set of users and their authorizations. Identity Management enables the new applications to use already existing infrastructure for users’ management and so it makes the time needed for implementation and management of new applications shorter.
Identity management increases user’s comfort. Strategy of identity management enables the new users to gain the access to applications much faster and saves their time. Simultaneously, it enables users to change their settings and preferences in once, instead of re-setting each application individually. Identity management increases application security and allows central management of passwords and privileges. This makes their use much simple and it also eliminates the temptation of users to put those information on paper by which they endanger the security system.