Automated User Administration
Hitachi ID Identity Manager (formerly ID-Synch) can monitor one or more systems of record on a periodic basis (e.g., nightly or every few hours), enumerating new, deleted and changed users. In the case of an HR application, for example, these changes may represent new hires, terminations and transfers. Auto-discovery is performed on all integrated systems and applications -- not just systems of record.
Changes detected by Identity Manager are passed through a data filter, which removes users that are outside Identity Manager's scope. For instance, in a scenario where Identity Manager manages all users in one country, but the HR system is global, Identity Manager would ignore changes to users from other countries.
All changes to a given user are aggregated and business logic is executed, with the set of changes as input. This is best illustrated with some examples:
|
Detected change
|
Actions
|
Net result |
|
New user appears in an HR application.
|
|
Auto-provisioning. |
|
New phone number detected on white pages directory.
|
|
Identity synchronization. |
|
Change to termination date is detected on the HR system.
|
|
Automated termination. |
|
User disappears from system of record (HR).
|
|
Automated termination (2nd method). |
|
User was added to Administrators group on Active Directory domain.
|
|
Detect unauthorized privilege escalation. |
Collectively, these processes are known as automated user management. They are implemented by the ID-Track component in Identity Manager.




