Case Study: IdaaS in Manufacturing
Challenge
A global manufacturing firm headquartered in the EU wanted to replace their current IAM solution as part of an overall modernization effort.
The company had a hybrid environment which consisted of a significant number of systems being delivered by SaaS providers while other systems were on-premise in their corporate datacenter. Some of these systems included Workday for HR, Oracle EBS for ERP, Freshservice, GitHub Enterprise, a PLM solution, Tableau for business intelligence, Azure AD with Office 365, and Active Directory.
The user community consisted of employees, contractors, customers, and vendors. All of these users needed access to the systems. The company required a unified IAM platform which could achieve the following:
- Support employees, customers and vendors from the same platform
- Automated user life-cycle management for employees by integrating with Workday
- Self-registration with validation for vendors and customers
- Single Sign-On (SSO) to business applications
- MFA (Multi-Factor Authentication) for improved security
- Self-service password reset for all users
- Workflow-based request approval functionality for employees
Solution Overview
After an extensive PoC and RFP process which included both SaaS and on-premise vendors, OpenIAM was selected. OpenIAM delivered an Identity-as-a-Service (IDaaS) solution that was hosted in the EU to comply with GDPR requirements. The solution consisted of identity governance, web access management, customer IAM and MFA. This provided the company with a single solution for each of their user communities.
User life cycle management
Automated user life-cycle management was enabled using the OpenIAM Workday connector in conjunction with business rules to support birthright access requirements and workflows for joiner, mover, and leaver processes.
Connectors were configured for all critical systems and in some cases, new connectors were developed.
Authentication
As part of the solution, end-users were provided with a customer branded central login interface and a self-service portal. The login UI, which is part of the OpenIAM Identity Provider (IdP) functionality, supports MFA. Since the customer had a mixed user community, multiple authentication policies were implemented. Depending on the type of user, they were able to authenticate using:
- OTP over e-mail, SMS or IVR
- OpenIAM authenticator app with push notification
To further improve security, the adaptive authentication functionality in OpenIAM was used to create authentication workflows that combined MFA with other factors such as location, device, and time.
Self-service portal
The self-service portal was configured so that each type of user could carry out their business-related tasks from a central location. Upon logging into the self-service portal, end-users can SSO to all of the applications that they were entitled to.
Authorized users could also create requests for additional access by using the workflow-driven service catalog and shopping cart. Similarly, approvers could view and process all incoming requests for access. If requests were approved, then the system would automatically provision the new privileges using the connectors.
The self-service portal also provided end-users with functionality for self-service password reset with password synchronization, further reducing the load on the help desk.
External users
External users, such as customers and vendors, were able to use the self-service portal and gain access to the systems by signing up using the self-registration functionality. Like internal users, external users were assigned roles as part of their birthright access to control the applications that they can access and what they can do within those applications.
Summary
The overall solution provided the company with a central platform which simplified how end-users, internal or external, interact with business-critical applications. The sign-up effort was significantly reduced along with the effort to manage the user lifecycle.
The OpenIAM platform had significantly reduced operational overhead and improved end-user productivity, while security and compliance with GDPR mandates had also been improved.
Let’s Connect
Managing identity can be complex. Let OpenIAM simplify how you manage all of your identities from a converged modern platform hosted on-premises or in the cloud.
For 15 years, OpenIAM has been helping mid to large enterprises globally improve security and end user satisfaction while lowering operational costs.