
EmpowerID Role Enforcer for Users automates the entire process of provisioning, management and de-provisioning of user accounts
across your multiple directories, based upon pre-defined role-based policies. EmpowerID's unique Role-Based Access Control (RBAC)
Metadirectory technology allows organizations to establish policies based upon a person's job function and location that will
determine the user accounts to be created in various enterprise directories. These user accounts are managed as
"Resource Entitlements" which are automatically provisioned, moved, and de-provisioned throughout the employee's lifecycle in an
organization. These RBAC policies eliminate the threat of privilege accumulation over time as an employee changes status within
an organization.
In an EmpowerID RBAC-automated enterprise, new hires, transfers, and terminations can be initiated via friendly Windows Workflow
Foundation processes by business users, or externally in an HR system monitored by EmpowerID. EmpowerID provides complete identity
lifecycle management by monitoring your enterprise directories for new account creation, password changes, attribute changes, and
account deletions. Newly detected accounts or account changes are fully tracked and logged for compliance reporting and can be
configured to trigger workflow processes. Flexible attribute flow rules determine which enterprise directories are authoritative for
specific directory attributes and which directories are subscribed to receive these changes. A full change history of each attribute,
with before and after values is maintained for detailed change tracking and auditing.
EmpowerID Role Enforcer modules cover a broad range of IT systems and resources including:
- Automated inventory of user identities from a wide variety of directory technologies
- Automated role-based user provisioning, moves, changes and de-provisioning of user accounts, initiated via workflow requests or changes in a monitored HR system
- Deleted user account recovery and associated Exchange mailboxes
- Flexible provisioning and account joining rules in workflow processes for new account discovery evaluation
- Self-service account registration requests with workflow approvals
- Flexible attribute flow rules to synchronize updated information between directories
- Policy-based attribute value assignment by geography, department, job function and other business-specific groupings
- Delegated identity administration via web interfaces and rich Windows Presentation Foundation clients
EmpowerID Role Enforcer for Users provides organizations with centralized workflow and role-driven automation of the entire
identity lifecycle. EmpowerID ensures that security policies are consistently applied, prevents the accumulation of privileges,
and provides a secure and auditable platform for compliance efforts.
|