Identity Lifestyle Management

Delivering on comprehensive identity and access management in the enterprise, Identity Lifecycle Manager (ILM) “2” changes the current state of the art of identity management. ILM "2" provides powerful end user self-service capabilities via Office and rich administrative tools and enhanced automation for IT professionals. In addition, ILM “2” is built on a .NET and WS-* based foundation for developers to build more customized and extensible solutions.

Features and Benefits:

  • Empowering people. ILM “2” empowers end users, IT professionals, and developers by putting the right tools in the right hands. With ILM “2”, end users can easily perform self-service tasks with self-help tools integrated into Microsoft Office software. Likewise, ILM “2” provides IT with the tools they need to manage identities through a SharePoint-based policy management console, and developers have access to extensibility features through .NET and WS-*.

  • Delivering agility and efficiency. By delivering automation and self-service, ILM “2” dramatically reduces the high costs and risk currently associated with identity management deployments. ILM “2” integrates enterprises’ heterogeneous identity infrastructure, including directories, databases, line of business applications. New extensibility points in ILM “2” enable management of heterogeneous strong authentication systems such as 3rd party Certificate Authorities and One-Time Password devices. This heterogeneous approach helps organizations maximize their existing identity infrastructure investments. By providing management across the identity infrastructure and integrating with familiar developer tools and technologies, ILM “2” makes it easier to enable business agility and new scenarios.

  • Increasing security and compliance. ILM “2” provides policy management features that enable system auditing and compliance. By integrating the tools IT uses to manage identities, credentials, and resources, ILM “2” helps organizations integrate policies across the organization and secure the enterprise. Furthermore, with strong authentication management tools integrated in ILM “2”, organizations can more easily enjoy the security benefits of strong authentication.

What’s New in ILM “2”

ILM "2" builds on the metadirectory, certificate and smart card management and user provisioning available in ILM 2007, and adds a rich management environment including integrated user management, self-service for comprehensive credential management, group management, policy management, and expanded extensibility and connectivity. ILM “2” feature investments can be categorized into four areas:

  • Policy Management: ILM “2” delivers a framework for identity management automation and integration so all enterprise systems run using the same set of enterprise policies

  • Credential Management. With ILM "2" organizations can manage multiple credentials in an integrated manner, using self-service tools that are available through the Windows logon for ease of discoverability and use.

  • User Management. One of the most important things Microsoft is delivering from a business standpoint is automated, codeless, user provisioning. ILM "2" delivers tools for integrated user management and self-service across enterprise applications without the costly coding of business rules or recoding of the target systems.

  • Group Management. ILM ”2” provides powerful capabilities out of the box that help increase the productivity of end users, frees up IT from repetitive tasks and provide better security and compliance outcomes.

ILM “2” Feature Highlights:
Policy Management
  • SharePoint-based console for policy authoring, enforcement & auditing
  • Extensible WS-* APIs and Windows Workflow Foundation workflows
  • Heterogeneous identity synchronization & consistency
Credential Management
  • Heterogeneous certificate management with 3rd party CA support
  • Management of multiple credential types, including OTP
  • Self-service password reset integrated with Windows logon
User Management
  • Integrated provisioning of identities, credentials, and resources
  • Automated, codeless user provisioning and deprovisioning
  • Self-service user profile management
Group Management
  • Rich Office-based self-service group management tools
  • Offline approvals through Office
  • Automated group and distribution list updates