Solution in Detail Rule engine for rule-based role and privilege assignments Multi-step approval framework Support for replacement of central user administration Predefined HTML-based reporting Support for mass user administration
Statistics state that up to 70% of IT projects run late, over-budget, or do not meet planned goals…Consequently, implementation risk is a critical factor…From “Introducing Packaged Solutions” by Michael Krigsman
Now when companies think about implementing an application, they really want to implement an integrated solution. Henry D. Morris, Senior Vice President of Worldwide Software and Services, IDC
Customers today want choices in how they scope, configure, and deploy business software. Peter M. Russo, Managing Director of Pierre Audoin Consultants
SAP NetWeaver Identity Management rapid-deployment solution This solution reduces total cost of ownership by
simplifying assignment of roles and privileges to users and reduces risk through compliance checks and remediation. With its predefined content, customers are able to implement the SAP NetWeaver® Identity Management in a short timeframe.
Get essential SAP NetWeaver Identity Management Functionality quickly and affordably
SAP NetWeaver Identity Management: The cost for user management, including user
master data, assigning privileges, and creating reports, is rising significantly.
Requesting permissions can be very time-consuming via manual workflows.
There is a need for reports on permissions and data access for internal and external audits. (Why does a user have a specific permission? Who approved the permission? Which users have the same critical permissions?)
IT systems have to be integrated into the security concept, and new employees need fast access to business applications.
What’s included Business benefits Lower role and privilege assignment efforts based
on rules Reduction of manual user administration efforts Minimized error rate
Rule engine for rule-based role and privilege assignments: scope and benefits
This function provides rule-based assignments of business roles and privileges. The rules are based on user attributes and will apply assignment changes (add/remove) based on changes of the user attributes. The main functions in detail includes the following: Rule engine applied once user attributes are
updated Rule-based assignment or removal of roles or
privileges Maintenance of rules based on an upload file or
What’s included Business benefits Simpler replacement of the central user
administration feature by the SAP NetWeaver Identity Management (SAP NetWeaver ID Management) component by keeping key features and user administration processes
For replacing a running Central User Administration with SAP NetWeaver ID Management, the rapid-deployment solution provides the most requested basic configuration in SAP NetWeaver ID Management.
Pre-configurations and step-by-step documentation to help run a project smoothly
Especially important for customers focused on provisioning for SAP software systems
Minimized implementation costs in a replacement project and faster implementation times
Support for replacement of central user administration: scope and benefits
This function supports the replacement of the central user administration feature, enhanced functionality is delivered (for example, jobs, tasks, Web UI tasks). In detail, the following support functions are provided: System-specific attribute provisioning License data provisioning (ABAP programming
language for the SAP NetWeaver Application Server component)
Reconciliation report to compare data between the back-end system and the internal database
Additional Web UI tasks (copy identity, lock/unlock identity, reset password, and more)
Provisioning of valid to dates for role assignments (ABAP for SAP NetWeaver Application Server)
Handling of provisioning failures and option for retry
Enhanced privilege information, such as single role, composite role, and members of composite role (ABAP for SAP NetWeaver Application Server)
What’s included Business benefits Simplified reporting without additional
implementation efforts No integration efforts for integration with SAP
NetWeaver Business Warehouse component Ad-hoc reporting in an easier and simpler
reporting format Able to more easily adapt reporting to custom
Web user interface or design requirements Easier creation of new custom reports Proven reporting functionality known from central
Predefined HTML-based reporting: scope and benefits
The solution provides HTML-based reports to analyze user and assignments data in the system. The reports can be viewed and executed via the Web user interface; additionally, the administrator is able to receive the report results via e-mail. The following reports are available: User details report User authorizations report User history report User list per business role User list per business role historical User list per privilege User list per privilege historical
What’s included Business benefits Easier handling of mass user administration More efficient and faster user administration Mass user administration functionality that
customers of central user administration are used to
Support for mass user administration: scope and benefits
This function supports mass user administration activities based on .csv upload files. This simplifies the administrative processes of, for example, role assignments, creation of roles, creation of identities, and resetting password.
Via a Web user interface, the mass user administration tasks can be executed and the file(s) can be uploaded
Rapid deployment of SAP NetWeaver Identity Management for go live in 5 weeks
The SAP NetWeaver Identity Management rapid-deployment solution offers customers pre-configured identity management functionality from SAP NetWeaver Identity Management. The customers can choose from several source and target systems that will be connected during implementation. The rapid-deployment solution delivers the most important and common scenarios, such as provisioning, approval workflows, and automatic authorization assignment, mass user operation jobs and e-mail notification framework out of the box. This service dramatically reduces the necessary time for an implementation. In addition, the customer can choose two different additional options: “Add-on 1” to connect to an additional target system (2 targets systems are included in the base RDS service), “Add-on 2” to get support for Go-Live.
A special step-by-step guide describes each activity during the deployment
The service offers customers a pre-configured identity management functionality of SAP NetWeaver Identity Management 7.2 in a development system.
The service is delivered as an implementation of best practice processes with a fixed scope including a defined set of customer specific configuration, connection of source- and target-systems and most important and common scenarios such as provisioning, approval workflows, and automatic authorization assignment, mass user administration jobs and e-mail notification framework out of the box.
The solution can be extended with additional add-on services:
Add-On 1: Connection to one additional SAP target system – multiple Add-Ons 1 for multiple additional SAP target systems
Add-On 2: Go-live support
SAP NetWeaver Identity Management rapid-deployment solutionSolution Components and Service Approach
Base Solution - Rapid deployment of SAP NetWeaver Identity Management in Development system
What does SAP deliver? What do you have to do? Provide resources for SAP NetWeaver Identity
Management 7.20 system setup (including operating system, database, AS Java, ID store, Web user interface).
Have source and target system ready for connection to identity management system, and have user with administrative authorization in place.
Provide administrative access to the Windows server and ID management console.
Manage overall project. Perform data migration and cleansing. Perform acceptance and performance testing. Conduct end-user training. Prepare for go-live. Deploy to production. Provide post go-live support.
Installation check Workshop to confirm the predefined requirements Project documents: work breakdown structure,
including a project schedule, test scripts, and scoping questionnaire
Activation and unit test of chosen packages for the SAP NetWeaver Identity Management rapid-deployment solution in the development system
Knowledge transfer to key users on configured SAP NetWeaver Identity Management rapid-deployment solution system
Support for going live (for service add-on only)
Rapid deployment of SAP NetWeaver Identity Management