Академический Документы
Профессиональный Документы
Культура Документы
Tilo Boettcher
Introduction
Identity Management Single Sign On Operations using System Center Operations Manager
ERP Intranet
CRM
ESS Internet
Groupware
Workflow
Logon
...
Logon
Logon
PC Logon
ERP Intranet
CRM
ESS Internet
Groupware
Workflow
...
Access
PC Logon
Central user management Single point of administration Assign user rights in various applications with one keystroke Lock or Delete users centrally Central user repository Avoid redundant user information
Introduction
Identity Management
Single Sign On Operations using System Center Operations Manager
User store
LDAP synchronisation
<=4.6C
RFC
LDAP
Active Directory
>=4.7
LDAP
Extraction Employee data: Personel number First Name Last Name ...
DEMO
Login over MS ADS
user
ALE
CUA on WebAS
SAP ABAP user management data can be synchronized with a LDAP directory with systems based on WebAS 6.10 or higher SAP Systems with Release 4.5 and higher can be integrated into LDAP using CUA LDAP directory interface provides mapping capabilities of LDAP attributes and SAP data fields SAP User synchronisation and distribution can be performed by background jobs
10
User is created / updated with basic user data from LDAP directory First Name Last Name eMail Roles (optional) Users are created without password Passwords are not needed if SSO using SAP Logon Tickets is used No security risk since users cannot log on without using SSO via Enterprise Portal using an initial password
11
MIIS will get additions with Identity Lifecycle Manager ILM 2007 soon
http://www.microsoft.com/windowsserver/ilm2007/default.mspx
12
Goals Use supported SAP interfaces SAP certification in progress Dont require reconfiguration of SAP Support default configurations out of the box Make it possible to use any BAPI on the SAP application server that can be called remotely Use SAP technology to connect directly to SAP Leverage SAP security infrastructure Eliminate manual file creation processes Scenarios Employees as authoritative data for provisioning Feed updated email, user ID attributes back to SAP Provision and manage SAP HR/CUA users
13
Architecture: Objectives
Provide ability to directly reach SAP for imports and exports use BAPIs to accomplish this integration Reuse SAPs technology and communication security for offbox invocation of BAPIs Allow for SAP configurations that arent the standard out of the box solution by making it possible to use a configuration tool that connects to the SAP application server and discovers the BAPI that can be called remotely. Build a UI that exposes features to help users arbitrarily map any BAPI parameter component to any connector space attributes for a particular set of MA operations. Allow user-defined operations to handle cases where retrieving a single object (for example an employee) might require calling several BAPIs to get the personal information, the communication ID, the organizational assignment, the managers ID, the department and cost center names, etc. All of these pieces of information require calling different BAPIs with a way to tie all of the information together into a single object. We designed the architecture to accommodate this kind of user-defined operation.
14
User Management integration with MIIS Provisioning, Deprovisioning, Synchronization, Password Synch., Users, Customers, Employees
MIIS Server
Export
SAP MA
BAPI BAPI
SAP
MIIS usage
User store
Provisioning
Data extraction
MIIS
Single Sign On
Operations using System Center Operations Manager
WebDynpro
Web Dynpro
SAP
WebAS
Initial
SAPGUI for HTML
Logon
SAP Logon Ticket
ITS
SAP
Web
Windows
20
SAP
21
22
Authentication
IIS
Kerberos Ticket
Identify user
25
Gartner Companies considering a management tool for their Windows centric server environment should definitely place MOM 2005 on their evaluation list. David Coyle, April 05 Forrester With the release of MOM 2005, Microsoft has made important improvements to the product it is set to become the No. 1 or No. 2 player in the Windows server platform management market within the next three years. Thomas Mendel, Sept 04 IDC Sept 05 numbers show MOM growing at 5x the market rate: Windows Perf Mgmt growing @ 13% yr/yr growth MOM growing at @ 60% yr/yr
26
DEMO
System Center MOM
No Agent needed: Use of WS-Management SAP NetWeaver 2004s Microsoft System Center Operations Manager
28
www.microsoft-sap.com