310 likes | 448 Views
Identity & Infrastructure Applications Development & Release Plans. Tim Purkiss. Outline. Identity & Infrastructure Applications Services Recent changes to UPI Identity & Access Management (Vidit) Live@UCL and Office 365 (Duncan) IDINA Release 2.0 Spring and Summer 2013. IDINA Services.
E N D
Identity & Infrastructure ApplicationsDevelopment & Release Plans Tim Purkiss
Outline • Identity & Infrastructure Applications Services • Recent changes to UPI • Identity & Access Management (Vidit) • Live@UCL and Office 365 (Duncan) • IDINA Release 2.0 • Spring and Summer 2013
IDINA Services • UPI: UCL Person Identifier • Services System • Computer Reps Tool • Find UPI • Database account registrations • Identity & Access Management • Live@UCL and Office 365
Recent changes to UPI • Materialized Views • Restructuring core views • Main Source • Unicode • Project work
Use of Materialized Views Person Data Person Data with preferences Key Records Main TelephoneMain E-mailMain UserID Main Source Associations
Core views – Before UPI_V_PERSON UPI_V_PERSON_ALL UPI_V_RL_PERSON UPI_V_SITS_PERSON UPI_V_SR_PERSON SITS ResourceLink Services System
Core views – Now UPI_V_PERSON_PREF Preferences Contact info UPI_V_PERSON UPI_V_PERSON_SEARCH UPI_V_PERSON_BASE UPI_V_RL_PERSON UPI_V_SITS_PERSON UPI_V_SR_PERSON SITS ResourceLink Services System
Main Source - Now 1 Resource Link 2 SITS 3 Services System
Main Source 1 Current associations? 2 Highest ranked association? Staff Hon PG UG Visitor Casual Alumni Applicant Ext. Examiner Invigilator
Identity and Access Management (IAM)Components • Microsoft Forefront Identity Manager (FIM) • Synchronise data between different data sources • Manage identities and groups, configure workflows and define rules and policies via a portal • Online User Registration (OUR) • Enable applicants to register personal credentials centrally • Allow UCL student joiners to collect UCL userid and set a password electronically • Role Account Registration and Management (RARM) • Facilitate members of ISD Service Desk to request role accounts and track their provisioning • Data store, procedures and jobs • Consolidate identity and preference data • Generate and maintain UCL userids
Value added so far • Near real-time (replace legacy overnight batch process) userid provisioning in: • UNIX • Active Directory (old and new) • Live@UCL email service for UCL Alumni • OUR integration with: • Student pre-enrolment system • UCAS applicant portal • Student accommodation system (StarRez) • RARM: Easy to use web application to request role accounts (e.g. administrator account) • Prevent bad practice of manually creating these accounts without any tracking/auditing • Allow user to request multiple accounts in one go (batch feature)
IAM Developments • User sID migration from the old domain to the new one • Remove dependency on ADMT • Group provisioning and management using FIM • OUR integration with: • Online Admissions system (direct applicants) • Improvements in RARM • Improvements in the userid generation process
Live@UCL / Office 365 • live@UCL: Project • Office 365: Project • live@UCL: The Service
Transition to Office 365 • All Live@edu service subscribers are required to move to Office 365 by September 2013
Transition to Office 365 • All Live@edu service subscribers are required to move to Office 365 by September 2013 • Phase one Like-for-like Hosted Mail and Calendar Service • 25GB mailbox • Minimal change to service wrap • Most preparatory work is behind the scenes and communications related: • AD changes • Identity Lifecycle Manager (ILM)/Directory Synchronisation • Provisioning scripts • Management Tools • Comprehensive test plan to document end user experience
Transition to Office 365 • All Live@edu service subscribers are required to move to Office 365 by September 2013 • Phase one Like-for-like Hosted Mail and Calendar Service • 25GB mailbox • Minimal change to service wrap • Most preparatory work is behind the scenes and communications related: • AD changes • Identity Lifecycle Manager (ILM)/Directory Synchronisation • Provisioning scripts • Management Tools • Comprehensive test plan to document end user experience • Phase two • Business requirements analysis with UCL community for future Office 365 enhancements (Sharepoint, Lync, WebApps)
Office 365 Schedule Development: In progress ADDEV -> EISD-DEV.ucl.ac.uk Test : 29 April 2013 ADTEST -> EISD-TEST.ucl.ac.uk Production: **12 July 2013 ** AD -> LIVE.ucl.ac.uk
live@UCL: support structure User Query AISC Service Desks ADS Service Desk SoP Service Desk ISD Service Desk 3rd Line Support (CIA) SOM & Deputy SOM – (CIA) SO – Maria Darmon
IDINA Release 2.0 • Main Source – phase III • Data cleansing • Service monitoring • IAM developments • Computer Reps Tools • Find UPI
Data Cleansing • Add Archive data from UPIMGR • Remove records from Services System • Tidy up Services System users/permissions
Service Monitoring • Fix Services System feedback • Rationalise multiple sync processes
IAM Developments • Userid sID migration from the old domain to the new one • Improvements in RARM • Improvements in the userid generation process
Computer Reps Tools • Include Role Accounts • Group membership look-up Find UPI • Move from as01 • Re-platform to Java/Spring
Next Steps for Release 2.0 • UAT prepared by 18th Jan • Details of what data will change and how. • Beta version of Comp Reps tool • Deploy Find UPI
Spring and Summer 2013 • CSO / Intranet groups • “Known As” names in searches • Improved Notifications • Interfaces • Decommission old UPI • Web Services?
CSO and Intranet • Remove batch file transfer • Standardize CSO/Directory data • Consistent results with other UPI data • Remove duplication
Notifications • Some systems use this mechanism to get Person updates. • Interfaces can benefit from only being notified for a change that interests that system.
Known As names in searches Interfaces • Reduce UPI duplication/misallocation • SITS • RALIC • Telecoms • Remedy / ITSM • RPS
Old UPIMGR Web Services…? • Continue decommissioning • Technology in need of application