Wednesday, May 18, 2016

Identity Audit

Identity Audit feature in OIM is used  to detect Segregation of Duties (SoD) violations. The detection mechanism of IDA monitors users' actual access to resources, and captures any violations on a continuous basis. 

  1. Detective mode: In a detective mode, the entire identity warehouse of users can be monitored for anomalies or toxic combinations of user access rights. 
  2. Preventive mode: In preventative mode, any access that is requested via the access catalog in real-time can be automatically detected as an Identity Audit policy violation, and preventative action can be taken.
Enabling Identity Audit in OIM R2 PS3 





















IDA Settings



Creating Identity Rules



Creating SoD Policies

Creating Scan Definition

Running and Viewing Policy Violations


Policy Violation Details

IDA Maintenance

Identity Audit Scan Cleanup Job + Identity Audit Maintenance Job
Records are purged from the following the tables
– IDA_SCAN_RUN_POLICIES
– IDA_SCAN_RUN_USERS


Policy Violation Reports

No comments:

Post a Comment