In my last article, I introduced the importance of understanding the HR system and putting that into the context of using HR data to manage identities. This is a big challenge because while the HR system is a technology, it is rarely managed by IT – more typically it is managed by an HR-owned administration [...]
Building the Foundation for Successful Password Self-Service Part 5: User Training and Wrap-up
So far this month, we’ve updated the <password policy>, created appropriate <challenge questions>, and come up with a strategy for setting initial passwords. Now we are ready to start training the users and wrap up the month’s activity Developing user training Unless you’ve already worked with Michael, chances are that the users at your organization [...]
Building the Foundation for Successful Password Self-Service Part 4: Initial Passwords
In the last article, we discussed how to establish appropriate challenge questions to facilitate password self-service. But that’s just half of the password self-service equation. The other half has to do with initial passwords, which is the topic of this article. Initial passwords All users are assigned an initial password of some sort, which must [...]
Building the Foundation for Successful Password Self-Service Part 3: Challenge Questions
So far we have established the value of properly implementing password self-service and successfully tackled building effective password governance. The next step is to develop “challenge questions.†Challenge questions – definitely a double-edged sword A key benefit of any password self-service system is the “forgot password†feature. If a user forgets their password, they click [...]
Building the Foundation for Successful Password Self-Service Part 2: Password Governance
In my last article, we explored how a properly implemented password self-service mechanism can yield a quick and early return on the identity management journey. Password self-service is a cornerstone in the foundation for reduced sign-on (which is essentially what SSO promised to be). But before we jump in on the password self-service technology, let’s [...]
Building the Foundation for Successful Password Self-Service: Part 1
Note from Michael: this month we’re going to try something different with this series by breaking the articles up into smaller chunks and serve them on a weekly basis. Same series, same great content, delivered in smaller chunks. Cool? By now, you’re so sick of userID cleanup that you’re probably wondering why you didn’t select [...]
Data Cleanup Part 2: Other UserIDs
By: Ioana Bazavan Justus Did last month’s exercise of mapping primary userIDs kill you? Is it still killing you? Unless a number of full-time resources were allocated on a project basis, the cleanup for a large organization can easily take months to complete so if you’re still working on it, don’t worry – you’re not [...]
Data Cleanup Part 1: Primary UserIDs

Welcome to the February issue of Identity Management in 13 Easy Steps. In most parts of the country the weather is cold and dreary, and what better weather for an ID cleanup? So roll up the sleeves, find the glasses, and brew a lot of extra-strong coffee – it’s time to tackle those primary userIDs. [...]
Driving Compliance: What We Have versus What We Need

By Jim McFee A common statement an auditor hears is, “our IT department is mature; we have everything we need for an IT Audit.†A common thought an auditor thinks is, “yeah, right.†So which of these statements is more accurate? More importantly, which one increases or decreases risk? Without creating a laundry list, let’s [...]
Prioritizing Systems Integrations

Avoiding the biggest mistake The biggest mistake that identity management implementers make is biting off way more than they can chew – we all have grandiose ideas of integrating all of the company’s systems and fully automating them, too! It never sounds that hard when the team is sitting around the conference room table, excitedly [...]



Engage with Michael Santarcangelo