• Link to LinkedIn
  • Link to Youtube
  • Request a demo
  • Resources
  • Events
  • English
    • Français
Identity and Access Management (IAM) software specialist
  • IAM Strategy
    • Access the overview
    • Which Industry Challenges?
      • Healthcare
      • Government
      • Banking, Finance and Insurance
      • Medias
    • Who?
      • Employees
      • Customers
      • Partners
    • What are the Benefits?
      • Security
      • Regulatory Compliance
      • User Experience
      • Digital Transformation
      • Extended Enterprise
      • ROI
    • Which Components?
      • Strong – Multi-factor- Adaptive Authentication
      • Identity Federation
      • Web SSO
      • Enterprise SSO
      • Self-Service Reset Password
      • Passwordless on ChromeOS
      • User Lifecycle Management
      • Access Rights Management
      • Provisioning
  • Our Platform
    • Ilex IAM Platform
      • IAM Platform overview
      • Ilex Identity Management
      • Ilex Access Management Solution
      • Ilex Credential Management System (CMS)
      • Ilex Customer IAM
    • Choose a deployment mode
      • Deployement overview
      • Ilex IAM Platform – On premise or private cloud
      • Ilex IAM Platform – SaaS
  • Our Expertise
    • A successful IAM project
    • Implementation Partners
    • Our Ecosystem
    • Our Services Offering
    • Training
    • Ilex Support
  • Customer Stories
  • Resources
  • About Us
    • Ilex
    • Careers
    • Events
    • News Room
  • Blog
  • Contact Us
  • Request a demo
  • Language
    • English
    • Français
  • Menu Menu
Identity Federation

Managing cloud users

Cloud or SaaS applications are increasingly used in enterprises. This is a strong market trend, as this technology makes it easier to provide applications and helps service providers be closer to their consumers, with no need to go through IT.

Enterprises must take into account these new application management modes. Indeed, companies are decentralised and although they use state-of-the-art interfaces, the people in charge of these applications have to manage users “manually” which, potentially, is a source of errors. The consequences of this type of management are well known in terms of security (passwords forgotten by users, multiple dormant accounts, weak password policy generating security holes), and in terms of cost (the price of the use of the service depends on its usage). The IAM solution (Identity & Access Management) which integrates support of cloud or SaaS applications is key as it gives control to people operating at a functional level.

How to perform cloud provisioning?

Il n’y a pas aujourd’hui de standard unique pour gérer le provisioning des applications en mode SaaS. Le standard SPML (Service Provisioning Markup Language) n’a pas pris sur ce segment. Quant au SCIM (System for Cross-domain Identity Management), il est encore très peu utilisé, même par les promoteurs de ce standard (Google, Ping Identity et SalesForce par exemple, ne l’utilisent pas pour le provisioning de leurs applications) , ou bien il est utilisé comme bannière marketing pour les nouveaux arrivants sur le marché de l’IAM. Il n’en reste pas moins que le standard SCIM, qui sera plus abouti en version 2.0, a de nombreux atouts pour l’avenir car il est simple d’utilisation via son interface REST, plus facile à paramétrer que le SPML et enfin plus extensible dans la définition de l’utilisateur.

En pratique, la gestion du provisioning de ces applications est basée sur des connecteurs réalisés « à façon », par exemple :

  • GoogleApps provisioning is based on REST APIs. The initial versions also had Java and Python implementations, but this is no longer supported by the current version. Google provides a very comprehensive API and enhances it constantly: so it is necessary to keep up to date. Note that the API has limitations in terms of use (frequency of use, for example) and that Google disclaims any responsibility concerning the use of the service.
  • The provisioning of Office 365 and Exchange Online is really operational only when using the PowerShell APIs, the REST interface is used for queries more specifically. The complexity lies in mastering the execution of the PowerShell from the dedicated Microsoft servers. Salesforce is interesting from an account creation management perspective as it can be performed on the fly, at connection time. For this, an identity federation must be implemented, where the identity server indicates to the Salesforce service the parameters required for the creation of the user, thus performing Just-In-Time (JIT) provisioning. Concerning the management of account modifications and deletions, the REST API must be used.

How to implement cloud provisioning in enterprises?

Cloud computing revolutionises business practices and the way enterprises use and manage their services. As far as identity management is concerned, it must continue to guarantee the company’s security policy that must be unique and centralised while flexible at the same time. Tools promoting identity management for cloud computing only are on the wrong track (or simply not good enough). Identity management tools must be adapted in order to manage cloud applications in the same way as internal applications. The level of service and ease of use of identity management functions do not depend on the location of servers!

We should also mention how Identity Federation mechanisms can also strengthen the security of these systems. This will be the topic of a future post.

As a conclusion, IAM solutions have a great future because if we want to control security and costs, we must be able to manage internal as well as external users – internal and external service consumers – in the best possible way.

Article updated on January 18, 2020
Share this entry
  • Share on Facebook
  • Share on X
  • Share on LinkedIn
  • Share by Mail
https://www.ilex-international.com/wp-content/uploads/2014/02/managing-cloud-users.jpg 533 800 Ilex https://www.ilex-international.com/wp-content/uploads/2025/03/logo_ilex_rvb_2.svg Ilex2014-02-14 09:59:552020-01-18 17:35:48Managing cloud users

Summary

Who we are​

Ilex IAM Platform is Nexpublica’s complete identity and access management offering.
Nexpublica has a long history of publishing in software for the public, semi-public, and private sectors. The company supports more than 4,000 public organizations and 1,200 private companies.

www.nexpublica.com

This content could interest you

  • SSO (Single Sign-On): definition, basic principles and global approach to single authentication
  • Five Key Access Management Considerations for 2018
  • Digital transformation: can security and IAM serve customer relations?
  • Are your identity and access management systems effective?
  • Identity federation: how to control cloud users?

Our latest news

  • Inetum Software becomes NexpublicaMarch 20, 2025
  • Ilex International receives the 2022 France Cybersecurity label for the contribution of its French solutions to digital sovereigntyFebruary 18, 2022
  • Inetum reinforces its expertise in cybersecurity with the acquisition of Ilex InternationalSeptember 6, 2021
  • What’s new on Sign&go Global SSO!June 25, 2021

Nexpublica

4-10, rue Mozart
92110 Clichy – France
+33(0)1 44 04 50 50

© Copyright - Ilex
  • Link to LinkedIn
  • Link to Youtube
  • Legal Notices and privacy policy
Link to: Managing cloud users Link to: Managing cloud users Managing cloud users
Scroll to top Scroll to top Scroll to top
X