Identity Virtualization

The Challenge of Consolidating Identity

Some organizations struggle to implement effective identity aware network access because they have a difficult time assigning a single access policy to all of their users. Organizations that have multiple identity domains within their identity management infrastructure may face challenges because user identities are inconsistent or in conflict across the different domains. This provides a very complex problem for policy management and enforcement.

Large organizations have applications their employees and partners need access to, and hundreds of databases that store details on their customers and other confidential data. Without proper handling of access to this sensitive data, the security of customer records and proprietary company information could be seriously compromised.

  • To alleviate data seepage, a centralized approach to policy enforcement and protecting the organization’s key network assets based on a validated user identity from a single authoritative source is becoming a necessity
  • Multiple identity stores evolve over time in either an ad-hoc fashion or through mergers and acquisitions.

Identity Aware Networks Require Global Identifiers

Applied Identity solves this problem by creating a global identity through virtualization technology. Identisphere ID-Unify can virtualize identities that enable policies to be associated with a normalized, single identity for users that exist in different directories. Multiple directories are common as they  mergers and acquisitions

ID-Unify is a deployment enabler for identity aware networks as it provides a single authoritative source of user identity for policy creation and enforcement. Applied Identity can virtualize an organization’s multiple identity stores - without the need for replication or modification to the original identity sources – to derive a global identity for a user.

  • With ID-Unify, a user authenticates to the network and are assigned a network access policy based on their global identity - regardless of the directory source of that authentication