Oracle Access Manager


Introduction

Oracle Access Manager is a state-of-the-art solution for both centralized identity management and access control, providing an integrated standards-based solution that delivers authentication, web single sign-on, access policy creation and enforcement, user self-registration and self-service, delegated administration, reporting, and auditing. Oracle Access Manager's unique coupling of access management and identity administration functionality is why it is established as the leading solution for web access management. It excels in complex, heterogeneous enterprise environments and integrates out-of-the-box with all leading directory servers, application servers, web servers, and enterprise applications. Oracle Access Manager is a component of Oracle Fusion Middleware, a well-integrated family of customer-proven software products designed to shine in the most demanding customer environments.

Oracle Access Manager helps enterprises create greater levels of business agility, ensure seamless business partner integration, and enable regulatory compliance. Oracle Access Manager's innovative, integrated architecture uniquely combines identity management and access control services to provide centralized authentication, policy-based authorizations, and auditing with rich identity administration functionality such as delegated administration and workflows. By protecting resources at the point of access and delegating authentication and authorization decisions to a central authority, Oracle Access Manager helps secure web, J2EE, and enterprise applications - such as Oracle PeopleSoft - while reducing cost, complexity, and administrative burdens.

Key Features

Benefits

Automates Identity and Access Management Reduces costs by automating the management of potentially millions of users in an online business environment.
Strengthens Security Strengthens security by eliminating latency in changes to identity policy information and by improving authentication flexibility.
Improves User Management Increases visibility into identity access events throughout the enterprise to drive decisions about user and application interactions.
Centralizes Identity Administration Improves efficiency through the use of a common workflow, administrative consoles, and reporting framework for identity and access management.
Streamlines Partner Integrations Thanks to flexible delegated administration capabilities, organizations can extend their reach when integrating customers or partners into their online business, and achieve administrative scalability.
Integrates with Strategic Applications Built-in to Oracle Fusion Middleware for seamless application integration and lower TCO.
Ensures Enterprise-wide Interoperability Open and hot-pluggable heterogeneous support. Provides support for the widest range of third party platforms including BEA WebLogic, IBM WebSphere and SAP.
Enables Regulatory Compliance Ensures compliance by enforcing consistent, streamlined business rules and practices. Provides auditing and reporting capabilities to demonstrate the consistent enforcement of such rules.

Authentication and Access Control Management

Oracle Access Manager's Access Server, Policy Manager, out-of-the-box web server plugins called WebGates, and security providers for leading J2EE application servers, work together to intercept access requests to resources, check for a pre-existing authentication, authenticate users, validate credentials, and enforce access policies on protected resources. Oracle Access Manager can match the security level of a protected resource, ensuring that stronger types of authentication or more strict authorization policies are applied to more sensitive applications and services. Features of the authentication and access control service include:

  • Controls access to web applications, Enterprise Java Beans (EJB) applications, J2EE resources, and common packaged enterprise applications.
  • Web single sign-on for secure access to multiple applications with one authentication step.
  • Flexible authentication support for all popular methods including login forms, digital certificates, and smart cards.
  • Centralized and delegated policy administration and enforcement that reduces cost and operational complexity for IT administrators.

Identity Administration

The identity administration service of Oracle Access Manager provides user and group management, password management and self-service. Its scalable architecture and delegated administration functionality enable it to support administration of large user populations in complex, real-world environments. Features of the identity administration service include:

  • Management of users, groups and organizations, including dynamic groups defined based on user attributes.
  • Integrated workflow capability for orchestrating identity profile updates and approvals.
  • User self-service administration and password management to help reduce help desk calls.
  • Delegated administration, allowing unlimited ability to delegate user administration to managers and partners.
  • Support for portal inserts, allowing administrative functionality to be seamlessly embedded into web applications.
  • Highly customizable browser-based and web service interfaces to administrative functionalities offers ultimate flexibility for integration.

Portal inserts allow the seamless insertion of identity administration
functionality into enterprise web applications


Support for Enterprise Applications

Oracle Access Manager integrates with existing e-business infrastructures (such as SAP, Siebel, PeopleSoft, and Oracle eBusiness Suite). It provides pre-built agents to protect, access, and manage all popular third-party web servers, application servers, portals, LDAP directories, email systems, and relational databases. Oracle Access Manager is an integral component of Oracle Fusion Middleware, Oracle’s common infrastructure for application deployment.

Compliance Reporting

Oracle Access Manager includes unified and centralized audit reporting for all Access Manager components, with all operations stored and correlated in a secure database for reporting and analysis. Oracle Access Manager comes with pre-built identity and security reports and integrates with common reporting tools to give greater visibility and reporting on common events such as user access attempts, successful or failed authentications, or identity administration tasks. These features improve an organization's ability to meet common governmental and industry regulations.

Bottom Line

Oracle Access Manager is the industry’s most comprehensive identity and access management solution with integrated identity administration, single sign-on, centralized policy management and a compliance-reporting framework. Oracle Access Manager supports a wide variety of authentication mechanisms - for example HTML Forms, X.509 certificates, and smart cards -  and has a flexible administration framework for creating, managing, or customizing access control policies. Authentication control and policy enforcement is provided out of the box for a wide variety of web servers, application servers, and packaged applications running on nearly any flavor of operating system, including Windows, SUSE Linux, RedHat Linux, Solaris, AIX, and HP-UX. Oracle Access Manager is the choice for complex, heterogeneous, highly distributed, or massively scaled environments, and has been consistently recognized as the leading web access management solution by the industry's most important analysts.


Top of Page


Oracle Corporation
World Headquarters
500 Oracle Parkway
Redwood Shores, CA 94065

Worldwide Inquiries:
+1.650.506.7000
Fax +1.650.506.7200
http://www.oracle.com/

Copyright© Oracle Corporation 2006
All Rights Reserved

This document is provided for informational purposes only,
and the information herein is subject to change
without notice. Please report any errors herein to
Oracle Corporation. Oracle Corporation does not provide
any warranties covering and specifically disclaims any
liability in connection with this document.

Oracle is a registered trademark of Oracle Corporation.

All other company and product names mentioned are used
for identification purposes only and may be trademarks of
their respective owners.

E-mail this page
Printer View Printer View
Oracle Is The Information Company About Oracle | Oracle RSS Feeds | Careers | Contact Us | Site Maps | Legal Notices | Terms of Use | Privacy