Professional Documents
Culture Documents
UHI advertising
UHI is important for the Highlands & Islands region and is an exciting place to work
You want to hear about IDM I want to talk about UHI and what we are doing
30 slides in 45 minutes: 90 seconds per slide So I will press on to the IDM part quite quickly
UHI Mission
To establish for the Highlands and Islands of Scotland a collegiate university which will reach the highest standards and play a pivotal role in our educational, economic, social and cultural development
y y y y
Inverness College SMO EO SFIA Argyll College & DML Perth College
A short history
1993: The University of the Highlands and Islands Project UHIp A dozen partners including 8 FE colleges, a NERC research institute, a statutory body, an industry-funded college, etc All partners have an independent IT history and therefore a dozen different legacies
September 1996: Millennium Commission announces 33m funding in c. 100m initiative Feb 1997: new offices, new staff, 3yr plan
More and faster kilostream connections (change of the cost trade-off between systems and telecoms)
300 miles
UHIs territory covers over half of Scotland 1/6th of the UKs area 1/60th of the UKs total population. HE + FE accessed by about 25,000 distinct people every year Most FE students are low FTE
SoL
EastMAN
JANET
UHI Today
April 2001: an HEI with SHEFC funding AY 2004/5: over 3,800 student FTEs
50% over age 25, 50%:50% gender balance, more than 5,200 enrolments
New Year 2005: moved to new HQ, this time moving about 70 staff over weekend 2007: University title ?
Student Records
Funds & Bursary Attendance
Funds &
Class List
Module Registration
Current Students
Attendance Class List Current Students Assessment Register Assessment
Bursary
SQA interface
SQA
SQA interface
SQA
Module Registration
Award or Progression
Assessment Register
Attendance
Class List
SQA interface
Assessment
Award or Progression
SQA Entry qualifications Manage & run UHI: UHI RAM IDM LIS & ICT systems
UHI username/password (Directories) H:/ folder (NetWare) UHI email (GroupWise) UHI library borrower (OLIB) Library card / ID card
Module registrations Minerva Groups
Attendance
Class List
SQA interface
Minerva People
Module Registration
Assessment Register
Assessment
Award or Progression
Course enrolment
PAT ESi
Module registrations
Module registrations
Why ?
Save IT and Library staff trouble?
It does, but that is not why we are doing it
Make Student Records a *management tool* for the business instead of being just a record of what has already happened
When ?
Allocate accounts *before* enrolment so as to assist induction processes
As soon as details are available Only applies to students who go through some kind of records processing before enrolment No help for walk-ins (but nothing is)
Lock accounts on the day individual students are *due* to leave (planned expiry) No summer gap for continuing students
No summer clearouts anymore: only delete expired accounts, and should be able to do so in-year
Student lifecycle
Lock on expiry
Siva2
eDirectory to everywhere else: CLAN vle, MVN forum, self-provisioning through GuanXi Idp, Shibb world, etc Alistair Young is our software development ID expert
ID Flow design
SITS:Vision student record holds permanent identity
PRS table
Create/ modify
Create/ modify
Create/ modify
DEP1 UHI_IDM_TREE identity management system Passwd sync Selfservice portal Passwd sync
Siva2
Comparison: Siva1
Home-made: very flexible but requires in-house effort for maintenance and development Create-only: seek and ignore existing accounts Deals with Students only Logic for user account defaults is in java code pliers utility to get data from SITS: unreliable Although Java code, method for GroupWise is Windows only: would prefer to be on Linux
Siva2
Will run from triggers in the eDirectory API Will not care how user is created: will fire for manual creates Can do anything, including modify eDirectory accounts
PRS table
Siva2
Passwd sync
Call a consultant !
If all our users lived in the same context Citrix would work just fine With IDM, they can ! A bespoke IDM driver maintains a secret area in the e-Directory This is a flat space with an alias for each user All users appear in the same context
Next Up
Bread & butter IDM becomes responsibility of records-oriented staff who know the data
Handle withdrawals etc. based on Academic Regulations (policy basis)
Provide more subtle information based on the information content of the student record
e.g. to run Sharepoint need up-to-the-minute Groups management in the Directory Same communities as in Siva but distinct IDM flow Common vocabulary so staff (users) can understand
Technology
Designer for Identity Manager on Windows XP
Very good tool Has all the basic drivers Use to control and deploy, as well as to design
IDM3 on NetWare/ED
For eDirectory accounts For GroupWise accounts
IDM3 on W2003/AD+ED
For AD accounts
IDM3 on NetWare/ED
VNC view of DSTRACE
iManager
Control of migration, driver On/Off, etc
Thank You!
Q&A