From 49868fe497c3661660cd2aed6918077bb2c0d227 Mon Sep 17 00:00:00 2001 From: Keith Hazelton Date: Mon, 17 May 2021 12:11:33 -0500 Subject: [PATCH] Update iam-functions-list.adoc --- iam-functions-list.adoc | 63 ++++++++++++++++++++++------------------- 1 file changed, 34 insertions(+), 29 deletions(-) diff --git a/iam-functions-list.adoc b/iam-functions-list.adoc index 23e9141..8a90634 100644 --- a/iam-functions-list.adoc +++ b/iam-functions-list.adoc @@ -2,16 +2,21 @@ *User management, user concerns* -identity registration, enrollment, -identity proofing -credentialing -account validation -attribute verification - -identity resolution -progressive profiling - -self-service identity management, credential binding, password management, profiling, preferences, account linking +identity registration, enrollment + +identity proofing + +credentialing + +account validation + +attribute verification + + +identity resolution + +progressive profiling + + +self-service identity management + +credential binding + +password management + +profiling + +preferences + +account linking + consent and privacy protection @@ -21,34 +26,34 @@ support for multiple identity records (and credentials) for a single person *IAM Capabilities* -multiple AuthN sources and styles, (local SSO, social, federated, protocol gateways), -password and MFA management -session mgmt, logout +multiple AuthN sources and styles, (local SSO, social, federated, protocol gateways) + +password and MFA management + +session mgmt, logout + -access policy management (coarse and fine grained) -Access Mgmt admin, (distributable) -request/approval processes -lifecycle transitions definition and admin +access policy management (coarse and fine grained) + +Access Mgmt admin, (distributable) + +request/approval processes + +lifecycle transitions definition and admin + -service accounts -apps, services as credentialed agents for invoking other services, apis +service accounts + +apps, services as credentialed agents for invoking other services, apis + -API management -API access to all IAM functionality -api authNZ, registry, gateway, specifications, style guidelines +API management + +API access to all IAM functionality + +api authNZ, registry, gateway, specifications, style guidelines + -provisioning, deprovisioning, -messaging and api integration with connected apps & services, app integration -batch reconciliation, near real time sync between registry and connected systems -auditing, logging, reporting, attestation +provisioning, deprovisioning + +messaging and api integration with connected apps & services, app integration + +batch reconciliation, near real time sync between registry and connected systems + +auditing, logging, reporting, attestation + - - - *Data Management* -directory services -IAM data dictionary -identity and entitlement data access +directory services + +IAM data dictionary + +identity and entitlement data access + - - -