<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Bob&#039;s Identity Management Blog &#187; ActiveRoles Server</title>
	<atom:link href="http://www.bobbobel.com/tag/activeroles-server/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.bobbobel.com</link>
	<description>&#34;Anyone can hold the helm when the sea is calm.&#34; - Syrus Publilius</description>
	<lastBuildDate>Mon, 16 Jan 2012 21:47:10 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
		<item>
		<title>Delegation over mail enabled users and contacts only</title>
		<link>http://www.bobbobel.com/delegation-over-mail-enabled-users-and-groups-only/</link>
		<comments>http://www.bobbobel.com/delegation-over-mail-enabled-users-and-groups-only/#comments</comments>
		<pubDate>Thu, 18 Aug 2011 12:49:21 +0000</pubDate>
		<dc:creator>Bob</dc:creator>
				<category><![CDATA[Active Directory]]></category>
		<category><![CDATA[Demo]]></category>
		<category><![CDATA[ActiveRoles Server]]></category>
		<category><![CDATA[Bob Bobel]]></category>
		<category><![CDATA[Delegation over mail enabled objects]]></category>

		<guid isPermaLink="false">http://www.bobbobel.com/?p=1118</guid>
		<description><![CDATA[The ActiveRoles product comes with Roles (a.k.a. Access Templates) that use the native permission model to provide delegation. To perform delegation you need to identify the Role, the Trustee (in this case an OU Admin) and the scope. The first two are simple as you just select an Access Template and a user or group [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>ActiveRoles</strong> product comes with Roles (a.k.a. Access Templates) that use the native permission model to provide delegation. To perform delegation you need to identify the Role, the Trustee (in this case an OU Admin) and the scope. The first two are simple as you just select an Access Template and a user or group while the third can also be simple if you understand how to define custom scopes using Managed Units.  In this video I will show you how to delegate managing email address over mail enabled users and contacts, but not mailbox enabled users or groups.</p>
<p><iframe src="http://www.youtube.com/embed/IiSD2979uSo?hl=en&amp;fs=1" frameborder="0" width="425" height="349"></iframe></p>
]]></content:encoded>
			<wfw:commentRss>http://www.bobbobel.com/delegation-over-mail-enabled-users-and-groups-only/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Top 10 Reasons ActiveRoles Beat the Competition</title>
		<link>http://www.bobbobel.com/top-10-reasons-activeroles-beats-the-competition/</link>
		<comments>http://www.bobbobel.com/top-10-reasons-activeroles-beats-the-competition/#comments</comments>
		<pubDate>Mon, 25 Jul 2011 09:00:56 +0000</pubDate>
		<dc:creator>Bob</dc:creator>
				<category><![CDATA[Active Directory]]></category>
		<category><![CDATA[Bobel]]></category>
		<category><![CDATA[Active Directory Help]]></category>
		<category><![CDATA[Active Directory Provisioning]]></category>
		<category><![CDATA[ActiveRoles Server]]></category>
		<category><![CDATA[AD Permission]]></category>
		<category><![CDATA[bv-admin]]></category>
		<category><![CDATA[NetIQ DRA]]></category>
		<category><![CDATA[PowerShell AD CMDLETS]]></category>
		<category><![CDATA[Privilege Account Management]]></category>
		<category><![CDATA[Virtual Directory]]></category>

		<guid isPermaLink="false">http://www.bobbobel.com/?p=1087</guid>
		<description><![CDATA[I get one question frequently from both customers and colleges. &#8220;Why was ActiveRoles able to so easily beat the competition over the past seven years?&#8221; Unfortunately, there isn&#8217;t a single answer, rather it is a combination of design elements put into the product over time. Purpose Built for Active Directory -Unlike other solutions, ActiveRoles was [...]]]></description>
			<content:encoded><![CDATA[<p>I get one question frequently from both customers and colleges. &#8220;Why was ActiveRoles able to so easily beat the competition over the past seven years?&#8221; Unfortunately, there isn&#8217;t a single answer, rather it is a combination of design elements put into the product over time.</p>
<ol>
<li><strong>Purpose Built for Active Directory -</strong><span>Unlike other solutions, <span>ActiveRoles</span> was purpose built for Active Directory while other solutions were built to manage the Windows NT account database.  Because solutions originally built for Windows NT could only be retrofitted to perform AD management they are not able to take advantage of core AD features many of which are discussed in this brief.<br />
 </span></li>
<li><strong>Integrated and timely support for key Microsoft platforms -</strong><span>Active Directory, Exchange, ADLDS <span>SharePoint</span>, ADSI and <span>PowerShell</span> are critical platform components that must be supported. While other products may take years to support the latest versions of these products, <span>ActiveRoles</span> typically supports them on the day they are released or at a maximum of 60 days post release.<br />
 </span></li>
<li><strong>Compatibility with Active Directory&#8217;s Security Model &#8211; </strong><span>The Active Directory permission model is based on a set of Access Control Lists that link directory rights to delegate trustees allowing the delegated admin to exercise those rights to perform some task in AD. Unlike <span>ActiveRoles</span> Server, most solutions require the use of a proprietary permission that have little or no understandable correlation to AD rights they grant. When the <span>ActiveRoles</span> service starts, the service creates a <span>virtualized</span> version of the AD rights used in the <span>ACLs</span> and then extends the list with several virtual permissions. To the person administrating security in <span>ActiveRoles</span> they seen an almost identically list of rights with the same look and feel of the native AD rights. <span>ActiveRoles</span> Server also has the added advantage of combining these rights into Roles for clarity and accuracy of security assignment and easy delegation of administration. A side benefit of compatibility with the Active Directory Security Model is the vast knowledge available on how AD permissions work and which permissions are required to perform specific tasks.<br />
 </span></li>
<li><strong>Compatibility with Active Directory Service Connection Points &#8211; </strong><span>A standard Active Directory service known as Service Connection Points (<span>SCPs</span>) allow applications to inform Active Directory of the applications presence in the enterprise. It is important to note that <span>SCPs</span> require no agents, customer configuration or changes to Active Directory. When the <span>ActiveRoles</span> Service executes it registers an SCP so that any console or web UI can locate the service instantly.<br />
 </span></li>
<li><strong>Compatibility with Active Directory&#8217;s DirSync service &#8211; </strong><span>A standard Active Directory services known as <span>DirSync</span> allow applications to instantly see what changes are happening within AD. This is the same service Domain Controllers use to exchange change information to determine what items need to be replicated. . It is important to note that the <span>DirSync</span> service requires no agents, customer configuration or changes to Active Directory. The <span>ActiveRoles</span> service listens to the <span>DirSync</span> service for changes made directly to Active Directory that may require <span>ActiveRoles</span> to perform some action such as enforce a group&#8217;s membership or send a change notification.<br />
 </span></li>
<li><strong>Virtual Unified Schema &#8211; </strong><span>Unlike other solutions that use a fixed schema and won&#8217;t recognize schema extensions, <span>ActiveRoles</span> uses a virtual unified schema built from the <span>schemas</span> of the domains being managed. When the <span>ActiveRoles</span> service starts it reads the schema of each domain being managed and adds that schema the <span>ActiveRoles</span> unified virtual schema. This unified virtual schema also includes any schema extensions that may be present in a particular domain so that applications that require data be populated during user provisioning or cleared during user <span>deprovisoning</span> can be supported. <span>ActiveRoles</span> also adds a set of virtual attributes to allow for more granular delegation over attributes or to allow other data not stored in AD to be associated with an object.<br />
 </span></li>
<li><strong>Real-time vs. Cached Data -</strong><span>To avoid the chance that two administrators open an AD object and view different information the retrieval of AD data must be done without caching of the data. Unlike many solutions that either load object data into a cache or into a separate database before an administrator accesses the object,  the <span>ActiveRoles</span> service retrieves the data in real-time.<br />
 </span></li>
<li><strong>Security Integrated <span><span>Workflow</span> </span>-</strong><span>The role based delegation of administration provided by <span>ActiveRoles</span> Server not only allows the customer to control what AD operations each administrator, help desk admin or end user can perform it also provides the security context for change approval and <span>workflow</span>. By integrating a <span>workflow</span> engine and <span>workflow</span> editor directly into <span>ActiveRoles</span>, the customer avoids the need to configure and maintain multiple products and maintain multiple delegation models.<br />
 </span></li>
<li><strong>Unified Storage -</strong><span>Unlike other solutions that may require both Microsoft SQL and Microsoft AD LDS or Microsoft Access, <span>ActiveRoles</span> requires only Microsoft SQL Server for operation. Both <span>ActiveRoles</span> Configuration and reporting utilize Microsoft SQL Server. Less moving parts make <span>ActiveRoles</span> is simpler to deploy and maintain.<br />
 </span></li>
<li><strong>Embedded Extensibility -</strong><span> Because no off the shelf product will meet every need a customer may have the ability for the solution to be extended easily and in a maintainable way. In addition to both an external ADSI and <span>PowerShell</span> interface, <span>ActiveRoles</span> provides an embedded script editor, script library directly in the product so that the system can run a script in response to some event such as when a user performs an operation in Active Directory.</span></li>
</ol>
]]></content:encoded>
			<wfw:commentRss>http://www.bobbobel.com/top-10-reasons-activeroles-beats-the-competition/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>bv-Admin EOL &#8211; RIP</title>
		<link>http://www.bobbobel.com/bv-admin-eol-rip/</link>
		<comments>http://www.bobbobel.com/bv-admin-eol-rip/#comments</comments>
		<pubDate>Fri, 08 Jul 2011 10:07:54 +0000</pubDate>
		<dc:creator>Bob</dc:creator>
				<category><![CDATA[Active Directory]]></category>
		<category><![CDATA[Bobel]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[ActiveRoles Server]]></category>
		<category><![CDATA[bv-admin]]></category>

		<guid isPermaLink="false">http://www.bobbobel.com/?p=1082</guid>
		<description><![CDATA[Some of you may not have heard that Symantec&#8217;s bv-Admin was officially end-of-lifed and is no longer supported as of early in 2011. Originally a Windows NT management tool, later it was retrofitted to manage AD. While bv-Admin had several ground breaking features for its time, the acquisition of Bindview, development challenges and competitive pressures appear [...]]]></description>
			<content:encoded><![CDATA[<p>Some of you may not have heard that Symantec&#8217;s bv-Admin was officially end-of-lifed and is no longer supported as of early in 2011. Originally a Windows NT management tool, later it was retrofitted to manage AD. While bv-Admin had several ground breaking features for its time, the acquisition of Bindview, development challenges and competitive pressures appear to have taken their toll.  <a href="http://www.symantec.com/business/support/index?page=content&amp;id=TECH131120">http://www.symantec.com/business/support/index?page=content&amp;id=TECH131120</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.bobbobel.com/bv-admin-eol-rip/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Setup FREE Syncronization from AD to AD/ADLDS in 15 minutes or less!</title>
		<link>http://www.bobbobel.com/setup-free-syncronization-from-ad-to-adadlds-in-15-minutes-or-less/</link>
		<comments>http://www.bobbobel.com/setup-free-syncronization-from-ad-to-adadlds-in-15-minutes-or-less/#comments</comments>
		<pubDate>Fri, 10 Dec 2010 18:17:02 +0000</pubDate>
		<dc:creator>Bob</dc:creator>
				<category><![CDATA[Active Directory]]></category>
		<category><![CDATA[Identity]]></category>
		<category><![CDATA[Active Directory Help]]></category>
		<category><![CDATA[Active Directory Synchronization]]></category>
		<category><![CDATA[ActiveRoles Server]]></category>
		<category><![CDATA[AD Sync]]></category>
		<category><![CDATA[ADAM Syncronziation]]></category>
		<category><![CDATA[ADLDS]]></category>
		<category><![CDATA[Free GAL Sync]]></category>
		<category><![CDATA[GAL Synchronization]]></category>
		<category><![CDATA[IIFP]]></category>
		<category><![CDATA[Quick Connect]]></category>
		<category><![CDATA[Synchronization]]></category>

		<guid isPermaLink="false">http://www.bobbobel.com/?p=1045</guid>
		<description><![CDATA[What is ActiveRoles Quick Connect Express? With the latest release of ActiveRoles Quick Connect we bundled the Synchronization engine, the AD connector and the ADLDS (formerly ADAM) connector together. The big news here is that we labeled this core piece &#8220;Quick Connect Express&#8221; and you can download and used it to sync objects between those [...]]]></description>
			<content:encoded><![CDATA[<p>What is <strong>ActiveRoles Quick Connect Express</strong>? With the latest release of ActiveRoles Quick Connect we bundled the Synchronization engine, the AD connector and the ADLDS (formerly ADAM) connector together. The big news here is that we labeled this core piece &#8220;Quick Connect Express&#8221; and you can download and used it to sync objects between those systems.  For those of you who remember Microsoft&#8217;s IIFP &#8211; this package was my way of picking up the torch when Microsoft stopped updating IIFP several years ago.</p>
<p><strong>Major benefits</strong></p>
<ul>
<li>After you install the application it takes less than <span style="text-decoration: underline;"><span style="color: #800000;">15 minutes to setup a sync between systems</span></span>; so this thing is extremely easy to use</li>
<li>Synchronize Users, Groups, Group memberships and almost all other objects in AD</li>
<li>Built-in rules for user name generation and attribute transformation</li>
<li>Efficient Group Membership Synchronization</li>
<li>Sync Passwords between systems using the password capture agent for Windows clients</li>
<li>Hosting company and consultant friendly</li>
<li>Integrated PowerShell scripting for extending functionality</li>
</ul>
<p><strong>Download it here </strong><a href="http://www.quest.com/activeroles-server/quickconnect-express-for-active-directory.aspx">http://www.quest.com/activeroles-server/quickconnect-express-for-active-directory.aspx</a></p>
<p><strong>Other free stuff from my team</strong></p>
<ul>
<li>SPML web service for provisioning AD or ActiveRoles Server <a href="http://www.quest.com/activeroles-server/spml.aspx">http://www.quest.com/activeroles-server/spml.aspx</a></li>
<li>PowerShell commandlets for AD and ActiveRoles Server <a href="http://www.quest.com/activeroles-server/extensible-platform.aspx">http://www.quest.com/activeroles-server/extensible-platform.aspx</a></li>
</ul>
<p><strong>Freeware use -</strong> becuase this is freeware Quest Support is not included without an actual purchase of the software. We do have an excellent forum where the answers to basic questions may have already been answered and of course you can always post a question of your own. <a href="http://activeroles.inside.quest.com/index.jspa">http://activeroles.inside.quest.com/index.jspa</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.bobbobel.com/setup-free-syncronization-from-ad-to-adadlds-in-15-minutes-or-less/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>ActiveRoles Sever 6.7 GA</title>
		<link>http://www.bobbobel.com/activeroles-sever-6-7-ga/</link>
		<comments>http://www.bobbobel.com/activeroles-sever-6-7-ga/#comments</comments>
		<pubDate>Wed, 01 Dec 2010 02:02:06 +0000</pubDate>
		<dc:creator>Bob</dc:creator>
				<category><![CDATA[Active Directory]]></category>
		<category><![CDATA[Active Directory Help]]></category>
		<category><![CDATA[Active Directory Identity Management]]></category>
		<category><![CDATA[ActiveRoles Server]]></category>
		<category><![CDATA[AD User and Group Management]]></category>
		<category><![CDATA[ADFS]]></category>
		<category><![CDATA[Attestation]]></category>
		<category><![CDATA[Bob Bobel]]></category>
		<category><![CDATA[Compliance]]></category>
		<category><![CDATA[Employee Account Review]]></category>
		<category><![CDATA[Entitlment Management]]></category>
		<category><![CDATA[GRC]]></category>
		<category><![CDATA[Identity Lifecycle]]></category>
		<category><![CDATA[IDM]]></category>
		<category><![CDATA[OCS]]></category>
		<category><![CDATA[Onboarding]]></category>
		<category><![CDATA[PowerShell AD CDLETS]]></category>
		<category><![CDATA[SAML]]></category>
		<category><![CDATA[Service Account Review]]></category>
		<category><![CDATA[SSO]]></category>
		<category><![CDATA[User and Group Certification]]></category>
		<category><![CDATA[User Deprovsioning]]></category>
		<category><![CDATA[User Provisoning]]></category>
		<category><![CDATA[Workflow Approvel in Microsoft Outlook]]></category>

		<guid isPermaLink="false">http://www.bobbobel.com/?p=1018</guid>
		<description><![CDATA[I am very proud to announce that ActiveRoles Server 6.7 and Quick Connect 4.7 become generally available (GA) today. Look for the new product to be on our download servers over the next several hours. As with all previous releases &#8211; this release has several building blocks that when exploited will have a huge impact on [...]]]></description>
			<content:encoded><![CDATA[<p><span>I am very proud to announce that <span>ActiveRoles </span>Server 6.7 and Quick Connect 4.7 become generally available (GA) today. Look for the new product to be on our download servers over the next several hours. As with all previous releases &#8211; this release has several building blocks that when exploited will have a huge impact on both our customers and the market. Below I have included a What&#8217;s New list for the core ActiveRoles Product. Over the next three days I will provide some additional posts discussion some of these new features in a little more detail.</span></p>
<p><span> </span><span><strong>What&#8217;s New in ActiveRoles Server 6.7</strong></span></p>
<ul><span></p>
<li><strong>The ActiveRoles Market -</strong>Improvements to policy extensions and workflow extensibility allow for more efficient tools for creating and deploying custom policy types that will be posted to the ActiveRoles Market</li>
<li><strong>Improved Import/Export -</strong>For some time, ActiveRoles has come with a tool to import and export configuration settings and this tool has been improved and will continue to evolve from importing and exporting roles and policies to much more. The next version will provide the ability to import and export entire new solution scenarios including scripts, policies, workflow activities and web interface customizations.</li>
<li><span><strong>Entitlement Profile &#8211; </strong>All-in-one view of each user’s entitlements to IT resources, which provides detailed<br />
information about the applications, services and data locations the user is entitled to access, use or manage</span></li>
<li><span><strong>Microsoft Outlook Approve/Reject buttons &#8211; </strong>Approval management tools integrated in Microsoft Office Outlook</span></li>
<li><span><strong>Reply to approve a request &#8211; </strong>Approval management using e-mail clients directly from desktop or mobile devices</span></li>
<li><span><strong>Workflow activity extensions &#8211; </strong>facilitates the creation, deployment and use of custom script-based activities</span></li>
<li><span><strong>Simplified Self-Service UI &#8211; </strong>Improvements to self-service pages, to make it easier for self-service users to locate, select<br />
and join groups and distribution lists</span></li>
<li><span><strong>Simplified Workflow Notifications -</strong> Improvments to make approval notifications easier to both read and action.</span></li>
<li><span><strong>New granular workflow triggers for Group Membership Requests &#8211; </strong>New workflow start options to distinguish between the “add to group” and “remove from group” requests</span></li>
<li><span><strong>Improved Workflow GUI Editor &#8211; </strong>New workflow options for configuring approval rules, notification recipients and notification messages</span></li>
<li><span><strong>See all parts of AD, not just the parts you own &#8211; </strong>Unmanaged account domains to reduce ActiveRoles Server licensing costs for areas of Active Directory not being managed by ActiveRoles Server</span></li>
<li><span><strong>MMC Tabs for OCS &#8211; </strong>Ability to configure domain user accounts for Microsoft Office Communications Server 2007 or 2007 R2, by using the ActiveRoles Server console</span></li>
<li><span><strong>Attestation for all AD Objects- </strong>Extended attestation capabilities, including the ability to review and certify almost any aspect of directory data, including data specific to user log-on accounts, service log-on accounts, group memberships, computers, contacts, and other types of directory objects.</span></li>
<p></span></ul>
<p><span> </span>To download this new version please go to: <a href="http://www.quest.com/common/registration.aspx?requestdefid=7910">http://www.quest.com/common/registration.aspx?requestdefid=7910</a> </p>
<ul> </ul>
]]></content:encoded>
			<wfw:commentRss>http://www.bobbobel.com/activeroles-sever-6-7-ga/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Microsoft PKI/Certificate Management made easier</title>
		<link>http://www.bobbobel.com/microsoft-pkicertificate-management-made-easier/</link>
		<comments>http://www.bobbobel.com/microsoft-pkicertificate-management-made-easier/#comments</comments>
		<pubDate>Wed, 08 Sep 2010 17:40:12 +0000</pubDate>
		<dc:creator>Bob</dc:creator>
				<category><![CDATA[Active Directory]]></category>
		<category><![CDATA[PowerShell]]></category>
		<category><![CDATA[Active Directory Help]]></category>
		<category><![CDATA[ActiveRoles Server]]></category>
		<category><![CDATA[AD PKI]]></category>
		<category><![CDATA[Finding Expired Certificates]]></category>
		<category><![CDATA[Issue Certs with PowerShell]]></category>
		<category><![CDATA[PowerShell Certificate Management]]></category>
		<category><![CDATA[PowerShell PKI management]]></category>
		<category><![CDATA[Quest AD CMDLETS]]></category>

		<guid isPermaLink="false">http://www.bobbobel.com/?p=978</guid>
		<description><![CDATA[Dmitry Sotnikov posted a brief article talking about the new PowerGUI power pack based on the ActiveRoles PowerShell CMDLETS (a.k.a. Quest&#8217;s AD CMDLETS) for Microsoft PKI management. Read the article here. Download the latest version of CMDLETS here.]]></description>
			<content:encoded><![CDATA[<p>Dmitry Sotnikov posted a brief article talking about the new PowerGUI power pack based on the ActiveRoles PowerShell CMDLETS (a.k.a. Quest&#8217;s AD CMDLETS) for Microsoft PKI management.</p>
<p><a href="http://dmitrysotnikov.wordpress.com/2010/09/07/pki-management-console-1-5/?utm_source=feedburner&amp;utm_medium=email&amp;utm_campaign=Feed:+DmitrysPowerblog+(Dmitry's+PowerBlog)" target="_blank">Read the article here.</a></p>
<p><a href="http://www.quest.com/powershell/activeroles-server.aspx" target="_blank">Download the latest version of CMDLETS here.</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.bobbobel.com/microsoft-pkicertificate-management-made-easier/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Remaining ActiveRoles Server User Group Meetings for 2010</title>
		<link>http://www.bobbobel.com/q4-activeroles-server-user-group-meetings/</link>
		<comments>http://www.bobbobel.com/q4-activeroles-server-user-group-meetings/#comments</comments>
		<pubDate>Wed, 08 Sep 2010 15:03:07 +0000</pubDate>
		<dc:creator>Allison</dc:creator>
				<category><![CDATA[Active Directory]]></category>
		<category><![CDATA[Active Directory Help]]></category>
		<category><![CDATA[ActiveRoles Server]]></category>
		<category><![CDATA[AD Help]]></category>
		<category><![CDATA[Administration]]></category>
		<category><![CDATA[Audit AD]]></category>
		<category><![CDATA[Deprovsion]]></category>
		<category><![CDATA[Provsion]]></category>

		<guid isPermaLink="false">http://www.bobbobel.com/?p=969</guid>
		<description><![CDATA[An ActivecRoles user&#8217;s group meeting may be headed for a city near you. Düsseldorf, Germany Oct 6th (TEC) Cleveland, Ohio Oct 12 Boston, MA Oct 14th London, England October 18th or 19th (Date to be determined) Houston, Texas October 26th Please email Allison Main or Bob Bobel for additional information or to register.]]></description>
			<content:encoded><![CDATA[<p>An ActivecRoles user&#8217;s group meeting may be headed for a city near you.</p>
<ul>
<li>
<div>Düsseldorf, Germany Oct 6th (TEC)</div>
</li>
<li>
<div>Cleveland, Ohio Oct 12</div>
</li>
<li>
<div>Boston, MA Oct 14th</div>
</li>
<li>
<div>London, England October 18th or 19th (Date to be determined)</div>
</li>
<li>
<div>Houston, Texas October 26th</div>
</li>
</ul>
<p>Please email <a href="mailto:allison.main@quest.com">Allison Main</a> or <a href="mailto:robert.bobel@quest.com">Bob Bobel</a> for additional information or to register.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.bobbobel.com/q4-activeroles-server-user-group-meetings/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Absolute Power: Controlling the Risk of Domain Admins</title>
		<link>http://www.bobbobel.com/absolute-power-controlling-the-risk-of-domain-admins/</link>
		<comments>http://www.bobbobel.com/absolute-power-controlling-the-risk-of-domain-admins/#comments</comments>
		<pubDate>Wed, 08 Sep 2010 14:56:53 +0000</pubDate>
		<dc:creator>Allison</dc:creator>
				<category><![CDATA[Active Directory]]></category>
		<category><![CDATA[ActiveRoles Server]]></category>
		<category><![CDATA[AD Domain Admins]]></category>
		<category><![CDATA[Control Domain Administrators]]></category>
		<category><![CDATA[Privilege AD Accounts]]></category>

		<guid isPermaLink="false">http://www.bobbobel.com/?p=963</guid>
		<description><![CDATA[Upcoming Live Webcast 9/21/2010 11:00:00 AM EST Register Today! One of my frequent consulting activities is performing audits of Active Directory for corporate Internal Audit departments and hardly an audit has gone by where I wasn’t obligated to bring to Board’s attention the number of all-powerful administrators present in Active Directory.  This is a real [...]]]></description>
			<content:encoded><![CDATA[<p><strong>Upcoming Live Webcast</strong></p>
<p><strong>9/21/2010 11:00:00 AM EST</strong></p>
<p><a href="http://www.ultimatewindowssecurity.com/webinars/register.aspx?id=106&amp;source=sp" target="_blank"><strong>Register Today!</strong></a></p>
<div>One of my frequent consulting activities is performing audits of Active Directory for corporate Internal Audit departments and hardly an audit has gone by where I wasn’t obligated to bring to Board’s attention the number of all-powerful administrators present in Active Directory.  This is a real risk that has to be addressed.  With an infrastructure security technology like Active Directory you can’t have scores of people with admin authority.  There’s just too much room for mistakes and malicious acts.  And the worst does happen – I’m sure you’ve heard the horror stories.</div>
<div>I’ve long preached about Active Directory’s built-in delegation of control feature that allows you to follow least privilege within the IT department.  In this webinar I will show you how to get the majority of people out of the Domain Admins group and grant them just the granular authority they actually need. </div>
<div>I will also show how can audit both the delegation of admin authority as well as the use of admin authority.  What I mean is using the security log to monitor when you make Bob an admin/subadmin as well as when Bob uses that authority to do something like creating a new user account.</div>
<div>Then I’ll look at ways to ensure that emergencies can still be handled after removing basically everyone from the domain admins group. </div>
<div>Even with all these capabilities though I find that many companies fail to secure admin authority and implement least privilege.  Plus I find so many IT departments where admins are wasting time doing the basically clerical tasks of carrying out the menial and repetitive access control and account management changes already initiated and approved by managers and the HR department.  With that in mind you will be interested in seeing how this webinar’s sponsor, Quest, can take you beyond the capabilities I demonstrate and make it so easy and manageable to follow least privilege and reduce IT staff workload through self-service and automation.  So you’ll see how you can solve these problems using native AD functionality and then how to take it to the next level. </div>
]]></content:encoded>
			<wfw:commentRss>http://www.bobbobel.com/absolute-power-controlling-the-risk-of-domain-admins/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Automatically Provisoning and Deprovison Postini</title>
		<link>http://www.bobbobel.com/automatically-provisoning-and-deprovison-postini/</link>
		<comments>http://www.bobbobel.com/automatically-provisoning-and-deprovison-postini/#comments</comments>
		<pubDate>Thu, 02 Sep 2010 12:07:45 +0000</pubDate>
		<dc:creator>Bob</dc:creator>
				<category><![CDATA[Active Directory]]></category>
		<category><![CDATA[ActiveRoles Server]]></category>
		<category><![CDATA[FIM]]></category>
		<category><![CDATA[Oracle IDM]]></category>
		<category><![CDATA[Provsion Postini]]></category>

		<guid isPermaLink="false">http://www.bobbobel.com/?p=948</guid>
		<description><![CDATA[Today our team uploaded an Policy Extension to the ActiveRoles community for Postini!  This policy will both provision and deprovision Postini gateway accounts when the associated Active Directory account is updated. To use this policy you simply download the policy, install it in ActiveRoles Server then configure the policy with your Postini account details. The new policy is free [...]]]></description>
			<content:encoded><![CDATA[<p>Today our team uploaded an <a href="http://wiki.activeroles.inside.quest.com/index.php/Category:Policy_Extension" target="_blank">Policy Extension</a> to the ActiveRoles community for Postini!  This policy will both provision and deprovision Postini gateway accounts when the associated Active Directory account is updated. To use this policy you simply download the policy, install it in ActiveRoles Server then configure the policy with your Postini account details. The new policy is free for ActiveRoles customers and you can download the the new policy here: <a href="http://wiki.activeroles.inside.quest.com/index.php/Postini_Services_provisioning_for_ActiveRoles_Server" target="_blank">DOWNLOAD NOW</a></p>
<div id="attachment_950" class="wp-caption aligncenter" style="width: 310px"><a href="http://www.bobbobel.com/wp-content/uploads/2010/09/PostiniServiceProvisioningForARS1.jpg"><img class="size-medium wp-image-950" title="PostiniServiceProvisioningForARS" src="http://www.bobbobel.com/wp-content/uploads/2010/09/PostiniServiceProvisioningForARS1-300x210.jpg" alt="ARS Postini Policy" width="300" height="210" /></a><p class="wp-caption-text">ActiveRoles Change History showing Postini Provsioning</p></div>
]]></content:encoded>
			<wfw:commentRss>http://www.bobbobel.com/automatically-provisoning-and-deprovison-postini/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>AD CMDLETS 1.4 now live!</title>
		<link>http://www.bobbobel.com/ad-cmdlets-1-4-now-live/</link>
		<comments>http://www.bobbobel.com/ad-cmdlets-1-4-now-live/#comments</comments>
		<pubDate>Thu, 15 Jul 2010 14:07:16 +0000</pubDate>
		<dc:creator>Bob</dc:creator>
				<category><![CDATA[Active Directory]]></category>
		<category><![CDATA[Active Directory Tools]]></category>
		<category><![CDATA[ActiveRoles Server]]></category>
		<category><![CDATA[AD Help]]></category>
		<category><![CDATA[AD Tools]]></category>
		<category><![CDATA[Bobel]]></category>
		<category><![CDATA[Finding Inactive Accounts]]></category>
		<category><![CDATA[Help with Active Directory]]></category>
		<category><![CDATA[PowerShell AD CMDLETS]]></category>
		<category><![CDATA[PowerShell C]]></category>
		<category><![CDATA[PowerShell Obsolete Accounts]]></category>

		<guid isPermaLink="false">http://www.bobbobel.com/?p=928</guid>
		<description><![CDATA[The 1.4 version of the ActiveRoles AD CMDLETS went live a few moments ago and you can download them here http://www.quest.com/powershell/activeroles-server.aspx.]]></description>
			<content:encoded><![CDATA[<p>The 1.4 version of the ActiveRoles AD CMDLETS went live a few moments ago and you can download them here <a href="http://www.quest.com/powershell/activeroles-server.aspx">http://www.quest.com/powershell/activeroles-server.aspx</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.bobbobel.com/ad-cmdlets-1-4-now-live/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>AD CMDLETS Version 1.4 (Early look)</title>
		<link>http://www.bobbobel.com/ad-cmdlets-version-1-4-early-look/</link>
		<comments>http://www.bobbobel.com/ad-cmdlets-version-1-4-early-look/#comments</comments>
		<pubDate>Tue, 18 May 2010 13:23:30 +0000</pubDate>
		<dc:creator>Bob</dc:creator>
				<category><![CDATA[Active Directory]]></category>
		<category><![CDATA[Active Directory Help]]></category>
		<category><![CDATA[ActiveRoles Server]]></category>
		<category><![CDATA[AD CMDLETS]]></category>
		<category><![CDATA[Bobel]]></category>
		<category><![CDATA[Deprovisioning]]></category>
		<category><![CDATA[inactive accounts enumeration]]></category>
		<category><![CDATA[obsolete accounts]]></category>
		<category><![CDATA[PowerShell]]></category>
		<category><![CDATA[PowerShell Certificate]]></category>
		<category><![CDATA[PowerShell PKI management]]></category>
		<category><![CDATA[Quest CMDLETS]]></category>

		<guid isPermaLink="false">http://www.bobbobel.com/?p=895</guid>
		<description><![CDATA[In late June or early July, a new version of the Active Directory PowerShell CMDLETS will be released. I wanted to give everyone a teaser about the new features to be added. Here you go! -        Certificate management -        Support for cross-domain group membership -        inactive accounts enumeration -        single command to search in multiple [...]]]></description>
			<content:encoded><![CDATA[<p>In late June or early July, a new version of the Active Directory PowerShell CMDLETS will be released. I wanted to give everyone a teaser about the new features to be added.</p>
<p>Here you go!</p>
<p>-        Certificate management<br />
-        Support for cross-domain group membership<br />
-        inactive accounts enumeration<br />
-        single command to search in multiple containers<br />
-        progress indication<br />
-        proxy addresses management</p>
<p>Stay tuned and I will blog with more details around each feature over the next several weeks.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.bobbobel.com/ad-cmdlets-version-1-4-early-look/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>ActiveRoles DC User&#8217;s Group</title>
		<link>http://www.bobbobel.com/activeroles-dc-users-group/</link>
		<comments>http://www.bobbobel.com/activeroles-dc-users-group/#comments</comments>
		<pubDate>Tue, 27 Apr 2010 16:00:36 +0000</pubDate>
		<dc:creator>Bob</dc:creator>
				<category><![CDATA[Active Directory]]></category>
		<category><![CDATA[Active Directory Help]]></category>
		<category><![CDATA[ActiveRoles Server]]></category>

		<guid isPermaLink="false">http://www.bobbobel.com/?p=850</guid>
		<description><![CDATA[Late last week I was in Washington DC where we held our first DC User&#8217;s group at our Rockville, MD location.  It was a pleasure to speak with the attendees and to discuss their requirements around ActiveRoles. It still amazes me that when I was given the ActiveRoles product we had around 60 customers and [...]]]></description>
			<content:encoded><![CDATA[<p>Late last week I was in Washington DC where we held our first DC User&#8217;s group at our Rockville, MD location.  It was a pleasure to speak with the attendees and to discuss their requirements around ActiveRoles. It still amazes me that when I was given the ActiveRoles product we had around 60 customers and now we have user groups around the world.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.bobbobel.com/activeroles-dc-users-group/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>ActiveRoles Toronto User&#8217;s Group</title>
		<link>http://www.bobbobel.com/toronto-users-group/</link>
		<comments>http://www.bobbobel.com/toronto-users-group/#comments</comments>
		<pubDate>Sun, 25 Apr 2010 23:34:06 +0000</pubDate>
		<dc:creator>Bob</dc:creator>
				<category><![CDATA[Active Directory]]></category>
		<category><![CDATA[Active Directory Help]]></category>
		<category><![CDATA[ActiveRoles Server]]></category>

		<guid isPermaLink="false">http://www.bobbobel.com/?p=843</guid>
		<description><![CDATA[Early last week I had a great opportunity to meet with customers in Toronto to speak about ActiveRoles and our future direction. The secret is that I actually got more out of the session than they did by hearing the challenges they face every day as they meet the expectation of their employers. On the [...]]]></description>
			<content:encoded><![CDATA[<p>Early last week I had a great opportunity to meet with customers in Toronto to speak about ActiveRoles and our future direction. The secret is that I actually got more out of the session than they did by hearing the challenges they face every day as they meet the expectation of their employers. On the way out to the airport I got to see the Toronto Star building &#8211; Hemingway worked for the Star as a journalist early in his career.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.bobbobel.com/toronto-users-group/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Moving from Group to Access Management</title>
		<link>http://www.bobbobel.com/moving-from-group-to-access-management/</link>
		<comments>http://www.bobbobel.com/moving-from-group-to-access-management/#comments</comments>
		<pubDate>Mon, 29 Mar 2010 20:37:15 +0000</pubDate>
		<dc:creator>Allison</dc:creator>
				<category><![CDATA[Access]]></category>
		<category><![CDATA[Active Directory]]></category>
		<category><![CDATA[Entitlement]]></category>
		<category><![CDATA[Identity]]></category>
		<category><![CDATA[Tech Demo]]></category>
		<category><![CDATA[ActiveRoles Server]]></category>
		<category><![CDATA[Automated Provisioning]]></category>
		<category><![CDATA[Compliance]]></category>
		<category><![CDATA[Group Management]]></category>
		<category><![CDATA[Quick Connect]]></category>

		<guid isPermaLink="false">http://www.bobbobel.com/?p=831</guid>
		<description><![CDATA[Managing access to applications and data resources can be a time-consuming and error-prone process. IT administrators are often asked to grant access to sensitive data without knowing the business justification why a user should have it. The result may be inappropriate authorization, access delays, or groups that are bloated, outdated and inaccurate. This lack of [...]]]></description>
			<content:encoded><![CDATA[<p>Managing access to applications and data resources can be a time-consuming and error-prone process. IT administrators are often asked to grant access to sensitive data without knowing the business justification why a user should have it. The result may be inappropriate authorization, access delays, or groups that are bloated, outdated and inaccurate. This lack of accountability may cause security breaches and compliance audit failure. During this archived webcast, you&#8217;ll see how ActiveRoles Server enables:</p>
<ul>
<li>Access Accountability</li>
<li>Authorizing groups today using roles and attribute access control (ABAC) to resources</li>
<li>Authorizing groups in the future with emerging technologies</li>
<li>Moving from Group Management to Access Governance and the keys to success</li>
</ul>
<p>Presented by:<br />
<em>Robert Bobel, Platform Director of Product Management, Quest Software<br />
</em><em>Jason Barnett, Partner and Information Security Practice Manager, Ingenuity Associates, </em></p>
<p><a href="http://www.quest.com/events/ListDetails.aspx?ContentID=11239" target="_blank">View Archived Webcast</a></p>
<p><!-- Begin Small Standard CSS Button--></p>
]]></content:encoded>
			<wfw:commentRss>http://www.bobbobel.com/moving-from-group-to-access-management/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>ActiveRoles Server added to 115 UK schools!</title>
		<link>http://www.bobbobel.com/activeroles-server-added-to-115-uk-schools/</link>
		<comments>http://www.bobbobel.com/activeroles-server-added-to-115-uk-schools/#comments</comments>
		<pubDate>Wed, 10 Feb 2010 00:09:21 +0000</pubDate>
		<dc:creator>Bob</dc:creator>
				<category><![CDATA[Active Directory]]></category>
		<category><![CDATA[Active Directory Help]]></category>
		<category><![CDATA[ActiveRoles Server]]></category>
		<category><![CDATA[Unity Partnership]]></category>

		<guid isPermaLink="false">http://www.bobbobel.com/?p=788</guid>
		<description><![CDATA[I stumbled upon a really interesting article about how Unity Partnership (a venture between Mouchel and Oldham Councils in the UK) was deploying ActiveRoles Server to provide group provisioning and to control management rights for the staff and students. To read the article here.]]></description>
			<content:encoded><![CDATA[<p>I stumbled upon a really interesting article about how Unity Partnership (a venture between Mouchel and Oldham Councils in the UK) was deploying ActiveRoles Server to provide group provisioning and to control management rights for the staff and students. <a href="http://www.realwire.com/release_detail.asp?ReleaseID=15044">To read the article here.</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.bobbobel.com/activeroles-server-added-to-115-uk-schools/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

