| Embedded provisioning engine and universal integration tools | Automates the implementation of administrative requests on the environment, and provides universal connectors for extending the management model to support new and custom environments | Quickly connect users to appropriate resources while reducing administration workload |
| Self-service interfaces | Enables users to perform password resets, password synchronization, and modification to personal information without administrative intervention | Helps reduce help-desk costs and ease the burden of daily administration on help-desk and IT staff |
| Closed loop user provisioning | Detects and corrects discrepancies between approved account access and local privileges | Demonstrate enforcement of internal controls to auditors and eliminate orphan or over privileged accounts |
| Access recertification | Provides ongoing certification process on whether user access is still valid and allows for automated remediation of access | Establishes formal process for validating access and facilitates critical compliance requirement |
| Role management | Enables automated assignment of user access rights via static, hierarchical and dynamic roles | Reduces cost of manual administration and enhances visibility of user access |
| Separation of duties | Prevents user access conflicts within organizational processes | Mitigates risk and enhances security by preventing user access conflicts up front |
| Group management | Centralizes the creation, modification and deletion of groups | Accelerates configuration of user administration |
| Auditing and reporting mechanisms | Enables administrators to produce reports on who has access to what | Quickly produce reports for internal audits and ensuring regulatory compliance |
| Provisioning policy impact simulation | Simulate impact of provisioning policy on user accounts before committing changes | Implement and modify provisioning policies more quickly and accurately |
| Centralized Web administration | Centralizes the definition of users and provisioning of user services | Consistent security implementation across the organization while simplifying management through a single interface |
| Role and rule-based delegated administration | Enables grouping of users according to business needs and delegation of administrative privileges along organizational and geographical boundaries | Helps reduce administration costs |