Windows IT Pro is the leading independent community for IT professionals deploying Microsoft Windows server and client applications and technologies.
  
  
  Advanced Search 


September 2007

Cross-Platform Identity Management Solutions for Single Sign-On

3 great products with different strengths, similar weaknesses
RSS
Subscribe to Windows IT Pro | See More Active Directory (AD) Articles Here | Reprints | Or get the Monthly Online Pass—only $5.95 a month!

Centrify DirectControl
Of the three products, the DirectControl text-based UNIX installation was the simplest. It asked a few simple questions and was installed in minutes. And as with the other two applications, the Windows installation of DirectControl went smoothly.

After the installation is complete, you can either start with the MMC AD Users and Computers snap-in to configure DirectControl or go straight to the Centrify DirectControl snap-in. Unlike the other two products, the Centrify product walks you through a comprehensive wizard to set up UNIX personality management in what DirectControl calls zones. Figure 3 shows the Create New Zone wizard. Of the three products, DirectControl is by far the most complex when it comes to setting up and using UNIX personality management, but it's also the most robust.

According to Centrify, zones are similar to AD domains and organize the different flavors of UNIX in your environment. For example, you could group all your Red Hat machines in one zone and your Solaris machines in another zone, then assign the separate zones different login shells or assign the zones to different groups.

DirectControl offers Group Policy support that's similar to that of VAS. Enabling this support in our tests was as simple as adding the centrifydc.adm template to a new GPO. We were surprised by just how many options you can configure, including password policies and UNIX login settings.

An interesting feature is Personality Account Management (PAM) Conflict Resolution. With the many user IDs, GUIDs, and accounts floating around in a large organization, there's bound to be a conflict or two. What should the system do if it discovers a conflict? You can choose Ignore (i.e., do nothing), Warn (i.e., warn the user of the conflict after logon), or Error (i.e., don't let the user log on). You control all these options, including the text of the error message that the user will see, via Group Policy.

DirectControl supports many UNIX clients, including Mac OS X, Red Hat Linux, SuSE Linux, and VMware ESX Server. To see a full list of supported UNIX clients, visit http://www.centrify.com/directcontrol

Summary
Centrify DirectControl

PROS: Doesn't require user to use "Domain Username" when logging on; detailed documentation explains how to authenticate multiple platforms and databases; software development kit (SDK) available to extend the default functionality; reporting capability; robust UNIX personality management
CONS: Requires AD Schema Extensions if not running Windows 2003 R2
RATING: 5 out of 5
PRICE: Starts at $800 for three nodes
RECOMMENDATION: If you want a seasoned contender with strong UNIX personality management and robust migration management, Centrify DirectControl gets our highest recommendation.
CONTACT: Centrify • http://www.centrify.com

Editors' Choice
All three products performed admirably in our tests and can accomplish what they advertise. Centeris Likewise Identity receives kudos for finding a way to let UNIX-based machines authenticate to AD without altering the AD schema. If you have many users, this shortcut can come at a price with reduced performance, but it's nice to have the option. For Group Policy functionality, Centrify DirectControl impressed us. We really liked the way that DirectControl uses ADM templates instead of adding additional bloat to AD Users and Computers. Quest Software Vintela Authentication Services stood out with such smart features as letting you choose which OU a new PC would be added to, and it doesn't make the user preface a logon name with the domain name.

What didn't we like? For all three products, adding or enabling UNIX personality management wasn't as easy as we thought it could be. In many cases, the vendors should just make the pop-up error messages more informative—rather than just telling the user to create a cell or a zone, let the user know where the tool is to accomplish the task.

Although all three products are first rate, Centrify DirectControl wins the Editors' Choice award, as it is the most robust product of all three. You can't go wrong if you choose Centrify.

End of Article

   Previous  1  2  [3]  Next  


Reader Comments

You must be a registered user or online subscriber to comment on this article. Please log on before posting a comment. Are you a new visitor? Register now




Top Viewed ArticlesView all articles
What You Need to Know About Microsoft's x64 Server Product Plans

What do Longhorn Server, Windows Compute Cluster Server, and Windows Vista have in common? The x64 platform. ...

WinInfo Short Takes: 4th of July Special Edition

An often irreverent look at some of the week's other news, including a shortened work week thanks to the 4th of July, expensive Windows 7 pricing, Bing's modest monthly gains, IE 8 heading to work, Steve Jobs back at Apple, and so much more ...

How can I stop and start services from the command line?

...


Active Directory (AD) Whitepapers Sustainable Compliance: How to reconnect compliance, security and business goals

Addressing the Insider Threat with NetIQ Security and Administration Solutions

Related Events WinConnections and Microsoft® Exchange Connections

Concrete Ways to Make Sure Your SharePoint Deployment Doesn't Blow Up

PCI Requirements for Windows and Active Directory: Straight from a Certified Auditor

Check out our list of Free Email Newsletters!

Active Directory (AD) eBooks The Essentials Series: Active Directory 2008 Operations

Keeping Your Business Safe from Attack: Monitoring and Managing Your Network Security

Windows 2003: Active Directory Administration Essentials

Related Active Directory (AD) Resources Introducing Left-Brain.com, the online IT bookstore
Looking for books, CDs, toolkits, eBooks? Prime your mind at Left-Brain.com

Discover Windows IT Pro eLearning Series!
Clear & detailed technical information and helpful how-to's, all in our trademark no-nonsense format

Test Drive IT Solutions and Get Free Music Downloads
Solve your toughest IT problems with these free downloads and receive 5 free music downloads!


Windows IT Pro Home Register FAQ for Windows WinInfo News
Europe Edition About Us Contact Us/Customer Service Media Kit Affiliates / Licensing  
SQL Server Magazine Office & SharePoint Pro DevProConnections IT Job Hound ITTV
IT Library Technology Resource Directory Connected Home asp.netPRO Windows SuperSite 
 
 Windows IT Pro is a Division of Penton Media Inc.
 © 2009 Penton Media, Inc. Terms of Use | Privacy Statement | Reprints and Licensing