<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.technet.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Enterprise IT Identity &amp; Access Management : 5. Reviews</title><link>http://blogs.technet.com/yaleli/archive/tags/5.+Reviews/default.aspx</link><description>Tags: 5. Reviews</description><dc:language>en-US</dc:language><generator>CommunityServer 2.1 SP1 (Build: 61025.2)</generator><item><title>Review - BMC Identity Management for .NET</title><link>http://blogs.technet.com/yaleli/archive/2006/06/01/428179.aspx</link><pubDate>Thu, 01 Jun 2006 22:00:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:428179</guid><dc:creator>Yale Li</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/yaleli/comments/428179.aspx</comments><wfw:commentRss>http://blogs.technet.com/yaleli/commentrss.aspx?PostID=428179</wfw:commentRss><wfw:comment>http://blogs.technet.com/yaleli/rsscomments.aspx?PostID=428179</wfw:comment><description>&lt;P&gt;&lt;SPAN style="FONT-SIZE: 10pt; COLOR: black; FONT-FAMILY: Arial; mso-fareast-font-family: 'Times New Roman'; mso-fareast-language: EN-US; mso-bidi-language: AR-SA; mso-ansi-language: EN-US; mso-bidi-font-weight: bold"&gt;&lt;FONT face="Times New Roman" size=3&gt;BMC IdM for .NET&amp;nbsp;offers a suite of solutions&amp;nbsp;in .NET environment&amp;nbsp;including workflow, directory management, audit, self service, password management, Web single sign-on, and federation.&lt;/FONT&gt;&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Pros:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;- Automated HR driven&amp;nbsp;provisioning&lt;/P&gt;
&lt;P&gt;- Role based access control&lt;/P&gt;
&lt;P&gt;-&amp;nbsp;Easy to navigate&amp;nbsp;UI&lt;/P&gt;
&lt;P&gt;- Connectivity Broker (web service) for seperation&amp;nbsp;of duties and connect to either ADAM or AD&lt;/P&gt;
&lt;P&gt;- Comprehensive audit and reporting for compliance&lt;/P&gt;
&lt;P&gt;- MIIS integration for backend synchronization and provsioning engine&lt;/P&gt;
&lt;P&gt;- Out of Box solution&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Cons:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;- price and time spent for the contract&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Overall Rating:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;8&amp;nbsp;out of 10&lt;/P&gt;
&lt;P&gt;(0-2: fail to work, 3-5:&amp;nbsp;work in&amp;nbsp;demo/test environment, 6-8: work in production environment, 9-10: excellent quality,&amp;nbsp;great value, highly recommended)&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=428179" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/yaleli/archive/tags/5.+Reviews/default.aspx">5. Reviews</category></item><item><title>Review - MIIS SP2 Password Management Beta 1</title><link>http://blogs.technet.com/yaleli/archive/2006/05/05/422580.aspx</link><pubDate>Fri, 05 May 2006 10:00:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:422580</guid><dc:creator>Yale Li</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/yaleli/comments/422580.aspx</comments><wfw:commentRss>http://blogs.technet.com/yaleli/commentrss.aspx?PostID=422580</wfw:commentRss><wfw:comment>http://blogs.technet.com/yaleli/rsscomments.aspx?PostID=422580</wfw:comment><description>&lt;P&gt;A major new feature in MIIS SP2 is Q/A (question/answer) based password reset self service. The password management application&amp;nbsp;has 4 UI compoments on top of MIIS SP2: User Registration, Password Self Reset, Password Helpdesk Reset, and Admin.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Pros:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;- Easy intallation with msi package&lt;/P&gt;
&lt;P&gt;- Flexible question configuration with admin defined or user defined questions&lt;/P&gt;
&lt;P&gt;- Data&amp;nbsp;is secured in storage and transmmition&lt;/P&gt;
&lt;P&gt;- Minimal coding effort&lt;/P&gt;
&lt;P&gt;- Can be used by both users and helpdesk&lt;/P&gt;
&lt;P&gt;-&amp;nbsp;No&amp;nbsp;additional cost&amp;nbsp;to MIIS &lt;/P&gt;
&lt;P&gt;- Great value to reduce helpdesk password reset cost&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Cons:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;- Smart Card is not supported&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Overall Rating:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;7 out of 10&lt;/P&gt;
&lt;P&gt;(0-2: fail to work, 3-5:&amp;nbsp;work in&amp;nbsp;demo/test environment, 6-8: work in production environment, 9-10: excellent quality,&amp;nbsp;great value, highly recommended)&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=422580" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/yaleli/archive/tags/5.+Reviews/default.aspx">5. Reviews</category></item><item><title>Review - Microsoft IAM Group Management Solution</title><link>http://blogs.technet.com/yaleli/archive/2006/04/05/424312.aspx</link><pubDate>Wed, 05 Apr 2006 10:00:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:424312</guid><dc:creator>Yale Li</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/yaleli/comments/424312.aspx</comments><wfw:commentRss>http://blogs.technet.com/yaleli/commentrss.aspx?PostID=424312</wfw:commentRss><wfw:comment>http://blogs.technet.com/yaleli/rsscomments.aspx?PostID=424312</wfw:comment><description>&lt;P&gt;One of&amp;nbsp;group management solutions is part of&amp;nbsp;Microsoft Identity and Access Management Series and you can download from: &lt;A href="http://www.microsoft.com/downloads/details.aspx?FamilyId=794571E9-0926-4C59-BFA9-B4BFE54D8DD8&amp;amp;displaylang=en"&gt;http://www.microsoft.com/downloads/details.aspx?FamilyId=794571E9-0926-4C59-BFA9-B4BFE54D8DD8&amp;amp;displaylang=en&lt;/A&gt;&amp;nbsp;or &lt;A href="http://www.microsoft.com/technet/security/topics/identitymanagement/idmanage/default.mspx?mfr=true"&gt;http://www.microsoft.com/technet/security/topics/identitymanagement/idmanage/default.mspx?mfr=true&lt;/A&gt;&lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P&gt;The group management&amp;nbsp;is&amp;nbsp;a subset of&amp;nbsp;"Provisioning and Workflow" in the series. The code is written in Visual Basic. In my environment, I don't have Sun One and Lotus Domino. So I simply&amp;nbsp;commented out several lines of provisioning code for Sun One Directory and Lotus mailbox, and re-compiled the solution. After&amp;nbsp;installation and configuration&amp;nbsp;on MIIS/SQL/IIS servers and in AD, I added more HR sample data, and defined several simple query groups and family of attribute groups through the Web UI. Then, I ran the supplied&amp;nbsp;batch file which called Group Populator and&amp;nbsp;MIIS 2003 run profiles. Finally, all groups showed up in AD and everything&amp;nbsp;worked as claimed in the doc. &lt;o:p&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P&gt;Although I like this "product", I ended up&amp;nbsp;with own&amp;nbsp;group management&amp;nbsp;solution from scratch&amp;nbsp;due to limitations explained in Cons.&lt;o:p&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Pros:&lt;o:p&gt;&lt;/o:p&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL type=disc&gt;
&lt;LI class=MsoNormal style="MARGIN: 0in 0in 0pt; mso-list: l1 level1 lfo1; tab-stops: list .5in; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto"&gt;Excellent and easy to follow documentation to explain all aspects of requirements, architecture, design, implementation, setup and operations.&lt;o:p&gt;&lt;/o:p&gt; 
&lt;LI class=MsoNormal style="MARGIN: 0in 0in 0pt; mso-list: l1 level1 lfo1; tab-stops: list .5in; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto"&gt;Good quality of code (I didn't encounter bugs/errors myself)&lt;o:p&gt;&lt;/o:p&gt; 
&lt;LI class=MsoNormal style="MARGIN: 0in 0in 0pt; mso-list: l1 level1 lfo1; tab-stops: list .5in; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto"&gt;Nice preview feature for simple groups in Web UI&lt;o:p&gt;&lt;/o:p&gt; 
&lt;LI class=MsoNormal style="MARGIN: 0in 0in 0pt; mso-list: l1 level1 lfo1; tab-stops: list .5in; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto"&gt;Logic builder in Web UI to create&amp;nbsp;attribute groups&lt;o:p&gt;&lt;/o:p&gt; 
&lt;LI class=MsoNormal style="MARGIN: 0in 0in 0pt; mso-list: l1 level1 lfo1; tab-stops: list .5in; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto"&gt;Source code provided for customization 
&lt;LI class=MsoNormal style="MARGIN: 0in 0in 0pt; mso-list: l1 level1 lfo1; tab-stops: list .5in; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto"&gt;Free of Charge&lt;o:p&gt;&lt;/o:p&gt;&lt;/LI&gt;&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;Cons:&lt;o:p&gt;&lt;/o:p&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL type=disc&gt;
&lt;LI class=MsoNormal style="MARGIN: 0in 0in 0pt; mso-list: l0 level1 lfo2; tab-stops: list .5in; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto"&gt;It works for single forest only and there is no way to get around to support multi-forests through code change. &lt;o:p&gt;&lt;/o:p&gt;
&lt;LI class=MsoNormal style="MARGIN: 0in 0in 0pt; mso-list: l0 level1 lfo2; tab-stops: list .5in; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto"&gt;It doesn’t build hierarchical groups by default. This could be resolved by code change but it is not an easy task.&lt;o:p&gt;&lt;/o:p&gt;&lt;/LI&gt;&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;Overall Rating:&lt;o:p&gt;&lt;/o:p&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;7&amp;nbsp;out of 10 &lt;/P&gt;
&lt;P&gt;(0-2: fail to work, 3-5:&amp;nbsp;work in&amp;nbsp;demo/test environment, 6-8: work in production environment, 9-10: excellent quality,&amp;nbsp;great value, highly recommended)&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=424312" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/yaleli/archive/tags/5.+Reviews/default.aspx">5. Reviews</category></item><item><title>Review - M-Tech ID-Sync</title><link>http://blogs.technet.com/yaleli/archive/2006/03/26/422290.aspx</link><pubDate>Sun, 26 Mar 2006 03:00:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:422290</guid><dc:creator>Yale Li</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/yaleli/comments/422290.aspx</comments><wfw:commentRss>http://blogs.technet.com/yaleli/commentrss.aspx?PostID=422290</wfw:commentRss><wfw:comment>http://blogs.technet.com/yaleli/rsscomments.aspx?PostID=422290</wfw:comment><description>&lt;P&gt;M-Tech has a suite of Identity Management products. ID-Sync is a user provisioning tool.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Pros:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;- Built in workflow engine &lt;/P&gt;
&lt;P&gt;- Integration with Microsoft MIIS&lt;/P&gt;
&lt;P&gt;- Provided SAP MA&lt;/P&gt;
&lt;P&gt;- Fast provisioning time&lt;/P&gt;
&lt;P&gt;-&amp;nbsp;Provision of non-HR identity data&lt;/P&gt;
&lt;P&gt;- Reasonable cost&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Cons:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;- HR is not authoritative (it is&amp;nbsp;one of&amp;nbsp;targets, not&amp;nbsp;a source in provisioning)&lt;/P&gt;
&lt;P&gt;- Postphoned de-provisioning is in question&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Overall Rating:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;8 out of 10&lt;/P&gt;
&lt;P&gt;(0-2: fail to work, 3-5:&amp;nbsp;work in&amp;nbsp;demo/test environment, 6-8: work in production environment, 9-10: excellent quality,&amp;nbsp;great value, highly recommended)&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=422290" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/yaleli/archive/tags/5.+Reviews/default.aspx">5. Reviews</category></item><item><title>Review - Microsoft CLM (Certificate Lifecycle Manager) Beta 1 (renamed from Alacris)</title><link>http://blogs.technet.com/yaleli/archive/2006/03/21/422186.aspx</link><pubDate>Tue, 21 Mar 2006 05:00:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:422186</guid><dc:creator>Yale Li</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/yaleli/comments/422186.aspx</comments><wfw:commentRss>http://blogs.technet.com/yaleli/commentrss.aspx?PostID=422186</wfw:commentRss><wfw:comment>http://blogs.technet.com/yaleli/rsscomments.aspx?PostID=422186</wfw:comment><description>&lt;P&gt;Don't let the word "Beta" fool you. CLM Beta 1 is actually renamed from the latest Alacris RTM version.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Pros:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;- Turn key system and no coding is required&lt;/P&gt;
&lt;P&gt;- Can manage both smart cards (including USB tokens) and certificates&lt;/P&gt;
&lt;P&gt;- Feature rich self service Web UI&lt;/P&gt;
&lt;P&gt;- Built-in work flow engine&amp;nbsp;to handle&amp;nbsp;approval and notification &lt;/P&gt;
&lt;P&gt;- Flexable policies&lt;/P&gt;
&lt;P&gt;- Temp smart card&lt;/P&gt;
&lt;P&gt;- Easy installation&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Cons:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;- Does not format smart card&lt;/P&gt;
&lt;P&gt;- In multiple forest environment, each forest needs its own CLM and SQL database.&lt;/P&gt;
&lt;P&gt;- SQL 2005 is not supported.&lt;/P&gt;
&lt;P&gt;- IE 7 is not supported&lt;/P&gt;
&lt;P&gt;- Microsoft base CSP is not supported&lt;/P&gt;
&lt;P&gt;- Granting permission is tedious work&lt;/P&gt;
&lt;P&gt;(some will be supported in Beta 2 or RTM)&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Overall Rating:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;6 out of 10&lt;/P&gt;
&lt;P&gt;(0-2: fail to work, 3-5:&amp;nbsp;work in&amp;nbsp;demo/test environment, 6-8: work in production environment, 9-10: excellent quality,&amp;nbsp;great value, highly recommended)&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=422186" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/yaleli/archive/tags/5.+Reviews/default.aspx">5. Reviews</category></item><item><title>Review - Quest ActiveRoles Server</title><link>http://blogs.technet.com/yaleli/archive/2006/03/19/422396.aspx</link><pubDate>Sun, 19 Mar 2006 04:00:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:422396</guid><dc:creator>Yale Li</dc:creator><slash:comments>1</slash:comments><comments>http://blogs.technet.com/yaleli/comments/422396.aspx</comments><wfw:commentRss>http://blogs.technet.com/yaleli/commentrss.aspx?PostID=422396</wfw:commentRss><wfw:comment>http://blogs.technet.com/yaleli/rsscomments.aspx?PostID=422396</wfw:comment><description>&lt;P&gt;Quest ActiveRoles Server enables automatic user/group provisioning&amp;nbsp;and make&amp;nbsp;entitlements management easier. &lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Pros:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;- Rule based automatic provisioning&lt;/P&gt;
&lt;P&gt;- Role based administration&lt;/P&gt;
&lt;P&gt;-&amp;nbsp;Easy to navigate&amp;nbsp;UI&lt;/P&gt;
&lt;P&gt;- AD focused but also handle Unix/Linux users/groups with Vintela Authentication Server&lt;/P&gt;
&lt;P&gt;- Dynamic group support&lt;/P&gt;
&lt;P&gt;- Fast provisioning time (instant - 10 min)&lt;/P&gt;
&lt;P&gt;- Postphoned deprovisioning&lt;/P&gt;
&lt;P&gt;- Comprehensive audit and reporting for compliance&lt;/P&gt;
&lt;P&gt;- MIIS integration&lt;/P&gt;
&lt;P&gt;- Multiple AD forests support&lt;/P&gt;
&lt;P&gt;- minimal custom coding&lt;/P&gt;
&lt;P&gt;(already considered&amp;nbsp;good improvements coming in June version)&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Cons:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;- to be find out&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Overall Rating:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;9 out of 10&lt;/P&gt;
&lt;P&gt;(0-2: fail to work, 3-5:&amp;nbsp;work in&amp;nbsp;demo/test environment, 6-8: work in production environment, 9-10: excellent quality,&amp;nbsp;great value, highly recommended)&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=422396" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/yaleli/archive/tags/5.+Reviews/default.aspx">5. Reviews</category></item><item><title>Review - Axalto .NET Smart Card</title><link>http://blogs.technet.com/yaleli/archive/2006/03/18/422402.aspx</link><pubDate>Sat, 18 Mar 2006 03:00:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:422402</guid><dc:creator>Yale Li</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/yaleli/comments/422402.aspx</comments><wfw:commentRss>http://blogs.technet.com/yaleli/commentrss.aspx?PostID=422402</wfw:commentRss><wfw:comment>http://blogs.technet.com/yaleli/rsscomments.aspx?PostID=422402</wfw:comment><description>&lt;P class=MsoNormal style="MARGIN: 4pt 0in 6pt 0.35in"&gt;&lt;FONT face=Arial&gt;Axalto (Schlumberger) has developed the new .NET Card Technology to seamlessly integrate with current software such as Word, Exchange, Windows XP, Windows CE, and upcoming products based on the .Net technology. The technology contains a multi-application smart card framework, which enables loading applications developed in any language supported by the .NET framework of Visual Basic NET, C#, J#. &lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 4pt 0in 6pt 0.35in"&gt;&lt;FONT face=Arial&gt;The Axalto .NET smart card (with 128KB memory) has card module software which supports the Microsoft Base CSP. Microsoft had developed a management tool called SDA (Smartcard Deployment Application) to manage the entire smartcard life cycle. SDA will be replaced by CLM (Certificate Lifecycle Manager) which is a Microsoft product with business acquisition of Alacris. A SDK is also provided to customize the smart card.&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 4pt 0in 6pt 0.35in"&gt;&lt;SPAN style="mso-fareast-language: ZH-CN; mso-bidi-font-family: Arial"&gt;&lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&lt;FONT face=Arial&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 4pt 0in 6pt 0.35in"&gt;&lt;SPAN style="mso-fareast-language: ZH-CN; mso-bidi-font-family: Arial"&gt;&lt;FONT face=Arial&gt;&lt;STRONG&gt;Pros:&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 4pt 0in 6pt 0.35in"&gt;&lt;FONT face=Arial&gt;&lt;SPAN style="mso-fareast-language: ZH-CN; mso-bidi-font-family: Arial"&gt;- &lt;/SPAN&gt;&lt;SPAN style="mso-fareast-language: ZH-CN; mso-bidi-font-family: Arial"&gt;Larger memmory sixe&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 4pt 0in 6pt 0.35in"&gt;&lt;FONT face=Arial&gt;&lt;SPAN style="mso-fareast-language: ZH-CN; mso-bidi-font-family: Arial"&gt;- Can &lt;/SPAN&gt;&lt;SPAN style="mso-fareast-language: ZH-CN; mso-bidi-font-family: Arial"&gt;combine smart card chip for logical access and RFID tag for physical access on the same badge. &lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 4pt 0in 6pt 0.35in"&gt;&lt;SPAN style="mso-fareast-language: ZH-CN; mso-bidi-font-family: Arial"&gt;&lt;FONT face=Arial&gt;- Easy applet development with .NET technology&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 4pt 0in 6pt 0.35in"&gt;&lt;FONT face=Arial&gt;&lt;SPAN style="mso-fareast-language: ZH-CN; mso-bidi-font-family: Arial"&gt;- &lt;/SPAN&gt;&lt;SPAN style="mso-fareast-language: ZH-CN; mso-bidi-font-family: Arial"&gt;Strong authentication&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 4pt 0in 6pt 0.35in"&gt;&lt;SPAN style="mso-fareast-language: ZH-CN; mso-bidi-font-family: Arial"&gt;&lt;o:p&gt;&lt;FONT face=Arial&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 4pt 0in 6pt 0.35in"&gt;&lt;SPAN style="mso-fareast-language: ZH-CN; mso-bidi-font-family: Arial"&gt;&lt;FONT face=Arial&gt;&lt;STRONG&gt;Cons:&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 4pt 0in 6pt 0.35in"&gt;&lt;FONT face=Arial&gt;&lt;SPAN style="mso-fareast-language: ZH-CN; mso-bidi-font-family: Arial"&gt;- &lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-fareast-font-family: Symbol; mso-fareast-language: ZH-CN; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&lt;FONT size=3&gt;Not supported by CLM Beta 1 (will be supported by CLM Beta 2)&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 4pt 0in 6pt 0.85in; TEXT-INDENT: -0.25in; mso-list: l0 level1 lfo2; tab-stops: list .85in"&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-fareast-font-family: Symbol; mso-fareast-language: ZH-CN; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&lt;FONT face=Arial&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&amp;nbsp;&lt;/P&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-fareast-font-family: Symbol; mso-fareast-language: ZH-CN; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&lt;FONT size=2&gt;
&lt;P class=MsoNormal style="MARGIN: 4pt 0in 6pt 0.35in"&gt;&lt;SPAN style="mso-fareast-language: ZH-CN; mso-bidi-font-family: Arial"&gt;&lt;FONT face=Arial size=3&gt;&lt;STRONG&gt;Overall Rating:&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 4pt 0in 6pt 0.35in"&gt;&lt;SPAN style="mso-fareast-language: ZH-CN; mso-bidi-font-family: Arial"&gt;&lt;FONT face=Arial size=3&gt;&amp;nbsp;8 out of 10&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=422402" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/yaleli/archive/tags/5.+Reviews/default.aspx">5. Reviews</category></item><item><title>Review - RSA SecurID</title><link>http://blogs.technet.com/yaleli/archive/2006/03/17/422403.aspx</link><pubDate>Fri, 17 Mar 2006 03:00:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:422403</guid><dc:creator>Yale Li</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/yaleli/comments/422403.aspx</comments><wfw:commentRss>http://blogs.technet.com/yaleli/commentrss.aspx?PostID=422403</wfw:commentRss><wfw:comment>http://blogs.technet.com/yaleli/rsscomments.aspx?PostID=422403</wfw:comment><description>&lt;P class=MsoNormal style="MARGIN: 4pt 0in 6pt 0.35in"&gt;&lt;SPAN style="COLOR: black; mso-bidi-font-family: Arial"&gt;&lt;FONT size=2&gt;&lt;FONT face=Arial&gt;SecurID for Windows fully integrates with Microsoft's Active Directory and enables domain-level access management along with new offline capabilities.&lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 4pt 0in 6pt 0.35in"&gt;&lt;FONT size=2&gt;&lt;FONT face=Arial&gt;&lt;SPAN style="COLOR: black; mso-bidi-font-family: Arial"&gt;At backend, RSA ACE Sever is required. The client requires the RSA ACE/Agent installed. The SecurID generates one time pass code and user types in PIN and pass code to logon.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;The pass code is synchronized with the backend. The authentication protocol is Kerberos in Windows. Unlike the smart card, Microsoft Kerberos doesn’t have any extensions to support OTP logon. Therefore, RSA ACE replaces SecurID with the user’s password in the background for actual authentication.&lt;/SPAN&gt;&lt;SPAN style="COLOR: black; mso-fareast-language: ZH-CN; mso-bidi-font-family: Arial"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 4pt 0in 6pt 0.35in"&gt;&lt;SPAN style="COLOR: #333333; mso-fareast-language: ZH-CN; mso-bidi-font-family: Arial"&gt;&lt;o:p&gt;&lt;FONT face=Arial size=2&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 4pt 0in 6pt 0.35in"&gt;&lt;SPAN style="COLOR: black; mso-fareast-language: ZH-CN; mso-bidi-font-family: Arial"&gt;&lt;FONT size=2&gt;&lt;FONT face=Arial&gt;&lt;STRONG&gt;Pros:&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 4pt 0in 6pt 0.35in"&gt;&lt;FONT size=2&gt;&lt;SPAN style="COLOR: black; mso-fareast-language: ZH-CN; mso-bidi-font-family: Arial"&gt;&lt;FONT face=Arial&gt;- &lt;/FONT&gt;&lt;/SPAN&gt;&lt;SPAN style="COLOR: black; mso-fareast-language: ZH-CN; mso-bidi-font-family: Arial"&gt;&lt;FONT face=Arial&gt;Relative larger installation base in the world&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 4pt 0in 6pt 0.35in"&gt;&lt;FONT face=Arial size=2&gt;&lt;SPAN style="COLOR: black; mso-fareast-language: ZH-CN; mso-bidi-font-family: Arial"&gt;- &lt;/SPAN&gt;&lt;/FONT&gt;&lt;SPAN style="COLOR: black; mso-fareast-language: ZH-CN; mso-bidi-font-family: Arial"&gt;&lt;FONT size=2&gt;&lt;FONT face=Arial&gt;Support OWA&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 4pt 0in 6pt 0.35in"&gt;&lt;SPAN style="COLOR: black; mso-fareast-language: ZH-CN; mso-bidi-font-family: Arial"&gt;&lt;o:p&gt;&lt;FONT face=Arial size=2&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 4pt 0in 6pt 0.35in"&gt;&lt;SPAN style="COLOR: black; mso-fareast-language: ZH-CN; mso-bidi-font-family: Arial"&gt;&lt;FONT size=2&gt;&lt;FONT face=Arial&gt;&lt;STRONG&gt;Cons:&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 4pt 0in 6pt 0.35in"&gt;&lt;FONT size=2&gt;&lt;SPAN style="COLOR: black; mso-fareast-language: ZH-CN; mso-bidi-font-family: Arial"&gt;&lt;FONT face=Arial&gt;- &lt;/FONT&gt;&lt;/SPAN&gt;&lt;SPAN style="COLOR: black; mso-fareast-language: ZH-CN; mso-bidi-font-family: Arial"&gt;&lt;FONT face=Arial&gt;Can not combine logical access and physical access in the same badge&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 4pt 0in 6pt 0.35in"&gt;&lt;FONT face=Arial size=2&gt;&lt;SPAN style="COLOR: black; mso-fareast-language: ZH-CN; mso-bidi-font-family: Arial"&gt;- &lt;/SPAN&gt;&lt;/FONT&gt;&lt;SPAN style="COLOR: black; FONT-FAMILY: Symbol; mso-fareast-font-family: Symbol; mso-fareast-language: ZH-CN; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="COLOR: black; mso-fareast-language: ZH-CN; mso-bidi-font-family: Arial"&gt;&lt;FONT size=2&gt;&lt;FONT face=Arial&gt;The underlying managed password authentication is the foundation thus the security strength is not as high as smart card&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 4pt 0in 6pt 0.35in"&gt;&lt;SPAN style="COLOR: black; mso-fareast-language: ZH-CN; mso-bidi-font-family: Arial"&gt;&lt;FONT face=Arial size=2&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 4pt 0in 6pt 0.35in"&gt;&lt;SPAN style="COLOR: black; mso-fareast-language: ZH-CN; mso-bidi-font-family: Arial"&gt;&lt;FONT face=Arial size=2&gt;&lt;STRONG&gt;Overall Rating:&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 4pt 0in 6pt 0.35in"&gt;&lt;SPAN style="COLOR: black; mso-fareast-language: ZH-CN; mso-bidi-font-family: Arial"&gt;&lt;FONT face=Arial size=2&gt;7 out of 10&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=422403" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/yaleli/archive/tags/5.+Reviews/default.aspx">5. Reviews</category></item><item><title>Review - Real User PassFace</title><link>http://blogs.technet.com/yaleli/archive/2006/03/16/423299.aspx</link><pubDate>Thu, 16 Mar 2006 03:00:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:423299</guid><dc:creator>Yale Li</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/yaleli/comments/423299.aspx</comments><wfw:commentRss>http://blogs.technet.com/yaleli/commentrss.aspx?PostID=423299</wfw:commentRss><wfw:comment>http://blogs.technet.com/yaleli/rsscomments.aspx?PostID=423299</wfw:comment><description>&lt;P class=MsoNormal style="MARGIN: 4pt 0in 6pt 27pt"&gt;&lt;SPAN style="COLOR: black; mso-bidi-font-family: Arial"&gt;&lt;FONT size=2&gt;&lt;FONT face=Arial&gt;Real User's Passface™ system is a &lt;SPAN style="mso-bidi-font-weight: bold; mso-bidi-font-style: italic"&gt;cognometric&lt;/SPAN&gt; method of personal authentication - based on the measurement of an innate cognitive function (of the human brain), specifically: its ability to recognize familiar faces. As with passwords and PINs (knowledge-factor authenticators), with Passfaces™ there is a shared secret between the user and the system. However, instead of relying on users to memorize and recall strings of characters and/or numbers, it employs (photographs of) faces as its "alphabet" and requires only familiarization and recognition on the part of the user.&amp;nbsp;&lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 4pt 0in 6pt 27pt"&gt;&lt;SPAN style="COLOR: black; mso-bidi-font-family: Arial"&gt;&lt;FONT size=2&gt;&lt;FONT face=Arial&gt;&lt;STRONG&gt;Pros:&lt;o:p&gt;&lt;/o:p&gt;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 4pt 0in 6pt 0.85in; TEXT-INDENT: -0.25in; mso-list: l0 level1 lfo1; tab-stops: list .85in"&gt;&lt;SPAN style="COLOR: black; FONT-FAMILY: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=2&gt;·&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="COLOR: black; mso-bidi-font-family: Arial"&gt;&lt;FONT size=2&gt;&lt;FONT face=Arial&gt;Purely software based and no hardware is required &lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 4pt 0in 6pt 0.85in; TEXT-INDENT: -0.25in; mso-list: l0 level1 lfo1; tab-stops: list .85in"&gt;&lt;SPAN style="COLOR: black; FONT-FAMILY: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=2&gt;·&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="COLOR: black; mso-bidi-font-family: Arial"&gt;&lt;FONT size=2&gt;&lt;FONT face=Arial&gt;Extremely low cost&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 4pt 0in 6pt 27pt"&gt;&lt;SPAN style="COLOR: black; mso-bidi-font-family: Arial"&gt;&lt;FONT size=2&gt;&lt;FONT face=Arial&gt;&lt;STRONG&gt;Cons:&lt;o:p&gt;&lt;/o:p&gt;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 4pt 0in 6pt 63pt; TEXT-INDENT: -0.25in; mso-list: l1 level1 lfo2; tab-stops: list 63.0pt"&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=2&gt;·&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="COLOR: black; mso-bidi-font-family: Arial"&gt;&lt;FONT face=Arial size=2&gt;Although used by US Congress, it is not a major industry standard&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 4pt 0in 6pt 63pt; TEXT-INDENT: -0.25in; mso-list: l1 level1 lfo2; tab-stops: list 63.0pt"&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=2&gt;·&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="COLOR: black; mso-bidi-font-family: Arial"&gt;&lt;FONT face=Arial size=2&gt;It is a wrapper/hash on top of password authentication, not two factor&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 4pt 0in 6pt 63pt; TEXT-INDENT: -0.25in; mso-list: l1 level1 lfo2; tab-stops: list 63.0pt"&gt;&lt;SPAN style="COLOR: black; mso-bidi-font-family: Arial"&gt;&lt;/SPAN&gt;&amp;nbsp;&lt;/P&gt;&lt;SPAN style="COLOR: black; mso-bidi-font-family: Arial"&gt;&lt;/SPAN&gt;&lt;SPAN style="COLOR: black; mso-bidi-font-family: Arial"&gt;&lt;FONT face=Arial size=2&gt;
&lt;P class=MsoNormal style="MARGIN: 4pt 0in 6pt 27pt"&gt;&lt;STRONG&gt;Overall Rating:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 4pt 0in 6pt 27pt"&gt;6&amp;nbsp;out of 10&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=423299" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/yaleli/archive/tags/5.+Reviews/default.aspx">5. Reviews</category></item></channel></rss>