In our opinion the "best practice" I.T solution to Identity Management on the market today is a solution based on a combination of products from Citrix and RSA. The simplicity of having two factor authentication, a key phob based password system, combined with password management software is a major step forward in security for commercial and government organisations who value the integrity of their systems.
The products in question are Password Manager and Secure Access Gateway from Citrix and RSA SecurID for Microsoft Windows.
Citrix Password ManagerTM is the most secure, efficient and easy-to-deploy enterprise single sign-on solution for accessing password-protected Windows, Web and host-based applications. Users authenticate once with a single password, and Password Manager automates logons, policy enforcement, and password changes, making connecting to applications easier, faster and more secure. As a stand-alone solution or within the Citrix Access Suite, Password Manager improves password security, makes computing easy and can lower help desk support costs by 25%.
Citrix Access GatewayTM is a universal SSL VPN appliance that provides a secure, always-on, single point-of-access to any information resource. It has all of the advantages of IPSec and typical SSL VPNs - without the costly and cumbersome implementation and management - making access easy for users, secure for the company and low-cost for IT administrators. It works in both non-Citrix and Citrix environments, and provides the best integration with Citrix Presentation Server.
RSA SecurID for Microsoft Windows - By replacing vulnerable passwords with the industry's leading two-factor authentication, RSA Security and Microsoft make it possible for customers to positively identify users before granting them access to valuable corporate resources accessed through Windows desktops and networks-while simultaneously delivering a simplified and consistent user login experience.
RSA SecurID for Microsoft Windows software helps to provide greater security than weak, static passwords. By combining something the user knows (i.e., a secret PIN) with something the user possesses (i.e., a unique RSA SecurID token that generates a one-time password every 60 seconds), Microsoft Windows customers gain an effective way to secure user access to valuable company resources.