Community vs Enterprise
OpenIAM is available in two versions: Community and Enterprise.
Community Edition (CE): A freely available release that customers can deploy in their environments. The CE represents the previous generation of the Enterprise Edition. For example, when v4.2.1 was released to the Enterprise, the last stable 4.2.0.x release was made available to the public as the CE. In this respect, the CE always has less features than the EE and support is provided through the community portal.
Enterprise Edition (EE): Only available through an active subscription and represents the latest stable release which customers can use in production. In addition to the commercial support, the EE contains a larger feature set in comparison to the CE. The version is being actively developed by the OpenIAM product engineering team to align with both customer requests and the published product roadmap.
Major differences between CE and EE
Authentication
The CE supports the following types of authentication: Password, OTP over email and SMS and limited adaptive authentication functionality. The EE supports all of the authentication methods found in the CE and adds OTP over IVR, certificate-based authentication, Kerberos, directory-based authentication, FIDO2 and the OpenIAM mobile authenticator with push notification. The EE also has broader adaptive authentication functionality.
User life cycle management
- Business rules engine: The EE includes a browser-based business rules engine to greatly simplify how entitlements are assigned and revoked. In the CE, this functionality needs to be implemented using groovy script.
- Orphan management: The EE provides a feature to detect and manage orphaned accounts. This functionality is not part of the CE.
- Improved performance: The EE includes performance and architectural improvements that allow for large datasets to be processed efficiently.
Single Sign-On (SSO)
Both the CE and EE support SSO using SAML, oAuth and OIDC. The EE version includes a reverse proxy (rProxy) to SSO into legacy applications.
Access request workflows
The EE allows users to create requests for entitlements for a period time, supports SLAs and escalations during the approval process, and provides the flexibility to send notifications to more than one person or group. These features are not available in the CE.
User access reviews
The EE builds on the functionality found in the CE to provide improvements to the reviewer interface, delegation and reporting.
Contractor management
Allows managers to manage the contractor life cycle. Only available in the EE.
Self-service portal
Contains numerous improvements to individual features as well as new features such as a dashboard to track active workflows.
Administrative tools
The EE extends the functionality in the CE and allows a larger of number of features to be configured from the user interface.
Architecture
CE deployments are limited to RPM and Docker Swarm. The EE can be deployed on Kubernetes and OpenShift as well as RPM. The EE contains significant architectural improvements that impact system performance, scalability, and high availability (HA). HA is only supported in the EE.
Feature Comparison
Features | Community | Enterprise |
---|---|---|
Current Release | 4.2.0.11 | 4.2.1.3 |
Authentication | ||
Password | Y | Y |
AD/LDAP authentication | Y | Y |
OTP over SMS | Y | Y |
OTP over email | Y | Y |
OTP over IVR | Y | |
FIDO 2 | Y | |
OpenIAM authenticator with push | Y | |
Certificate-based auth | Y | |
Kerberos | Y | |
Social authentication | Y | |
Adaptive authentication | Y | |
Single sign-on (SSO) | ||
SAML | Y | Y |
oAuth | Y | Y |
OIDC | Y | Y |
Reverse proxy | Y | Y |
User life cycle management | ||
Automated provisioning | Y | Y |
Joiners (new users) | Y | Y |
Movers (position change) | Y | Y |
Leavers (disable, terminate) | Y | Y |
Role-based provisioning | Y | Y |
Reconciliation | Y | Y |
Business rules engine | Y | |
Orphan management | Y | |
Entitlement management | ||
Flexible RBAC model | Y | Y |
Entitlement viewer and editor | Y | Y |
Custom entitlement types | Y | Y |
Direct entitlements | Y | Y |
Unified view of IAM and target system entitlements | Y | Y |
Entitlement synchronization from target applications | Y | Y |
Entitlement provisioning to target | Y | |
Access request and approvals (workflow) | ||
Service catalog and shopping cart-based request-approval | Y | Y |
Multi-step approvals | Y | Y |
Integrated into self-service portal | Y | Y |
Profile templates | Y | |
Time-based auto-revocation | Y | |
SLAs and escalations | Y | |
Line-item level approval/rejections | Y | |
Approval delegation | Y | |
Out-of-office delegation | Y | |
Email-based approval | Y | |
Request administration (monitor, delegate, cancel) | Y | |
User access reviews | ||
User-based certifications | Y | Y (Improved) |
Entitlement-based certifications | Y | Y (Improved) |
Privileged and service account | Y | Y |
Reports | Y | Y |
Self-service portal | ||
Supports integration with third party IdP for SSO | Y | Y |
Unified SSO application launch pad | Y | Y |
Self-service password reset (SSPR) | Y | Y |
Change password | Y | Y |
Profile management | Y | Y |
View your access | Y | Y (Improved) |
View your direct reports and their access | Y | Y (Improved) |
Self-registration | Y | Y (Improved) |
Integrated request/approval | Y | Y |
Integrated access review | Y | Y |
Corporate directory lookup | Y | Y |
Password management | ||
Flexible password policy | Y | Y |
Password synchronization | Y | Y |
Password dictionary | Y | |
Active Directory password filter | Y | |
Self-service password reset | ||
Challenge questions | Y | Y |
One-time link | Y | Y |
SMS-based one-time token | Y | Y |
Credential provider | ||
Windows | Y | |
MacOS | Y | |
Integration connectors | ||
Core connectors | Y | Y |
Cloud connectors | Y | |
Enterprise connectors | Y | |
General features | ||
Integration API | Y | Y |
RPM deployment | Y | Y |
Docker Swarm | Y | Y |
Kubernetes | Y | |
Supports High Availability (HA) | Y | |
Localization languages | 5 | 13 |
Support | Community | Commercial |
Let’s connect
Managing identity can be complex. Let OpenIAM simplify how you manage all of your identities from a converged modern platform hosted on-premises or in the cloud.
For 15 years, OpenIAM has been helping mid to large enterprises globally improve security and end user satisfaction while lowering operational costs.