Delivering Identity Governance at Express Speed

ČD Cargo: Replacing a legacy Oracle Waveset Identity Management solution with midPoint in less than 4.5 months

About About ČD Cargo

ČD Cargo is a leading provider of freight transport services in the Czech Republic. As one of the five largest rail freight carriers among EU member states, the company provides rail freight transportation services throughout the Czech Republic and, through its branches and subsidiaries, across Europe. Identity governance is one of the key pillars of ČD Cargo’s internal cybersecurity strategy. With a large network of employees, contractors, and external users requiring access to business systems, the company relies on identity governance to ensure every access is secure and compliant.

Challenge

ČD Cargo’s identity management processes were built on Oracle Waveset IDM. However, when the solution reached its end-of-life, it could no longer meet the organization’s growing requirements for reliable and secure management of user accounts and access rights. Following the end of product support, maintaining the platform became increasingly difficult and costly, while the need for modern identity security capabilities grew day by day.

To address these challenges, ČD Cargo launched a procurement process for a replacement solution. Evolveum midPoint was selected as the new Identity Governance and Administration (IGA) platform, with AMI Praha chosen as the implementation partner. The project was subject to an ambitious (and at the time seemingly impossible) implementation timeline, with the new solution required to be deployed within just 4.5 months.

Objective

The objective of the project was not only to replace the existing Oracle Waveset Identity Management solution with midPoint, but also to review the company’s identity management processes and modernize them to reflect current business and security requirements.

The main goals of the project were to:
– Strengthen cybersecurity by addressing current security gaps and improving access governance
– Migrate existing identity data and adapt established identity management processes to the new platform
– Introduce modern identity governance capabilities, including advanced auditing and reporting
– Implement end-to-end identity lifecycle management for employees, contractors, and external users
– Integrate eight business systems, including Active Directory, Microsoft Entra ID, and SAP

Process

Due to the limited timeframe, the project could not follow a traditional waterfall project management approach. Implementation activities were carried out in parallel, with development, documentation, testing, and training progressing simultaneously.

Identity lifecycle management

MidPoint manages the complete identity lifecycle for employees, temporary workers, external contractors, administrative accounts, and service accounts. Each identity type follows its own lifecycle and governance policies, ensuring that provisioning, changes and deprovisioning are handled according to predefined requirements.

Employee and temporary worker identities are sourced from the HR system (EGJE). Where an individual holds multiple roles within the organization, these are consolidated into a single identity while preserving seperate employment records. External contractors are created directly in midPoint and their creation are subject to an approval workflow before accounts are provisioned.

Administrative accounts are managed seperately from standard user accounts and linked to their respective owners. Their provisioning requires approval, and their lifecycle is tied to the lifecycle of the account owner. Administrative accounts are also goverened according to a Tier model, that separates administrative access based on different tiers.

Access governance

Acess governance is based on role based access control (RBAC) and supported by approval workflows and control mechanisms. The solution includes a role catalog, access requests with approval processes, and periodic recertification of manually assigned entitlements. Automatic role assignment is built on on rules that evaluate combinations of user attributes.

Self-service portal

MidPoint also provides a self-service portal for administrators, users, and managers. The portal supports access requests, approvals, and external user management, empowering business leaders to manage a lot of identity governance activities through self-service without the reliance on the IT department.

System integration

The platform was integrated with both authoritative source systems and target systems where user accounts and access rights are managed. These integrations included:
– Elanor Global Java Edition (HR system)
– Active Directory
– Microsoft Entra ID
– Microsoft Exchange
– SAP through SAP Central User Administration (SAP CUA)
– Logserver, Moodle, and Feedback (internal apps)
Additional solution capabilities include centralized password lifecycle management, Active Directory computer account management, Segregation of Duties (SoD) controls, multilingual support in Czech, English, and German, and graphical configuration of automated role assignment rules.

Outcome

The project was completed within the required 4.5 months timeframe, successfully replacing the legacy Oracle Waveset platform with a modern IGA platform. Following deployment, midPoint proved stable and reliable in production, with no critical data migration issues and only minor post-implementation adjustments.

Today, ČD Cargo benefits from centralized identity lifecycle management, automated provisioning and deprovisioning, role-based access governance, and standardized identity processes across its IT environment. The new platform provides a solid foundation for improving cybersecurity and accommodating business and technology needs.