Discovery of services in combination with enabling data protection and other workflows
An automatic process for discovering as service, such as a Software as a Service (SaaS), leverages a user authentication service such as a Single Sign On (SSO) service. Automatic service discovery can be triggered either as a scheduled job or as a response to an external event (for example, when a new virtual SaaS service is integrated within an SSO). The only action required by the user is to provide service access credentials for the discovery process to access the remote service(s).
1 . An automatic Software as a Service (SaaS) resource discovery method comprising:
accessing an Identity Provider (IdP) service to initially obtain access credentials for the SaaS resource;
accessing the SaaS resource using the access credentials;
invoking a service-specific discovery method to issue one or more service-specific operations via an API of the SaaS resource for further discovering-resiliency-related data protection attributes specific to the SaaS resource, and wherein such resiliency-related data protection attributes comprise information indicative of one or more of:
a can backup capability,
recovery readiness,
restore configuration, or
inclusion in a backup or restore sequencing group,
and wherein, for a hierarchical SaaS resource having at least two levels, the resiliency-related data protection attributes indicate at which levels the resiliency-related data protection attributes are supported by functions of the SaaS resource itself.
2 . The method of claim 1 wherein the method is triggered either as a scheduled job or when a new SaaS is integrated with the identity service or when initiated by a user or a service.
3 . The method of claim 1 where the identity service is a Single Sign On (SSO) service.
4 . The method of claim 1 wherein the resiliency-related data protection attributes further comprise information specific to whether the SaaS resource includes one or more of a backup method, a default data protection built into the service, recovery resource method, recovery status method, or a recovery configuration method.
5 . The method of claim 1 additionally wherein:
discovering resiliency-related data protection attributes specific to the SaaS resource further includes discovering one or more of hasChildResources, backupSeqGroup, or restoreSeqGroup.
6 . The method of claim 1 wherein
accessing the IdP service obtains access for two or more SaaS resources; and
discovering resiliency-related data protection attributes utilizes a different service-specific discovery method for at least two of the two or more SaaS resources.
7 . An apparatus, comprising:
a hardware processor; and
computer memory holding computer program instructions executed by the hardware processor for Software as a Service (SaaS) resource discovery and data protection configuration, the computer program instructions configured for:
accessing an identity provider (IdP) service to initially obtain access credentials for the SaaS resource;
accessing the SaaS resource using the access credentials; and
invoking a service-specific discovery method to issue one or more service-specific operations via an API of the SaaS resource for discovering resiliency-related data protection attributes specific to the SaaS resource, and wherein such resiliency-related data protection attributes comprise information indicative of one or more of:
a can backup capability,
recovery readiness,
restore configuration, or
inclusion in a backup or restore sequencing group,
and wherein, for a hierarchical SaaS resource having at least two levels, the resiliency-related data protection attributes indicate at which levels the resiliency-related data protection attributes are supported by functions of the SaaS resource itself.
8 . A computer program product in a non-transitory computer readable medium for Software as a Service (SaaS) resource discovery and data protection configuration, the computer program product holding computer program instructions that, when executed by a data processing system, is configured for:
a. accessing an identity provider (IdP) service to initially obtain access credentials for the SaaS resource;
b. accessing the SaaS resource using the access credentials; and
c. invoking a service-specific discovery module to issue one or more service-specific operations via an API of the SaaS resource for further discovering resiliency-related data protection attributes specific to the SaaS resource, and wherein such resiliency-related data protection attributes comprise information indicative of one or more of:
a can backup capability,
recovery readiness,
restore configuration, or
inclusion in a backup or restore sequencing group,
and wherein, for a hierarchical SaaS resource having at least two levels, the resiliency-related data protection attributes indicate at which levels the resiliency-related data protection attributes are supported by functions of the SaaS resource itself.
9 . The computer program product of claim 8 further configured to be triggered either as a scheduled job or when a new SaaS is integrated with the identity service or when initiated by a user or a service.
10 . The computer program product of claim 8 where the identity service is a Single Sign On (SSO) service.
11 . The computer program product of claim 8 wherein the resiliency-related data protection attributes further comprise information specific to whether the SaaS resource includes one or more of a backup method, a default data protection built into the service, recovery resource method, recovery status method, or recovery configuration method.
12 . The computer program product of claim 8 further configured for:
discovering resiliency-related data protection attributes specific to the SaaS resource including discovering one or more of default data resiliency, canBackup, hasChildResources, backupSeqGroup, or restoreSeqGroup.
13 . The computer program product of claim 8 wherein the attributes include a canBackup attribute, the resource is a hierarchical resource having at least two levels, and the canBackup indicates one or more levels of the hierarchy resource for which backup is implemented by the service.
14 . The computer program product of claim 8 further configured for:
accessing the IdP service obtains access for two or more SaaS resources; and
discovering data resiliency attributes utilizes a different service-specific discovery method for at least two of the two or more SaaS resources.
15 . The method of claim 1 , wherein the discovery of SaaS resources is initiated by querying the Identity Provider (IdP) for a list of authenticated SaaS services associated with a tenant identity.
16 . The computer program product of claim 8 , wherein the discovery of SaaS resources is initiated by querying the Identity Provider (IdP) for a list of authenticated SaaS services associated with a tenant identity.