The solution is good, but it's pretty complex. So, I wouldn't recommend this solution to anyone without extensive security knowledge. The administration and configuration aren't straightforward. If the implementation takes up to six months, it will be costly. On a scale from one to ten, I would give IBM Tivoli Federated Identity Manager an eight.