Roles or Active Directory group management?
Posted by
Edward Killeen on Thu, Jun 07, 2012
Emerging technologies are challenging old paradigms and unveiling new ways of approaching the security discipline that enables the right individuals to access the right resources at the right times for the right reasons.
EmpowerID has embedded innovative technologies in every aspect, providing flexible and mature IAM capabilities in the cloud, on premise and in hybrid environments, addressing the mission-critical need across increasingly heterogeneous technology environments, and meeting increasingly rigorous compliance requirements.
It's an age old question, do you want to go with roles or Active Directory group management? The answer is, why do you have to choose? Do both. Roles and groups.
Let me explain.
Windows uses security groups, there is no getting around that. You have probably accumulated a ton of these groups over the years (and that's a problem in and of itself, ahem, token bloat). But, the best part is that roles and Active Directory groups can co-exist and even complement each other.
Roles, and especially dynamic roles, are invaluable. They exist outside of AD so they can be applied to enterprise authorization for any system, they can be applied to file share permissions, they can be applied to any flavor of LDAP directory or even databases. They can even determine who can do what to AD groups.
And here's the kicker, you can make a role equal an Active Directory group. So if you have one specific group that you know is updated (or if you manage that group dynamically) and you want to assign rights and permissions outside of the Microsoft ecosystem, make the membersip of that role an AD group in your RBAC powered metadirectory and you suddenly have an Active Directory group granting permissions everywhere!
This is especially useful if you have invested heavily in Active Directory group management in the past and want to leverage all of that hard work.
Contact us for a demonstration of how to make roles and AD groups live peacefully together.
EmpowerID is the all-in-one Identity Management and Cloud Security platform designed for people. Globally managing millions of identities in diverse enterprises, EmpowerID offers comprehensive provisioning, single sign-on and access governance coupled with an industry leading user experience.
Built on a single codebase for manageability and scalability, EmpowerID ships with a powerful API, a visual workflow designer and over 400 ready-to-use workflows for rapid deployment.