Tags: Single Sign-on (SSO), Role Based Access Control (RBAC), User provisioning
Cloud provisioning: user then access then SSO
Posted by
Edward Killeen on Thu, Aug 02, 2012
Emerging technologies are challenging old paradigms and unveiling new ways of approaching the security discipline that enables the right individuals to access the right resources at the right times for the right reasons.
EmpowerID has embedded innovative technologies in every aspect, providing flexible and mature IAM capabilities in the cloud, on premise and in hybrid environments, addressing the mission-critical need across increasingly heterogeneous technology environments, and meeting increasingly rigorous compliance requirements.
Talking to a client the other day about enterprise to cloud access, it became apparent that before considering cloud SSO, cloud provisioning needed to be taken care of. More than that, role based cloud provisioning.
And this is where it gets tricky in the IAM marketplace. There are a few companies offering cloud single sign on and doing it well. They just don't have the platform in place to integrate with the on premise world and do role based provisioning to the cloud as part of that solution.
And, think about your business goal here for a second. You want to make sure that the right users have the right access to the right applications. So, first you need to do role based provisioning; anyone in sales and support needs access to salesforce. Only those users should be provisioned; after moving to another department they should be deprovisioned. Data security is one thing to consider but so is license consumption...you pay monthly for these licenses.
Once you've provisioned the correct users to the cloud application (in this case salesforce), you need some role mapping. That sales rep should have different access than the sales manager than the support rep. Map your corporate roles to the cloud app role and not only do you get user accounts for the right folks but they get the right access. As they move jobs, the dynamic role in your enterprise directory maps to the cloud role and presto boomo, accurate access to cloud applications!
And, now for the thing that people worry about. Cloud single sign on...federating with the cloud application. This is arguably the least important step but the one that gets the most attention. Who cares if you only need one password if you have the wrong users getting access? Luckily, it's possible to do all three and leverage the same directory if you can do SAML federation from the directory that is handling the cloud provisioning and access.
There must be others doing all three aspects of this cloud provisioning, but if any of this rings true to you, schedule a demonstration of EmpowerID and see how to get the right users the right access to the right cloud resources, and SSO them while you're at it!
Tags: Single Sign-on (SSO), Role Based Access Control (RBAC), User provisioning
EmpowerID is the all-in-one Identity Management and Cloud Security platform designed for people. Globally managing millions of identities in diverse enterprises, EmpowerID offers comprehensive provisioning, single sign-on and access governance coupled with an industry leading user experience.
Built on a single codebase for manageability and scalability, EmpowerID ships with a powerful API, a visual workflow designer and over 400 ready-to-use workflows for rapid deployment.