Download presentation
Presentation is loading. Please wait.
Published byMelvin Rose Modified over 8 years ago
1
RBAC and certification with ID-Driven Hugh Simpson-Wells 2016 Redmond Summit | Identity Without Boundaries May 24 th 2016 CEO #OCGUS16 @OCGUSOfficial
2
A personal and incomplete look at ID-Driven – you can hear the rest of the story elsewhere! ID-Driven and MIM ID-Driven certification (attestation) for cloud Agenda
3
RBAC
4
RBAC and MIM
5
ID-Driven
6
MIM plus BHOLD - conceptually Active Directory HR SAP Another Dir
7
Management agent (MA)
8
MIM and BHOLD really Active Directory
9
Management agent (MA)
10
MIM and ID-Driven Active Directory HR SSO
11
MIM and ID-Driven Active Directory HR
12
Demo
13
Certification Users will make sure they get the permissions they need... but do not usually pester anyone to take them away again Few organizations have a formal access (role) management system The result is that many users have permissions they should not have
14
Certification/attestation Invoicing Bill Jane Order approval Susan Bert Jim Responses complete Campaign starts Authoritative for (e.g.) 6 months
15
Can be manual, but there are huge benefits in an automated, workflow-based approach An attestation/certification campaign must be low friction – easy to administer and use, and flexible – or people will not use it properly (note that it can be based on roles, permissions or accounts) A campaign Attestation/ Certification Campaign Applications Permissions Users Organizational Units Stewards Email Revoked Azure AD Group 1 User 1ApproveRevoke User 2ApproveRevoke Group 2 User 1ApproveRevoke User 3ApproveRevoke Application 1 Permission A User 2ApproveRevoke User 3ApproveRevoke Permission B User 1ApproveRevoke User 4ApproveRevoke Application 2 Reminder
16
Demo
17
Summary
Similar presentations
© 2025 SlidePlayer.com. Inc.
All rights reserved.