map

Attribute Based Access Control in Active Directory

In attribute-based access control, access to resources is based on the attributes of a user, not from the resource owner specifically granting access to that user.  The user proves their claim based on attributes associated with them rather than having joined a group and/or a role. Example of ABAC (Attribute based Access Control) A great…

map

Synchronizing Active Directory user attributes with an HR database

Nobody’s Active Directory is perfect.  And by “perfect” I mean with accurate identity information.  Users are an ever-changing group, they switch jobs, last names, phone numbers, cubicles, departments, and projects.  The users know this information but, guess what, IT doesn’t always. So Active Directory gets lonely and out of date.  Eventually, nobody’s identity information is…

map

Top uses for Active Directory groups

Active Directory literally sits in the middle of everything.  As the King of IT Infrastructure, it holds the ceremonial middle spot in any server rack.  Well, maybe I’m mis-using literally.  But figuratively? You bet it sits in the middle of everything. We have carved out a niche as THE software solution for managing Active Directory…

map

A better way to manage Active Directory or SharePoint group permissions

While reading Gartner’s research paper titled, “Identity in SharePoint 2010” by Kevin Kampman, I was struck by one particular phrase that is at the heart of the Active Directory or SharePoint group debate: “visibility is not provided into domain group memberships; SharePoint administrators cannot directly examine the members of an Active Directory group, although it…

map

Using Active Directory Groups for Cloud Identity Management

I recently watched a great video on cloud federation by Coreblox and Ping Identity.  You know the problem they’re trying to solve, your users are using applications in the cloud and your access and authorization solutions are stuck on premise.  Ping Identity solves that beautifully. Here’s the gist: an Active Directory user is added to…

map

Best Windows product: Imanami GroupID

They say a picture is worth a thousand words. So behold this novella: Imanami’s GroupID won the Best Windows Product award at the recent Windows Connections conference in Las Vegas. Our HQ lobby is filled with awards and plaques and other achievements but I find this one a little more satisfying than most. Why? Because…

map

The Best Way to Expire an Active Directory Group

In the world of Active Directory, groups are binary: they exist or they don’t.  Other Active Directory objects can be tombstoned, but with groups, they become useless once tombstoned since all of the ACLs and memberships are lost.  And Active Directory doesn’t give you the ability to expire and renew them while keeping all of…

map

Accurate Active Directory Group Membership with High Employee Turnover

The average organization has just under 20% annual internal turnover.  This means that 1 in 5 employees will change jobs per year.  At the same time, external turnover is approximately 5%, meaning 1 in 20 employees will leave the organization.  That, my friend, is a lot of change. But it is nothing compared to the…

map

Sweet 16! Imanami Selected As SINET 16 Innovator

Imanami has been chosen as a SINET 16 Innovator and asked to present at the annual SINET Showcase. Each year, a select group of technology companies that can improve efficiency and security at government agencies are asked to present and demonstrate their solutions. Imanami’s GroupID will help solve identity management security problems from group-based access control…